[LTP] Inquiry: Country of Origin for LCOV Version 1.x

Peter Oberparleiter oberpar@linux.ibm.com
Fri Jul 8 15:35:38 CEST 2022


Hi,

please find my reply to your questions regarding LCOV below.

>> Hello, my name is Cynthia and I am a Supply Chain Risk Management
>> Analyst at NASA. NASA is currently conducting a supply chain
>> assessment of LCOV Version 1.x.  As stated in Sections 208 and 514 of
>> the Consolidated Appropriations Act, 2022, Public Law 117-103, enacted
>> March 15, 2022, a required step of our process is to verify the
>> Country of Origin (CoO) information for the product (i.e., the country
>> where the products were developed, manufactured, and assembled.) As
>> LCOV Version 1.x is open source, we understand that this inquiry is
>> not directly applicable, as contributions may be made from individuals
>> from around the world. In this case, NASA is interested in confirming
>> the following information:
>>
>>   1.  Is there an organization which sponsors/publishes the project,
>>       or a primary developer who audits the code for potential
>>       vulnerabilities, errors, or malicious code? Y/N
>>
>>   2.  Does LCOV Version 1.x have an overseeing organization or
>>       individual along these lines? Y/N

IBM is the main sponsor of work on the upstream LCOV repository [1], and
I'm working as maintainer of the LCOV code base. In this role I review
code contributions from other developers for apparent errors, and
alignment with LCOV’s project goals [2] and coding style before inclusion.

However there is no formal procedure established to audit the code
specifically for potential vulnerabilities or malicious code. Therefore
the answer to these two questions is no.

>>   1.  If so, please provide the name of the organization and country
>>   they are established in.  If the information above is unknown or
>>   cannot be provided, we request that you provide the country or list
>>   of countries where the majority of contributions originate from to
>>   satisfy Sections 208 and 514 of the Consolidated Appropriations Act,
>>   2022, Public Law 117-103, enacted March 15, 2022.

At the time of writing (July 2022), the majority (>90%) of code as
measured in lines of code in the LCOV repository was developed by myself
on behalf of “IBM Deutschland Research & Development GmbH” which is a
German subsidiary of the US-based IBM Corporation.

Furthermore the LCOV git repository [1] contains a record of all
contributions, including the e-mail address of each contributor, but no
attribution to countries of origin.


Regards,
  Peter

[1] https://github.com/linux-test-project/lcov
[2] https://github.com/linux-test-project/lcov/blob/v1.16/CONTRIBUTING#L51

-- 
Peter Oberparleiter
Linux on IBM Z Development
IBM Deutschland Research & Development GmbH

Vorsitzender des Aufsichtsrats: Gregor Pillen
Geschäftsführung: David Faller
Sitz der Gesellschaft: Böblingen
Registergericht: Amtsgericht Stuttgart, HRB 243294	


More information about the ltp mailing list