2026-08-12 TSC Minutes

2026-08-12 TSC Minutes

 

 

Representatives & Attendees

Quick Links: TSC Mailing List | Meeting Recordings

TSC Members

Company

TSC Members

Company

TSC Members may indicate their attendance by changing the cell background for their name to green.

@Sana Tariq

TELUS, Canada

@Ciaran Johnston (Ericsson)

Ericsson

@balaji varadaraju

Red Hat

@Timo Perala (Nokia)

Nokia

@Hsiu-Chi “蔡秀吉”

National Yang Ming Chiao Tung University (NYCU)

@Raj Panchapakesan

AccuKnox Inc

@Girish Kumar

Infosys

Community members may @ tag themselves below to show their attendance.

@Liam Fallon


You can add action items anywhere in the minutes by typing “/action” and pressing enter

Action Items:

 

LF Staff:

Agenda

The project's Antitrust Policy, which you can find linked from the LF and project websites. The policy is important where multiple companies, including potential industry competitors, are participating in meetings. Please review and if you have any questions, please contact your company legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.

Key Updates

  • Potential LFN developer event during the LFN Japan ONE Summit - need to determine if there is interest from the Nephio community to participate

    • @Ciaran Johnston (Ericsson) to discuss options with @Casey Cain

    • Will we submit a proposal from the Nephio community?

    • 2026-08-12: @Hsiu-Chi “蔡秀吉” will likely participate

    • Next developer face-to-face

      • Potential cross-community collaboration with https://www.stratoweave.org/

      • @Casey Cain to trigger an introductory email with the StratoWeave community

      • Potential paper for Japan summit?

  • Discuss on “coding agent contribution readiness”

    • @Liam Fallon has agreed to look at this from SIG Auto perspective

    • 2026-06-17: no update yet, this was discussed with @Liam Fallon recently – would be good to get concluded before end of June

    • 2026-07-15: we will adapt the kpt variant in porch, and propose an approach for the rest of the Nephio repos after that

    • 2026-08-12: @Liam Fallon on leave, will revert on his return

  • Need to document a vulnerability reporting process. It then needs to be documented.

    • 2026-06-17: no progress

  • @Hsiu-Chi “蔡秀吉” About the TSC meeting at 2026-06-03 TSC Minutes . As a volunteer on the vulnerability-reporting item, I've drafted a lightweight Nephio Security Response process — GitHub Private Vulnerability Reporting alongside sig-security@, a small rotating Security Response Committee with a 3-working-day triage SLA, an embargo/coordinated-disclosure policy with a zero-day fast-path, and CVEs issued via GitHub Security Advisories — and I've already privately identified and runtime-validated several security issues in main that we can run as the first real cases through it; I'll share the draft with Casey and Ciaran for their recommendation.

    • 2026-08-12: @Hsiu-Chi “蔡秀吉” : I've drafted the security-response process and sent it to Casey and Ciaran today. I'm asking that we stand up a small private intake now a draft advisory per issue plus a 2–3 person interim groupso the issues already noted on 15 July can be handled under embargo. I'd welcome a couple of volunteers!!!

    • Actions:

      • identify a security team

        • Team identified as @balaji varadaraju , @Ciaran Johnston (Ericsson) , @Timo Perala (Nokia) , @Hsiu-Chi “蔡秀吉”

        • Need to identify someone from SIG Auto on this as well

      • remove non-members of the security team from sig-security@ (or create a new “security-reporting@” email list)

        • @Casey Cain to create a private list in some way - same way as FD.io

      • Use some of the identified security issues as pipecleaners for the process of reporting

        • @Hsiu-Chi “蔡秀吉” to send an issue to the above list

  • @Liam Fallon to add @Hsiu-Chi “蔡秀吉” as a reviewer if necessary to make the upstream commits to fix the vulnerabilities

Ideas for the next developer face-to-face event
Companies begin 2027 budget planning within the next one to two months, and most budgets are finalized between September and November. For the TAC to bring a proposal to the Governing Board early enough for board members to take it back to their own budget teams, we need ideas from the communities now.

Travel budgets are tight, and "it would be good to attend" is no longer enough to get people approved. We would like each community to identify a concrete outcome that requires being in the same room. Starting points from the TAC discussion:

  • Structured contributor training for upstream work

  • Hands-on labs with a defined deliverable at the end

  • On-site certification

  • Architecture or design working sessions on problems that are slow to resolve over email and video calls

Worth covering in your discussion: what your community would produce during the event, who needs to be there for that to work, and where it lands relative to your release cycle.

@Ciaran Johnston (Ericsson) : the proposal for Nephio restructuring is the major body of work required to make Nephio reusable in a broader organization before considering other topics for a F2F

A named contact for AI discoverability and agentic consumption

Roughly 60 percent of traffic to LFN web properties now comes from LLM scrapers. Developers increasingly hand an abstract task to a coding agent and let the agent choose the technology, which means coding agents are now part of the audience for our projects. Most LFN projects are components inside a larger system, so the practical risk is that agents assemble solutions without selecting our projects at all.

The TAC is asking each project to name a contact person to lead this work for your community. The TSC chair is the default if the community does not nominate someone else. This is ongoing work rather than a one-time task, so pick someone who can stay with it.

The mechanisms already exist, including AGENTS.md, MCP servers, A2A, and answer engine optimization on project sites. There is no single approach that fits every project, so each community will need to decide what suits its technology and do the work to apply it.

Two tests you can run on your own project in the meantime:

  • Ask an LLM for an overview of your project and see how much depth comes back beyond a few surface bullets.

  • Describe a generic problem in your domain without naming LFN or your project, ask for a detailed system design, and see whether your project gets selected.

Please reply to lfn-tac@lists.lfnetworking.org by August 18 with your community's ideas on the event and the name of your AI contact. Both will be on the agenda at the next TAC meeting.

Happy to answer questions or join your TSC meeting if it would help to talk it through.

@Ciaran Johnston (Ericsson) as default AI representative and we will discuss in more detail on next TSC call what we want to achieve from AI use of community assets

SIG Status

Network Architecture

Automation

  •  

Release

  • .

Security

  • .

Other Updates

  • .

Action Items Review

Minutes