GNU bug report logs - #51976
Inquiry: gzip for NASA Use

Previous Next

Package: gzip;

Reported by: "Zhang, Cynthia X. (GSFC-705.0)[TELOPHASE CORP]" <cynthia.x.zhang <at> nasa.gov>

Date: Fri, 19 Nov 2021 19:10:01 UTC

Severity: normal

Done: Paul Eggert <eggert <at> cs.ucla.edu>

Bug is archived. No further changes may be made.

Full log


Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):

From: "Zhang, Cynthia X. (GSFC-705.0)[TELOPHASE CORP]"
 <cynthia.x.zhang <at> nasa.gov>
To: "bug-gzip <at> gnu.org" <bug-gzip <at> gnu.org>
Subject: Inquiry: gzip for NASA Use
Date: Fri, 19 Nov 2021 19:04:40 +0000
[Message part 1 (text/plain, inline)]
Hello, my name is Cynthia and I am a Supply Chain Risk Management Analyst at NASA. NASA is currently conducting a supply chain assessment of gzip. As stated by Sections 208 and 514 of the Consolidated Appropriations Act, 2021, Public Law 116-260, enacted December 27, 2020, a required step of our process is to verify the Country of Origin (CoO) information for the product, aka the country where the products were developed, manufactured, and assembled. As gzip is open source, we understand that this inquiry is not directly applicable, as contributions may be made from individuals from around the world. In this case, NASA is interested in confirming whether there is an organization which sponsors/publishes the project, or a primary developer who audits the code for potential vulnerabilities, errors, or malicious code. Does gzip have overseeing organization or individual along these lines? If so, please provide the country they are established in so we can provide as much insight as possible following our federal mandate.

Thank you,
Cynthia

[Message part 2 (text/html, inline)]

This bug report was last modified 3 years and 186 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.