On 2021-02-12 at 15:20:07, Doggett, Thomas C. (GSFC-705.0)[TELOPHASE CORP] wrote: > Hello, > > My name is Thomas Doggett and I am a Supply Chain Risk Management Coordinator at NASA. As such, I ensure that all NASA acquisitions of Covered Articles comply with Section 208 of the Further Consolidated Appropriations Act, 2020, Public Law 116-94, enacted December 20, 2019. To do so, the Country of Origin (CoO) information must be obtained from the company that develops, produces, manufactures, or assembles the product(s). Specifically, identify the country where each of the following products were developed, manufactured, and assembled: > > Git GUI for Windows 2.30.0 You are referring to what is probably part of Git for Windows and should be addressed to the Git for Windows project at https://github.com/git-for-windows/git/. They provide the Windows binaries, since the Git project doesn't provide binaries of any sort. The vast majority of the code for Git GUI is shared between the two projects, though. > If the CoO is outside the United States, please provide any information you may have stating that testing is performed in the United States prior to supplying products to customers. Additionally, if available, please identify all authorized resellers of the product(s) in question. > > Lastly, as required by Section 889 of the Fiscal Year 2019 National Defense Authorization Act (NDAA) please > > 1.) advise if the product(s) in question is/are not manufactured by, contain components manufactured by or substantial influence from prohibited entities - Huawei, ZTE, Hytera, Hikvision, and Dahua and their subsidiaries and affiliates, and, > > 2.) advise if your organization has the covered telecommunications and/or video surveillance equipment or services as a substantial or essential component of any system, or as critical technology as part of any system within the organization. > > Product / Service Description: Git GUI for Windows 2.30.0 > Model Number (if applicable): 2.30.0 > Country (or Countries) of Origin: [[please provide your answer here]] > NDAA Section 889, Part A Compliant (Y, N, N/A) : [[please provide your answer here - (Y, N, N/A) ]] > NDAA Section 889, Part B Compliant (Y, N) : [[please provide your answer here - (Y, N) ]] > > Is final testing performed in the United States?: > > Recognizing that these questions don't fit open source software very well, will add that I've tried some workarounds - like your affiliation with the Software Freedom Conservancy, but their entry on SAM.gov is expired (current entries would have NDAA attestations on them). > > For these purposes, the country of origin of software is the country where the software was compiled and converted into object code. I will just say that since Git is open source software, it's a bit rude of you to ask us to do your compliance paperwork for you, since it's significant work with no other benefit you are not paying us for, and we're otherwise under no obligation to do so. Many contributors contribute to Git on their own time and equipment in order to benefit the community and aren't in need of additional paperwork. Since we provide open source software, if you need a version that is compiled or tested in a particular locale or a particular way, you are of course free to do so on your own systems at your own expense, or hire an appropriate party to do it for you, such as 18F[0]. Moreover, in many cases the code could have been compiled on an ephemeral cloud server in one of many locations, so the information you seek may not even be knowable. Major Linux distros such as Debian even compile packages for different architectures in different locations: amd64 packages are compiled in Austria, Greece, the United States, or Canada, but the ppc64el packages from the same source code might be in either the United States or Brazil, and different versions, including security updates, may be compiled on different systems in different countries. Git, and Git for Windows, have numerous contributors from all over the world, and we appreciate all of their contributions, regardless of their respective nationalities. We don't inquire about where people do their development work, since that information, given our respective projects and the context of open source software, is irrelevant and asking would be seen as invasive. As a result, that information is also probably unknowable. (For example, I don't recall which countries I, personally, have done Git development in, although I know the number is greater than one.) Before you head over to Git for Windows, I should also point out that the main Git for Windows maintainer, while residing out of the United States, is a colleague and a respected member of this community, and I very much value his contributions to this project and that one. Your questions, even if required by law, seem like they might come off as offensive or insensitive, and so I'd encourage you to be very careful treading here to avoid offense. In that vein, I would also advise you to read and understand the codes of conduct for Git and Git for Windows. So to get at least some of the information you seek here, you'd have to ask the Git for Windows project, but don't be surprised if the maintainers aren't delighted you came by. [0] https://18f.gsa.gov/ -- brian m. carlson (he/him or they/them) Houston, Texas, US
Attachment:
signature.asc
Description: PGP signature