Academy Software Foundation Technical Advisory Council (TAC) Meeting - August 19, 2026

Join the meeting at https://zoom-lfx.platform.linuxfoundation.org/meetings/aswf?view=list&projects=aswf

Voting Representative Attendees

Premier Member Representatives

  • Alejandro Arango - Epic Games, Inc
  • Andy Jones - Netflix, Inc.
  • Chris Hall - Advanced Micro Devices (AMD)
  • Christopher Moore - Skydance Animation, LLC
  • Eric Enderton - NVIDIA Corporation
  • Gordon Bradley - Autodesk
  • Greg Denton - Microsoft Corporation
  • Jonathan Gerber - LAIKA, LLC
  • Kimball Thurston - Wētā FX Limited
  • Larry Gritz - Sony Pictures Imageworks
  • Mark Wiebe - Amazon Web Services, Inc.
  • Matthew Low - DreamWorks Animation
  • Michael Min - Adobe Inc.
  • Michael B. Johnson - Apple Inc.
  • Rebecca Bever - Walt Disney Animation Studios
  • Scott Dyer - Academy of Motion Picture Arts and Sciences
  • Sean Mcduffee - Intel Corporation
  • Youngkwon Lim - Samsung Electronics Co. Ltd.

Project Representatives

  • Carol Payne - OpenColorIO Representative
  • Cary Phillips - OpenEXR Representative
  • Chris Kulla - Open Shading Language Representative
  • Daniel Greenstein - OpenImageIO Representative
  • Diego Tavares Da Silva - OpenCue Representative
  • Jonathan Stone - MaterialX Representative
  • Karen Ruggles - Diversity & Inclusion Working Group Representative
  • Ken Museth - OpenVDB Representative
  • Nick Porcino - Universal Scene Description Working Group Representative

Industry Representatives

  • Jean-Francois Panisset - Visual Effects Society

Non-Voting Attendees

Non-Voting Project and Working Group Representatives

  • Alexander Schwank - Universal Scene Description Working Group Representative
  • Anton Dukhovnikov - rawtoaces Representative
  • Daryll Strauss - Zero Trust Working Group Representative
  • Eric Reinecke - OpenTimelineIO Representative
  • Erik Strauss - Open Review Initiative Representative
  • Gary Oberbrunner - OpenFX Representative
  • Jean-Christophe Morin - Rez Representative
  • John Mccarten - Rongotai Model Train Club (RMTC) Representative
  • Jon Lanz - MoonRay Representative
  • Josh Bainbridge - OpenQMC Representative
  • Philip Grobler - OpenAssetIO Representative
  • Sebastian Herholz - Open Path Guiding Library (OpenPGL) Representative
  • Stephen Mackenzie - Rez Representative
  • Tommy Burnette - Dailies Notes Assistant Representative

LF Staff

  • David Morin - Individual - No Account
  • Emily Olin - Academy Software Foundation
  • John Mertic - The Linux Foundation
  • Yarille Ortiz - The Linux Foundation

Other Attendees

  • Lindah Lovell
  • JT Nelson - Pasadena Open Source consortium / SoCal Blender group
  • Lee Kerley - Apple
  • Olga Avramenko - Imageworks / DNA
  • Doug Walker - Autodesk / OCIO
  • Jonathan Swartz - NVIDIA /OpenVDB
  • Andrew Pearce
  • Bill Ballew - Dreamworks
  • Gaspard

Meeting Assets

Antitrust Policy Notice

Linux Foundation meetings involve participation by industry competitors, and it is the intention of the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws.

Examples of types of actions that are prohibited at Linux Foundation meetings and in connection with Linux Foundation activities are described in the Linux Foundation Antitrust Policy available at linuxfoundation.org/antitrust-policy. If you have questions about these matters, please contact your company counsel, or if you are a member of the Linux Foundation, feel free to contact Andrew Updegrove of the firm of Gesmer Updegrove LLP, which provides legal counsel to the Linux Foundation.

Agenda

  • General Updates
    • AGENDA TOPIC: GitHub Security Manager role #1434
    • Dev Days 2026 - Sept 17th #1446
  • Add Guide #1105
  • Annual Review: OpenImageIO #509

Notes

  • General Updates
    • AGENDA TOPIC: GitHub Security Manager role #1434
    • Dev Days 2026 - Sept 17th #1446
      • Olga: coming up on Sept 17. If all the projects can groom their issues, assign a point person, put something in their chat, let people at their company no. 2 inperson events, Vancouver and LA. Please plan to attend, a great opportunity, the previous ones went great.
      • Dev Days org team is now 5 volunteers, should help with the organization. Please reach out if you have any questions.
      • Carol: it is an expectation that all projects participate in DevDays, have their “Good First Issues” in order and their getting started documentation. Each project is in different spots, but baseline expectations of having these requirements available on the day.
      • Carol: will have more as we get closer. If you have feedback on how to make this better for projects and companies, let us know.
  • Add Guide #1105
    • John: took a first past at structuring the Landscape guide with Claude, but could use a review. Did Claude get the structure really off?
    • Longer term could use help to make sure the structure is correct. I could really use the help.
    • Carol: at base level, everyone should look at the link, even if you don’t want to volunteer the time.
    • JF: feedback about new projects, or projects that are no longer in use in the industry would be useful. John: for instance if GitHub repo is gone.
    • John: for now reviewing the guide itself is the ask.
    • Carol: best way to give feedback? Note on the issue? John: yes, best on the PR
    • Landscape Overlay
  • Virtual Town Halls
  • Annual Review: OpenImageIO #509
    • Danny Greenstein, TSC Chair
    • Presentation Slides
    • Toolset and library to deal with images. Handles different image formats, a cornerstone of image manipulation in VFX and Animation.
    • Danny is TSC Chair, Larry is architect / original author.
    • TSC has members from different studios and industries. Had a few TSC members drop off this year for various reasons, so if anyone wants to get involved, we would welcome. Many studios rely on OIIO. We meet every 2 weeks, the regulars who meet at very helpful, looking to strengthen the core group. Participation can mean several things, for instance feedback on how you using OIIO in your workflows. Also code reviews, code contributions…
    • OIIO doesn’t directly manipulate OpenEXR images, it uses the OpenEXR library.
    • CLI tools: oiiotool, maketx, also Python bindings. Texture system is often used inside renderers.
    • Central project started by Larry in 2008.
    • A dependency of other ASWF projects: OSL and many others. We depend on OpenEXR, OCIO. “Sits in the middle”, embedded in many DCCs: Houdini, Katana. Used in pretty much every pipeline.
    • 2025: transition from Incubation to Accepted, now have TAC voting rights.
    • 450 git commits by 50 unique contributors (up from 41 last year), although we shifted annual review by 2 months. So mostly flat / a small increase.
    • OpenImageIO 3.1 release (oct 2025)
    • Release branch patches on 1st of every month
    • Dev Days
      • Sept 2025: merged 6 PRs
      • May 2026: merged 8 PRs
      • We see repeat external contributors contribute during Dev Days
    • OpenSSF Security: maintained 100% passing, 95% silver, 78% cold compliance
    • Contributor list: a handful of consistent participants from year to year, and a core group of consistent contributors, with of course Larry. But some big and meaningful chunks from others.
    • Vulnerapocalypse of 2026
      • Since last VTH, 31 externally reported vulnerabilities
        • 19 issues since start of July
        • 23 issues CVEs, 1 pending
          • CVE request mechanism from GitHub is mostly broken, used to be 3 day turnaround
        • Plus discovered via fuzzing + coding tool audits
      • Added our own fuzzer to help catch before reports
      • Since mid-June: 81 security /input hardening patches
      • Average > 10/week, including SIGGRAPH and LG’s vacation
      • Why? LLM coding assistants (but also part of the solution)
        • Coding assistants making those fixes much faster
    • Roadmap : 3.2 release September
      • New dependency minimums
        • fmt 8->9, libRaw 0.20->0.21, cmake 3.18.2 -> 3.23.0, libjpeg 8->9, libtiff 4.0->4.1
        • Deprecates old icc compiler
      • Safety
      • Python bindings: switch to Nanobind (Aleksandr Mot…)
      • FLIP image comparison (ImageBufAlgo, oiiotool -flip_diff)
      • oiiotool can get/set thumbnails for several formats
      • Color Management
        • Follow Color Interop Forum guidelines
        • CICP and ICC support added to JPEG-XL
        • More coming!
      • Experimental: hwy-enabled SIMD IBA speeds
      • In progress/maybe: KTX2 texture support
    • AI/ML Code Generation
      • LLM Coding assistants are permitted, with rules
        • Humans must always be in the loop, and is the responsible party
        • No “vibe coding”: all code must be fully understood and reviewed
        • Interact with the project and community yourself, not by agent
        • Disclose tools used: Assisted-by: TOOL / MODEL
        • Don’t waste maintainer’s time with low quality PRs
        • Don’t stomp on Dev Days or Good First Issues
      • Status
        • Substantial portion of PRs have some coding tool assistance
        • PR quality is as high as ever - no slop detected
        • No noted increase in PRs (other than responding to security vulns)
        • Vuln reports are 50x the prior background rate, but so far all have been legit
          • It has been exhausting, but the code base is more robust for it
        • This is in contrast to many other projects (outside of ASWF) who are completely overwhelmed - we are lucky
    • Areas the project could use help on
      • Help Wanted!
      • S-Size:
        • support issues, dependency wrangling, CI, security, releasing, Windows
      • M-Size:
        • need more TSC members and involvement
        • Color management (in progress - Zach Lewis leading it)
        • Metadata strategy cleanup (watch this space)
        • Overhauls needed for DSLR raw, HEIC, video/ffmpeg
      • L-Size:
    • Feedback on working with ASWF
      • WG-CI and its work are indispensable
      • Thanks for the infrastructure: meetings, calendars, TSCs, …
      • Great collaboration / synergy with other projects: OCIO, CIF, OpenEXR, OSL, MaterialX, WG-CI and others
      • Builds awareness around the essential work…
    • TAC Open Discussion
      • Eric: how many of the security issues ended up being upstream in dependencies? Larry: none, we made our guidelines clear, people generating those reports are pretty good at triaging where to report these. They were all legit, some are related with how we interact with the dependency, like not checking a return code correctly, but the fault was ours. A small blessing if we had to triage reports that belong to dependencies.
      • Larry: this is used in most of your products and studio pipelines, but we only have a handful of people on the TSC. Please participate if you can. The project looks like it’s solid, but sometimes it’s a struggle to hold it together.
      • Carol: good to hear the positive feedback, and thanks for all the work, it’s a big project. It’s also been fun to collaborate in the Color Interop Forum.
      • Cary: curious if you are experience that security advisories have trailed off as for OpenEXR? Larry: yes, the arrival has trailed off. Not sure why, we’ve fixed a lof of the low hanging fruit, and have introduced the fuzzer, so we found a lot as well. Also people looking for those may have switched their attention. No new ones are coming in rapidly, working through “burn down” list, patches in review, or PRs not submitted yet, but list is getting shorter. Hope to have queue emptied out by the time we do 3.2 release.
      • Cary: I’m hopeful the worst is pass for us. Larry: until the next model is released!
      • JF: I often tell projects asking for CI inspiration to look at OIIO and OpenEXR
      • Larry: happy to share advice on the fuzzing infrastructure we put in place. I feel there’s a core group of projects: OIIO, OCIO, OpenEXR, MaterialX, OSL that are very “tight”, they have shared TSC members, code / infrastructure ideas diffuse into the other projects fairly quickly. In ASWF as a whole, there are other projects that are not as well connected to this “core”, those projects could benefit from cross pollination. A good idea quickly spreads between the “core group” projects.
      • Doug Walker (chat): OCIO learns a lot from looking at OIIO and OpenEXR.
      • Carol: TAC is supposed to be where this happens, but TAC is big, and we don’t necessarily have the time to do that.
  • GitHub Security Manager role #1434
    • Cary: Would like to clean up the way access is granted to GitHub security advisories. Currently (for OpenEXR) access is granted to repo admins, for OpenEXR there is another group called “AcademySoftwareFoundation” which also gets access, but membership in that group seems a bit random. The proper way to do this is through the GitHub Security Manager role: certain individuals are designated as Security Managers, and gives them access to advisories. Role is designated at Org level. Would have access to all advisories across all projects. You want to be cautious, but seems positive. We should start using this, identify individuals such as project leads. But would also like to designate Kimbal and Peter. They would have access to advisories to other projects, I think that would be a good strategy to share security across projects. Would like to talk about it. Would anyone disagree with having people from other projects have access to your security advisories.
    • Eric: when we add a project, we add new people who have access to all security advisories? These may be people we know or not? Cary: we don’t have to add all project leads as Security Manager, so for instance a new project doesn’t necessarily become a Security Manager. Carol: sandbox projects may not have many security advisories, maybe incubated / graduated projects get added? There may be people in sandbox stage which could justify it.
    • Carol: we would have to have the discussion for projects coming in at incubation level. Cary: consistent with my general thought, a good thing to have a subcommittee within the foundation which is “security attentive people”, talk about security issues and best practices. We could use the Security Manager role to designate who is in that role. Carol: I like that idea. We often do want to share security issues between projects, want to give them a heads up. Cary: I have an open ticket with LF helpdesk to proceed setting up this role.
    • JF: may want to clarify is that’s at the “GitHub Enterprise” level, or at the GitHub namespace level.
    • Larry: being careful of who we give access to, I think it’s good to give leads of the “big” projects insight on advisories against other projects. For me seeing both OIIO and OSL has been helpful.
    • Cary: I will keep making progress on this.
    • Eric (chat): I generally like this idea - agree it should be a specifically curated list of people and probably not automatically fold in project leads.
    • Matthew (chat): There does seem to be enterprise-level security oversight

Next Meeting Agenda

  • General Updates
    • Vulnerapocalypse #1403
    • 2026 Security Reviews #1137
  • Annual Review: rawtoaces #475
  • Annual Review: Dailies Notes Assistant (DNA) #1040
  • Revamp Annual Review Structure/Template #1336
  • AGENDA TOPIC ASWF Project Health & Resource Framework #1377
  • 2026 TAC Priorities #1208
  • CRA Compliance #1442