Does it then apply to the oss projects that the steward
is using/depending upon to provide that build server
(eg. compilers, encryption, dependency mgmt systems,
etc)?
No, this focuses strictly on severe incidents affecting
infrastructure provided to stewarded projects. Not CVEs in
the infrastructure's components.
Huh? The log4j vulnerability (e.g.) was a severe incident that
affected much sw infrastructure...provided to projects of many
kinds, build systems, etc...as well as many other kinds of
components (open source and commercial). I don't see how you can
you separate 'infrastructure provided to stewarded projects' from
'infrastructure' in general.
No. log4j was a vulnerability, not an incident. An incident is when a vulnerability is actually exploited, or some other event occurs, resulting in a compromise or material disruption of the infrastructure. So in the log4j case, a steward would have notification requirements for a vulnerability if they were the steward of log4j AND were actively involved in its development. They would have a notification requirement of a severe incident if running an unpatched version of log4j caused a build server they provided to a project to be compromised.