Skip to content

Security - Review against OpenSSF Open Source Project Security Baseline #55

@matglas

Description

@matglas

I highly recommend reviewing the project against the OpenSSF Security Baseline (https://baseline.openssf.org/). It is the recommend starting point for open source projects to establish a foundation for securely developing open source projects. As part of maturing this project into something solid it would be very important.

The baseline project maintains three levels depending on the maturity of the project that is evaluated. Here are the levels.

Level 1: for any code or non-code project with any number of maintainers or users
Level 2: for any code project that has at least 2 maintainers and a small number of consistent users
Level 3: for any code project that has a large number of consistent users

When we do this and action on it we should be able to communicate more easily on the posture of our security practices.
Besides this baseline there is the scorecard.dev project by OpenSSF that complements it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions