BlockchainCommons / BlockchainCommons/Community

Project: Document Best Practices for Secure Software Open Development

Offen
#129 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
good first issue intern project
Vorherrschende Sprache
Keine Sprachdaten
Sterne
68
Forks
7
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).

Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.

However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.

The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).

Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Es werden keine Dateien oder Tests genannt. Beginnen Sie mit einer Untersuchung der Leitfäden der Linux Foundation und von Google, der Praktiken von Sicherheitsprojekten, der Praktiken von Blockchain Commons, reproduzierbaren Builds, Skripten zum Schutz von Branches und der Git-Signierung. Als erledigt gilt die Dokumentation einer Bedrohungs- und Aufwandsanalyse, praktischer Empfehlungen für kleine Projekte sowie relevanter Tooling- oder Nutzungsbeispiele.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git, github-actions
Bereich
cli, devops, documentation, security
Issue-Typ
Dokumentation
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.