BlockchainCommons / BlockchainCommons/Community

Project: Document Best Practices for Secure Software Open Development

Abierto
#129 1 comentario 0 reacciones 0 asignados Ver en GitHub
good first issue intern project
Lenguaje dominante
Sin datos de lenguaje
Estrellas
68
Forks
7
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).

Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.

However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.

The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).

Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

No se nombran archivos ni pruebas. Empieza revisando las directrices de Linux Foundation y Google, las prácticas de los proyectos de seguridad, las prácticas de Blockchain Commons, las compilaciones reproducibles, los scripts de protección de ramas y la firma de Git. Se considera terminado cuando se documenten un análisis de amenazas y esfuerzo, recomendaciones prácticas para proyectos pequeños y ejemplos relevantes de herramientas o de uso.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
git, github-actions
Área
cli, devops, documentation, security
Tipo de issue
Documentación
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
25/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.