BlockchainCommons / BlockchainCommons/Community
Project: Document Best Practices for Secure Software Open Development
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 68
- Forks
- 7
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).
Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.
However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.
The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).
Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel
Guía de contribución
Línea de trabajo
No se nombran archivos ni pruebas. Empieza revisando las directrices de Linux Foundation y Google, las prácticas de los proyectos de seguridad, las prácticas de Blockchain Commons, las compilaciones reproducibles, los scripts de protección de ramas y la firma de Git. Se considera terminado cuando se documenten un análisis de amenazas y esfuerzo, recomendaciones prácticas para proyectos pequeños y ejemplos relevantes de herramientas o de uso.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- git, github-actions
- Área
- cli, devops, documentation, security
- Tipo de issue
- Documentación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Estancado
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 25/100