BlockchainCommons / BlockchainCommons/Community

Project: Document Best Practices for Secure Software Open Development

Ouverte
#129 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
good first issue intern project
Langage dominant
Aucune donnée de langage
Étoiles
68
Forks
7
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).

Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.

However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.

The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).

Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Aucun fichier ni test n’est nommé. Commencez par examiner les recommandations de Linux Foundation et de Google, les pratiques des projets de sécurité, les pratiques de Blockchain Commons, les builds reproductibles, les scripts de protection des branches et la signature Git. Le travail est considéré comme terminé lorsque sont documentés une analyse des menaces et de l’effort, des recommandations pratiques pour les petits projets, ainsi que des exemples pertinents d’outillage ou d’utilisation.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
git, github-actions
Domaine
cli, devops, documentation, security
Type d'issue
Documentation
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.