BlockchainCommons / BlockchainCommons/Community

Project: Document Best Practices for Secure Software Open Development

Aperta
#129 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
good first issue intern project
Lingua principale
Nessun dato sulla lingua
Stelle
68
Fork
7
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).

Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.

However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.

The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).

Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Non vengono indicati file o test. Inizia esaminando le linee guida di Linux Foundation e Google, le pratiche dei progetti di sicurezza, le pratiche di Blockchain Commons, le build riproducibili, gli script per la protezione dei branch e la firma Git. Il lavoro è completato quando sono documentati un’analisi delle minacce e dell’impegno richiesto, raccomandazioni pratiche per i progetti piccoli ed esempi pertinenti di strumenti o di utilizzo.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
git, github-actions
Ambito
cli, devops, documentation, security
Tipo di issue
Documentazione
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.