BlockchainCommons / BlockchainCommons/Community

Project: Document Best Practices for Secure Software Open Development

Đang mở
#129 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
good first issue intern project
Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
68
Fork
7
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).

Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.

However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.

The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).

Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Không có tệp hoặc bài kiểm thử nào được nêu tên. Hãy bắt đầu bằng cách khảo sát hướng dẫn của Linux Foundation và Google, các thực hành của các dự án bảo mật, các thực hành của Blockchain Commons, các bản build có thể tái lập, các script bảo vệ branch và việc ký Git. Hoàn thành nghĩa là ghi lại một phân tích về mối đe dọa và công sức, các khuyến nghị thực tế cho những dự án nhỏ, cùng các ví dụ liên quan về công cụ hoặc cách sử dụng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
git, github-actions
Lĩnh vực
cli, devops, documentation, security
Loại issue
Tài liệu
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.