[New Process Improvement Need]: Third-Party Software Vetting
Open
Nobody has claimed this yet.
governance
low complexity
more requested
- Dominant language
- JavaScript
- Stars
- 36
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
Checked for duplicates
Yes - I've already checked
Category
Security - application, network, hardware, etc. security topics
Describe the need
We have a need for a more defined process for vetting and managing 3rd-party software installed in development and deployment environments. (+1'd by mcduffie)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Review the repository's existing governance and lifecycle materials first, then define what a complete process for vetting and managing third-party software in development and deployment environments should cover.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100