OpenAssetIO / OpenAssetIO/OpenAssetIO
Set up a project security policy
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 348
- Forks
- 47
- PR merge metrics
- No merged PRs in 30d
Description
Copy SECURITY.md from OpenEXR or one of the other ASWF projects, and delete whatever doesn't apply to your project. This cover several of the OpenSSF badge requirements, like the policy, vulnerability reporting, and expectations.
Other related steps to take:
- Set up security@openassetio.org that forwards to your technical steering committee. The LF can help configure this.
- On the "Code security & analysis" page of your GitHub repo settings, enable private vulnerability reporting.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing SECURITY.md from OpenEXR or another ASWF project and compare it with this project's needs. Confirm the policy, vulnerability-reporting process, and expectations are adapted, then coordinate setup of security@openassetio.org and enable private vulnerability reporting under the repository's Code security & analysis settings. Done means the policy is committed and both reporting paths are configured.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100