OpenAssetIO / OpenAssetIO/OpenAssetIO

Set up a project security policy

Open
#1,412 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
348
Forks
47
PR merge metrics
No merged PRs in 30d

Description

Copy SECURITY.md from OpenEXR or one of the other ASWF projects, and delete whatever doesn't apply to your project. This cover several of the OpenSSF badge requirements, like the policy, vulnerability reporting, and expectations.

Other related steps to take:

  1. Set up security@openassetio.org that forwards to your technical steering committee. The LF can help configure this.
  2. On the "Code security & analysis" page of your GitHub repo settings, enable private vulnerability reporting.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing SECURITY.md from OpenEXR or another ASWF project and compare it with this project's needs. Confirm the policy, vulnerability-reporting process, and expectations are adapted, then coordinate setup of security@openassetio.org and enable private vulnerability reporting under the repository's Code security & analysis settings. Done means the policy is committed and both reporting paths are configured.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.