asyncapi / asyncapi/.github

Adopt Core Infrastructure Initiative Best Practices

Open
#38 6 comments 2 reactions 0 assignees View on GitHub
enhancement keep-open
Dominant language
No language data
Stars
36
Forks
91
PR merge metrics
No merged PRs in 30d

Description

#### Reason/Context

All projects from the AsyncAPI Initiative are licensed as [Open Source Software](https://opensource.org/faq#osd), in particular [Apache 2.0](https://www.apache.org/licenses/LICENSE-2.0) license is used by default for new projects.

In an effort to offer high-quality software, not just in terms of code but also in terms of security, transparency, and accessibility, in alignment with our Vision **The AsyncAPI community grows 400%** stated [here](https://github.com/asyncapi/website/pull/189) we (may) want to adopt the [Linux Foundation Core Infrastructure Initiative Best Practices](https://bestpractices.coreinfrastructure.org/en/criteria/0). It also sounds ideal after our announcement made [here](https://www.asyncapi.com/blog/governance-motivation) about AsyncAPI joining a foundation.

Some context:

> The Linux Foundation (LF) Core Infrastructure Initiative (CII) Best Practices badge is a way for Free/Libre and Open Source Software (FLOSS) projects to show that they follow best practices.
> ...
> The Best Practices Program is an open source secure development maturity model. Projects having a CII badge will showcase the project’s commitment to security.
> ...
> Examples of initial criteria include basic open source development practices (website, open source license, and user engagement), use of change control tools, attention to quality (automated test suite), and focus on security (secure project delivery method, use of dynamic and static analysis tools, as appropriate for the project).

There are different badges for the different criteria levels a project can achieve. Ordered from the most permissive to the most restrictive:

- [Passing](https://bestpractices.coreinfrastructure.org/en/criteria/0): focuses on best practices that well-run FLOSS projects typically already follow.
- [Silver](https://bestpractices.coreinfrastructure.org/en/criteria/1): is a more stringent set of criteria than passing but is expected to be achievable by small and single-organization projects.
- [Gold](https://bestpractices.coreinfrastructure.org/en/criteria/2): is even more stringent than silver and includes criteria that are not achievable by small or single-organization projects.

#### Description

Even though we may want to achieve the **Gold** level, **Passing** and **Silver** criteria levels should be previously achieved.
That's perfect for splitting this task into smaller actionables so we can adopt each level iteratively.

At least one GH issue should be created per level so we can properly track progress isolated. We can list them right here:

- **Passing** level issue: TBD
- **Silver** level issue: TBD
- **Gold** level issue: TBD

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the linked Linux Foundation Core Infrastructure Initiative criteria and the AsyncAPI governance context referenced in the issue. No source files, tests, or entry points are named; the work is complete only when separate, agreed issues track the Passing, Silver, and Gold levels.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.