finos / finos/git-proxy

Check GitProxy's adherence to OSPS baseline and open issues for fixes

Open
#1,697 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
249
Forks
176
Avg merge
3d 8h
Merged PRs (30d)
20

Description

In #1665 we talked about using [OSPS (Open Source Project Securtiy) baseline](https://baseline.openssf.org/versions/2026-02-19) by OSSF to check GitProxy's adherence to security best practices. As more firms adopt the project, we should aim to cover all 3 levels:

> The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture. The controls are organized by maturity level and category. In the detailed subsections you will find the control, rationale, and details notes.
>
> Where possible, we have added control mappings to external frameworks. These are not guaranteed to be 100% matches, but instead serve as references to external elements that the Baseline maintainers believe relate to the Baseline control. This is not a functional connection, and does not imply that progress on one will necessarily result in progress on the other.

> [Level 1](https://baseline.openssf.org/versions/2026-02-19#level-1): for any code or non-code project with any number of maintainers or users
> [Level 2](https://baseline.openssf.org/versions/2026-02-19#level-2): for any code project that has at least 2 maintainers and a small number of consistent users
> [Level 3](https://baseline.openssf.org/versions/2026-02-19#level-3): for any code project that has a large number of consistent users

**Describe the solution you'd like**
We should check whether GitProxy complies with all the criteria, or make issues if there are any points that need to be improved.

Contributor guide

Open the contributing guide

Research direction

Start with the OSPS Baseline version linked in the issue and review its Level 1, Level 2, and Level 3 criteria against GitProxy. Record which controls GitProxy satisfies and open separate issues for each unmet improvement; the assessment and resulting issue set define done.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.