loopbackio / loopbackio/security

Track potential adoption of OpenSSF Project Security Information Specification

Open
#24 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
4
Forks
1
PR merge metrics
No merged PRs in 30d

Description

The OpenSSF Project Security Information Specification "provides a mechanism for projects to report information about their security in a machine-processable way."

This specification is currently a draft. Hence, we should wait and see how it progresses. This issue is to keep track of this OpenSSF initiative.

see: https://github.com/ossf/wg-identifying-security-threats
see: https://github.com/ossf/wg-identifying-security-threats/issues/19
see: https://docs.google.com/document/d/1Hqks2J0wVqS_YFUQeIyjkLneLfo3_9A-pbU-7DZpGwM/edit

#TODO: Difference between this and OSSF Security Insights 1.0 specification

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the OpenSSF Project Security Information Specification, the linked working-group issue 19, and the referenced Security Insights issue 37. Compare the two specifications and record whether this project should adopt the OpenSSF initiative once its draft stabilizes; the issue currently names no files or tests.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.