loopbackio / loopbackio/security
Track potential adoption of OpenSSF Project Security Information Specification
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
The OpenSSF Project Security Information Specification "provides a mechanism for projects to report information about their security in a machine-processable way."
This specification is currently a draft. Hence, we should wait and see how it progresses. This issue is to keep track of this OpenSSF initiative.
see: https://github.com/ossf/wg-identifying-security-threats
see: https://github.com/ossf/wg-identifying-security-threats/issues/19
see: https://docs.google.com/document/d/1Hqks2J0wVqS_YFUQeIyjkLneLfo3_9A-pbU-7DZpGwM/edit
#TODO: Difference between this and OSSF Security Insights 1.0 specification
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the OpenSSF Project Security Information Specification, the linked working-group issue 19, and the referenced Security Insights issue 37. Compare the two specifications and record whether this project should adopt the OpenSSF initiative once its draft stabilizes; the issue currently names no files or tests.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100