loopbackio / loopbackio/security
Track potential adoption of OpenSSF Project Security Information Specification
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- TypeScript
- Sterne
- 4
- Forks
- 1
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
The OpenSSF Project Security Information Specification "provides a mechanism for projects to report information about their security in a machine-processable way."
This specification is currently a draft. Hence, we should wait and see how it progresses. This issue is to keep track of this OpenSSF initiative.
see: https://github.com/ossf/wg-identifying-security-threats
see: https://github.com/ossf/wg-identifying-security-threats/issues/19
see: https://docs.google.com/document/d/1Hqks2J0wVqS_YFUQeIyjkLneLfo3_9A-pbU-7DZpGwM/edit
#TODO: Difference between this and OSSF Security Insights 1.0 specification
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Überprüfe die OpenSSF Project Security Information Specification, das verknüpfte working-group issue 19 und das referenzierte Security Insights issue 37. Vergleiche die beiden Spezifikationen und halte fest, ob dieses Projekt die OpenSSF-Initiative übernehmen sollte, sobald deren Entwurf stabil ist; im Issue sind derzeit keine Dateien oder Tests genannt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Bereich
- security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 15/100