loopbackio / loopbackio/security
Standards/specifications/guidance/recommendations to comply with
Open
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
There's quite a few. This issue is to provide a consolidated list, and to discuss how we can uniformly show our compliance.
| Name | Category | Issue |
|---|---|---|
| OSSF Security Insights 1.0 | - | https://github.com/loopbackio/security/issues/37 |
| OSSF NPM Best Practives v1 | - | https://github.com/loopbackio/security/issues/33 |
| OSSF Scorecards | - | https://github.com/loopbackio/security/issues/25 |
| OSSF Best Practices | - | https://github.com/loopbackio/security/issues/21 |
| OSSF Project Security Information Specification | - | https://github.com/loopbackio/security/issues/24 |
| FIRST Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure | - | https://github.com/loopbackio/security/issues/29 |
| OpenJSF SBOM/S-SCRM Recommendations | - | https://github.com/loopbackio/security/issues/39 |
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked issues 37, 33, 25, 21, 24, 29, and 39 to understand each listed standard or recommendation. The work is done when the requirements are consolidated with categories and the project has an agreed way to show compliance uniformly.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100