ossf / ossf/community

Review and refine top-level pages of site to put more context to assist with project selection

Open
#35 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
SCSS
Stars
11
Forks
8
Avg merge
5d 3h
Merged PRs (30d)
3

Description

From discussion in the 7/28 Security Architecture meeting (with additional comments from Evan):

  1. The Personas page for individual roles is sort of a project-dump rather than providing some guidance about what problems that role may be looking to solve.  I'm not sure if this is a new YAML file or fits in one of the existing files, but I don't see this data in the source content today.
  2. Feedback we heard from a few people was the personas don't necessarily intuitively identify the value of the problem solutions.  We probably need to back up a little bit and do a better job explaining the risks that the problem solutions address.  e.g. talking with Scala devs, they didn't understand the intrinsic value of signing & verification, but were willing to trust an expert from the OpenSSF because they were already working together.  Explaining the risks could help bridge that credibility gap.
  3. I see we have some threats enumerated already (and @CRob has opinions here), but maybe a higher-level risk-focused version could be helpful, particularly if we don't end up with a dense matrix of every risk, every persona, every project.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Personas page and inspect the linked _data directory, existing source content, and currently enumerated threats. Review the top-level pages against the three requested areas: role-specific problem guidance, explanations of the risks and value behind solutions, and a possible higher-level risk-focused view. Done means the pages give clearer project-selection context without requiring a dense persona-risk-project matrix.

Written by the indexing model from the issue text.

Assessment

Tech stack
scss, yaml
Domain
content, documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.