Review and refine top-level pages of site to put more context to assist with project selection
Open
Nobody has claimed this yet.
- Dominant language
- SCSS
- Stars
- 11
- Forks
- 8
- Avg merge
- 5d 3h
- Merged PRs (30d)
- 3
Description
From discussion in the 7/28 Security Architecture meeting (with additional comments from Evan):
- The Personas page for individual roles is sort of a project-dump rather than providing some guidance about what problems that role may be looking to solve. I'm not sure if this is a new YAML file or fits in one of the existing files, but I don't see this data in the source content today.
- Feedback we heard from a few people was the personas don't necessarily intuitively identify the value of the problem solutions. We probably need to back up a little bit and do a better job explaining the risks that the problem solutions address. e.g. talking with Scala devs, they didn't understand the intrinsic value of signing & verification, but were willing to trust an expert from the OpenSSF because they were already working together. Explaining the risks could help bridge that credibility gap.
- I see we have some threats enumerated already (and @CRob has opinions here), but maybe a higher-level risk-focused version could be helpful, particularly if we don't end up with a dense matrix of every risk, every persona, every project.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Personas page and inspect the linked _data directory, existing source content, and currently enumerated threats. Review the top-level pages against the three requested areas: role-specific problem guidance, explanations of the risks and value behind solutions, and a possible higher-level risk-focused view. Done means the pages give clearer project-selection context without requiring a dense persona-risk-project matrix.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- scss, yaml
- Domain
- content, documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100