Document scope and duration of support for each release
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 271
- Forks
- 129
- Avg merge
- 3h 46m
- Merged PRs (30d)
- 4
Description
Ensure that OSV schema repository actions or documents meet the needs of the OpenSSF baseline requirement OSPS-DO-04.01.
Requirement: When the project has made a release, the project documentation MUST include a descriptive statement about the scope and duration of support for each release.
Recommendation: In order to communicate the scope and duration of support for the project's released software assets, the project should have a SUPPORT.md file, a "Support" section in SECURITY.md, or other documentation explaining the support lifecycle, including the expected duration of support for each release, the types of support provided (e.g., bug fixes, security updates), and any relevant policies or procedures for obtaining support.
Control applies to: Maturity Level 3
External Framework Mappings
BPB: R-B-3
SSDF: PO.4.2, PS.3.1, RV.1.3
ISO-18974: 4.1, 4.3.1
PSSCRM: E1.6
SAMM: Operations -Operational Management -System Decommissioning -Legacy Management Lvl1
PCIDSS: 2.1.1, 3.1.1, 3.2.1, 4.1.1, 5.1.1, 6.1.1, 6.3.3, 7.1.1, 8.1.1, 11.1.1
UKSSCOP: 4.1, 4.2
800-161: PL-1, PL-2, SI-4
https://baseline.openssf.org/versions/2025-10-10#osps-do-0401
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the OSPS-DO-04.01 requirement and the repository's existing release documentation, if any. Decide whether SUPPORT.md, a Support section in SECURITY.md, or another document fits the project, then document the support duration, scope, update types, and support procedures for each release; done means the repository meets the cited requirement.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100