ossf / ossf/security-baseline

[feedback] How can projects express they meet a given OSPS level?

Open
#257 8 comments 0 reactions 1 assignee View on GitHub

@evankanderson is already working on this.

Since Jul 7, 2026.

question
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

tl;dr

Projects need a mechanism, today, that allows them to express how they meet a given OSPS level or set of OSPS criteria. We've been point at security-insights.yml but it isnt ready yet.

Details

We've rolled out the baselines, defined the criteria, and how projects can implement the criteria, but not yet provided them a mechanism by which they can capture the how. We currently are currently surfing some momentum given OSPS awareness, but this can quickly die if we fail to provide the means for projects to do this. Many individuals I've presented the OSPS baselines to cite this makes sense, they're already doing a lot of them, now how do they show it?

UX

For now, i've recommended to project to create a project page or file in their repo that grabs the criteria and just write out how they do it. This means they'll have double effort first in writing it out and then in converting to the security-insights.yml spec when it is ready. We need to narrow the window for projects jumping on this in the time between our announcement and the tooling/spec to allow expression to happen so we don't inadvertently introduce more effort or stale information that projects then need to go back and convert.

Desired Outcome

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.