ossf / ossf/security-baseline

Design expression of Baseline conformance

Open
#274 5 comments 0 reactions 1 assignee View on GitHub

@mlieberman85 is already working on this.

Since Apr 29, 2025.

documentation
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

As discussed in today's SIG meeting, we discussed the need to have a manual Baseline attestation predicate:

  • While we’re waiting for tools to support automated scanning and reports we should probably have some mechanism.
  • You can’t hold an automated tool accountable; you can hold a human accountable.
  • Even with automated tooling, a human needs to sign off on the conformance to Baseline.
  • We need some sort of manual attestation format (e.g. an in-toto attestation with some evidence or points to some evidence)

@mlieberman85 and @evankanderson volunteered to draft this.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.