ossf / ossf/security-baseline

Proposal to merge OSPS-LE-03.0*

Open
#400 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

criteria
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

Merger Suggestion 2

OSPS-LE-03.01: While active, the license for the source code MUST be maintained in the corresponding repository's LICENSE file, COPYING file, or LICENSE/ directory.
OSPS-LE-03.02: While active, the license for the released software assets MUST be included in the released source code, or in a LICENSE file, COPYING file, or LICENSE/ directory alongside the corresponding release assets.

Similarly, these two items are exhibiting a nuance that is unnecessary for Security Baseline and likely opening up a bag of worms. I would simplify it to:

OSPS-LE-03.01: The license for the project's source and artifacts MUST be clearly identified in a standard file (e.g. LICENSE, COPYING) with standard file extension (e.g. .md, .txt)."

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the OSPS-LE-03.01 and OSPS-LE-03.02 wording quoted in this issue. Check the repository's existing Security Baseline requirement materials, which are not identified here, and confirm that the proposed single requirement preserves the intended source and release-asset coverage before considering the wording complete.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.