ossf / ossf/security-baseline

Consider dropping legal requirements

Open
#403 22 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

blocked criteria
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

Most, perhaps all, of the legal requirements are not meaningfully attached to security threats. While they're all good things for projects to do, they seem out of scope for a security baseline and thus violate the "meaningful" part of the "FRAM" guidance.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked FRAM guidance and identifying the legal requirements this issue questions. Compare each requirement with the stated security-baseline scope; done requires a decided, documented boundary for which requirements remain, rather than an implementation change.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.