ossf / ossf/security-baseline

Help maintainers with answering questions as much as possible

Open
#421 4 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

The checklist contains various controls for which either

  • I don't know if it's the case (e.g. OSPS-AC-01.01 and OSPS-AC-02.01) where it would be helpful if you could tell me something like "if you're using GitHub you can check this", or
  • The language or requirement is ambiguous (e.g. OSPS-DO-01.01) where examples would be helpful to at least get an idea of what is expected, or
  • The language is highly security-technical (e.g. OSPS-BR-06.01) where a maintainer might not have the relevant knowledge to answer it (which can lead to either doubtfully leaving it unchecked when it should be checked or over-confidently checking it when it shouldn't be checked).

(more examples, and feedback, in https://github.com/ericcornelissen/shescape/issues/2237#issuecomment-3539079639)

As much as possible, help a maintainer trying to fill out the checklist, at least in the most common case (i.e. probably a project on GitHub). I don't think the current content of https://baseline.openssf.org/maintainers.html is sufficient.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with https://baseline.openssf.org/maintainers.html and review the examples and feedback linked in shescape issue 2237. Improve guidance for maintainers completing the checklist, especially common GitHub cases, ambiguous requirements, and security-technical controls; done means the page provides actionable help for the cited examples.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.