"When the project has made a release" is confusing
Open
@funnelfiasco is already working on this.
Since Nov 17, 2025.
bug
criteria
- Dominant language
- Go
- Stars
- 166
- Forks
- 44
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 13
Description
Does it mean "if there has ever been a release do X" or "for every release do X"? For some controls the former makes sense (e.g. OSPS-SA-03.02) while for other controls the latter makes sense (e.g. OSPS-QA-02.02) to me.
If it's the former, what's the point? Why would I follow this checklist for a project that will never be released? If the release hasn't happened yet, of course I won't do release-related tasks until there is a release.
This problem is very similar to https://github.com/ossf/security-baseline/issues/398
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.