ossf / ossf/security-baseline

Make explicit when a control builds on an earlier control

Open
#423 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement help wanted
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

I went through to checklist for a project and found myself thinking "haven't I answered this already" several times, in most cases this happened because a control build on an earlier one (e.g. OSPS-VM-03.01 and OSPS-VM-02.01). It would be very helpful if this was explicit and I'm not left guessing. And no, the numbering in the IDs isn't clear enough for someone not involved/familiar with the project (in fact, I'm only assuming there's some kind of logic by which I could have told one builds on the other).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the checklist entries for OSPS-VM-03.01 and OSPS-VM-02.01, then inspect how control relationships are currently represented. Make the dependency explicit wherever one control builds on an earlier control, and verify that the checklist makes this relationship understandable without relying on the numbering.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.