ossf / ossf/security-baseline

Tracking: legal (OSPS-LE) requirement decisions

Open
#536 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

criteria
Dominant language
Go
Stars
166
Forks
44
Avg merge
1d 7h
Merged PRs (30d)
13

Description

Centralized view of all open issues touching the legal (OSPS-LE) requirements, so duplicates and dependencies are visible in one place. Everything below hinges on the scope ruling in #403.

Blocking decision

  • #403 — Consider dropping legal requirements entirely (vs. splitting into profiles/tracks per @puerco). All items below are blocked on or obviated by this ruling.

Blocked on #403

  • #397 — Remove OSPS-LE-01.01 (contribution authorization / DCO)
  • #399 — Merge OSPS-LE-02.01 + OSPS-LE-02.02 (OSI/FSF license definition)
  • #400 — Merge OSPS-LE-03.01 + OSPS-LE-03.02 (LICENSE file locations)
  • #401 — Add machine-readable license metadata requirement (would be a new LE control; only relevant if LE stays)

Adjacent (not strictly legal, but raised in the same review and touches LE wording)

  • #398 — "while active" phrasing is confusing (affects OSPS-LE-02.0x/LE-03.0x among others; consensus already reached to drop the phrase and scope EOL projects out)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the scope ruling in issue #403, then review the linked legal requirement issues #397, #399, #400, and #401, plus adjacent wording issue #398. Done means the ruling is reflected in this tracker and the affected issues have clear dependency or duplicate status; all listed work is currently blocked on #403.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.