ossf / ossf/tac

[Technical Initiative Funding Request]: Technical writer for OSPS Baseline

Open
#511 23 comments 0 reactions 2 assignees View on GitHub

@Naomi-Wash is already working on this.

Since Aug 14, 2025.

administration For Review gitvote gitvote/closed gitvote/passed TI Funding Request
Dominant language
No language data
Stars
152
Forks
86
Avg merge
5d 14h
Merged PRs (30d)
9

Description

Technical Initiative

Open Source Project Security Baseline

Lifecycle Phase

Incubating

Funding amount

3000

Problem Statement

The OSPS Baseline is primarily prose that needs to be clearly understood by open source project maintainers across a range of security knowledge, as well as a wide variety of language and cultural backgrounds. Unclear language can lead to confusion, as already evidenced in issues ossf/security-baseline#100 and ossf/security-baseline#255.

Who does this affect?

Maintainers of open source projects who are considering whether or not to evaluate their project against the OSPS Baseline.

Have there been previous attempts to resolve the problem?

We created an issue for existing contributors to develop and apply a style guide but due to expertise and time constraints, there has been no progress.

Why should it be tackled now and by this TI?

The OSPS Baseline is still relatively new. Fixing language issues and creating a style guide to help with future language use will help avoid misunderstandings that can lead to reputational harm. This is especially true as LF leadership looks to promote Baseline across projects.

Give an idea of what is required to make the funding initiative happen
  1. We will contract a technical writer to develop a style guide suitable for the project
  2. Writer will draft a pull request in https://github.com/ossf/security-baseline
  3. Community will provide feedback on the style guide
  4. Writer will respond to the feedback and maintainers will merge the PR
  5. Technical writer will update existing content to conform with style guide and to improve general comprehensibility
What is going to be needed to deliver this funding initiative?

A technical writer

Are there tools or tech that still need to be produced to facilitate the funding initiative?

No

Give a summary of the requirements that contextualize the costs of the funding initiative

The request is intended to fund 30 hours of a technical writer at a maximum rate of $100/hour. This is in line with the rate approved in TAC funding request #414 and represents an reasonable rate for contract technical writers in the current market.

Who is responsible for doing the work of this funding initiative?

The selected contract technical writer

Who is accountable for doing the work of this funding initiative?

Ben Cotton, lead of OSPS Baseline SIG

If the responsible or accountable parties are no longer available, what is the backup contact or plan?

Eddie Knight, chair of ORBIT Working Group

What license is this funding initiative being used under?

https://github.com/ossf/security-baseline/blob/main/LICENSE

Code of Conduct
  • I agree to follow the OpenSSF's Code of Conduct
List the major milestones by date and identify the overall timeline within which the technical initiative plans to accomplish their goals. Any payments for services, sponsorships, etc., will require LF Legal and Financial review.
  • Upon approval: Post contract role
  • Approval +2 weeks: select contractor
  • Approval +4 weeks: contractor provides draft style guide
  • Approval +6 weeks: final style guide committed
  • Approval +8 weeks: Existing text aligned with style guide
  • Approval +10 weeks: Additional wording improvements submitted
If this is a request for funding to issue a contract, then OpenSSF will issue that contract. Please provide a Statement of Work (SOW) that we may review. Any contracting action will take 4-6 weeks to issue.

The SOW will be drafted in concert with OpenSSF staff based on the “Give an idea of what is required” section.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.