[Technical Initiative Funding Request]: Technical writer for OSPS Baseline
@Naomi-Wash is already working on this.
Since Aug 14, 2025.
- Dominant language
- No language data
- Stars
- 152
- Forks
- 86
- Avg merge
- 5d 14h
- Merged PRs (30d)
- 9
Description
Technical Initiative
Open Source Project Security Baseline
Lifecycle Phase
Incubating
Funding amount
3000
Problem Statement
The OSPS Baseline is primarily prose that needs to be clearly understood by open source project maintainers across a range of security knowledge, as well as a wide variety of language and cultural backgrounds. Unclear language can lead to confusion, as already evidenced in issues ossf/security-baseline#100 and ossf/security-baseline#255.
Who does this affect?
Maintainers of open source projects who are considering whether or not to evaluate their project against the OSPS Baseline.
Have there been previous attempts to resolve the problem?
We created an issue for existing contributors to develop and apply a style guide but due to expertise and time constraints, there has been no progress.
Why should it be tackled now and by this TI?
The OSPS Baseline is still relatively new. Fixing language issues and creating a style guide to help with future language use will help avoid misunderstandings that can lead to reputational harm. This is especially true as LF leadership looks to promote Baseline across projects.
Give an idea of what is required to make the funding initiative happen
- We will contract a technical writer to develop a style guide suitable for the project
- Writer will draft a pull request in https://github.com/ossf/security-baseline
- Community will provide feedback on the style guide
- Writer will respond to the feedback and maintainers will merge the PR
- Technical writer will update existing content to conform with style guide and to improve general comprehensibility
What is going to be needed to deliver this funding initiative?
A technical writer
Are there tools or tech that still need to be produced to facilitate the funding initiative?
No
Give a summary of the requirements that contextualize the costs of the funding initiative
The request is intended to fund 30 hours of a technical writer at a maximum rate of $100/hour. This is in line with the rate approved in TAC funding request #414 and represents an reasonable rate for contract technical writers in the current market.
Who is responsible for doing the work of this funding initiative?
The selected contract technical writer
Who is accountable for doing the work of this funding initiative?
Ben Cotton, lead of OSPS Baseline SIG
If the responsible or accountable parties are no longer available, what is the backup contact or plan?
Eddie Knight, chair of ORBIT Working Group
What license is this funding initiative being used under?
https://github.com/ossf/security-baseline/blob/main/LICENSE
Code of Conduct
- I agree to follow the OpenSSF's Code of Conduct
List the major milestones by date and identify the overall timeline within which the technical initiative plans to accomplish their goals. Any payments for services, sponsorships, etc., will require LF Legal and Financial review.
- Upon approval: Post contract role
- Approval +2 weeks: select contractor
- Approval +4 weeks: contractor provides draft style guide
- Approval +6 weeks: final style guide committed
- Approval +8 weeks: Existing text aligned with style guide
- Approval +10 weeks: Additional wording improvements submitted
If this is a request for funding to issue a contract, then OpenSSF will issue that contract. Please provide a Statement of Work (SOW) that we may review. Any contracting action will take 4-6 weeks to issue.
The SOW will be drafted in concert with OpenSSF staff based on the “Give an idea of what is required” section.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.