-
Notifications
You must be signed in to change notification settings - Fork 12
Description
I highly recommend reviewing the project against the OpenSSF Security Baseline (https://baseline.openssf.org/). It is the recommend starting point for open source projects to establish a foundation for securely developing open source projects. As part of maturing this project into something solid it would be very important.
The baseline project maintains three levels depending on the maturity of the project that is evaluated. Here are the levels.
Level 1: for any code or non-code project with any number of maintainers or users
Level 2: for any code project that has at least 2 maintainers and a small number of consistent users
Level 3: for any code project that has a large number of consistent users
When we do this and action on it we should be able to communicate more easily on the posture of our security practices.
Besides this baseline there is the scorecard.dev project by OpenSSF that complements it.