Skip to content

Blog post: List of principles when interacting with Open Source communities#179

Draft
sjn wants to merge 33 commits intomainfrom
sjn-principles-post
Draft

Blog post: List of principles when interacting with Open Source communities#179
sjn wants to merge 33 commits intomainfrom
sjn-principles-post

Conversation

@sjn
Copy link
Copy Markdown
Contributor

@sjn sjn commented Aug 8, 2025

This article is still a WIP.

The goal here is to enumerate some of the base (high-level) assumptions that needs to be in place for making sensible and constructive decisions around securing open source ecosystems like CPAN and Perl's.

Audience: Management-level; Market authorities; Secure software development guidance authors; etc.

Note: copied in from sjn-principles-post-2025-05 branch

@sjn sjn self-assigned this Aug 8, 2025
@sjn sjn added the blog Editorial blog post for the CPANSec website label Aug 8, 2025
@sjn sjn changed the title Add separate branch for principles post Blog post: List of principles when interacting with Open Source communities Aug 8, 2025
@sjn sjn moved this to In Progress in Security Information & Outreach Aug 20, 2025
@sjn
Copy link
Copy Markdown
Contributor Author

sjn commented Sep 5, 2025

I'm thinking about good ways to introduce context to this topic.
First thought is to talk about "due diligence" and "due care" and how Open Source projects play into this.
Comments?

@robrwo
Copy link
Copy Markdown
Contributor

robrwo commented Dec 3, 2025

This article is still a WIP.

You can turn it into a draft, which also prevents accidental merging.

@sjn sjn marked this pull request as draft March 30, 2026 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

blog Editorial blog post for the CPANSec website

Projects

Development

Successfully merging this pull request may close these issues.

2 participants