-
Notifications
You must be signed in to change notification settings - Fork 111
Open
Labels
security baselinehttps://github.com/ossf/tac/blob/main/process/security_baseline.mdhttps://github.com/ossf/tac/blob/main/process/security_baseline.md
Milestone
Description
Address OSPS-VM-05.01 baseline requirement.
Requirement: While active, the project documentation MUST include a policy that defines a threshold for remediation of SCA findings related to vulnerabilities and licenses.
Recommendation: Document a policy in the project that defines a threshold for remediation of SCA findings related to vulnerabilities and licenses. Include the process for identifying, prioritizing, and remediating these findings.
Control applies to: Maturity Level 3
https://baseline.openssf.org/versions/2025-10-10#osps-vm-0501
Metadata
Metadata
Assignees
Labels
security baselinehttps://github.com/ossf/tac/blob/main/process/security_baseline.mdhttps://github.com/ossf/tac/blob/main/process/security_baseline.md