Skip to content

Commit c5c685d

Browse files
committed
improved SCA requirement text
Signed-off-by: Eddie Knight <knight@linux.com>
1 parent f0c75ee commit c5c685d

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

baseline/OSPS-VM.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -247,10 +247,10 @@ controls:
247247
that verify compliance with that policy prior to release.
248248
- id: OSPS-VM-05.03
249249
text: |
250-
All changes to the project's codebase with new dependencies MUST
251-
be automatically evaluated against a documented policy for known
252-
vulnerabilities and blocked in the event of violations except when
253-
declared and suppressed as non-exploitable.
250+
All changes to the project's codebase MUST be automatically evaluated
251+
against a documented policy for malicious dependencies and
252+
known vulnerabilities in depenencies and blocked in the event of
253+
violations except when declared and suppressed as non-exploitable.
254254
applicability:
255255
- Maturity Level 3
256256
recommendation: |

0 commit comments

Comments
 (0)