Skip to content

Commit e4102c3

Browse files
authored
Define the scope better. (#389)
This is my attempt at updating PR #333, which stalled. Signed-off-by: Ben Cotton <[email protected]>
1 parent 2b62c06 commit e4102c3

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

docs/faq.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,12 @@ Since the Baseline is designed for the developers of a project, not the consumer
7373
OSPS Baseline compliance is a point-in-time status.
7474
We encourage projects using the OSPS Baseline to say something like “As of April 31, 2025, this project complies with OSPS Baseline version 2025-02-30 level 2.”
7575

76+
## What is in scope for OSPS Baseline?
77+
78+
OSPS Baseline seeks to address security hygiene elements — those which secure the ways of working, delivering the product, and equipping its users to adopt it safely.
79+
80+
To use an analogy, Baseline is similar to health department guidelines that require a food processing plant to have practices that ensure safe food products: wearing hair nets, regularly cleaning and sanitizing equipment, monitoring refrigerator temperatures, handling recalls, etc.
81+
7682
## How can I get involved in the OSPS Baseline project?
7783
The OSPS Baseline project welcomes contributions in the [GitHub repository](https://github.com/ossf/security-baseline/pull/24/files).
7884
For discussion, join us in [#sig-security-baseline](https://openssf.slack.com/archives/C07DC6TT2QY) in the OpenSSF Slack instance.

0 commit comments

Comments
 (0)