generated from ossf/project-template
-
Notifications
You must be signed in to change notification settings - Fork 28
Open
Description
The Security Baseline aims to measure and recommend controls for open source projects.
Unfortunately, we haven't defined what a "project" is anywhere, and we often conflate projects with source code repositories or specific released artifacts. Some projects consist of multiple repositories (e.g. projects with a separate repository for each plugin, or projects that separate website, automation), or produce multiple packages possibly in different distribution channels.
We need a definition of project which allows producers and consumers to understand what is in and out of scope of a particular assessment of baseline compliance, as well as to enable discovery of baseline maturity given a particular resource.
Metadata
Metadata
Assignees
Labels
No labels