Skip to content

Define what baseline applies to #340

@evankanderson

Description

@evankanderson

The Security Baseline aims to measure and recommend controls for open source projects.

Unfortunately, we haven't defined what a "project" is anywhere, and we often conflate projects with source code repositories or specific released artifacts. Some projects consist of multiple repositories (e.g. projects with a separate repository for each plugin, or projects that separate website, automation), or produce multiple packages possibly in different distribution channels.

We need a definition of project which allows producers and consumers to understand what is in and out of scope of a particular assessment of baseline compliance, as well as to enable discovery of baseline maturity given a particular resource.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions