In #1665 we talked about using OSPS (Open Source Project Securtiy) baseline by OSSF to check GitProxy's adherence to security best practices. As more firms adopt the project, we should aim to cover all 3 levels:
The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture. The controls are organized by maturity level and category. In the detailed subsections you will find the control, rationale, and details notes.
Where possible, we have added control mappings to external frameworks. These are not guaranteed to be 100% matches, but instead serve as references to external elements that the Baseline maintainers believe relate to the Baseline control. This is not a functional connection, and does not imply that progress on one will necessarily result in progress on the other.
Level 1: for any code or non-code project with any number of maintainers or users
Level 2: for any code project that has at least 2 maintainers and a small number of consistent users
Level 3: for any code project that has a large number of consistent users
Describe the solution you'd like
We should check whether GitProxy complies with all the criteria, or make issues if there are any points that need to be improved.
In #1665 we talked about using OSPS (Open Source Project Securtiy) baseline by OSSF to check GitProxy's adherence to security best practices. As more firms adopt the project, we should aim to cover all 3 levels:
Describe the solution you'd like
We should check whether GitProxy complies with all the criteria, or make issues if there are any points that need to be improved.