Skip to content

Check GitProxy's adherence to OSPS baseline and open issues for fixes #1697

Description

@jescalada

In #1665 we talked about using OSPS (Open Source Project Securtiy) baseline by OSSF to check GitProxy's adherence to security best practices. As more firms adopt the project, we should aim to cover all 3 levels:

The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture. The controls are organized by maturity level and category. In the detailed subsections you will find the control, rationale, and details notes.

Where possible, we have added control mappings to external frameworks. These are not guaranteed to be 100% matches, but instead serve as references to external elements that the Baseline maintainers believe relate to the Baseline control. This is not a functional connection, and does not imply that progress on one will necessarily result in progress on the other.

Level 1: for any code or non-code project with any number of maintainers or users
Level 2: for any code project that has at least 2 maintainers and a small number of consistent users
Level 3: for any code project that has a large number of consistent users

Describe the solution you'd like
We should check whether GitProxy complies with all the criteria, or make issues if there are any points that need to be improved.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions