Skip to content

Help maintainers with answering questions as much as possible #421

@ericcornelissen

Description

@ericcornelissen

The checklist contains various controls for which either

  • I don't know if it's the case (e.g. OSPS-AC-01.01 and OSPS-AC-02.01) where it would be helpful if you could tell me something like "if you're using GitHub you can check this", or
  • The language or requirement is ambiguous (e.g. OSPS-DO-01.01) where examples would be helpful to at least get an idea of what is expected, or
  • The language is highly security-technical (e.g. OSPS-BR-06.01) where a maintainer might not have the relevant knowledge to answer it (which can lead to either doubtfully leaving it unchecked when it should be checked or over-confidently checking it when it shouldn't be checked).

(more examples, and feedback, in ericcornelissen/shescape#2237 (comment))

As much as possible, help a maintainer trying to fill out the checklist, at least in the most common case (i.e. probably a project on GitHub). I don't think the current content of https://baseline.openssf.org/maintainers.html is sufficient.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions