generated from ossf/project-template
-
Notifications
You must be signed in to change notification settings - Fork 33
Open
Description
The checklist contains various controls for which either
- I don't know if it's the case (e.g. OSPS-AC-01.01 and OSPS-AC-02.01) where it would be helpful if you could tell me something like "if you're using GitHub you can check this", or
- The language or requirement is ambiguous (e.g. OSPS-DO-01.01) where examples would be helpful to at least get an idea of what is expected, or
- The language is highly security-technical (e.g. OSPS-BR-06.01) where a maintainer might not have the relevant knowledge to answer it (which can lead to either doubtfully leaving it unchecked when it should be checked or over-confidently checking it when it shouldn't be checked).
(more examples, and feedback, in ericcornelissen/shescape#2237 (comment))
As much as possible, help a maintainer trying to fill out the checklist, at least in the most common case (i.e. probably a project on GitHub). I don't think the current content of https://baseline.openssf.org/maintainers.html is sufficient.
jpower432
Metadata
Metadata
Assignees
Labels
No labels