tag-security icon indicating copy to clipboard operation
tag-security copied to clipboard

[Suggestion] Scrub Security TAG project resources against OpenSSF disclosure guide

Open TheFoxAtWork opened this issue 3 years ago • 5 comments

Description: OpenSSD released an Open SSF vulnerability disclosure guide for OSS projects. We want to review our existing project resources and information and ensure it is alignment with the OpenSSF guide.

Impact: discrepancies between these may be confusing for projects.

Scope:

  • [ ] Review the OpenSSF guide.
  • [ ] Review the Project Resources.
  • [ ] Identify missing, incomplete, or different information in the Project resources*
  • [ ] Add the OpenSSF guide as a resource in project resources
  • [ ] Open a PR with changes to move the project resources in alignment

*There is expected to be some difference, we're focused more on the process and references and less on the "does it say email list or slack channel".

TheFoxAtWork avatar Sep 27 '21 17:09 TheFoxAtWork

@TheFoxAtWork Can I help with this?

sayantani11 avatar Nov 05 '21 05:11 sayantani11

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jan 05 '22 10:01 stale[bot]

This appears to be a good initiative? what's the current status with the fact that @TheFoxAtWork left and there has been no activity since November 5th past year?

dutchshark avatar Feb 09 '22 16:02 dutchshark

Chairs/TLs are meeting with NIST SSDF folks soon. Please remind me to update this issue with more info in a couple of weeks or so.

PushkarJ avatar Feb 09 '22 19:02 PushkarJ

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Apr 12 '22 00:04 stale[bot]

@PushkarJ any update? I'd be interested in helping out.

szh avatar Oct 31 '22 19:10 szh

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Dec 31 '22 23:12 stale[bot]

Given there wasn't any meaningful activity here since the issue was first proposed in Sep 27, 2021, I'll proceed to close. Should there be renewed interest in revisiting the proposed initiative, we can reopen the issue and prioritize accordingly.

anvega avatar Jun 20 '23 23:06 anvega