OWASP / packman

A documentation and tracking project with the goal of making package management systems more secure.
47 stars 11 forks source link

Clarification of support levels for items in Tiers #18

Open lirantal opened 4 years ago

lirantal commented 4 years ago

Can we add a description of values and their definitions for security criteria items so that it is better understood what each mean. For example, I found the following for npm.md unclear:

stevespringett commented 4 years ago

Related to: SCVS 4.3 - Package repository requires strong authentication SCVS 4.4 - Package repository enables multi-factor authentication component publishing SCVS 4.5 - Package repository components have been published with multi-factor authentication SCVS 4.8 - Package repository notifies publishers of security issues SCVS 4.9 - Package repository notifies users of security issues SCVS 4.18 - Package manager does not execute code

Note: SCVS is currently in pre-draft and is subject to change