galasa-dev / projectmanagement

Project Management repo for Issues and ZenHub
7 stars 3 forks source link

OpenSSF Best Practices Badge #1587

Open louisa-seers opened 9 months ago

louisa-seers commented 9 months ago

Story

As a customer of galasa, I want to see that it follows all the OpenSSF best practices, so that I can have confidence in the code and how it was developed, and trust that using the code is safe to do.

Background

Start to work towards the OpenSSF Best Practices badge. This will move us from being an incubation project within the OMP and towards being an Active project.

Criteria: https://www.bestpractices.dev/en/criteria/0

Tasks

Basic project website content

FLOSS license

Documentation

Other

Change Control

Public version-controlled source repository

Release notes

Reporting

Bug-reporting process

Vulnerability report process

Quality

Working build system

Automated test suite

New functionality testing

Warning flags

Secured delivery against man-in-the-middle (MITM) attacks

Publicly known vulnerabilities fixed

Other security issues

Static code analysis

louisa-seers commented 5 months ago

Website reference: https://www.bestpractices.dev/en/projects/8343#analysis

louisa-seers commented 2 months ago

Spent time with John Mertic going through the badge yesterday, we are almost there at 80%. I have the following things to add to the repos: