microsoft / code-with-engineering-playbook

This is the playbook for "code-with" customer or partner engagements
https://microsoft.github.io/code-with-engineering-playbook/
Creative Commons Attribution 4.0 International
2.15k stars 567 forks source link

Evaluate OSS for Security #1040

Closed balteravishay closed 3 months ago

balteravishay commented 3 months ago

Pull Request Template

What are you trying to address

This PR addresses issue #1039 by proposing a set of checks and tools that can be applied when evaluating an OSS package.

Checklist

[READY TO PR? Use the check-list below to ensure your branch is ready for PR.]

Note: You may see link check errors on pages you have not touched. This is normal, and due to either broken links or sites that reject link checker bots. The reviewer will help you get to a green state on these.

superhindupur commented 3 months ago

Thanks for adding this, very helpful. As discussed on the EMEA security committee call, it would be great if we can add some guidance to check for the dependency tree of a new open source dependency during a code review.

balteravishay commented 3 months ago

thanks @superhindupur, great feedback! added a section on "When to evaluate OSS", wdyt?