mojaloop / project

Repo to track product development issues for the Mojaloop project.
Other
24 stars 15 forks source link

Formalize an open source software (OSS) policy #2984

Open godfreykutumela opened 2 years ago

godfreykutumela commented 2 years ago

Goal:

As a security governance officer

`I want to' compliment the current statement on the Mojaloop OSS licensing by introducing a formal OSS policy to guide and govern the selection of safe to use and permissive OSS components. I spotted this as gap while I was busy finalizing the code security standard which will now reference this policy for anything OSS related and allowing the standard to focus on the secure design and securing the custom written code.

This policy does not replace Mojaloop OSS software's license is here: https://docs.mojaloop.io/getting-started/license.html but rather provide a governance framework to ensure alignment with it.

so that we can enforce compliance with the Mojaloop OSS license category while ensuring that only secure, up to date and supported OSS components are used within all Mojaloop codebases - core, vnext and Actio

Acceptance Criteria:

Complexity: Low

Uncertainty: Low

Tasks:

Done

Pull Requests:

Follow-up:

Dependencies:

Accountability:

godfreykutumela commented 2 years ago

Draft policy for review until 19 Oct 2022 - https://docs.google.com/document/d/1pMgnRLUUo6bEDvLXufWj4ahd6xUCQHXU/edit?usp=sharing&ouid=111271012303486374335&rtpof=true&sd=true

godfreykutumela commented 2 years ago

Additional Guideline on OSS License Categories. CAST-Highlight-Open-Source-License-Rulebook (1).pdf