ossf / alpha-omega

Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
https://alpha-omega.dev
Apache License 2.0
84 stars 51 forks source link

engagements/2023/jquery/README.md: Unclear purpose (introduction) #353

Open Chealer opened 8 months ago

Chealer commented 8 months ago

The README file about the jQuery engagement starts with an introduction:

The purpose of this Alpha engagement is to provide security resources to the jQuery project in key areas, including:

  • Secure the consumer web
  • Reduce potential security incidents for jQuery by modernizing its consumers and its code
  • Conduct an ecosystem security risk audit
  • Modernize infrastructure
  • Web Modernization Campaign

Please clarify what the following fragments mean:

  1. "the consumer web"
  2. "its consumers"
  3. "Conduct an ecosystem security risk audit"
  4. "Web Modernization Campaign"
By the way There is a typo ("Janurary") in the first item of the _Monthly Updates_ section.
hyandell commented 4 months ago

On the ask for more information here, this is content from the OpenJS Foundation (jQuery) and we should follow up with them for clarity if available.

My belief of each item is:

Chealer commented 4 months ago

Thank you @hyandell If you're correct about #1, this should be phrased much more precisely. Regarding #3 and #4, you are visibly right, but it is very hard to guess that. Either the labels should be more precise, or they should link to details. For #3, it should be clarified which ecosystem is referred to. For #4, even the details are quite unclear (what does reducing "the footprint of legacy jQuery code" mean?).