ossf / package-manager-best-practices

Collection of security best practices for package managers.
Apache License 2.0
159 stars 19 forks source link

Publish draft of npm best practices guide #3

Closed jeffmendoza closed 2 years ago

jeffmendoza commented 2 years ago

Step 2 of process.md. Publishing this draft to the drafts/ directory for further refinement before proposal. Closes #2

jeffmendoza commented 2 years ago

@ljharb fyi We'll be presenting the process in tomorrow morning's WG meeting for how a doc will go from draft to rfc to published. At this point, I'm converting from a Google doc to markdown, and am not addressing comments. Once we have it in drafts/ comments can be opened as issues, but the main period where authors will be addressing comments is during the 30-day review period. Thanks.

ljharb commented 2 years ago

ok, thanks for clarifying.

jeffmendoza commented 2 years ago

@laurentsimon Should all be here, ptal. I'll move over the existing comments as new issues once merged.