ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.37k stars 481 forks source link

SECURITY-INSIGHTS.yml implementation #2479

Open luigigubello opened 1 year ago

luigigubello commented 1 year ago

Hi :wave: as a project in the working group "Identifying Security Threats", we are working on the SECURITY-INSIGHTS.yml specification. SECURITY INSIGHTS would like to provide information regarding security posture and practices in place in an open-source project in both human-readable and machine-readable format (YAML). The original idea was to create something like security.txt, but containing more information and evidence. In the last months, we collected feedback from OpenSSF Slack channels and the community (Twitter), and now we have a first version that should be enough mature to be used. We would like to introduce this specification in some of the OpenSSF repositories (list at the bottom) to see how the community welcomes this news and how we can improve the specification. So, could we introduce SECURITY-INSIGHTS.yml in this repo? I can proceed to fill out the YAML (here is a sample) and prepare a PR by asking you for a review. Introducing this specification in the repo of OpenSSF might help to spread it into the community.

Repos where would be nice to introduce SECURITY-INSIGHTS.yml :

Let me know :)

(this proposal is partially related to https://github.com/ossf/scorecard/issues/2305)

github-actions[bot] commented 11 months ago

Stale issue message - this issue will be closed in 7 days

github-actions[bot] commented 9 months ago

This issue is stale because it has been open for 60 days with no activity.

github-actions[bot] commented 4 months ago

This issue has been marked stale because it has been open for 60 days with no activity.