Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions baseline/OSPS-GV.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,8 @@ controls:
assessment-requirements:
- id: OSPS-GV-01.01
text: |
While active, the project documentation MUST include a list of
project members with access to sensitive resources.
The project documentation MUST include a list of project members with
access to sensitive resources.
applicability:
- maturity-2
- maturity-3
Expand All @@ -32,8 +32,8 @@ controls:
of maintainers, or more complex depending on the project's governance.
- id: OSPS-GV-01.02
text: |
While active, the project documentation MUST include descriptions of
the roles and responsibilities for members of the project.
The project documentation MUST include descriptions of the roles and
responsibilities for members of the project
applicability:
- maturity-2
- maturity-3
Expand All @@ -53,7 +53,7 @@ controls:
assessment-requirements:
- id: OSPS-GV-02.01
text: |
While active, the project MUST have one or more mechanisms for public
The project MUST have one or more mechanisms for public
discussions about proposed changes and usage obstacles.
applicability:
- maturity-1
Expand All @@ -74,8 +74,8 @@ controls:
assessment-requirements:
- id: OSPS-GV-03.01
text: |
While active, the project documentation MUST include an explanation
of the contribution process.
The project documentation MUST include an explanation of the
contribution process, or clearly state that public contributions are not accepted
applicability:
- maturity-1
- maturity-2
Expand All @@ -86,7 +86,7 @@ controls:
engaging with the project maintainers.
- id: OSPS-GV-03.02
text: |
While active, the project documentation MUST include a guide for code
The project documentation MUST include a guide for code
contributors that includes requirements for acceptable contributions.
applicability:
- maturity-2
Expand All @@ -109,7 +109,7 @@ controls:
assessment-requirements:
- id: OSPS-GV-04.01
text: |
While active, the project documentation MUST have a policy that code
The project documentation MUST have a policy that code
collaborators are reviewed prior to granting escalated permissions to
sensitive resources.
applicability:
Expand Down
10 changes: 5 additions & 5 deletions baseline/OSPS-LE.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ controls:
assessment-requirements:
- id: OSPS-LE-01.01
text: |
While active, the version control system MUST require all code
The version control system MUST require all code
contributors to assert that they are legally authorized to make the
associated contributions on every commit.
applicability:
Expand Down Expand Up @@ -51,7 +51,7 @@ controls:
assessment-requirements:
- id: OSPS-LE-02.01
text: |
While active, the license for the source code MUST meet the OSI Open
The license for the source code MUST meet the OSI Open
Source Definition or the FSF Free Software Definition.
applicability:
- maturity-1
Expand All @@ -67,7 +67,7 @@ controls:
this control if there are no other encumbrances such as patents.
- id: OSPS-LE-02.02
text: |
While active, the license for the released software assets MUST meet
The license for the released software assets MUST meet
the OSI Open Source Definition or the FSF Free Software Definition.
applicability:
- maturity-1
Expand All @@ -93,7 +93,7 @@ controls:
assessment-requirements:
- id: OSPS-LE-03.01
text: |
While active, the license for the source code MUST be maintained in
The license for the source code MUST be maintained in
the corresponding repository's LICENSE file, COPYING file,
LICENSES/ directory, or LICENSE/ directory.
applicability:
Expand All @@ -109,7 +109,7 @@ controls:
includes the license file.
- id: OSPS-LE-03.02
text: |
While active, the license for the released software assets MUST be
The license for the released software assets MUST be
included in the released source code, or in a LICENSE file, COPYING
file, or LICENSE/ directory alongside the corresponding release
assets.
Expand Down
6 changes: 3 additions & 3 deletions baseline/OSPS-QA.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ controls:
assessment-requirements:
- id: OSPS-QA-01.01
text: |
While active, the project's source code repository MUST be publicly
The project's source code repository MUST be publicly
readable at a static URL.
applicability:
- maturity-1
Expand Down Expand Up @@ -152,7 +152,7 @@ controls:
assessment-requirements:
- id: OSPS-QA-05.01
text: |
While active, the version control system MUST NOT contain generated
The version control system MUST NOT contain generated
executable artifacts.
applicability:
- maturity-1
Expand All @@ -166,7 +166,7 @@ controls:
fetched during a specific well-documented pipeline step.
- id: OSPS-QA-05.02
text: |
While active, the version control system MUST NOT contain unreviewable
The version control system MUST NOT contain unreviewable
binary artifacts.
applicability:
- maturity-1
Expand Down
20 changes: 10 additions & 10 deletions baseline/OSPS-VM.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-01.01
text: |
While active, the project documentation MUST
The project documentation MUST
include a policy for coordinated vulnerability disclosure (CVD), with a clear
timeframe for response.
applicability:
Expand All @@ -43,7 +43,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-02.01
text: |
While active, the project documentation MUST contain
The project documentation MUST contain
security contacts.
applicability:
- maturity-1
Expand All @@ -63,7 +63,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-03.01
text: |
While active, the project documentation MUST
The project documentation MUST
provide a means for private vulnerability reporting directly to
the security contacts within the project.
applicability:
Expand All @@ -85,7 +85,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-04.01
text: |
While active, the project documentation MUST
The project documentation MUST
publicly publish data about discovered vulnerabilities.
applicability:
- maturity-2
Expand All @@ -98,7 +98,7 @@ controls:
instructions for mitigation or remediation.
- id: OSPS-VM-04.02
text: |
While active, any vulnerabilities in the
Any vulnerabilities in the
software components not affecting the project MUST be accounted for
in a VEX document, augmenting the vulnerability report with
non-exploitability details.
Expand All @@ -121,7 +121,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-05.01
text: |
While active, the project documentation MUST include a policy that
The project documentation MUST include a policy that
defines a threshold for remediation of SCA findings related to
vulnerabilities and licenses.
applicability:
Expand All @@ -133,7 +133,7 @@ controls:
these findings.
- id: OSPS-VM-05.02
text: |
While active, the project documentation MUST include a policy to
The project documentation MUST include a policy to
address SCA violations prior to any release.
applicability:
- maturity-3
Expand All @@ -143,7 +143,7 @@ controls:
that verify compliance with that policy prior to release.
- id: OSPS-VM-05.03
text: |
While active, all changes to the project's codebase MUST be
All changes to the project's codebase MUST be
automatically evaluated against a documented policy for malicious
dependencies and known vulnerabilities in dependencies, then blocked
in the event of violations, except when declared and suppressed as
Expand All @@ -167,7 +167,7 @@ controls:
assessment-requirements:
- id: OSPS-VM-06.01
text: |
While active, the project documentation MUST include a policy that
The project documentation MUST include a policy that
defines a threshold for remediation of SAST findings.
applicability:
- maturity-3
Expand All @@ -178,7 +178,7 @@ controls:
these findings.
- id: OSPS-VM-06.02
text: |
While active, all changes to the project's codebase MUST be
All changes to the project's codebase MUST be
automatically evaluated against a documented policy for security
weaknesses and blocked in the event of violations except when declared
and suppressed as non-exploitable.
Expand Down
Loading