Skip to content

[SECURITY REVIEW] OpenSSF OSPS Baseline v2026.08.28 readiness — identify evidence and gaps #82

Description

Purpose

Assess ENTITY against the current OpenSSF Open Source Project Security (OSPS) Baseline v2026.08.28 and identify what is already evidenced publicly, what is ambiguous, and what remains incomplete.

This is a readiness/evidence review. BTG is not claiming an OpenSSF Best Practices or OSPS Baseline badge in this issue. A badge or compliance level should only be stated after the applicable OpenSSF process is actually completed.

Current baseline reference:
https://baseline.openssf.org/

OpenSSF Best Practices Badge program:
https://www.bestpractices.dev/

Why external review is useful

ENTITY already publishes several security-development signals, including CI, dependency review, OpenSSF Scorecard, security documentation, protected release evidence and public conformance work. The useful question is not whether those look good in isolation; it is whether they provide the evidence required by the current OSPS Baseline and where the project has real gaps.

An unrelated reviewer is especially useful because maintainers can easily overestimate how clear their own evidence is.

Bounded task

Pick one OSPS Baseline v2026.08.28 control or one control family and report:

OSPS control / section:
Status: evidenced / partially evidenced / not evidenced / unclear
Public evidence URL(s):
Why the evidence is sufficient or insufficient:
Missing evidence or control:
Recommended remediation (optional):
Reviewer environment/context (optional):

Useful evidence surfaces

Start with:

Do not assume a badge in the README proves a specific baseline control; inspect the underlying evidence.

Scope boundary

This task does not replace an independent security audit, penetration test, legal assessment or OpenSSF's own badge/self-certification process. It is a public gap-analysis and evidence-mapping exercise.

Negative findings are welcome. If a control is not met or cannot be evidenced, say so directly and provide a reproducible basis where possible.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    evidenceEvidence objects, claim states, attestations, anchors, or qualification evidencehelp wantedMaintainers welcome external contributionsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions