Skip to content

Add OpenSSF Baseline compliance files#189

Closed
mlieberman85 wants to merge 0 commit intokusaridev:mainfrom
mlieberman85:fix/openssf-baseline-compliance
Closed

Add OpenSSF Baseline compliance files#189
mlieberman85 wants to merge 0 commit intokusaridev:mainfrom
mlieberman85:fix/openssf-baseline-compliance

Conversation

@mlieberman85
Copy link

Summary

This PR adds files required for OpenSSF Baseline compliance at Levels 1-3.

Changes

  • CODEOWNERS - Defines code ownership (@mlieberman85, @pxp928, @funnelfiasco)
  • MAINTAINERS.md - Documents project maintainers and responsibilities
  • GOVERNANCE.md - Establishes project governance model
  • SUPPORT.md - Provides support channels and resources
  • Bug report template - Standardized issue template for bug reports
  • SECURITY.md - Updated with VEX policy section
  • DCO enforcement - Workflow for Developer Certificate of Origin
  • dependabot.yml - Updated dependency scanning configuration

Controls Addressed

Control Description
OSPS-GV-01.01 Governance documentation
OSPS-GV-01.02 Maintainer documentation
OSPS-GV-04.01 Code ownership
OSPS-DO-02.01 Bug report template
OSPS-DO-03.01 Support documentation
OSPS-VM-04.02 VEX policy
OSPS-LE-01.01 DCO enforcement

Verification

Re-run the OpenSSF Baseline audit after merging to verify compliance improvements.

@mlieberman85 mlieberman85 force-pushed the fix/openssf-baseline-compliance branch from 8d06161 to 401d2b1 Compare February 3, 2026 19:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant