Skip to content

Add OpenSSF Baseline compliance files#190

Closed
mlieberman85 wants to merge 0 commit intokusaridev:mainfrom
mlieberman85:fix/openssf-baseline-upstream
Closed

Add OpenSSF Baseline compliance files#190
mlieberman85 wants to merge 0 commit intokusaridev:mainfrom
mlieberman85:fix/openssf-baseline-upstream

Conversation

@mlieberman85
Copy link

Summary

This PR adds documentation and configuration files to improve OpenSSF Baseline compliance.

Changes

  • CODEOWNERS - Defines code ownership for review requirements
  • MAINTAINERS.md - Documents project maintainers (@mlieberman85, @pxp928, @funnelfiasco)
  • GOVERNANCE.md - Describes project governance model
  • SUPPORT.md - Provides support channels and resources
  • Bug report template - Standardized issue template for bug reports
  • SECURITY.md - Updated with VEX policy section
  • DCO enforcement - GitHub Action for Developer Certificate of Origin
  • dependabot.yml - Updated dependency scanning configuration

OpenSSF Baseline Controls Addressed

Control Description Status
OSPS-GV-01.01 Governance documentation ✅ Fixed
OSPS-DO-02.01 Bug report template ✅ Fixed
OSPS-DO-03.01 Support documentation ✅ Fixed

Remaining

  • OSPS-SA-03.02 - Threat model documentation (requires manual creation)

🤖 Generated with Claude Code

@mlieberman85 mlieberman85 force-pushed the fix/openssf-baseline-upstream branch from e432025 to 401d2b1 Compare February 4, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant