Skip to content

GSoC 2024: Adapting to Google Open Source Security Rules, Policies, standards #470

Open
@henrykironde

Description

@henrykironde

An example of a project using OSSF

Project Pipeline source code Results visualized
NumPy actions yaml file Logs
  • Inclusion of support for Fuzzing via OSS-Fuzz, or expansion of fuzzing coverage where already present.
  • Remediation of known vulnerabilities.
  • Enhancement of build/release security by automating builds and releases, incorporating build provenance, implementing signing procedures, and improving reproducibility.
  • Enhancement of OpenSSF Scorecard scores for projects.

Ref: https://github.com/ossf/scorecard?tab=readme-ov-file

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions