Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assess package evaluation criteria based on OpenSSF #302

Open
lirantal opened this issue Feb 13, 2024 · 0 comments
Open

Assess package evaluation criteria based on OpenSSF #302

lirantal opened this issue Feb 13, 2024 · 0 comments

Comments

@lirantal
Copy link
Owner

lirantal commented Feb 13, 2024

OpenSSF released Principles for Package Repository Security which addresses package registries themselves, but could be helpful in providing idea and insights in terms of safe-guards to watch out for that could be automated with npq.

For example: To prevent domain resurrection for account takeover via the recovery process, the package repository detects abandoned email domains. This may look like doing a WHOIS lookup on all registered email domains, and removing the ability to recover an account via an email domain that has been abandoned.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant