Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Supplemental Material for deeper dives and clarification #24

Open
adriandiglio opened this issue Jun 23, 2023 · 2 comments
Open

Comments

@adriandiglio
Copy link
Contributor

adriandiglio commented Jun 23, 2023

Definition of Supplemental Material: A 1-2 page write up to provide clarification on certain scenarios.

Example list of initial Supplemental Guides:

  • How S2C2F applies to C/C++ OSS
  • How OSS consumers SHOULD use metadata (i.e. OSS Scorecard) to make their own risk-based policies for consumption
  • How S2C2F applies to Linux rpm/deb packages
  • How to securely configure package source files for ENF-1
  • Elaborate on validating provenance (AUD-1), to include validating SLSA provenance
@jasminewang0
Copy link
Contributor

jasminewang0 commented Jul 13, 2023

Another supplemental guide example that came up was one about branch protections and approvals

@joshuagl
Copy link
Member

joshuagl commented Apr 9, 2024

It would be great to see some supplemental guidance around AUD-5 / Validate the author of your OSS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants