Project: Document Best Practices for Secure Software Open Development
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- ドキュメント
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- git, github-actions
- 領域
- cli, devops, documentation, security
調査の方向性
ファイルやテストは指定されていません。まず、Linux Foundation と Google のガイダンス、セキュリティプロジェクトの実践、Blockchain Commons の実践、再現可能なビルド、ブランチ保護スクリプト、Git 署名を調査します。脅威と工数の分析、小規模プロジェクト向けの実践的な推奨事項、関連するツールまたは使用例を文書化できれば完了です。
索引モデルが issue の本文から書いたものです。
説明
This is another project that would be good for a team with mixed skills, and does not require deeper software engineering experience (but at least one should have experience with build processes).
Various organizations (Linux Foundation, Google, etc.) have offered guidance as to the practices of security, supply chain, etc. , but also emphasize enterprise and OS supply chain use cases. There are also a number of automated tools (apps, GitHub actions, etc.) that can be used to audit on some of these.
However, many are not practical for smaller projects, especially the emerging blockchain security repos, where only a few people may be contributing.
The goal of this project is to survey the existing recommended practices, best practices of various important security projects (including Blockchain Commons practices), etc., to identify which address the biggest threats given the effort (threat analysis), are practical for small projects to implement, which we might be able to offer some documentation and examples of how best to install and use, and guidance to contributors to small projects on how to tool and support this practices (like docs teaching git signing for writers contributing documentation to a secure repo).
Related to: reproducible builds, scripts for protecting master branch, etc.. What are our best practices and what do we recommend to other parties (especially for our CLI apps) @nochiel
- 主要言語
- 言語のデータがありません
- スター
- 68
- フォーク
- 7
- PR マージ指標
- 30日以内にマージされた PR はありません
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
BlockchainCommons/Community のほかの issue
-
deliverable: services deliverable: website
BlockchainCommons/Community#199 · 担当者 3 名 ·
-
Update Esplora オープンdeliverable: services
BlockchainCommons/Community#194 · 担当者 1 名 ·
-
deliverable: services
BlockchainCommons/Community#192 · 担当者 1 名 ·
-
deliverable: docs
BlockchainCommons/Community#190 · 担当者 1 名 ·
-
deliverable: website
BlockchainCommons/Community#181 · 担当者 1 名 ·
BlockchainCommons/Community の issue をすべて見る
似ている issue
-
clawsweeper:fix-shape-clear clawsweeper:queueable-fix clawsweeper:source-repro impact:ux-friction issue-rating: 🦞 diamond lobster no-stale P2
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
anthropics/skills#1811 · コメント 1 件 ·
-
category/development priority/P2 scope/file-operations scope/testing type/enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
CachyOS/distribution#587 ·
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
datalayer/mcp-compose#42 ·