Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Track potential adoption of OpenSSF Project Security Information Specification

Open
#24 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
15/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Stale
Domain
security

Research direction

Review the OpenSSF Project Security Information Specification, the linked working-group issue 19, and the referenced Security Insights issue 37. Compare the two specifications and record whether this project should adopt the OpenSSF initiative once its draft stabilizes; the issue currently names no files or tests.

Written by the indexing model from the issue text.

Description

The OpenSSF Project Security Information Specification "provides a mechanism for projects to report information about their security in a machine-processable way."

This specification is currently a draft. Hence, we should wait and see how it progresses. This issue is to keep track of this OpenSSF initiative.

see: https://github.com/ossf/wg-identifying-security-threats
see: https://github.com/ossf/wg-identifying-security-threats/issues/19
see: https://docs.google.com/document/d/1Hqks2J0wVqS_YFUQeIyjkLneLfo3_9A-pbU-7DZpGwM/edit

#TODO: Difference between this and OSSF Security Insights 1.0 specification

Dominant language
TypeScript
Stars
4
Forks
1
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from loopbackio/security

All issues in loopbackio/security

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.