Standards/specifications/guidance/recommendations to comply with

Open
#40 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Stale

Research direction

Start by reviewing the linked issues 37, 33, 25, 21, 24, 29, and 39 to understand each listed standard or recommendation. The work is done when the requirements are consolidated with categories and the project has an agreed way to show compliance uniformly.

Written by the indexing model from the issue text.

Description

There's quite a few. This issue is to provide a consolidated list, and to discuss how we can uniformly show our compliance.

Name Category Issue
OSSF Security Insights 1.0 - https://github.com/loopbackio/security/issues/37
OSSF NPM Best Practives v1 - https://github.com/loopbackio/security/issues/33
OSSF Scorecards - https://github.com/loopbackio/security/issues/25
OSSF Best Practices - https://github.com/loopbackio/security/issues/21
OSSF Project Security Information Specification - https://github.com/loopbackio/security/issues/24
FIRST Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure - https://github.com/loopbackio/security/issues/29
OpenJSF SBOM/S-SCRM Recommendations - https://github.com/loopbackio/security/issues/39
Dominant language
TypeScript
Stars
4
Forks
1
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from loopbackio/security

All issues in loopbackio/security

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.