Skip to content

Commit

Permalink
Update security_baseline_sandbox_stage.md
Browse files Browse the repository at this point in the history
to address feedback from @sevansdell 

Signed-off-by: Dana Wang <[email protected]>
  • Loading branch information
Danajoyluck authored Jul 12, 2024
1 parent a551b41 commit d563c44
Showing 1 changed file with 6 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@

The goal of this SIG is to evolve [OpenSSF security baseline](https://github.com/ossf/tac/blob/a90b9838739ac18df43197fdd89f045c1a1e4dc3/process/security_baseline.md) for Linux Foundation wide adoption.

This SIG creates a venue for other participating foundations to help evolve the OpenSSF security baseline into a security baseline that can be applied to a broad range of software-based projects. The group will define the right level of risks that the baseline is applicable for, the effectiveness measurement of the baseline, and the adoption path of the baseline at the minimum.

Members of this group will be from various Linux foundations and entities outside of Linux FOundation. Reducing duplicate effort and achieving a higher level of security across Linux FOundation participating foundations is the starting focus of this group.

### List SIG Lead(s)
The SIG must have a minimum of 1 Lead
* Eddie Knight, OpenSSF Security Insights lead, Sonatype, GitHub ID: eddie-knight

Check failure on line 13 in process/sig-lifecycle-documents/security_baseline_sandbox_stage.md

View workflow job for this annotation

GitHub Actions / Check Spelling

`eddie` is not a recognized word. (unrecognized-spelling)
Expand All @@ -20,6 +24,8 @@ The SIG have a minimum of 3 members with 2 different organizational affiliations
SIGs may report to an existing OpenSSF Working Group or directly to the TAC as their governing body. The SIG commits to providing the governing body quarterly updates on progress.
* Security Best Practices Working Group

CRob and Dana Wang had conversations about this inititve. CRob has agreed to be the sponsor of this SIG and welcome the group to join Security Best Practices Working Group.

Check failure on line 27 in process/sig-lifecycle-documents/security_baseline_sandbox_stage.md

View workflow job for this annotation

GitHub Actions / Check Spelling

`inititve` is not a recognized word. (unrecognized-spelling)

### SIG References
The SIG should provide a list of existing resources with links to the repository, and if available, website, a roadmap, demos and walkthroughs, and any other material to showcase the existing breadth, maturity, and direction of the SIG.
| Reference | URL |
Expand Down

0 comments on commit d563c44

Please sign in to comment.