Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Creation of org-wide landing page #26

Open
7 tasks
haydentherapper opened this issue Dec 10, 2024 · 2 comments
Open
7 tasks

Creation of org-wide landing page #26

haydentherapper opened this issue Dec 10, 2024 · 2 comments

Comments

@haydentherapper
Copy link

As part of needing an org-wide security.md, let's create a landing page for the organization.

More info: https://docs.github.com/en/organizations/collaborating-with-groups-in-organizations/customizing-your-organizations-profile, https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file

What we need to do:

  • Create slsa-framework/.github
  • Create profile/README.md
  • Create SECURITY.md

Some nice-to-haves:

  • CONTRIBUTING.md
  • CODE_OF_CONDUCT.md
  • GOVERNANCE.md with a link to our governance repo (or maybe remove that governance repo in favor of this repo?)
  • Default issue templates
@marcelamelara
Copy link

marcelamelara commented Dec 10, 2024

Thanks for this checklist @haydentherapper ! I just happened to be looking into creating a SECURITY.md file for us. Do you know if OpenSSF provides a default SECURITY.md template we can use? I haven't been able to find one.

EDIT: Here's a template provided by the OpenSSF.

@haydentherapper
Copy link
Author

I'd also consider suggesting reporting via GitHub, instead of over email - https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability

This will send a report to the repo's admins. The only issue is if we go with what I suggested about having only the SC members be admins while repository owners are maintainers, then a SC member must get involved to accept the report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants