Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/ossf/security-insights-spec
OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
https://github.com/ossf/security-insights-spec
Last synced: about 1 month ago
JSON representation
OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
- Host: GitHub
- URL: https://github.com/ossf/security-insights-spec
- Owner: ossf
- License: other
- Created: 2022-01-16T23:19:12.000Z (almost 3 years ago)
- Default Branch: main
- Last Pushed: 2024-08-24T14:54:13.000Z (4 months ago)
- Last Synced: 2024-08-24T15:59:41.475Z (4 months ago)
- Size: 15.3 MB
- Stars: 48
- Watchers: 12
- Forks: 9
- Open Issues: 16
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE.md
- Security: SECURITY-INSIGHTS.yml
- Governance: GOVERNANCE.md
- Roadmap: docs/roadmap/security-insights-v1.1.md
Awesome Lists containing this project
- awesome-software-supply-chain-security - OpenSSF Security Insights Spec
README
[](https://openssf.slack.com/messages/security_insights/)
# Security Insights Specification
This specification provides a mechanism for projects to report information about their security in a machine-processable way. It is formatted as a YAML file to make it easy to read and edit by humans.
The data tracked within this specification is intended to fill the gaps between simplified solutions such as `SECURITY.md` and comprehensive automatable solutions such as SBOMs. In that gap lay elements that must be self-reported by projects to allow end-users to make informed security decisions.
As the adoption of Security Insights grows, so does the opportunity to automatically ingest it. For example, the Linux Foundation's [CLOMonitor](https://clomonitor.io/) parses a project's Security Insights file to determine whether projects have reported on select security factors prioritized by the foundation.
All information regarding the maintenance, security, and consumption of the Security Insights Specification can be found in this repo within the latest version of the [official specification file](/specification.md).
Please use GitHub issues to discuss the maintenance of this specification, and review the [Contributor Guidelines](./CONTRIBUTING.md) for more information.