|
Renaming whitelist->acceptlist, blacklist->denylist
All:
This pull request:https://github.com/coreinfrastructure/best-practices-badge/pull/1449
renames “whitelist” to “acceptlist” and “blacklist” to “denylist" everywhere
in the CII Best
All:
This pull request:https://github.com/coreinfrastructure/best-practices-badge/pull/1449
renames “whitelist” to “acceptlist” and “blacklist” to “denylist" everywhere
in the CII Best
|
By
David A. Wheeler
·
#593
·
|
|
Re: has anyone scripted doing updates to the CII site?
It uses TLS to authenticate the best practices server, as well as provide
confidentiality & integrity between client & server.
Login session management uses an HTTP cookie, not basic
It uses TLS to authenticate the best practices server, as well as provide
confidentiality & integrity between client & server.
Login session management uses an HTTP cookie, not basic
|
By
David A. Wheeler
·
#592
·
|
|
Re: has anyone scripted doing updates to the CII site?
David, here are some questions not answered by that page:
* Does the REST API support basic authentication (over TLS)? Or some other HTTPS authentication method?
* When using the PATCH verb, what is
David, here are some questions not answered by that page:
* Does the REST API support basic authentication (over TLS)? Or some other HTTPS authentication method?
* When using the PATCH verb, what is
|
By
Tony Hansen
·
#591
·
|
|
Re: has anyone scripted doing updates to the CII site?
On Wed, Aug 12, 2020 at 12:10 AM Tony Hansen <tony@...> wrote:
...
> So I’d like a tool that could be used to do an identical update across a variety of CII projects. I’d like such a tool to
On Wed, Aug 12, 2020 at 12:10 AM Tony Hansen <tony@...> wrote:
...
> So I’d like a tool that could be used to do an identical update across a variety of CII projects. I’d like such a tool to
|
By
David A. Wheeler
·
#590
·
|
|
has anyone scripted doing updates to the CII site?
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we
|
By
Tony Hansen
·
#589
·
|
|
Software report on Zephyr notes CII Best Practices badge
All:
Here's a team report, as part of an architecture class, where they
examined open source software projects:
https://se.ewi.tudelft.nl/desosa2019/
If you look at a part that discusses Zephyr:
All:
Here's a team report, as part of an architecture class, where they
examined open source software projects:
https://se.ewi.tudelft.nl/desosa2019/
If you look at a part that discusses Zephyr:
|
By
David A. Wheeler
·
#588
·
|
|
CHAOSS Podcast #10 posted, notes the CII Best Practices Badge
All:
CHAOSS Podcast #10 is now available, titled "Managing Risks and
Opportunities in Open Source with Frank Nagle & David A. Wheeler". The
hosts were Georg Link, Sean Goggins, and Kate Stewart.
The
All:
CHAOSS Podcast #10 is now available, titled "Managing Risks and
Opportunities in Open Source with Frank Nagle & David A. Wheeler". The
hosts were Georg Link, Sean Goggins, and Kate Stewart.
The
|
By
David A. Wheeler
·
#587
·
|
|
Mailing list server will be moving the Linux Foundation Single Sign-On (SSO)
All:
The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system
for logging in to the mailing list service. This is part of an LF effort to have
All:
The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system
for logging in to the mailing list service. This is part of an LF effort to have
|
By
David A. Wheeler
·
#586
·
|
|
Please participate in the LF CII / Harvard LIST FOSS Survey!
If you're a contributor to Free/Libre and Open Source Software (FOSS),
please participate in the LF CII / Harvard FOSS survey!
Here are more details, with a link at the bottom to the actual
If you're a contributor to Free/Libre and Open Source Software (FOSS),
please participate in the LF CII / Harvard FOSS survey!
Here are more details, with a link at the bottom to the actual
|
By
David A. Wheeler
·
#585
·
|
|
FYI: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL”
All:
A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact
of a Major Security Event on an Open Source Project:The Case of
OpenSSL” by James Walden, 2020,
All:
A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact
of a Major Security Event on an Open Source Project:The Case of
OpenSSL” by James Walden, 2020,
|
By
David A. Wheeler
·
#584
·
|
|
"Why CII best practices gold badges are important":
All - I thought you might like to know that I recently posted a blog
post titled "Why CII best practices gold badges are
All - I thought you might like to know that I recently posted a blog
post titled "Why CII best practices gold badges are
|
By
David A. Wheeler
·
#583
·
|
|
Re: The Linux kernel has earned a gold badge!
Excellent news! Kudo's to Greg and the other contributors to making this happen!
Excellent news! Kudo's to Greg and the other contributors to making this happen!
|
By
Kate Stewart
·
#582
·
|
|
Re: The Linux kernel has earned a gold badge!
This is fantastic news!
Congratulations to the Linux Kernel.
Thanks for highlighting this achievement.
Georg
--
Georg Link, PhD
(he/him)
This is fantastic news!
Congratulations to the Linux Kernel.
Thanks for highlighting this achievement.
Georg
--
Georg Link, PhD
(he/him)
|
By
Georg Link
·
#581
·
|
|
The Linux kernel has earned a gold badge!
All: I want to formally congratulate the Linux kernel project for
earning a gold badge!! You can see their details here:
https://bestpractices.coreinfrastructure.org/en/projects/34
The Linux kernel
All: I want to formally congratulate the Linux kernel project for
earning a gold badge!! You can see their details here:
https://bestpractices.coreinfrastructure.org/en/projects/34
The Linux kernel
|
By
David A. Wheeler
·
#580
·
|
|
Should the badge app switch to a different translation management system (from translation.io)?
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or
|
By
David A. Wheeler
·
#579
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practicesbadge application covering the month 2020-05.
Here are some selected statistics for most recent completed month,preceded by the same
This is an automated monthly status report of the best practicesbadge application covering the month 2020-05.
Here are some selected statistics for most recent completed month,preceded by the same
|
By
badgeapp@...
·
#578
·
|
|
Re: Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
Wow, unanimous agreement is rare! Thank you everyone for your comments.
While we’re changing this text, I propose that we make a few more tweaks:
- I checked, and GitLab-hosted project repos have
Wow, unanimous agreement is rare! Thank you everyone for your comments.
While we’re changing this text, I propose that we make a few more tweaks:
- I checked, and GitLab-hosted project repos have
|
By
David A. Wheeler
·
#577
·
|
|
Re: [EXT] [CII-badges] Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
This change makes perfect since.
Best,
Jason N. Dossett, Ph.D.
Research Staff Member
Institute for Defense Analyses
4850 Mark Center Drive, Alexandria, VA 22311
Phone: 703-578-2773
Email:
This change makes perfect since.
Best,
Jason N. Dossett, Ph.D.
Research Staff Member
Institute for Defense Analyses
4850 Mark Center Drive, Alexandria, VA 22311
Phone: 703-578-2773
Email:
|
By
Jason Dossett
·
#576
·
|
|
Re: Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
The change seems pragmatic, and makes sense to me.
The change seems pragmatic, and makes sense to me.
|
By
Alton Blom
·
#575
·
|
|
Re: Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
I endorse this change.
--
Dan Kohn <dan@...> +1-415-233-1000
General Manager, LF Public Health, lfph.io
dankohn.com or book on my calendar: dankohn.com/c
I endorse this change.
--
Dan Kohn <dan@...> +1-415-233-1000
General Manager, LF Public Health, lfph.io
dankohn.com or book on my calendar: dankohn.com/c
|
By
Dan Kohn
·
#574
·
|