|
Plan to modify assurance case format (more claims, use SACM notation) - any thoughts? 2 messages
For the BadgeApp we include an “assurance case”, that is, a set of claims/arguments/evidence explaining why we think it’s secure. You can see the assurance case here: https://github.com/coreinfrastruc
For the BadgeApp we include an “assurance case”, that is, a set of claims/arguments/evidence explaining why we think it’s secure. You can see the assurance case here: https://github.com/coreinfrastruc
|
By David A. Wheeler
·
|
|
Rate limits for non-badge-image requests 2 messages
Some overeager people are trying to spider the entire best practices site all at once. This can cause trouble for everyone else. Our current rate limits don’t trigger soon enough, because they cover *
Some overeager people are trying to spider the entire best practices site all at once. This can cause trouble for everyone else. Our current rate limits don’t trigger soon enough, because they cover *
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-08. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-08. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Proposed criteria introduction text
All: Here's some proposed criteria introduction text. Comments? It's lengthy, so I want to fix it up *before* our translators have to deal with it. The plan is to use this text to enable people to mor
All: Here's some proposed criteria introduction text. Comments? It's lengthy, so I want to fix it up *before* our translators have to deal with it. The plan is to use this text to enable people to mor
|
By David A. Wheeler
·
|
|
Rename route "/criteria"->"/criteria_stats", /criteria to display criteria
FYI: I intend to soon rename the route "/criteria" to "/criteria_stats". We can then use "/criteria" to display the actual criteria in the selected locale. This is technically a change in the user-vis
FYI: I intend to soon rename the route "/criteria" to "/criteria_stats". We can then use "/criteria" to display the actual criteria in the selected locale. This is technically a change in the user-vis
|
By David A. Wheeler
·
|
|
Renaming whitelist->acceptlist, blacklist->denylist 2 messages
All: This pull request:https://github.com/coreinfrastructure/best-practices-badge/pull/1449 renames “whitelist” to “acceptlist” and “blacklist” to “denylist" everywhere in the CII Best Practices badge
All: This pull request:https://github.com/coreinfrastructure/best-practices-badge/pull/1449 renames “whitelist” to “acceptlist” and “blacklist” to “denylist" everywhere in the CII Best Practices badge
|
By David A. Wheeler
·
|
|
has anyone scripted doing updates to the CII site? 4 messages
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we ch
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we ch
|
By Tony Hansen
·
|
|
Software report on Zephyr notes CII Best Practices badge
All: Here's a team report, as part of an architecture class, where they examined open source software projects: https://se.ewi.tudelft.nl/desosa2019/ If you look at a part that discusses Zephyr: https
All: Here's a team report, as part of an architecture class, where they examined open source software projects: https://se.ewi.tudelft.nl/desosa2019/ If you look at a part that discusses Zephyr: https
|
By David A. Wheeler
·
|
|
CHAOSS Podcast #10 posted, notes the CII Best Practices Badge
All: CHAOSS Podcast #10 is now available, titled "Managing Risks and Opportunities in Open Source with Frank Nagle & David A. Wheeler". The hosts were Georg Link, Sean Goggins, and Kate Stewart. The p
All: CHAOSS Podcast #10 is now available, titled "Managing Risks and Opportunities in Open Source with Frank Nagle & David A. Wheeler". The hosts were Georg Link, Sean Goggins, and Kate Stewart. The p
|
By David A. Wheeler
·
|
|
Mailing list server will be moving the Linux Foundation Single Sign-On (SSO)
All: The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system for logging in to the mailing list service. This is part of an LF effort to have *one
All: The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system for logging in to the mailing list service. This is part of an LF effort to have *one
|
By David A. Wheeler
·
|
|
Please participate in the LF CII / Harvard LIST FOSS Survey!
If you're a contributor to Free/Libre and Open Source Software (FOSS), please participate in the LF CII / Harvard FOSS survey! Here are more details, with a link at the bottom to the actual survey: ht
If you're a contributor to Free/Libre and Open Source Software (FOSS), please participate in the LF CII / Harvard FOSS survey! Here are more details, with a link at the bottom to the actual survey: ht
|
By David A. Wheeler
·
|
|
FYI: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL”
All: A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL” by James Walden, 2020, https://arxiv.org/abs/2005.142
All: A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL” by James Walden, 2020, https://arxiv.org/abs/2005.142
|
By David A. Wheeler
·
|
|
"Why CII best practices gold badges are important":
All - I thought you might like to know that I recently posted a blog post titled "Why CII best practices gold badges are important": https://www.linuxfoundation.org/blog/2020/06/why-cii-best-practices
All - I thought you might like to know that I recently posted a blog post titled "Why CII best practices gold badges are important": https://www.linuxfoundation.org/blog/2020/06/why-cii-best-practices
|
By David A. Wheeler
·
|
|
The Linux kernel has earned a gold badge! 3 messages
All: I want to formally congratulate the Linux kernel project for earning a gold badge!! You can see their details here: https://bestpractices.coreinfrastructure.org/en/projects/34 The Linux kernel ha
All: I want to formally congratulate the Linux kernel project for earning a gold badge!! You can see their details here: https://bestpractices.coreinfrastructure.org/en/projects/34 The Linux kernel ha
|
By David A. Wheeler
·
|
|
Should the badge app switch to a different translation management system (from translation.io)?
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or informa
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or informa
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-05. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-05. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites 4 messages
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
|
By David A. Wheeler
·
|
|
[EXT] [CII-badges] Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
|
By Jason Dossett
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|