|
Summary data from badges (so far) 6 messages
Here's some data to work from. Below is a short Ruby snippet to sum up the results for each criterion, followed by a CSV formatted result from when it was executed. Anyone who's interested can load th
Here's some data to work from. Below is a short Ruby snippet to sum up the results for each criterion, followed by a CSV formatted result from when it was executed. Anyone who's interested can load th
|
By David A. Wheeler
·
|
|
LF Badging Program for OPNFV project 4 messages
Emily, David, all My name is Sona Sarmadi, I am one of the OPNFV security members. I am leading the LF Badging Program for OPNFV project, I have created some tasks in Jira for all criteria/items we ne
Emily, David, all My name is Sona Sarmadi, I am one of the OPNFV security members. I am leading the LF Badging Program for OPNFV project, I have created some tasks in Jira for all criteria/items we ne
|
By
Sona Sarmadi
·
|
|
GnuPG and some charts... 3 messages
We have another project with a passing badge: GnuPG. Details here: https://bestpractices.coreinfrastructure.org/projects/197 That’s an important project that many depend on, so I’m very glad to see it
We have another project with a passing badge: GnuPG. Details here: https://bestpractices.coreinfrastructure.org/projects/197 That’s an important project that many depend on, so I’m very glad to see it
|
By David A. Wheeler
·
|
|
Plan to allow specification projects as well as projects with code, per project #180 (ODPi specifications) 4 messages
The badging project was designed for “FLOSS projects” - and we had expected only projects with *code* would be asking for a badge. However, project #180 takes an unexpected new direction: it’s a proje
The badging project was designed for “FLOSS projects” - and we had expected only projects with *code* would be asking for a badge. However, project #180 takes an unexpected new direction: it’s a proje
|
By David A. Wheeler
·
|
|
FLOSS weekly & Linux.com article!
In case you haven’t seen it… FLOSS weekly had a show where Emily & I talked about the best practices badge: https://twit.tv/shows/floss-weekly/episodes/389 There’s also a Linux.com article about the b
In case you haven’t seen it… FLOSS weekly had a show where Emily & I talked about the best practices badge: https://twit.tv/shows/floss-weekly/episodes/389 There’s also a Linux.com article about the b
|
By David A. Wheeler
·
|
|
Nice comments from Colin O'Dell (project league/commonmark)
I got a nice email from Colin O'Dell, who got a badge for league/commonmark (a CommonMark implementation). The badge entry is here: https://bestpractices.coreinfrastructure.org/projects/126 In the ema
I got a nice email from Colin O'Dell, who got a badge for league/commonmark (a CommonMark implementation). The badge entry is here: https://bestpractices.coreinfrastructure.org/projects/126 In the ema
|
By David A. Wheeler
·
|
|
Subject: First impressions on CII Best Practices and badges -- part 2 5 messages
Hope you are ready for some more questions and comments. :) 1) One question asks for the CPE name and refers to https://nvd.nist.gov/cpe.cfm I looked all over that page and still was unable to find ho
Hope you are ready for some more questions and comments. :) 1) One question asks for the CPE name and refers to https://nvd.nist.gov/cpe.cfm I looked all over that page and still was unable to find ho
|
By Kevin W. Wall
·
|
|
First impressions on CII Best Practices and badges -- part 3 3 messages
Okay, this is a question about interpretations of the 'crypto_password_storage' question. The question I am referring to was this: If passwords are stored for authentication of external users, the pro
Okay, this is a question about interpretations of the 'crypto_password_storage' question. The question I am referring to was this: If passwords are stored for authentication of external users, the pro
|
By Kevin W. Wall
·
|
|
First impressions on CII Best Practices and badges -- part 1 4 messages
Okay, my intent is to try to keep my emails short with only one or two main comments per post. So, first, please give me the "big picture"? 1) What is the overall intent? Is the primary focus merely o
Okay, my intent is to try to keep my emails short with only one or two main comments per post. So, first, please give me the "big picture"? 1) What is the overall intent? Is the primary focus merely o
|
By Kevin W. Wall
·
|
|
First impressions on CII Best Practices and badges -- part 4 6 messages
Okay, I'm through with my initial questions (at least until I first get some answers to the other questions that I asked), but I do have a few comments. To me one of the most significant indicators re
Okay, I'm through with my initial questions (at least until I first get some answers to the other questions that I asked), but I do have a few comments. To me one of the most significant indicators re
|
By Kevin W. Wall
·
|
|
First impressions on CII Best Practices and badges -- part 0 2 messages
Hello. This is my first post to this mailing list. At the urging of some other OWASP colleagues, I recently completed filling out all the CII Badging for the OWASP ESAPI 2.x project (/ESAPI/esapi-java
Hello. This is my first post to this mailing list. At the urging of some other OWASP colleagues, I recently completed filling out all the CII Badging for the OWASP ESAPI 2.x project (/ESAPI/esapi-java
|
By Kevin W. Wall
·
|
|
OWASP+Badges
Greeting to the list members. Excited to see this project moving. OWASP Foundation www.owasp.org with rough concensous is also going to intergrate into the gamification process and drive all projects
Greeting to the list members. Excited to see this project moving. OWASP Foundation www.owasp.org with rough concensous is also going to intergrate into the gamification process and drive all projects
|
By Tom Brennan
·
|
|
Dynamic Analysis 4 messages
Hi All, The section on Dynamic Analysis appears to be mandatory. My application is pretty much all Puppet code and I'm not quite sure how to perform dynamic analysis on this code. Any suggestions woul
Hi All, The section on Dynamic Analysis appears to be mandatory. My application is pretty much all Puppet code and I'm not quite sure how to perform dynamic analysis on this code. Any suggestions woul
|
By Trevor Vaughan
·
|
|
Other suggestions for helping implement sites_https (HTTPS support on project sites)? 2 messages
We have at least one project that doesn't have full HTTPS support on their project sites (sites_https). We already mentioned Let's Encrypt, but their case, the problem seems to be that Github lacks na
We have at least one project that doesn't have full HTTPS support on their project sites (sites_https). We already mentioned Let's Encrypt, but their case, the problem seems to be that Github lacks na
|
By David A. Wheeler
·
|
|
Press release about the badging project launch 6 messages
All - here's a press release with more information about the badging project launch: https://www.coreinfrastructure.org/news/announcements/2016/05/free-badge-program-signals-what-open-source-projects-
All - here's a press release with more information about the badging project launch: https://www.coreinfrastructure.org/news/announcements/2016/05/free-badge-program-signals-what-open-source-projects-
|
By David A. Wheeler
·
|
|
We've launched! THANK YOU.
I suspect everyone here already knows, but in case you didn’t, we’ve officially launched. That doesn’t mean the work ends; in some sense, it’s only beginning. Now that people are seriously trying to g
I suspect everyone here already knows, but in case you didn’t, we’ve officially launched. That doesn’t mean the work ends; in some sense, it’s only beginning. Now that people are seriously trying to g
|
By David A. Wheeler
·
|
|
NTIA survey on handling vulnerability disclosures
Hi list -- A topic near and dear to my heart is how both open source and proprietary software handle vulnerability disclosures. The National Telecommunications and Information Administration, part of
Hi list -- A topic near and dear to my heart is how both open source and proprietary software handle vulnerability disclosures. The National Telecommunications and Information Administration, part of
|
By Tod Beardsley
·
|
|
Potential criterion for cryptographic signatures 11 messages
I propose that we try (as a group) to create a potential criterion for cryptographic signatures. We can then decide if it's appropriate to add at this time & at this level. Here's a first cut (markdow
I propose that we try (as a group) to create a potential criterion for cryptographic signatures. We can then decide if it's appropriate to add at this time & at this level. Here's a first cut (markdow
|
By David A. Wheeler
·
|
|
BadgeApp now using poltergeist (#288) - BadgeApp co-developers will need to change some things 5 messages
Here’s info for those are co-developing the BadgeApp application… A *big* thanks to Dan Kohn, who fixed our test framework so that we can include web browser tests with Javascript. We’ve had the capab
Here’s info for those are co-developing the BadgeApp application… A *big* thanks to Dan Kohn, who fixed our test framework so that we can include web browser tests with Javascript. We’ve had the capab
|
By David A. Wheeler
·
|
|
asan rule 8 messages
Hi, Hope I'm not too late to propose a change. I'm currently on a mission to tell every foss dev that they should test their stuff with asan. Now there currently already is a rule for that in the badg
Hi, Hope I'm not too late to propose a change. I'm currently on a mission to tell every foss dev that they should test their stuff with asan. Now there currently already is a rule for that in the badg
|
By Hanno Böck
·
|