|
has anyone scripted doing updates to the CII site? 4 messages
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we ch
I’m one of the many people working on the Linux ONAP (Open Networking Automation Platform) Project. We chose to pursue CII badges from the very beginning, but because of the size of the project, we ch
|
By Tony Hansen
·
|
|
Software report on Zephyr notes CII Best Practices badge
All: Here's a team report, as part of an architecture class, where they examined open source software projects: https://se.ewi.tudelft.nl/desosa2019/ If you look at a part that discusses Zephyr: https
All: Here's a team report, as part of an architecture class, where they examined open source software projects: https://se.ewi.tudelft.nl/desosa2019/ If you look at a part that discusses Zephyr: https
|
By David A. Wheeler
·
|
|
CHAOSS Podcast #10 posted, notes the CII Best Practices Badge
All: CHAOSS Podcast #10 is now available, titled "Managing Risks and Opportunities in Open Source with Frank Nagle & David A. Wheeler". The hosts were Georg Link, Sean Goggins, and Kate Stewart. The p
All: CHAOSS Podcast #10 is now available, titled "Managing Risks and Opportunities in Open Source with Frank Nagle & David A. Wheeler". The hosts were Georg Link, Sean Goggins, and Kate Stewart. The p
|
By David A. Wheeler
·
|
|
Mailing list server will be moving the Linux Foundation Single Sign-On (SSO)
All: The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system for logging in to the mailing list service. This is part of an LF effort to have *one
All: The CII mailing list service is expected to soon switch to the “Linux Foundation Single Sign-on (SSO)” system for logging in to the mailing list service. This is part of an LF effort to have *one
|
By David A. Wheeler
·
|
|
Please participate in the LF CII / Harvard LIST FOSS Survey!
If you're a contributor to Free/Libre and Open Source Software (FOSS), please participate in the LF CII / Harvard FOSS survey! Here are more details, with a link at the bottom to the actual survey: ht
If you're a contributor to Free/Libre and Open Source Software (FOSS), please participate in the LF CII / Harvard FOSS survey! Here are more details, with a link at the bottom to the actual survey: ht
|
By David A. Wheeler
·
|
|
FYI: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL”
All: A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL” by James Walden, 2020, https://arxiv.org/abs/2005.142
All: A recent paper looked at Heartbleed’s impact on OpenSSL: “The Impact of a Major Security Event on an Open Source Project:The Case of OpenSSL” by James Walden, 2020, https://arxiv.org/abs/2005.142
|
By David A. Wheeler
·
|
|
"Why CII best practices gold badges are important":
All - I thought you might like to know that I recently posted a blog post titled "Why CII best practices gold badges are important": https://www.linuxfoundation.org/blog/2020/06/why-cii-best-practices
All - I thought you might like to know that I recently posted a blog post titled "Why CII best practices gold badges are important": https://www.linuxfoundation.org/blog/2020/06/why-cii-best-practices
|
By David A. Wheeler
·
|
|
The Linux kernel has earned a gold badge! 3 messages
All: I want to formally congratulate the Linux kernel project for earning a gold badge!! You can see their details here: https://bestpractices.coreinfrastructure.org/en/projects/34 The Linux kernel ha
All: I want to formally congratulate the Linux kernel project for earning a gold badge!! You can see their details here: https://bestpractices.coreinfrastructure.org/en/projects/34 The Linux kernel ha
|
By David A. Wheeler
·
|
|
Should the badge app switch to a different translation management system (from translation.io)?
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or informa
Georg Link has proposed that we switch from the translation.io translation management system to a different system (in particular, Weblate). If you have thoughts on such a potential change, or informa
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-05. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-05. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites 4 messages
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
|
By David A. Wheeler
·
|
|
[EXT] [CII-badges] Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
|
By Jason Dossett
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
I now work at the Linux Foundation!
All: As of today, I am a full-time employee of the Linux Foundation. My official title is "Director, Open Source Supply Chain Security". Basically, I'm going to working full-time on various efforts to
All: As of today, I am a full-time employee of the Linux Foundation. My official title is "Director, Open Source Supply Chain Security". Basically, I'm going to working full-time on various efforts to
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-02. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-02. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
More on spam countering efforts
FYI, we have implemented some simple spam countering mechanisms on the best practices badge application. Most trivially, whenever someone tries to create a project badge entry, they now see this: We'v
FYI, we have implemented some simple spam countering mechanisms on the best practices badge application. Most trivially, whenever someone tries to create a project badge entry, they now see this: We'v
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-01. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-01. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Need some advice addressing "unfixable" publicly known vulnerabilities 3 messages
CII Badging community, I just updated the ESAPI project on the CII Badges site to account for a newly discovered CVE. Specifically, I added this verbiage: Most Software Compositional Analysis tools /
CII Badging community, I just updated the ESAPI project on the CII Badges site to account for a newly discovered CVE. Specifically, I added this verbiage: Most Software Compositional Analysis tools /
|
By Kevin W. Wall
·
|
|
Did logins change because of the CII-Badges new spam defenses? 2 messages
David, et al, Does the username / password for https://bestpractices.coreinfrastructure.org/ now require it to be done via GitHub? I just tried to login using my Gmail account (which was how I registe
David, et al, Does the username / password for https://bestpractices.coreinfrastructure.org/ now require it to be done via GitHub? I just tried to login using my Gmail account (which was how I registe
|
By Kevin W. Wall
·
|