Skip to content

OpenSSF Gold: track the two externally-gated criteria (unassociated contributors, security review) #220

Description

@IngmarVG-IB

Tracking issue for the two Gold criteria that can't be closed by engineering work alone (execution plan: docs/proposals/openssf-best-practices.md, PR #216):

contributors_unassociated (Gold MUST)

Requires two significant contributors not associated with the same organization. Current state: all three maintainers are Infoblox-affiliated; 210 of ~221 human commits are from one person. Candidates exist in the pipeline (IETF draft co-authors, ARD-ecosystem developers).

  • Review candidate progress at each release
  • good first issue labels maintained to feed the pipeline (Gold small_tasks)
  • Aligns with the LF-graduation goals in MAINTAINERS.md (external maintainer, second org)

security_review (Gold MUST)

Decided route: Infoblox product-security team review, with reviewers independent of the dev team. Scope: the assurance case (docs/security/assurance-case.md, PR #217), SSRF/input-validation paths, DNSSEC/DANE trust handling, release pipeline.

  • Request review from Infoblox product security (owner: @ivanglabbeek)
  • Written report linked from SECURITY.md; findings triaged as issues

Everything else on the Gold list is covered by PRs #217/#218, the coverage push, and org settings (require-2FA, enforce_admins — the latter already enabled).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions