Skip to content

Split OSPS-VM-01.01 into two requirements - #555

Open
Satarupa22-SD wants to merge 3 commits into
ossf:mainfrom
Satarupa22-SD:OSPS-VM-01.01
Open

Satarupa22-SD wants to merge 3 commits into
ossf:mainfrom
Satarupa22-SD:OSPS-VM-01.01

Conversation

@Satarupa22-SD

@Satarupa22-SD Satarupa22-SD commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

refer #546

Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>

@funnelfiasco funnelfiasco left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is a case of needing to retire a control and introduce a new one. Ultimately, we're still asking for the same result. The timeframe for response is one required element of the CVD policy

Comment thread baseline/OSPS-VM.yaml Outdated
Comment on lines +23 to +31
Retired in https://github.com/ossf/security-baseline/pull/555
applicability:
- maturity-2
- maturity-3
state: Retired
- id: OSPS-VM-01.02
text: |
The project documentation MUST include a coordinated
vulnerability disclosure (CVD) policy.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can get behind Ben's idea here... We are loosening this slightly, but not changing the meaning. Adding strictness or changing meaning would demand a retirement.

Suggested change
Retired in https://github.com/ossf/security-baseline/pull/555
applicability:
- maturity-2
- maturity-3
state: Retired
- id: OSPS-VM-01.02
text: |
The project documentation MUST include a coordinated
vulnerability disclosure (CVD) policy.
The project documentation MUST include a coordinated
vulnerability disclosure (CVD) policy.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In that case, should i just update the existing control instead of splitting this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I think so. The text should just say "have a policy" and we can include the desired elements in the description.

@evankanderson evankanderson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm with Ben here -- I think this is one check, rather than "is there a policy" and "does the policy contain certain content". More granularity and more checks is not necessarily better, even if we have a few checks which are too big.

Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>
Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants