Skip to content

Commit 8a135a2

Browse files
authored
Update README.md
updated group-approved MVSR Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
1 parent 312bb4d commit 8a135a2

File tree

1 file changed

+37
-10
lines changed

1 file changed

+37
-10
lines changed

README.md

Lines changed: 37 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -4,19 +4,17 @@
44

55
Anyone is welcome to join our open discussions related to the group's mission and charter.
66

7-
## Objective
7+
## Mission
88

9-
Our objective is to provide open source developers with best practices recommendations, and with an easy way to learn and apply them.
9+
Our Mission is to provide open source developers with security best practices recommendations and easy ways to learn and apply them.
1010

11-
Unlike other existing best practices list, we want it to be widely distributed to open source developers and community-sourced. And we want these practices to stick, thanks to an effective learning platform.
11+
We seek to fortify the open-source ecosystem by championing and embedding best security practices, thereby creating a digital environment where both developers and users can trust and rely on open-source solutions without hesitation.
1212

13-
## Vision
14-
15-
Our vision is to make it easy for developers to adopt these best practices, thanks to:
1613

17-
- _Identifying_ good practices, requirements, and tools that help open source developers create and maintain more secure software
18-
- Helping maintainers _Learn_ to write secure software
19-
- Provide tools to help developers _Adopt_ these good practices into their daily work
14+
## Vision
15+
- We envision a world where software developers can easily IDENTIFY good practices, requirements and tools that help them create and maintain secure world-class software, helping foster a community where security knowledge is shared and amplified.
16+
- We seek to provide means to LEARN techniques of writing and identifying secure software using methods best suited to learners of all types.
17+
- We desire to provide tools to help developers ADOPT these good practices seamlessly into their daily work.
2018

2119
<img align="top" src="https://github.com/ossf/wg-best-practices-os-developers/blob/main/img/OpenSSF%20Dev%20Best%20Practices%20Projects%20Relations.png">
2220

@@ -28,7 +26,36 @@ The Developer Best Practices group wants to help identify and curate an accessib
2826
- Categorized per technology, language, framework
2927
- Community-curated
3028

31-
Help build a community
29+
## Strategy
30+
31+
To achieve our Mission and Vision, the BEST Working group will execute on the following strategy:
32+
33+
- Collaborate with security experts to draft a comprehensive set of best practices tailored for open-source projects.
34+
- Identify gaps in tools and resources that provide opportunities to promote and implement secure development practices.
35+
- Evangelize and drive adoption of our artifacts (ex: guides, trainings, tools) through community outreach and targeted maintainer engagement.
36+
- Collaborate with other OpenSSF and open source efforts to provide comprehensive guidance, advice, and tooling for software developers and open source software consumers to use, implement, and evaluate the security qualities of software.
37+
38+
39+
## Roadmap
40+
41+
To deliver on our Strategy, the BEST Working Group will do the following:
42+
43+
- Evangelize OpenSSF “best practices” and tooling through blogs, podcasts, conference presentations, and the like.
44+
-- Create a “Secure from the (open) source” expert podcast to showcase the work across the foundation.
45+
-- As new guides/best practices are launched, we will create blogs and a conference presentation to raise awareness about it.
46+
-- Amplify talks and artifacts created by other groups within the foundation
47+
-- Create 3 EvilTux artifacts each quarter
48+
- Create express learning classes for our body of work: working group explainer, SCM BP Guide, C/C++ Guide, Scorecard/Badges, Concise Guides
49+
- Create a “Best Practices Member Badge” for member organizations
50+
- Support and promote our sub-projects with contributions and feedback - Scorecard, BP Badges, OpenSSF - SkillFoundry, Classes, and Guides, Secure Software Guiding Principles (SSGP)
51+
- Create a Memory Safety W3C-style workshop to assemble development leaders to talk about how to integrate memory safe languages and techniques more deeply into the oss ecosystem.
52+
- Expand DEI AMA Office Hours to more broadly engage new-to-oss individuals and provide a forum for mentorship and guidance as they launch into and grow within their careers.
53+
- Identify, curate, produce, and deliver new secure development education such as Developer Manager Training, Implementing/Integrating OSSF tools such as Scorecard, Badges, OSV, OpenVEX, etc), advanced secure development techniques, and more.
54+
- On Roadmap above, do we want to commit to taking all of our guides and seeing what makes sense to integrate into Scorecard?
55+
56+
57+
58+
## Help build a community
3259

3360
- Program to attract open source contributors and incentivize them to use and contribute to the inventory
3461

0 commit comments

Comments
 (0)