You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+37-10Lines changed: 37 additions & 10 deletions
Original file line number
Diff line number
Diff line change
@@ -4,19 +4,17 @@
4
4
5
5
Anyone is welcome to join our open discussions related to the group's mission and charter.
6
6
7
-
## Objective
7
+
## Mission
8
8
9
-
Our objective is to provide open source developers with best practices recommendations, and with an easy way to learn and apply them.
9
+
Our Mission is to provide open source developers with security best practices recommendations and easy ways to learn and apply them.
10
10
11
-
Unlike other existing best practices list, we want it to be widely distributed to open source developers and community-sourced. And we want these practices to stick, thanks to an effective learning platform.
11
+
We seek to fortify the open-source ecosystem by championing and embedding best security practices, thereby creating a digital environment where both developers and users can trust and rely on open-source solutions without hesitation.
12
12
13
-
## Vision
14
-
15
-
Our vision is to make it easy for developers to adopt these best practices, thanks to:
16
13
17
-
-_Identifying_ good practices, requirements, and tools that help open source developers create and maintain more secure software
18
-
- Helping maintainers _Learn_ to write secure software
19
-
- Provide tools to help developers _Adopt_ these good practices into their daily work
14
+
## Vision
15
+
- We envision a world where software developers can easily IDENTIFY good practices, requirements and tools that help them create and maintain secure world-class software, helping foster a community where security knowledge is shared and amplified.
16
+
- We seek to provide means to LEARN techniques of writing and identifying secure software using methods best suited to learners of all types.
17
+
- We desire to provide tools to help developers ADOPT these good practices seamlessly into their daily work.
@@ -28,7 +26,36 @@ The Developer Best Practices group wants to help identify and curate an accessib
28
26
- Categorized per technology, language, framework
29
27
- Community-curated
30
28
31
-
Help build a community
29
+
## Strategy
30
+
31
+
To achieve our Mission and Vision, the BEST Working group will execute on the following strategy:
32
+
33
+
- Collaborate with security experts to draft a comprehensive set of best practices tailored for open-source projects.
34
+
- Identify gaps in tools and resources that provide opportunities to promote and implement secure development practices.
35
+
- Evangelize and drive adoption of our artifacts (ex: guides, trainings, tools) through community outreach and targeted maintainer engagement.
36
+
- Collaborate with other OpenSSF and open source efforts to provide comprehensive guidance, advice, and tooling for software developers and open source software consumers to use, implement, and evaluate the security qualities of software.
37
+
38
+
39
+
## Roadmap
40
+
41
+
To deliver on our Strategy, the BEST Working Group will do the following:
42
+
43
+
- Evangelize OpenSSF “best practices” and tooling through blogs, podcasts, conference presentations, and the like.
44
+
-- Create a “Secure from the (open) source” expert podcast to showcase the work across the foundation.
45
+
-- As new guides/best practices are launched, we will create blogs and a conference presentation to raise awareness about it.
46
+
-- Amplify talks and artifacts created by other groups within the foundation
47
+
-- Create 3 EvilTux artifacts each quarter
48
+
- Create express learning classes for our body of work: working group explainer, SCM BP Guide, C/C++ Guide, Scorecard/Badges, Concise Guides
49
+
- Create a “Best Practices Member Badge” for member organizations
50
+
- Support and promote our sub-projects with contributions and feedback - Scorecard, BP Badges, OpenSSF - SkillFoundry, Classes, and Guides, Secure Software Guiding Principles (SSGP)
51
+
- Create a Memory Safety W3C-style workshop to assemble development leaders to talk about how to integrate memory safe languages and techniques more deeply into the oss ecosystem.
52
+
- Expand DEI AMA Office Hours to more broadly engage new-to-oss individuals and provide a forum for mentorship and guidance as they launch into and grow within their careers.
53
+
- Identify, curate, produce, and deliver new secure development education such as Developer Manager Training, Implementing/Integrating OSSF tools such as Scorecard, Badges, OSV, OpenVEX, etc), advanced secure development techniques, and more.
54
+
- On Roadmap above, do we want to commit to taking all of our guides and seeing what makes sense to integrate into Scorecard?
55
+
56
+
57
+
58
+
## Help build a community
32
59
33
60
- Program to attract open source contributors and incentivize them to use and contribute to the inventory
0 commit comments