OpenSSF Open Source Project Security Baseline (OSPS Baseline)
BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-BR-02.02: OSPS-BR-02.02 Assign Unique Version Identifiers

OSPS-BR-02 Assign Unique Version Identifiers (maturity level 3). Requirement: When an official release is created, all assets within that release MUST be clearly associated with the release identifier or another unique identifier for the asset. Objective of the control: Ensure that each software asset produced by the project is uniquely identified, enabling users to track changes and updates to the project over time. Recommendation: Assign a unique version identifier to each software asset produced by the project, following a consistent naming convention or numbering scheme. Examples include SemVer, CalVer, or git commit id.

Maintained by Gerard Blokdyk

Other controls in BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.