OpenSSF Open Source Project Security Baseline (OSPS Baseline)
BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-BR-03.01: OSPS-BR-03.01 Use Encrypted Channels for Development & Release Activity

OSPS-BR-03 Use Encrypted Channels for Development & Release Activity (maturity levels 1, 2, 3). Requirement: When the project lists a URI as an official project channel, that URI MUST be exclusively delivered using encrypted channels. Objective of the control: Protect the confidentiality and integrity of project source code during development, reducing the risk of eavesdropping or data tampering. Recommendation: Configure the project's websites and version control systems to use encrypted channels such as SSH or HTTPS for data transmission. Ensure all tools and domains referenced in project documentation can only be accessed via encrypted channels.

Maintained by Gerard Blokdyk

Other controls in BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.