OpenSSF Open Source Project Security Baseline (OSPS Baseline)
DO: Documentation – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-DO-02.01: OSPS-DO-02.01 Provide Mechanisms for Reporting Defects

OSPS-DO-02 Provide Mechanisms for Reporting Defects (maturity levels 1, 2, 3). Requirement: When the project has made a release, the project documentation MUST include a guide for reporting defects. Objective of the control: Enable users and contributors to report defects or issues with the released software assets, facilitating communication and collaboration on defect fixes and improvements. Recommendation: It is recommended that projects use their VCS default issue tracker. If an external source is used, ensure that the project documentation and contributing guide clearly and visibly explain how to use the reporting system. It is recommended that project documentation also sets expectations for how defects will be triaged and resolved.

Maintained by Gerard Blokdyk

Other controls in DO: Documentation – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.