OpenSSF Open Source Project Security Baseline (OSPS Baseline)
DO: Documentation – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-DO-04.01: OSPS-DO-04.01 Publish Support Scope and Duration

OSPS-DO-04 Publish Support Scope and Duration (maturity level 3). Requirement: When the project has made a release, the project documentation MUST include a descriptive statement about the scope and duration of support for each release. Objective of the control: Provide users with clear expectations regarding the project's support lifecycle in such a way that enables downstream consumers to ensure the continued functionality and security of their systems. Recommendation: In order to communicate the scope and duration of support for the project's released software assets, the project should have a SUPPORT.md file, a "Support" section in SECURITY.md, or other documentation explaining the support lifecycle, including the expected duration of support for each release, the types of support provided (e.g., bug fixes, security updates), and any relevant policies or procedures for obtaining support.

Maintained by Gerard Blokdyk

Other controls in DO: Documentation – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.