OpenSSF Open Source Project Security Baseline (OSPS Baseline)
LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-LE-01.01: OSPS-LE-01.01 Require Code Contributors to Assert Right to Commit

OSPS-LE-01 Require Code Contributors to Assert Right to Commit (maturity levels 2, 3). Requirement: The version control system MUST require all code contributors to assert that they are legally authorized to make the associated contributions on every commit. Objective of the control: Ensure that code contributors are aware of and acknowledge their legal responsibility for the contributions they make to the project, reducing the risk of intellectual property disputes against the project. Recommendation: Include a DCO in the project's repository, requiring code contributors to assert that they are legally authorized to commit the associated contributions on every commit. Use a status check to ensure the assertion is made. A CLA also satisfies this requirement. Some version control systems, such as GitHub, may include this in the platform terms of service. It is understood that projects with a lengthy history prior to adopting OSPS Baseline may not be able to retroactively enforce this requirement.

Maintained by Gerard Blokdyk

Other controls in LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.