OpenSSF Open Source Project Security Baseline (OSPS Baseline)
LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-LE-02.01: OSPS-LE-02.01 Ensure Project Licenses are Fully Open Source

OSPS-LE-02 Ensure Project Licenses are Fully Open Source (maturity levels 1, 2, 3). Requirement: The license for the source code MUST meet the OSI Open Source Definition or the FSF Free Software Definition. Objective of the control: Ensure that the project's source code is distributed under a recognized and legally enforceable open source software license, providing clarity on how the code can be used and shared by others. Recommendation: Add a LICENSE file to the project's repo with a license that is an approved license by the Open Source Initiative (OSI), or a free license as approved by the Free Software Foundation (FSF). Examples of such licenses include the MIT, BSD 2-clause, BSD 3-clause revised, Apache 2.0, Lesser GNU General Public License (LGPL), and the GNU General Public License (GPL). Releasing to the public domain meets this control if there are no other encumbrances such as patents.

Maintained by Gerard Blokdyk

Other controls in LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.