OpenSSF Open Source Project Security Baseline (OSPS Baseline)
LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-LE-03.01: OSPS-LE-03.01 Maintain and Release Licenses in a Well Known Location

OSPS-LE-03 Maintain and Release Licenses in a Well Known Location (maturity levels 1, 2, 3). Requirement: The license for the source code MUST be maintained in the corresponding repository's LICENSE file, COPYING file, LICENSES/ directory, or LICENSE/ directory. Objective of the control: Ensure that the project's source code and released software assets are distributed with the appropriate license terms, making it clear to users and contributors how each can be used and shared. Recommendation: Include the project's source code license in the project's LICENSE file, COPYING file, LICENSES/ directory, or LICENSE/ directory to provide visibility and clarity on the licensing terms. The filename MAY have an extension. If the project has multiple repositories, ensure that each repository includes the license file.

Maintained by Gerard Blokdyk

Other controls in LE: Legal – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.