OpenSSF Open Source Project Security Baseline (OSPS Baseline)
QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-QA-04.01: OSPS-QA-04.01 Enforce Security Requirements on All Codebases

OSPS-QA-04 Enforce Security Requirements on All Codebases (maturity levels 1, 2, 3). Requirement: Projects with multiple repositories MUST document a list of codebases that are part of the project. Objective of the control: Ensure that all codebases produced by the project are well documented and held to the same security standard. Recommendation: Document any additional subproject code repositories produced by the project and compiled into a release. This documentation should include the status and intent of the respective codebase.

Maintained by Gerard Blokdyk

Other controls in QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.