OpenSSF Open Source Project Security Baseline (OSPS Baseline)
QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-QA-04.02: OSPS-QA-04.02 Enforce Security Requirements on All Codebases

OSPS-QA-04 Enforce Security Requirements on All Codebases (maturity level 3). Requirement: When the project has made a release comprising multiple source code repositories, all subprojects MUST enforce security requirements that are as strict or stricter than the primary codebase. Objective of the control: Ensure that all codebases produced by the project are well documented and held to the same security standard. Recommendation: Any additional subproject code repositories produced by the project and compiled into a release must enforce security requirements as applicable to the status and intent of the respective codebase. In addition to following the corresponding OSPS Baseline requirements, this may include requiring a security review, ensuring that it is free of vulnerabilities, and ensuring that it is free of known security issues.

Maintained by Gerard Blokdyk

Other controls in QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.