OpenSSF Open Source Project Security Baseline (OSPS Baseline)
QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-QA-05.01: OSPS-QA-05.01 Prevent Executables in the Codebase

OSPS-QA-05 Prevent Executables in the Codebase (maturity levels 1, 2, 3). Requirement: The version control system MUST NOT contain generated executable artifacts. Objective of the control: Reduce the risk of including generated executable artifacts in the project's version control system, ensuring that only source code and necessary files are stored in the repository. Recommendation: Remove generated executable artifacts in the project's version control system. It is recommended that any scenario where a generated executable artifact appears critical to a process such as testing, it should be instead be generated at build time or stored separately and fetched during a specific well-documented pipeline step.

Maintained by Gerard Blokdyk

Other controls in QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.