OpenSSF Open Source Project Security Baseline (OSPS Baseline)
QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-QA-06.01: OSPS-QA-06.01 Use Automated Testing in CI/CD Pipelines

OSPS-QA-06 Use Automated Testing in CI/CD Pipelines (maturity levels 2, 3). Requirement: Prior to a commit being accepted, the project's CI/CD pipelines MUST run at least one automated test suite to ensure the changes meet expectations. Objective of the control: Ensure that the project uses at least one automated test suite for the source code repository and clearly documents when and how tests are run. Recommendation: Automated tests should be run prior to every merge into the primary branch. The test suite should be run in a CI/CD pipeline and the results should be visible to all contributors. The test suite should be run in a consistent environment and should be run in a way that allows contributors to run the tests locally. Examples of test suites include unit tests, integration tests, and end-to-end tests.

Maintained by Gerard Blokdyk

Other controls in QA: Quality – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.