Skip to content

Commit

Permalink
docs: Clarify OpenSSF Best Practices vs Scorecard
Browse files Browse the repository at this point in the history
that actually documents OpenSSF Best Practices. Scorecard [0] is a
different OpenSSF project, that incorporates Best Practices, but is
distinct in its objectives and how it achieves them.
This change clarifies the terminology, and also removes any
implication that Gold Best Practices is an award rather than a self
certification programme.
As curl was a leader in implementing Best Practices some folk may be
more familiar with the earlier Core Infrastructure Initiative (CII)
naming, so a reference to that has been added.

[0] https://scorecard.dev/

Signed-off-by: Chris Swan <478926+cpswan@users.noreply.github.com>
Ref: curl#14319
  • Loading branch information
cpswan committed Aug 21, 2024
1 parent 3065f10 commit 772cc4f
Showing 1 changed file with 12 additions and 10 deletions.
22 changes: 12 additions & 10 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,13 +15,15 @@ libcurl, report it on [HackerOne](https://hackerone.com/curl).

We treat security issues with confidentiality until controlled and disclosed responsibly.

## OpenSSF Scorecard

curl has earned Gold status on the OpenSSF Best Practices, reflecting its adherence to
rigorous security and best practice standards. This achievement highlights curl's
comprehensive documentation, secure development processes, effective change control
mechanisms, and strong maintenance routines. Meeting these criteria demonstrates curl's
commitment to security and reliability, ensuring the project's sustainability and
trustworthiness. This recognition by OpenSSF underscores curl's role as a leader in
open-source software practices. More information can be found on
their [OpenSSF page](https://www.bestpractices.dev/projects/63).
## OpenSSF Best Practices

curl has achieved Gold status on the Open Source Security Foundation (OpenSSF)
[Best Practices](https://bestpractices.dev/) (formerly Core Infrasturcture
Inititative [CII] Best Practices), reflecting its adherence to rigorous
security and best practice standards. This achievement highlights curl's
comprehensive documentation, secure development processes, effective change
control mechanisms, and strong maintenance routines. Meeting these criteria
demonstrates curl's commitment to security and reliability, ensuring the
project's sustainability and trustworthiness. This underscores curl's role as
a leader in open-source software practices. More information can be found on
[curl's OpenSSF Best Practices project page](https://www.bestpractices.dev/projects/63).

0 comments on commit 772cc4f

Please sign in to comment.