Skip to content

Commit 989e50a

Browse files
authored
Update security_baseline.md
Updated "SHOULD" to "MUST" for Scorecard onboarding for to becoming incubating Signed-off-by: Dana Wang <[email protected]>
1 parent 5145d96 commit 989e50a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

process/security_baseline.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -89,7 +89,7 @@ When the project starts, it's critical to have a security foundation to reduce a
8989

9090
### Baseline - To Become Incubating
9191

92-
As the project codebase grows and more features are added, increasing complexity, it becomes crucial to leverage security tools to identify vulnerabilities in the codebase or dependent software early on. Addressing critical issues early prevents costly fixes in the future. At this stage, projects SHOULD onboard to OpenSSF Scorecard by following the [installation instructions](https://github.com/ossf/scorecard-action#installation) of [Scorecard GitHub Action](https://github.com/ossf/scorecard-action). The Action runs on any repository change and raises alerts. ​​Repository administrators, organization owners, and people with write or maintain access to a repository can view the alerts in the repository’s Security tab. Ensure Scorecard is enabled for the project by following [Scorecard Verify Runs](https://github.com/ossf/scorecard-action?tab=readme-ov-file#verify-runs) instruction.
92+
As the project codebase grows and more features are added, increasing complexity, it becomes crucial to leverage security tools to identify vulnerabilities in the codebase or dependent software early on. Addressing critical issues early prevents costly fixes in the future. At this stage, projects MUST onboard to OpenSSF Scorecard by following the [installation instructions](https://github.com/ossf/scorecard-action#installation) of [Scorecard GitHub Action](https://github.com/ossf/scorecard-action). The Action runs on any repository change and raises alerts. ​​Repository administrators, organization owners, and people with write or maintain access to a repository can view the alerts in the repository’s Security tab. Ensure Scorecard is enabled for the project by following [Scorecard Verify Runs](https://github.com/ossf/scorecard-action?tab=readme-ov-file#verify-runs) instruction.
9393

9494
| Security Baseline | Objective | How to Implement | How to Verify|
9595
|-------|-------|-------|-------|

0 commit comments

Comments
 (0)