Skip to content

Security Best Practices Checklist and Advice for those looking to determine best steps for security of their project

License

Notifications You must be signed in to change notification settings

ostif-org/best-practices-guide

Repository files navigation

Security Best Practices Guide

Who is this for?

This document is to help those maintainers, developers, or project managers looking to take first steps in securing their project. Ideally, adhering to best practices can address low-hanging security issues, harden against basic vulnerability exploits, and streamline project management, therefore decreasing liability to bad actors and improving transparency with your users and community.

While following best practices should help improve your project’s overall security health, they are not intended to replace security efforts like audits, bug bounties, or tooling. This document, outlining community recommended security practices, functions as an initial launching point to provide context and education on security measures for projects. As a project is living and always changing, so is this document. This self-assessment is a collaborative contribution started by the Open Source Technology Improvement Fund (OSTIF) and contributed by the community of security auditors, cybersecurity professionals, and maintainers from the open source world. If you would like to contribute, see CONTRIB.

Chapters

  1. Introduction
  2. A private security reporting pipeline with a designated handler
  3. Internal Vulnerability Response Policies
  4. Follow best practices for development, build pipelines, etc.
  5. Up to Date Security (CVEs, necessary patches, etc)
  6. Updated Knowledgebase keeping track of security efforts, access privileges, etc.
  7. Milestones in mind for when you need to increase security efforts (e.g. harden further, get an audit, etc)
  8. What to do next

Contributors

About

Security Best Practices Checklist and Advice for those looking to determine best steps for security of their project

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published