From 8a7eb68e0440960cf2dbb891e5a22c839ac06155 Mon Sep 17 00:00:00 2001 From: CRob <69357996+SecurityCRob@users.noreply.github.com> Date: Mon, 27 Nov 2023 10:38:40 -0500 Subject: [PATCH] Update TI-Gives+Gets.md more lining Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com> --- process/TI-Gives+Gets.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/process/TI-Gives+Gets.md b/process/TI-Gives+Gets.md index 9bb198c1..e29309a6 100644 --- a/process/TI-Gives+Gets.md +++ b/process/TI-Gives+Gets.md @@ -30,8 +30,8 @@ In exchange for meeting certain requirements, the TIs are eligible to receive an | TI must have documented, initial group governance. | With additional TAC or WG approval, may fundraise for dedicated project funds, coordinated by the OpenSSF. | | Maintains a point of contact for vulnerability reports in the security.md | Receives support with vulnerability disclosure from the OpenSSF (Vulnerability Disclosure WG). | | Implements, practices, and refines mature software development and release practices such as following a version schema. | -| TI Follows security best practices (as recommended by the OpenSSF and others), including passing the OpenSSF Best Practices criteria | | -| Project should be integrating with Scorecards | May post project updates and tutorials to the OpenSSF blog. | | +| TI Follows security best practices (as recommended by the OpenSSF and others), including passing the OpenSSF Best Practices criteria | May post project updates and tutorials to the OpenSSF blog. | +| Project should be integrating with Scorecards | | | Begins to establish the appropriate governance that enables its sustainment for potential graduation.| | | Projects should be Securing Code Repository -> Managing Contributions Commit Signing , Secret Scanning, Code Scanning (OSFUZZ at a minimum) + Self-assessment Should OpenSSF require these if the SCM supports it, especially using Sigstore? | |