Skip to content

Implement OSPS-VM-05 #35

@eddie-knight

Description

@eddie-knight

The following test requirements need to be implemented:

  • While active, the project documentation MUST include a policy that defines a threshold for remediation of SCA findings related to vulnerabilities and licenses.
  • While active, the project documentation MUST include a policy to address SCA violations prior to any release.
  • While active, all changes to the project's codebase MUST be automatically evaluated against a documented policy for malicious dependencies and known vulnerabilities in dependencies, then blocked in the event of violations, except when declared and suppressed as non-exploitable.

OSPS-VM-05 Docs

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions