
What's in the SOSS? An OpenSSF Podcast A Deep Dive into the Open Source Project Security (OSPS) Baseline
9 snips
Nov 4, 2025 Ben Cotton, Open Source Community Lead at Kusari, and Eddie Knight, Security Compliance Specialist at Sonatype, dive into the Open Source Project Security Baseline. They discuss how this baseline provides a framework for enhancing software security and simplifying requirements for maintainers. The GUAC case study showcases its real-world application, while the importance of documentation in securing software deployment is emphasized. Future directions focus on improving tooling and community engagement, allowing for continued refinement and increased confidence in open source projects.
AI Snips
Chapters
Transcript
Episode notes
Baseline Defines Project Security Hygiene
- The OSPS Baseline defines security hygiene for open source projects focused on build practices rather than product quality.
- It uses three tiers so projects can claim a clear, common security level (e.g., Level 1, 2, 3).
Make Controls Mandatory, Not Aspirational
- Do focus on 'must' controls rather than a long wishlist to avoid overwhelming maintainers.
- Provide a succinct, mandatory checklist so volunteers can implement practical security tasks quickly.
Common Language Bridges Maintainers And Vendors
- A common language (baseline levels) helps maintainers and vendors align security expectations.
- Vendors can request a baseline level and give specific tasks to help projects reach it.
