What's in the SOSS? An OpenSSF Podcast

A Deep Dive into the Open Source Project Security (OSPS) Baseline

9 snips
Nov 4, 2025
Ben Cotton, Open Source Community Lead at Kusari, and Eddie Knight, Security Compliance Specialist at Sonatype, dive into the Open Source Project Security Baseline. They discuss how this baseline provides a framework for enhancing software security and simplifying requirements for maintainers. The GUAC case study showcases its real-world application, while the importance of documentation in securing software deployment is emphasized. Future directions focus on improving tooling and community engagement, allowing for continued refinement and increased confidence in open source projects.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Baseline Defines Project Security Hygiene

  • The OSPS Baseline defines security hygiene for open source projects focused on build practices rather than product quality.
  • It uses three tiers so projects can claim a clear, common security level (e.g., Level 1, 2, 3).
ADVICE

Make Controls Mandatory, Not Aspirational

  • Do focus on 'must' controls rather than a long wishlist to avoid overwhelming maintainers.
  • Provide a succinct, mandatory checklist so volunteers can implement practical security tasks quickly.
INSIGHT

Common Language Bridges Maintainers And Vendors

  • A common language (baseline levels) helps maintainers and vendors align security expectations.
  • Vendors can request a baseline level and give specific tasks to help projects reach it.
Get the Snipd Podcast app to discover more snips from this episode
Get the app