Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-11 Thread Sebastien Lorquet
Being cheeky here, but these are only good if we enforce these, and if they are actually enforceable :) Self-certification is considered a joke in many industrial places :) Also, as an open source project, we are protected by the apache licence, which says that we offer no warranty. The euro

Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-10 Thread Alin Jerpelea
Hi Sebastien, we will keep the discusion open here, until next week, then I will propose a vote and we can proceed with the details how we implement it(if there is interest and the vote passes) Best regards Alin On Mon, 10 Feb 2025, 18:15 Sebastien Lorquet, wrote: > Hi, > > Good point, it is i

Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-10 Thread Tomek CEDRO
On Mon, Feb 10, 2025 at 10:14 AM Alin Jerpelea wrote: > Hi all, > I was considering to apply to the Open SSF Best practice badge > https://www.bestpractices.dev/en > this badge should should allow us to show that we use best practices in an > OSS project > Are there any concerns? Let's discuss Ve

Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-10 Thread Sebastien Lorquet
Hi, Good point, it is interesting as a checklist, that is right. The list is here, BTW: https://www.bestpractices.dev/en/criteria/0 it's long! Glancing at it "in diagonal" as we say in french, it seems that we're doing stuff in all these categories. But the devil is in the detail and checkin

Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-10 Thread Alin Jerpelea
Hi Sebastian, don't you think that such checklist would help identify the issues and help us fix them? Best regards Alin On Mon, 10 Feb 2025, 17:16 Sebastien Lorquet, wrote: > Hello > > I have obvious concerns that I will not repeat here. > > We could apply to this once the current management

Re: [DISCUSS] OpenSSF Best Practices Badge Program

2025-02-10 Thread Sebastien Lorquet
Hello I have obvious concerns that I will not repeat here. We could apply to this once the current management issues are resolved, as I think they will. Sebastien On 10/02/2025 10:12, Alin Jerpelea wrote: Hi all, I was considering to apply to the Open SSF Best practice badge https://www.b