Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

OpenSSF Releases Security Baseline for Open Source Projects

The Open Source Security Foundation (OpenSSF) has created a structured set of security requirements for open source projects.

Vulnerability

The Linux Foundation’s Open Source Security Foundation (OpenSSF) on Tuesday announced the initial release of a project designed to establish minimum security requirements for open source software.

Named Open Source Project Security Baseline, or OSPS Baseline, the initiative aims to enhance the security of open source projects by providing guidance on implementing a minimum set of best practices aimed at reducing the risk of vulnerabilities and improving a project’s trustworthiness.

The OSPS Baseline is a security checklist that is based on guidance from OpenSSF and other groups. It outlines tasks, artifacts, processes and configurations, and it has been described by its developers as a tiered framework that grows alongside a project.

The baseline can help developers understand others’ expectations in terms of security. It can also be useful for marketing purposes — users are more likely to adopt a project that takes security seriously. 

Unless required by a sponsor to meet a specific baseline level, all projects are encouraged to achieve at least level 1 requirements, which establish what OSSF describes as a “universal security floor” for open source projects.

Projects that have a large number of regular users are advised to adhere to level 3, which is the top tier. 

Advertisement. Scroll to continue reading.

Level 1 includes the use of MFA, requirements related to whom and how they can contribute to a project, release and licensing requirements, as well as issues related to version control and project documentation. 

Level 3 focuses more on privilege management, releases and project documentation, and testing.

“The Open Source Project Security Baseline is a vital tool for enhancing the security of open source projects,” said Per Beming, chief standardization officer at Ericsson. “By offering a comprehensive set of actionable measures, the Security Baseline provides effective guidance for all stakeholders in the open source ecosystem – manufacturers, stewards, and projects alike – to collaboratively assume responsibility and take meaningful steps to secure the open source supply chain on which we all rely.”

The OSPS Baseline is maintained by a special interest group, but all stakeholders are encouraged to contribute to refining the framework, as well as to promote its use. 

Related: Cyber Insights 2025: Open Source and Software Supply Chain Security

Related: Google Open Sources Security Patch Validation Tool for Android

Related: Google Releases Open Source Library for Software Composition Analysis

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.