Skip to content

Update baseline rule naming based on 2025-02-25 #339

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 24, 2025

Conversation

evankanderson
Copy link
Member

The 2025-02-25 baseline renamed rules from the format OSPS-{CATEGORY}-{NUMBER} to OSPS-{CATEGORY}-{NUMBER}.{SUB-NUMBER}, and adjusted many of the rule numbers. Update the current rules to the same naming scheme, and fill gaps where possible (e.g. AC-01.01 and QA-04.01 are not currently achievable -- AC-01.01 needs an "organization" object, and it's not clearly defined how to tell if a project is "complete").

Removed controls from Baseline Level between 31 Jan 2025 and 25 Feb 2025:

* OSPS-BR-09: Released software assets are delivered using HTTPS

  Entirely removed

* OSPS-DO-13: the project documentation MUST include a descriptive statement about the scope and duration of support for each release

  Moved to level 3 (kept ruletype, removed from baseline profile)

@evankanderson evankanderson requested a review from a team as a code owner July 23, 2025 20:12
@evankanderson evankanderson merged commit 98d0a63 into mindersec:main Jul 24, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants