Update baseline rule naming based on 2025-02-25 #339
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The 2025-02-25 baseline renamed rules from the format
OSPS-{CATEGORY}-{NUMBER}
toOSPS-{CATEGORY}-{NUMBER}.{SUB-NUMBER}
, and adjusted many of the rule numbers. Update the current rules to the same naming scheme, and fill gaps where possible (e.g. AC-01.01 and QA-04.01 are not currently achievable -- AC-01.01 needs an "organization" object, and it's not clearly defined how to tell if a project is "complete").Removed controls from Baseline Level between 31 Jan 2025 and 25 Feb 2025:
* OSPS-BR-09: Released software assets are delivered using HTTPS
Entirely removed
* OSPS-DO-13: the project documentation MUST include a descriptive statement about the scope and duration of support for each release
Moved to level 3 (kept ruletype, removed from baseline profile)