March 11, 2025
OpenSSF creates Project Security Baseline
The Open Source Security Foundation (OpenSSF) has created a Project Security Baseline that helps open source projects of all sizes ensure that their efforts are secure. The baseline defines a minimum set of requirements for application security that developers can do to enforce secure development practices, such as how they need to configure their tools and infrastructure to ensure the integrity, confidentiality and availability of their work. According to Chris “CRob” Robinson, chief security architect at OpenSSF, there are three tiers to the baseline, depending on the number of contributors and maintainers. “Dozens of open source projects, when you think