generated from ossf/project-template
-
Notifications
You must be signed in to change notification settings - Fork 28
Closed
Labels
enhancementNew feature or requestNew feature or request
Description
The security baseline has requirement "A dependencies policy is published, maintained and followed." for a project to become incubating. To ease the burden from adopting the baseline, I'm proposing adding a dependency policy file to project-template. When a new repo is created using the project template, the repo will have a default dependency policy file to use right away, or customize it when needed.
For existing repos, I'm proposing adding dependency policy file as a default community health file to organizations' .github.
The dependency policy will use the Concise Guide for Evaluating Open Source Software
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request