OpenSSF publication

OSPS Baseline

The Open Source Project Security Baseline — a consensus-driven minimum set of security requirements for projects to adopt and for consumers to expect.

How each persona uses OSPS Baseline

Software Developer / Maintainer Developer

Adopts the OSPS Baseline to implement fundamental security steps, like secure workflows and disclosure policies, early in development.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Uses the OSPS Baseline to define and enforce security expectations for projects across the enterprise.

See everything for OSPO →

Security Engineer / Architect Security

Integrates the OSPS Baseline to enforce structured security requirements and reduce defects early in the software creation phase.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Configures pipeline guardrails to automatically verify that projects adhere to the fundamental practices outlined in the baseline.

See everything for DevOps →

Package & Repository Manager Package Manager

Requires adherence to the baseline as a prerequisite for verifying or promoting packages within the repository ecosystem.

See everything for Package Manager →

Executive / End-User Consumer Executive

Adopts the structured baseline to ensure organizational compliance with policies and regulations like the Cyber Resilience Act.

See everything for Executive →

Problems OSPS Baseline helps with

Policy & Compliance Enforcement Compliance

Provides a consensus minimum set of requirements that maps cleanly onto regulations like the Cyber Resilience Act.

See everything for Compliance →

Measuring Security Posture Posture

Defines the floor of expected security practices so projects can be measured against a shared bar.

See everything for Posture →