OpenSSF publication
OSPS Baseline
The Open Source Project Security Baseline — a consensus-driven minimum set of security requirements for projects to adopt and for consumers to expect.
How each persona uses OSPS Baseline
Software Developer / Maintainer Developer
Adopts the OSPS Baseline to implement fundamental security steps, like secure workflows and disclosure policies, early in development.
Open Source Professional (OSPO) OSPO
Uses the OSPS Baseline to define and enforce security expectations for projects across the enterprise.
Security Engineer / Architect Security
Integrates the OSPS Baseline to enforce structured security requirements and reduce defects early in the software creation phase.
CI/CD DevOps & Tooling Integrator DevOps
Configures pipeline guardrails to automatically verify that projects adhere to the fundamental practices outlined in the baseline.
Package & Repository Manager Package Manager
Requires adherence to the baseline as a prerequisite for verifying or promoting packages within the repository ecosystem.
Executive / End-User Consumer Executive
Adopts the structured baseline to ensure organizational compliance with policies and regulations like the Cyber Resilience Act.
Problems OSPS Baseline helps with
Policy & Compliance Enforcement Compliance
Provides a consensus minimum set of requirements that maps cleanly onto regulations like the Cyber Resilience Act.
Measuring Security Posture Posture
Defines the floor of expected security practices so projects can be measured against a shared bar.