Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature: Document policies and processes #31

Open
pawamoy opened this issue Jul 9, 2024 · 0 comments
Open

feature: Document policies and processes #31

pawamoy opened this issue Jul 9, 2024 · 0 comments
Labels
feature New feature or request fund Issue priority can be boosted

Comments

@pawamoy
Copy link
Owner

pawamoy commented Jul 9, 2024

Taken from the Tidelift survey:

  • Formal processes or standards to verify all contributors
  • Provide fixes and recommendations for vulnerabilities
  • Static code analysis
  • Disclosure plan on how you should be contacted about security issues
  • Dynamic code analysis
  • Third-party security audits
  • Two-factor authentication for source code hosting and package managers
  • Secure build tooling
  • Signed releases and published artifact provenance
  • Secrets management

Also:

  • Formal policy about backwards compatibility
  • Formal processes or standards to prioritize the order in which pull requests and issues are addressed
  • Reproducible and verifiable build processes
  • Defined dependency management process
  • Code peer review process with multiple reviewers
  • Formal processes or standards to verify all new contributors

Also:

  • Clearly defined process for conflict resolution
  • Published code of conduct
  • Documented release notes and upgrade considerations
  • Published contributor guide
  • Continuance or succession plan in case you or other maintainers leave the project
  • Clearly documented open source license

Boost priority

  • Boost priority in our backlog through Polar.sh. Higher pledge, higher priority.
  • Minimum pledge by user/organization is $5, minimum amount for boost is $30.
  • View all issues with pledges.
  • We receive the funds once the issue is completed and confirmed by you.
  • Features with the insiders label are released to sponsors first, and tied to a funding goal.
Fund with Polar
@pawamoy pawamoy added feature New feature or request fund Issue priority can be boosted labels Oct 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature New feature or request fund Issue priority can be boosted
Projects
None yet
Development

No branches or pull requests

1 participant