Pinned Repositories
great-mfa-project
Memory-Safety
oss-vulnerability-guide
A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
presentations
Presentations CRob has given over the years
sbom-everywhere
Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
scorecard
OpenSSF Scorecard - Security health metrics for Open Source
security-baseline
SIRT
OSS-SIRT SIG
SecurityCRob's Repositories
SecurityCRob/presentations
Presentations CRob has given over the years
SecurityCRob/security-baseline
SecurityCRob/great-mfa-project
SecurityCRob/Memory-Safety
SecurityCRob/oss-vulnerability-guide
A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
SecurityCRob/sbom-everywhere
Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
SecurityCRob/scorecard
OpenSSF Scorecard - Security health metrics for Open Source
SecurityCRob/SIRT
OSS-SIRT SIG
SecurityCRob/slf4j
Simple Logging Facade for Java
SecurityCRob/wg-best-practices-oss-developers
OSSF Working group: secure code best practices for open source developers
SecurityCRob/wg-digital-identity-attestation
Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
SecurityCRob/wg-identifying-security-threats
The purpose of the Identifying Security Threats working group is to enable stakeholders to have informed confidence in the security of open source projects. We do this by collecting, curating, and communicating relevant metrics and metadata from open source projects and the ecosystems of which they are a part.
SecurityCRob/wg-securing-critical-projects
Helping allocate resources to secure the critical open source projects we all depend on.
SecurityCRob/wg-vulnerability-disclosures
Our vision is an open source software ecosystem where the time to fix a vulnerability and deploy that fix across the ecosystem is measured in minutes, not months.