typo3-upgrade-effort-model-skill

遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。

没有一套可以保证软件永远不会有缺陷或漏洞的做法;如果规范或假设是错误的,即使合适的方法也可能失败。也没有哪些做法可以保证一个项目能够维持健康和运作良好的开发者社区。但是,遵循最佳做法可以帮助改善项目的成果。例如,一些做法可以在发布之前进行多人评估,这可以帮助您找到其他难以找到的技术漏洞,并帮助建立信任,并希望不同公司的开发人员之间进行重复的交互。要获得徽章,必须满足所有“必须”和“禁止”的条款,满足所有“应该”条款或有合适的理由,和所有“建议”条款必须满足或未满足(至少希望考虑)。欢迎通过 GitHub网站创建问题或提出请求进行反馈。另外还有一个一般讨论邮件列表。

如果这是您的项目,请在您的项目页面上显示您的徽章状态!徽章状态如下所示: 项目15075的徽章级别为in_progress 这里是如何嵌入它:
您可以通过将其嵌入在您的Markdown文件中:
[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/15075/badge)](https://www.bestpractices.dev/projects/15075)
或将其嵌入到HTML中来显示您的徽章状态:
<a href="https://www.bestpractices.dev/projects/15075"><img src="https://www.bestpractices.dev/projects/15075/badge"></a>


这些是通过级别条款。您还可以查看白银或黄金级别条款。

Baseline Series: 基准等级1 基准等级2 基准等级3

        

 基本 13/13 ●

 变更控制 8/9 ●

 报告 7/8 ●

 质量 11/13 ●

 安全 12/16 ●

  • 安全开发知识


    该项目必须至少有一个主要开发人员知道如何设计安全软件。 [know_secure_design]
    这需要了解以下设计原则,包括 Saltzer和Schroeder 中的8项原则:
    • 机制经济(保持设计简单实用,例如采用彻底简化)
    • 故障安全默认(默认情况下,访问决策应拒绝),项目安装应默认安全)
    • 完全仲裁(必须检查每个可能被限制的访问权限,并且不可绕过)
    • 开放式设计(安全机制不应该依赖于攻击者对其设计的无知,而应该更容易地保护和更改信息,例如密钥和密码)
    • 特权分离(理想情况下,对重要对象的访问应该取决于多个条件,从而破坏一个保护系统将无法实现完全访问。如,多因子身份验证,要求密码和硬件令牌,比单因子认证安全性更高)
    • 最小权限(进程应该以最少的权限运行)
    • 最少的公共机制(设计应该最大限度地减少所有用户所依赖的,涉及到多个用户的共同机制,如,临时文件的目录)
    • 心理可接受性(人机接口必须设计为易于使用 —— 设计为“最不惊讶”)
    • 有限的攻击面(攻击面 —— 一组不同的入口,其​​中攻击者可以尝试输入或提取数据 —— 应该受到限制)
    • 输入验证与白名单(输入通常应该在被接受之前检查以确定是否有效;此验证应使用白名单(仅接受已知的有效值),而不是黑名单(尝试列出已知的非法值))。
    项目中的“主要开发人员”的定义是熟悉项目代码的任何人,很乐意对其进行更改,并被项目中大多数其他参与者确认。主要开发人员通常会在过去一年中通过代码,文档或回答问题提供一些贡献。开发人员通常被认为是主要开发人员,如果他们启动项目(并且还没有离开项目满三年),可以选择在私人漏洞报告渠道(如果有的话)上接收信息,可以代表项目接受提交,或执行项目软件的最终版本发布。如果只有一个开发者,那个人是主要开发人员。

    Repository security guidance and automation do not establish the required knowledge of a named primary developer. A maintainer must confirm secure-design principles and common relevant error/mitigation knowledge. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/CONTRIBUTING.md https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md



    该项目的主要开发人员中,至少有一个必须知道导致这类型软件漏洞的常见错误类型,以及至少有一种方法来对付或缓解这些漏洞。 [know_common_errors]
    示例(取决于软件的类型)包括SQL注入,操作系统注入,经典缓冲区溢出,跨站点脚本(XSS),缺少认证和缺少授权。请参阅 CWE/SANS 25种最常见漏洞或 OWASP十大漏洞类型项目。

    Repository security guidance and automation do not establish the required knowledge of a named primary developer. A maintainer must confirm secure-design principles and common relevant error/mitigation knowledge. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/CONTRIBUTING.md https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md


  • 使用基础的良好加密实践

    请注意,某些软件不需要使用加密机制。

    项目生成的软件默认情况下,只能使用由专家公开发布和审查的加密协议和算法(如果使用加密协议和算法)。 [crypto_published]
    这些加密条款并不总是适用,因为某些软件不需要直接使用加密功能。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    如果项目生成的软件是应用程序或库,其主要目的不是实现加密,那么它应该只调用专门设计实现加密功能的软件,而不应该重新实现自己的。 [crypto_call]

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    项目所产生的软件中,所有依赖于密码学的功能必须使用FLOSS实现。 [crypto_floss]

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    项目生成的软件中的安全机制使用的默认密钥长度必须至少达到2030年(如2012年所述)的NIST最低要求。必须提供配置,以使较小的密钥长度被完全禁用。 [crypto_keylength]
    这些最小位长度是:对称密钥112,因式分解模数2048,离散对数密钥224,离散对数组2048,椭圆曲线224和散列224(密码散列不涉及该位长度),关于密码散列的更多信息可以在 crypto_password_storage 条款)。请参阅 http://www.keylength.com 以比较不同组织的密钥长度建议。在某些配置中,软件可能允许较小的密钥长度(理想情况下不会,因为这允许降级攻击,但是互操作性有时需要较短的密钥长度)。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    项目产生的软件中的默认安全机制不得取决于已被破解的密码算法(例如,MD4,MD5,单DES,RC4,Dual_EC_DRBG)或使用不适合上下文的密码模式(例如,ECB模式几乎不适当,因为它揭示了密文中相同的块,如 ECB企鹅所示。CTR模式通常是不合适的,因为如果重复输入状态,则它不执行认证并导致重复)。 [crypto_working]
    在许多情况下,最好选择设计用于组合保密和认证的块密码算法模式,例如Galois / Counter Mode(GCM)和EAX。项目可以允许用户为必要的兼容性启用已被破解的加密机制,但是需要用户知道他们正在这么做。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    由项目产生的软件中的默认安全机制不应该依赖于具有已知严重弱点的加密算法或模式(例如,SHA-1密码散列算法或SSH中的CBC模式)。 [crypto_weaknesses]
    在 CERT:SSH CBC漏洞中讨论了SSH中CBC模式的问题。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    项目产生的软件中的安全机制应该​​对密钥协商协议实施完美的前向保密(PFS),如果长期密钥集合中的一个长期密钥在将来泄露,也不能破坏从一组长期密钥导出的会话密钥。 [crypto_pfs]

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    如果项目产生的软件存储用于外部用户认证的密码,则必须使用密钥拉伸(迭代)算法(例如,PBKDF2,Bcrypt或Scrypt)将密码存储为每用户盐值不同的迭代散列 。 [crypto_password_storage]
    此条款仅适用于软件强制使用密码验证用户身份的情况(如服务器端Web应用程序)。在软件存储用于认证到其他系统的密码(例如,该软件实现某个其他系统的客户端)的情况下,这是不适用的,因为该软件的至少某个部分必须经常访问未散列加密的密码。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills



    由项目生成的软件中的安全机制必须使用密码学安全的随机数生成器生成所有加密密钥和随机数,并且不得使用密码学不安全的生成器。 [crypto_random]
    密码安全的随机数生成器可以是硬件随机数生成器,或者它可以是使用诸如Hash_DRBG,HMAC_DRBG,CTR_DRBG,Yarrow或Fortuna之类的算法的加密安全的伪随机数生成器(CSPRNG)。对安全性随机数生成器的调用示例包括Java的java.security.SecureRandom和JavaScript的window.crypto.getRandomValues。调用不安全随机数生成器的示例包括Java的java.util.Random和JavaScript的Math.random。

    The delivered product is declarative skill/reference content with no executable runtime helper or service. It does not implement cryptography, password storage, network sessions or key generation; CI/release signing is assessed separately. https://github.com/netresearch/typo3-upgrade-effort-model-skill/tree/55b42d34db8fd103ba85b92b5b22e7dd4e4de9d3/skills


  • 安全交付防御中间人(MITM)的攻击


    该项目必须使用一种针对MITM攻击的传递机制。使用https或ssh + scp是可以接受的。 [delivery_mitm]
    一个更强大的机制是使用数字签名的软件包发布软件,因为这样可以减轻对分发系统的攻击,但只有在用户确信签名的公钥是否正确的情况下才可以确定。用户实际上会检查签名。

    The official repository, issue tracker, releases and listed package-installation channels use HTTPS. Release checksums and signature bundles are delivered through the same HTTPS GitHub release channel. https://github.com/netresearch/typo3-upgrade-effort-model-skill https://github.com/netresearch/typo3-upgrade-effort-model-skill/releases/tag/v1.4.1



    不得通过http协议获取加密散列(例如,sha1sum)并直接使用,而不检查密码学签名。 [delivery_unsigned]
    这些散列可以在传输过程中修改。

    The official repository, issue tracker, releases and listed package-installation channels use HTTPS. Release checksums and signature bundles are delivered through the same HTTPS GitHub release channel. https://github.com/netresearch/typo3-upgrade-effort-model-skill https://github.com/netresearch/typo3-upgrade-effort-model-skill/releases/tag/v1.4.1


  • 修正公开的漏洞


    被公开了超过60天的中等或更高严重程度的漏洞,必须被修复。 [vulnerabilities_fixed_60_days]
    该漏洞必须由项目本身修补和发布(修补程序可能在其他地方开发)。一旦漏洞具有公开发布的非付费信息的CVE(例如,在国家漏洞数据库)或项目已被通知,且信息已经发布给公众(可能是项目自己发布),则视为漏洞已经公众所知。如果其 CVSS 2.0 基本分数为4或更高,则漏洞是中等到高的严重性。 注意:这意味着全世界的所有攻击者可能会对用户造成长达60天的伤害。这个标准通常比Google在重新启动负责任的披露中所推荐的容易得多。因为Google建议,如果报告不是公开的,那么当项目得到通知,甚至报告尚未公开时,60天的时间段就会开始。

    The published vulnerability policy and advisory channel were reviewed, but a complete inventory of reported/known vulnerabilities and actual remediation dates was not available. No assurance of absence or timeliness is inferred from an empty advisory list. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md https://github.com/netresearch/typo3-upgrade-effort-model-skill/security/advisories



    项目在得到报告后应该迅速修复所有致命漏洞。 [vulnerabilities_critical_fixed]

    The published vulnerability policy and advisory channel were reviewed, but a complete inventory of reported/known vulnerabilities and actual remediation dates was not available. No assurance of absence or timeliness is inferred from an empty advisory list. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md https://github.com/netresearch/typo3-upgrade-effort-model-skill/security/advisories


  • 其他安全问题


    公共存储库不得泄漏旨在限制公众访问的有效私人凭证(例如,工作密码或私钥)。 [no_leaked_credentials]
    项目可以泄漏测试和不重要数据库的“样本”凭据,只要它们不旨在限制公共访问。

    Current authenticated GitHub secret-scanning alert state reports zero open alerts, with secret scanning and push protection enabled. No valid leaked private credential is known from this evidence as of 2026-09-29; this is a current bounded observation, not proof against unknown future findings. https://github.com/netresearch/typo3-upgrade-effort-model-skill/security/secret-scanning https://api.github.com/repos/netresearch/typo3-upgrade-effort-model-skill/secret-scanning/alerts?state=open


 分析 5/8 ●


您可以使用工具和AI系统通过简单的URL提交变更建议,例如 https://www.bestpractices.dev/zh-CN/projects/15075/choose/edit?osps_ac_01_01_status=Met&osps_ac_01_01_justification=GitHub+enforced。请参阅我们的自动化提案系统,了解具体操作方法。 该数据可在社区数据许可协议 – 许可性,版本 2.0 (CDLA-Permissive-2.0)下获取。这意味着数据接收方可以共享数据,无论是否经过修改,只要数据接收方在共享数据时提供本协议文本。请注明Sebastian Mendel和OpenSSF最佳实践徽章贡献者。

项目徽章条目拥有者: Sebastian Mendel.
最后更新于 2026-09-29 06:09:16 UTC, 最后更新于 2026-09-29 15:39:33 UTC。