遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/3816)
<a href="https://www.bestpractices.dev/projects/3816"><img src="https://www.bestpractices.dev/projects/3816/badge"></a>
GlobaLeaks is free, open source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform
https://github.com/globaleaks/GlobaLeaks/blob/main/GOVERNANCE.md
The original authors are all major contributors: Arturo Filastò, Claudio Agosti, Fabio Pietrosanti, Giovanni Pellerano, Michele Orrù Full contributors list at: https://github.com/globaleaks/globaleaks-whistleblowing-software/graphs/contributors
The license is not exposes in every source file but widely communicated in all the main relevant assets.
Repository on GitHub, which uses git. git is distributed.
Good First Issues are used to support this process: https://github.com/globaleaks/globaleaks-whistleblowing-software/labels/Good%20First%20Issue
2FA is use on any system
TOTP is adopted as 2FA mechanism
Code review is documented in Code Review section of the Quality Assurance documentation: https://docs.globaleaks.org/en/stable/qualityassurance/index.html
Every pull request is merge with a review by a contributor other than the author of the edit.
https://github.com/globaleaks/globaleaks-whistleblowing-software/blob/stable/scripts/build.sh
https://github.com/globaleaks/globaleaks-whistleblowing-software/tree/stable/.github/workflows
https://docs.globaleaks.org/en/stable/qualityassurance/index.html
https://docs.globaleaks.org/en/main/security/index.html
https://docs.globaleaks.org/en/stable/security/ApplicationSecurity.html
https://docs.globaleaks.org/en/stable/security/PenetrationTests.html
后退