Skip to content

Update reference-ids in OSPS-GV.yaml#464

Merged
eddie-knight merged 3 commits intomainfrom
SecurityCRob-patch-13
Feb 19, 2026
Merged

Update reference-ids in OSPS-GV.yaml#464
eddie-knight merged 3 commits intomainfrom
SecurityCRob-patch-13

Conversation

@SecurityCRob
Copy link
Copy Markdown
Contributor

bsi mappings to gv

bsi mappings to gv

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
@SecurityCRob
Copy link
Copy Markdown
Contributor Author

SecurityCRob commented Jan 13, 2026

depends on:
#459
#460

related to:
#461
#462
#463
#464
#465
#466
#467

Comment thread baseline/OSPS-GV.yaml
Copy link
Copy Markdown
Contributor

@evankanderson evankanderson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd argue that GV-04 ("code contributors reviewed prior to granting escalated permissions") should have a mapping to GV.02 ("the project's ... MUST be protected against unauthorized actions"), even though it's not in the BSI TR-03185-2 document.

Comment thread baseline/OSPS-GV.yaml Outdated
Comment thread baseline/OSPS-GV.yaml
Co-authored-by: Eddie Knight <knight@linux.com>
Signed-off-by: Ben Cotton <bcotton@funnelfiasco.com>
Comment thread baseline/OSPS-GV.yaml
@eddie-knight eddie-knight merged commit fa261cf into main Feb 19, 2026
5 checks passed
@eddie-knight eddie-knight deleted the SecurityCRob-patch-13 branch April 1, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants