Skip to content

docs: add detailed-guide to security-insights.yml for OSPS-DO-01 - #200

Merged
jmeridth merged 1 commit into
ossf:mainfrom
jmeridth:si-detailed-guide
Aug 28, 2026
Merged

docs: add detailed-guide to security-insights.yml for OSPS-DO-01#200
jmeridth merged 1 commit into
ossf:mainfrom
jmeridth:si-detailed-guide

Conversation

@jmeridth

Copy link
Copy Markdown
Member

What/Why

The first Octo STS federated baseline scan (run 33216205594) reports OSPS-DO-01.01 failing: "User guide was NOT specified in Security Insights data". The scanner checks project.documentation.detailed-guide; this points it at https://security-insights.openssf.org/.

Proof it works

cue vet -d '#SecurityInsights' ./spec .github/security-insights.yml passes. The next scheduled scan (Mondays 09:00 UTC) should flip OSPS-DO-01.01 to passing.

Risk + AI role

Low -- one added line in our own Security Insights metadata. AI-generated (Claude Fable 5) from the scan finding.

Review focus

Whether the docs site is the right detailed-guide target, or whether a more specific page (e.g. the schema reference) fits better.

The first Octo STS federated baseline scan (run 33216205594) reports
OSPS-DO-01.01 failing because no user guide is specified in the
Security Insights data. The scanner checks
project.documentation.detailed-guide; point it at the documentation
site.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth self-assigned this Aug 28, 2026
@jmeridth
jmeridth marked this pull request as ready for review August 28, 2026 22:39
@jmeridth
jmeridth requested a review from a team as a code owner August 28, 2026 22:39
@jmeridth
jmeridth merged commit 5b27e34 into ossf:main Aug 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants