遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/9485)
<a href="https://www.bestpractices.dev/projects/9485"><img src="https://www.bestpractices.dev/projects/9485/badge"></a>
SW360 is an open source software project licensed under the EPL-2.0 that provides both a web application and a repository to collect, organize and make available information about software components. It establishes a central hub for software components in an organization.
https://eclipse.dev/sw360/docs/development/dev-dod-and-style/
Project uses Eclipse Contributor Agreement: https://www.eclipse.org/legal/eca/
https://www.eclipse.org/org/documents/
https://github.com/eclipse-sw360/sw360/blob/main/CODE_OF_CONDUCT.md
https://projects.eclipse.org/projects/technology.sw360/who
https://github.com/JetBrains-Research/bus-factor-explorer has been used to calculate bus fact of 2
https://github.com/orgs/eclipse-sw360/projects/8/views/2
https://www.eclipse.org/security/policy/
https://eclipse.dev/sw360/docs/
https://github.com/eclipse-sw360/sw360.website
https://github.com/eclipse-sw360/sw360?tab=readme-ov-file#readme
https://github.com/eclipse-sw360/sw360-frontend/tree/main/messages
No password or secret is stored.
https://eclipse.dev/sw360/docs/deployment/upgrading/
https://github.com/eclipse-sw360/sw360/issues
No vulnerability reported.
https://github.com/eclipse-sw360/sw360/blob/main/CONTRIBUTING.md
https://github.com/eclipse-sw360/sw360/blob/main/README.md#local-building
Project has no cross-dependencies
The builds are reproducible from Maven
https://eclipse.dev/sw360/docs/deployment/baremetal/deploy-natively/
Docker containers are provided for developers: https://github.com/eclipse-sw360/sw360/blob/main/README_DOCKER.md
https://github.com/eclipse-sw360/sw360/blob/main/pom.xml
https://github.com/eclipse-sw360/sw360/blob/main/.github/dependabot.yml
https://github.com/eclipse-sw360/sw360/actions/workflows/build_and_test.yml
Never been considered on developer documentation https://eclipse.dev/sw360/docs/development/
警告:需要更长的理由。
Internally used hashing algorithm can be switched easily.
The credentials are delegated to external provider like KeyCloak or stored securely in the DB which requires no recompilation.
The project depends on external application server Apache Tomcat which can be configured to provide secure communication.
https://github.com/eclipse-sw360/sw360/tags
CodeQL is used: https://github.com/eclipse-sw360/sw360/actions/workflows/codeql.yml
The project is written in Java which is memory safe.
后退