From 9c683bd6902560569f5bb019feda5c65335f21ba Mon Sep 17 00:00:00 2001 From: Ulises Gascon Date: Mon, 31 Jul 2023 14:57:48 +0200 Subject: [PATCH] feat: update responses ref: https://github.com/nodejs/security-wg/pull/955#discussion_r1279257647 --- tools/ossf_best_practices/silver_criteria.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/ossf_best_practices/silver_criteria.md b/tools/ossf_best_practices/silver_criteria.md index ce08724e..1f5a7fb2 100644 --- a/tools/ossf_best_practices/silver_criteria.md +++ b/tools/ossf_best_practices/silver_criteria.md @@ -313,7 +313,7 @@ https://github.com/nodejs/node/blob/main/doc/contributing/releases.md#11-tag-and > Hardening mechanisms SHOULD be used in the software produced by the project so that software defects are less likely to result in security vulnerabilities. -_Possible answers: Met/Unmet/NA_ +**NA** > The project MUST provide an assurance case that justifies why its security requirements are met. The assurance case MUST include: a description of the threat model, clear identification of trust boundaries, an argument that secure design principles have been applied, and an argument that common implementation security weaknesses have been countered. (URL required)