I'd like to propose to evaluate and (selectively) adopt secure software development best practices recommended by the Open Source Security Foundation (OpenSSF) [1]. The OpenSSF Scorecard project checks various development best practices of open source projects hosted on GitHub and provides guidance on how to improve those practices [2]. The overall goal of this issue is to adopt best practices to further mature the project.
The proposed steps include:
- running Scorecards against the ecchronos repo,
- evaluation of the scan results of Scorecards in terms of applicability,
- adoption and/or implementation of the recommendation considered feasible and valuable.
[1] https://openssf.org/
[2] https://github.com/ossf/scorecard/tree/main#scorecard-checks