Search / openssf/osps-baseline-to-cra / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-cra Mapping Document

openssf/osps-baseline-to-cra

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to EU Cyber Resilience Act. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-cra --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-cra:v0.0.0-dev-671f23f
Manifest digest
sha256:7e84e4d7d85ac903579f712e5afb5ca39f1a4425646ad7f8048dce6754fda4c0
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-cra --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
e0efbfd8e1b9… application/vnd.gemara.artifact.v1+yaml 7.1 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-cra",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-cra",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-cra.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-cra.yaml",
            "digest": {
              "sha256": "e0efbfd8e1b9e147fded9cd444c029800233ea2c3445451ad79f63f9b8fb1794"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:18.938772184Z",
          "finishedOn": "2026-05-29T03:57:19.065443695Z"
        },
        "byproducts": [
          {
            "name": "osps-to-cra.yaml",
            "digest": {
              "sha256": "e0efbfd8e1b9e147fded9cd444c029800233ea2c3445451ad79f63f9b8fb1794"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-cra.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-cra",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-01-CRA
    relationship: relates-to
    source: OSPS-AC-01
    targets:
      - entry-id: 1.2d
      - entry-id: 1.2e
      - entry-id: 1.2f
  - id: M-OSPS-AC-02-CRA
    relationship: relates-to
    source: OSPS-AC-02
    targets:
      - entry-id: 1.2f
  - id: M-OSPS-AC-03-CRA
    relationship: relates-to
    source: OSPS-AC-03
    targets:
      - entry-id: 1.2f
  - id: M-OSPS-AC-04-CRA
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: 1.2d
      - entry-id: 1.2e
      - entry-id: 1.2f
  - id: M-OSPS-BR-01-CRA
    relationship: relates-to
    source: OSPS-BR-01
    targets:
      - entry-id: 1.2f
  - id: M-OSPS-BR-02-CRA
    relationship: relates-to
    source: OSPS-BR-02
    targets:
      - entry-id: 1.2f
  - id: M-OSPS-BR-03-CRA
    relationship: relates-to
    source: OSPS-BR-03
    targets:
      - entry-id: 1.2d
      - entry-id: 1.2e
      - entry-id: 1.2f
      - entry-id: 1.2i
      - entry-id: 1.2j
      - entry-id: 1.2k
  - id: M-OSPS-BR-04-CRA
    relationship: relates-to
    source: OSPS-BR-04
    targets:
      - entry-id: 1.2d
      - entry-id: 1.2f
      - entry-id: 1.2h
      - entry-id: 1.2j
      - entry-id: 1.2l
      - entry-id: "2.5"
  - id: M-OSPS-BR-05-CRA
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: 1.2b
      - entry-id: 1.2d
      - entry-id: 1.2f
      - entry-id: 1.2h
      - entry-id: 1.2j
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.3"
  - id: M-OSPS-DO-01-CRA
    relationship: relates-to
    source: OSPS-DO-01
    targets:
      - entry-id: 1.2b
      - entry-id: 1.2j
      - entry-id: 1.2k
  - id: M-OSPS-DO-02-CRA
    relationship: relates-to
    source: OSPS-DO-02
    targets:
      - entry-id: 1.2c
      - entry-id: 1.2l
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.5"
      - entry-id: "2.6"
  - id: M-OSPS-DO-03-CRA
    relationship: relates-to
    source: OSPS-DO-03
    targets:
      - entry-id: 1.2d
  - id: M-OSPS-DO-05-CRA
    relationship: relates-to
    source: OSPS-DO-05
    targets:
      - entry-id: 1.2c
      - entry-id: "2.6"
  - id: M-OSPS-DO-06-CRA
    relationship: relates-to
    source: OSPS-DO-06
    targets:
      - entry-id: "2.1"
  - id: M-OSPS-GV-02-CRA
    relationship: relates-to
    source: OSPS-GV-02
    targets:
      - entry-id: 1.2l
      - entry-id: "2.3"
      - entry-id: "2.4"
      - entry-id: "2.6"
  - id: M-OSPS-GV-03-CRA
    relationship: relates-to
    source: OSPS-GV-03
    targets:
      - entry-id: 1.2l
      - entry-id: "2.4"
  - id: M-OSPS-GV-04-CRA
    relationship: relates-to
    source: OSPS-GV-04
    targets:
      - entry-id: 1.2d
      - entry-id: 1.2l
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.5"
      - entry-id: "2.6"
  - id: M-OSPS-LE-01-CRA
    relationship: relates-to
    source: OSPS-LE-01
    targets:
      - entry-id: 1.2b
      - entry-id: 1.2f
  - id: M-OSPS-LE-02-CRA
    relationship: relates-to
    source: OSPS-LE-02
    targets:
      - entry-id: 1.2b
  - id: M-OSPS-LE-03-CRA
    relationship: relates-to
    source: OSPS-LE-03
    targets:
      - entry-id: 1.2b
  - id: M-OSPS-QA-01-CRA
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: 1.2b
      - entry-id: 1.2f
      - entry-id: 1.2j
  - id: M-OSPS-QA-02-CRA
    relationship: relates-to
    source: OSPS-QA-02
    targets:
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.3"
  - id: M-OSPS-QA-03-CRA
    relationship: relates-to
    source: OSPS-QA-03
    targets:
      - entry-id: 1.2f
      - entry-id: 1.2k
  - id: M-OSPS-QA-04-CRA
    relationship: relates-to
    source: OSPS-QA-04
    targets:
      - entry-id: 1.2b
      - entry-id: 1.2f
  - id: M-OSPS-QA-05-CRA
    relationship: relates-to
    source: OSPS-QA-05
    targets:
      - entry-id: 1.2b
  - id: M-OSPS-QA-06-CRA
    relationship: relates-to
    source: OSPS-QA-06
    targets:
      - entry-id: "2.3"
  - id: M-OSPS-SA-01-CRA
    relationship: relates-to
    source: OSPS-SA-01
    targets:
      - entry-id: 1.2a
      - entry-id: 1.2b
  - id: M-OSPS-SA-02-CRA
    relationship: relates-to
    source: OSPS-SA-02
    targets:
      - entry-id: 1.2a
      - entry-id: 1.2b
  - id: M-OSPS-SA-03-CRA
    relationship: relates-to
    source: OSPS-SA-03
    targets:
      - entry-id: "1.1"
      - entry-id: 1.2j
      - entry-id: 1.2k
      - entry-id: "2.2"
  - id: M-OSPS-VM-01-CRA
    relationship: relates-to
    source: OSPS-VM-01
    targets:
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.3"
      - entry-id: "2.6"
      - entry-id: "2.7"
      - entry-id: "2.8"
  - id: M-OSPS-VM-02-CRA
    relationship: relates-to
    source: OSPS-VM-02
    targets:
      - entry-id: "2.5"
  - id: M-OSPS-VM-03-CRA
    relationship: relates-to
    source: OSPS-VM-03
    targets:
      - entry-id: "2.5"
      - entry-id: "2.6"
  - id: M-OSPS-VM-04-CRA
    relationship: relates-to
    source: OSPS-VM-04
    targets:
      - entry-id: 1.2a
      - entry-id: 1.2b
      - entry-id: "2.1"
      - entry-id: "2.4"
      - entry-id: "2.6"
  - id: M-OSPS-VM-05-CRA
    relationship: relates-to
    source: OSPS-VM-05
    targets:
      - entry-id: 1.2a
      - entry-id: 1.2b
      - entry-id: 1.2c
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.3"
      - entry-id: "2.4"
  - id: M-OSPS-VM-06-CRA
    relationship: relates-to
    source: OSPS-VM-06
    targets:
      - entry-id: 1.2a
      - entry-id: 1.2b
      - entry-id: 1.2c
      - entry-id: "2.1"
      - entry-id: "2.2"
      - entry-id: "2.3"
      - entry-id: "2.4"
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: |
    Cross-walk from the Open Source Project Security (OSPS) Baseline
    controls to EU Cyber Resilience Act. Each mapping asserts a "relates-to"
    relationship; strength, confidence-level, and rationale are left
    unset and should be added as the mappings are individually
    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-cra
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: Regulation (EU) 2024/2847 of the European Parliament and of the
        Council of 23 October 2024 on horizontal cybersecurity requirements for
        products with digital elements and amending Regulations (EU) No 168/2013
        and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
        (Text with EEA relevance)
      id: CRA
      title: Cyber Resilience Act
      url: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#tit_1
      version: 20.11.2024
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: CRA
title: OSPS Baseline to EU Cyber Resilience Act Mapping