Search / openssf/osps-baseline-to-ssdf / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-ssdf Mapping Document

openssf/osps-baseline-to-ssdf

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST SSDF. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-ssdf --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-ssdf:v0.0.0-dev-671f23f
Manifest digest
sha256:6a047812544311cbf4c9e8eb4ddf6beaac96923c079e3cb9d472e653eed5cee1
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-ssdf --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
f5c26bc67b8f… application/vnd.gemara.artifact.v1+yaml 8.0 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-ssdf",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-ssdf",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-ssdf.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-ssdf.yaml",
            "digest": {
              "sha256": "f5c26bc67b8fb57613201cd228e3d28fd75979aeb132e52772c98c191a661f98"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:20.803011511Z",
          "finishedOn": "2026-05-29T03:57:20.914077584Z"
        },
        "byproducts": [
          {
            "name": "osps-to-ssdf.yaml",
            "digest": {
              "sha256": "f5c26bc67b8fb57613201cd228e3d28fd75979aeb132e52772c98c191a661f98"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-ssdf.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-ssdf",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-01-SSDF
    relationship: relates-to
    source: OSPS-AC-01
    targets:
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-AC-02-SSDF
    relationship: relates-to
    source: OSPS-AC-02
    targets:
      - entry-id: PO.2
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-AC-03-SSDF
    relationship: relates-to
    source: OSPS-AC-03
    targets:
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-AC-04-SSDF
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: PO.2
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-BR-01-SSDF
    relationship: relates-to
    source: OSPS-BR-01
    targets:
      - entry-id: PO.3.2
      - entry-id: PO.5.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-BR-02-SSDF
    relationship: relates-to
    source: OSPS-BR-02
    targets:
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: PS.3
  - id: M-OSPS-BR-03-SSDF
    relationship: relates-to
    source: OSPS-BR-03
    targets:
      - entry-id: PO.3.2
      - entry-id: PO.5.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-BR-04-SSDF
    relationship: relates-to
    source: OSPS-BR-04
    targets:
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: PS.3
      - entry-id: PW.1.2
  - id: M-OSPS-BR-05-SSDF
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-BR-06-SSDF
    relationship: relates-to
    source: OSPS-BR-06
    targets:
      - entry-id: PO.5.2
      - entry-id: PS.2
      - entry-id: PS.2.1
      - entry-id: PW.6.2
  - id: M-OSPS-BR-07-SSDF
    relationship: relates-to
    source: OSPS-BR-07
    targets:
      - entry-id: PO.1.1
      - entry-id: P0.3.1
      - entry-id: P0.4.2
      - entry-id: PO.5.1
      - entry-id: PW.1.2
      - entry-id: PW.1.3
      - entry-id: PW.5.1
  - id: M-OSPS-DO-01-SSDF
    relationship: relates-to
    source: OSPS-DO-01
    targets:
      - entry-id: PW.1.2
  - id: M-OSPS-DO-02-SSDF
    relationship: relates-to
    source: OSPS-DO-02
    targets:
      - entry-id: PW.1.2
      - entry-id: RV.1.1
      - entry-id: RV.2.1
      - entry-id: RV.1.2
  - id: M-OSPS-DO-03-SSDF
    relationship: relates-to
    source: OSPS-DO-03
    targets:
      - entry-id: PO.4.2
      - entry-id: PS.2
      - entry-id: PS.2.1
      - entry-id: PS.3.1
      - entry-id: RV.1.3
  - id: M-OSPS-DO-04-SSDF
    relationship: relates-to
    source: OSPS-DO-04
    targets:
      - entry-id: PO.4.2
      - entry-id: PS.3.1
      - entry-id: RV.1.3
  - id: M-OSPS-GV-02-SSDF
    relationship: relates-to
    source: OSPS-GV-02
    targets:
      - entry-id: PS.3
      - entry-id: PW.1.2
  - id: M-OSPS-GV-03-SSDF
    relationship: relates-to
    source: OSPS-GV-03
    targets:
      - entry-id: PW.1.2
  - id: M-OSPS-GV-04-SSDF
    relationship: relates-to
    source: OSPS-GV-04
    targets:
      - entry-id: PO.2
      - entry-id: PO.3.2
  - id: M-OSPS-LE-01-SSDF
    relationship: relates-to
    source: OSPS-LE-01
    targets:
      - entry-id: PO.3.2
      - entry-id: PS.1
      - entry-id: PW.1.2
      - entry-id: PW.2.1
  - id: M-OSPS-LE-02-SSDF
    relationship: relates-to
    source: OSPS-LE-02
    targets:
      - entry-id: PO.3.2
  - id: M-OSPS-LE-03-SSDF
    relationship: relates-to
    source: OSPS-LE-03
    targets:
      - entry-id: PO.3.2
  - id: M-OSPS-QA-01-SSDF
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: PS.3
      - entry-id: PW.1.2
      - entry-id: PW.2.1
  - id: M-OSPS-QA-02-SSDF
    relationship: relates-to
    source: OSPS-QA-02
    targets:
      - entry-id: PO.3.3
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: PS.3.2
      - entry-id: PW.4
  - id: M-OSPS-QA-03-SSDF
    relationship: relates-to
    source: OSPS-QA-03
    targets:
      - entry-id: PO.4.1
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: RV.1.2
  - id: M-OSPS-QA-04-SSDF
    relationship: relates-to
    source: OSPS-QA-04
    targets:
      - entry-id: PO.3.2
      - entry-id: PO.4.1
      - entry-id: PS.1
      - entry-id: PS.2
      - entry-id: RV.1.2
  - id: M-OSPS-QA-05-SSDF
    relationship: relates-to
    source: OSPS-QA-05
    targets:
      - entry-id: PS.1
      - entry-id: PS.2
  - id: M-OSPS-QA-06-SSDF
    relationship: relates-to
    source: OSPS-QA-06
    targets:
      - entry-id: PW.8.2
  - id: M-OSPS-SA-01-SSDF
    relationship: relates-to
    source: OSPS-SA-01
    targets:
      - entry-id: PO.1
      - entry-id: PO.2
      - entry-id: PO.3.2
  - id: M-OSPS-SA-02-SSDF
    relationship: relates-to
    source: OSPS-SA-02
    targets:
      - entry-id: PW.1.2
  - id: M-OSPS-SA-03-SSDF
    relationship: relates-to
    source: OSPS-SA-03
    targets:
      - entry-id: PO.5.1
      - entry-id: PW.1.1
  - id: M-OSPS-VM-01-SSDF
    relationship: relates-to
    source: OSPS-VM-01
    targets:
      - entry-id: RV.1.3
  - id: M-OSPS-VM-02-SSDF
    relationship: relates-to
    source: OSPS-VM-02
    targets:
      - entry-id: RV.1.3
  - id: M-OSPS-VM-04-SSDF
    relationship: relates-to
    source: OSPS-VM-04
    targets:
      - entry-id: PO.4.1
      - entry-id: RV.2.1
      - entry-id: RV.2.2
  - id: M-OSPS-VM-05-SSDF
    relationship: relates-to
    source: OSPS-VM-05
    targets:
      - entry-id: PO.4
      - entry-id: PW.1.2
      - entry-id: PW.8.1
      - entry-id: RV.1.2
      - entry-id: RV.1.3
      - entry-id: RV.2.1
      - entry-id: RV.2.2
  - id: M-OSPS-VM-06-SSDF
    relationship: relates-to
    source: OSPS-VM-06
    targets:
      - entry-id: PO.4
      - entry-id: PW.1.2
      - entry-id: PW.8.1
      - entry-id: RV.1.2
      - entry-id: RV.1.3
      - entry-id: RV.2.1
      - entry-id: RV 2.2
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: |
    Cross-walk from the Open Source Project Security (OSPS) Baseline
    controls to NIST SSDF. Each mapping asserts a "relates-to"
    relationship; strength, confidence-level, and rationale are left
    unset and should be added as the mappings are individually
    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-ssdf
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: The Secure Software Development Framework (SSDF) is a set of
        fundamental, sound, and secure software development practices based on
        established secure software development practice documents from
        organizations such as BSA, OWASP, and SAFECode. Few software development
        life cycle (SDLC) models explicitly address software security in detail,
        so practices like those in the SSDF need to be added to and integrated
        with each SDLC implementation. Following the SSDF practices should help
        software producers reduce the number of vulnerabilities in released
        software, reduce the potential impact of the exploitation of undetected
        or unaddressed vulnerabilities, and address the root causes of
        vulnerabilities to prevent recurrences. Also, because the SSDF provides
        a common language for describing secure software development practices,
        software producers and acquirers can use it to foster their
        communications for procurement processes and other management
        activities.
      id: SSDF
      title: Secure Software Development Framework
      url: https://csrc.nist.gov/pubs/sp/800/218/final
      version: "1.1"
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: SSDF
title: OSPS Baseline to NIST SSDF Mapping