Search / openssf/osps-baseline-to-uksscop / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-uksscop Mapping Document

openssf/osps-baseline-to-uksscop

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to UK NCSC Software Security Code of Practice. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-uksscop --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-uksscop:v0.0.0-dev-671f23f
Manifest digest
sha256:fd0670e0863a069ddd11a5b0d12418071d55cbde2e50946375277598c115cfdc
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-uksscop --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
8943e688dec6… application/vnd.gemara.artifact.v1+yaml 6.6 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-uksscop",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-uksscop",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-uksscop.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-uksscop.yaml",
            "digest": {
              "sha256": "8943e688dec68e013a4aa3d0e99571aac96738989610c589ade8a0953db0b651"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:21.031409641Z",
          "finishedOn": "2026-05-29T03:57:21.108501911Z"
        },
        "byproducts": [
          {
            "name": "osps-to-uksscop.yaml",
            "digest": {
              "sha256": "8943e688dec68e013a4aa3d0e99571aac96738989610c589ade8a0953db0b651"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-uksscop.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-uksscop",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-01-UKSSCOP
    relationship: relates-to
    source: OSPS-AC-01
    targets:
      - entry-id: Claim 1.4.2
      - entry-id: Claim 2.1.5
      - entry-id: Claim 2.2.2
  - id: M-OSPS-AC-02-UKSSCOP
    relationship: relates-to
    source: OSPS-AC-02
    targets:
      - entry-id: Claim 2.2.2
  - id: M-OSPS-AC-03-UKSSCOP
    relationship: relates-to
    source: OSPS-AC-03
    targets:
      - entry-id: Claim 1.1.4
      - entry-id: Claim 2.2.2
  - id: M-OSPS-AC-04-UKSSCOP
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: Claim 2.1.1
      - entry-id: Claim 2.1.3
      - entry-id: Claim 2.2.2
  - id: M-OSPS-BR-01-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-01
    targets:
      - entry-id: Claim 2.1.2
      - entry-id: Claim 2.2.2
  - id: M-OSPS-BR-02-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-02
    targets:
      - entry-id: Claim 1.1.4
      - entry-id: Claim 3.1.1
      - entry-id: Claim 3.4.2
  - id: M-OSPS-BR-03-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-03
    targets:
      - entry-id: Claim 3.1.2
  - id: M-OSPS-BR-04-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-04
    targets:
      - entry-id: Claim 1.1.4
      - entry-id: Claim 2.2.3
      - entry-id: Claim 3.1.1
  - id: M-OSPS-BR-05-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: Claim 1.2.1
      - entry-id: Claim 1.2.5
  - id: M-OSPS-BR-06-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-06
    targets:
      - entry-id: Claim 1.2.2
      - entry-id: Claim 3.1.1
  - id: M-OSPS-BR-07-UKSSCOP
    relationship: relates-to
    source: OSPS-BR-07
    targets:
      - entry-id: Claim 1.4.3
      - entry-id: Claim 1.4.5
  - id: M-OSPS-DO-01-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-01
    targets:
      - entry-id: "4.1"
  - id: M-OSPS-DO-02-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-02
    targets:
      - entry-id: "1.1"
      - entry-id: "1.3"
  - id: M-OSPS-DO-03-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-03
    targets:
      - entry-id: "3.1"
  - id: M-OSPS-DO-04-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-04
    targets:
      - entry-id: "4.1"
      - entry-id: "4.2"
      - entry-id: Claim 4.1.1
      - entry-id: Claim 4.1.2
      - entry-id: Claim 4.2.1
  - id: M-OSPS-DO-05-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-05
    targets:
      - entry-id: "3.5"
      - entry-id: "4.1"
      - entry-id: Claim 4.1.1
      - entry-id: Claim 4.2.1
  - id: M-OSPS-DO-06-UKSSCOP
    relationship: relates-to
    source: OSPS-DO-06
    targets:
      - entry-id: "1.2"
      - entry-id: "3.3"
      - entry-id: Claim 1.2.1
      - entry-id: Claim 1.2.2
  - id: M-OSPS-GV-01-UKSSCOP
    relationship: relates-to
    source: OSPS-GV-01
    targets:
      - entry-id: Claim 2.1.1
  - id: M-OSPS-GV-03-UKSSCOP
    relationship: relates-to
    source: OSPS-GV-03
    targets:
      - entry-id: Claim 2.1.1
  - id: M-OSPS-QA-01-UKSSCOP
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: Claim 2.2.3
  - id: M-OSPS-QA-02-UKSSCOP
    relationship: relates-to
    source: OSPS-QA-02
    targets:
      - entry-id: Claim 1.2.1
      - entry-id: Claim 1.2.2
      - entry-id: Claim 3.1.1
  - id: M-OSPS-QA-03-UKSSCOP
    relationship: relates-to
    source: OSPS-QA-03
    targets:
      - entry-id: Claim 1.3.2
      - entry-id: Claim 1.3.3
  - id: M-OSPS-SA-01-UKSSCOP
    relationship: relates-to
    source: OSPS-SA-01
    targets:
      - entry-id: Claim 1.1.5
  - id: M-OSPS-SA-02-UKSSCOP
    relationship: relates-to
    source: OSPS-SA-02
    targets:
      - entry-id: Claim 1.1.5
  - id: M-OSPS-SA-03-UKSSCOP
    relationship: relates-to
    source: OSPS-SA-03
    targets:
      - entry-id: Claim 1.4.1
  - id: M-OSPS-VM-01-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-01
    targets:
      - entry-id: Claim 3.4.1
      - entry-id: Claim 3.5.1
      - entry-id: Claim 4.1.2
  - id: M-OSPS-VM-02-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-02
    targets:
      - entry-id: "3.2"
  - id: M-OSPS-VM-03-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-03
    targets:
      - entry-id: "3.2"
  - id: M-OSPS-VM-04-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-04
    targets:
      - entry-id: "3.4"
      - entry-id: "3.5"
      - entry-id: "4.3"
  - id: M-OSPS-VM-05-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-05
    targets:
      - entry-id: "1.2"
      - entry-id: "3.3"
  - id: M-OSPS-VM-06-UKSSCOP
    relationship: relates-to
    source: OSPS-VM-06
    targets:
      - entry-id: "1.3"
      - entry-id: "1.4"
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: >
    Cross-walk from the Open Source Project Security (OSPS) Baseline

    controls to UK NCSC Software Security Code of Practice. Each mapping asserts
    a "relates-to"

    relationship; strength, confidence-level, and rationale are left

    unset and should be added as the mappings are individually

    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-uksscop
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: The Software Code of Practice has been created by DSIT and the
        National Cyber Security Centre (NCSC), the UK’s technical authority for
        cyber security, and is co-sealed by the Canadian Centre for Cyber
        Security (CCCS). The Code reflects the government’s ongoing focus on
        codifying minimum standards for technology providers to reduce cyber
        risk. It is aimed at professionals who are responsible for overseeing
        the development of ‘commodity’ software, including technical,
        compliance, and risk experts. For those organisations that require a
        higher level of assurance in the resilience of their connected products
        and technology, consider using the NCSC’s Cyber Resilience Testing
        scheme.
      id: UKSSCOP
      title: United Kingdom National Cyber Security Centre Software Security Code of
        Practice
      url: https://www.ncsc.gov.uk/guidance/software-security-code-of-practice-assurance-principles-claims
      version: 2025-05-07
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: UKSSCOP
title: OSPS Baseline to UK NCSC Software Security Code of Practice Mapping