Secure OSS Development Guide

Introduction

Welcome to the Secure OSS Development Guide. The goal of this wiki is to provide a list of best practices that are recommended for securely developing an open source project.

Note: This development guide is currently a work in progress. At this point the guide should not be considered complete, and current content will not necessarily be included in the final draft.

Development Guide

<under construction>

The Tools page has a long list of tools that can automate finding (some kinds of) security problems.

Many open-source projects have a suite of regression tests, often run by typing make check or make test or make all from the command line. (See https://en.wikibooks.org/wiki/Make#make_check ).

Password hashing is one of the few Solved Problems in security. Password hashing best practices:

“CISA: America's Cyber Defence Agency” has made a number of recommendations to improve the security of software, including open-source software:

development-guide.txt · Last modified: 2025/11/15 07:25 by davidcary
 
Except where otherwise noted, content on this wiki is licensed under the following license: CC Attribution-Noncommercial-Share Alike 3.0 Unported
Recent changes RSS feed Donate to DokuWiki Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki Powered by OpenVZ Powered by Openwall GNU/*/Linux