Skip to content

Add terms to OpenSSF glossary #52

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
di opened this issue Apr 11, 2025 · 6 comments
Open

Add terms to OpenSSF glossary #52

di opened this issue Apr 11, 2025 · 6 comments

Comments

@di
Copy link
Member

di commented Apr 11, 2025

In #51 (comment), we struggled a bit with aligning terminology across ecosystems, and disambiguating certain terms.

The WG should publish a glossary at https://repos.openssf.org/glossary contribute to https://glossary.openssf.org/ to define our preferred terms for various concepts, as well as "a mega synonym table mapping concept across ecosystem" (per @joelverhagen). We should also update currently published models/guides to align around these terms.

Some examples, loosely grouped & not exhaustive, that should be included:

  • package / project / release / version / artifact / module / distribution / binary / file
  • package repository / package index / package manager / installer / uploader / publisher
  • maintainer / owner / consumer / user / admin
  • yank / soft delete / delete
  • upload / publish
@simi
Copy link
Contributor

simi commented Apr 11, 2025

  • namespace

@david-a-wheeler
Copy link

May I instead strongly recommend you contribute to the OpenSSF-wide glossary, here?: https://glossary.openssf.org/

This effort's been quietly ongoing for a while (slow because other tasks need to be done too), so many terms aren't defined yet. But it'd be good for at least there to be agreement on terms across the OpenSSF.

@GeauxJD has been leading this charge.

@david-a-wheeler
Copy link

We've already set up a pretty-looking glossary page, formatting stuff, etc. Just add markdown files with definitions, and it magically looks good.

@di
Copy link
Member Author

di commented Apr 15, 2025

That's great, I didn't know that existed! Yes of course.

@di di changed the title Create a glossary Add terms to OpenSSF glossary Apr 15, 2025
@david-a-wheeler
Copy link

We frankly haven't done a good-enough job pointing people to it. It's hard to get people to use a glossary when it has no contents :-). So... let's fix that :-).

@GeauxJD
Copy link

GeauxJD commented Apr 15, 2025

We will be sharing it with the BEST WG soon and inviting contributions but I want to get the search functioning in it first (there's an issue in the repo for that)

Also the Security Baseline project has a "Lexicon" section with could be useful https://baseline.openssf.org/versions/2025-02-25#lexicon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants