Skip to content

Add 2026 Q2 Best Practices WG quarterly report#598

Open
balteravishay wants to merge 6 commits into
ossf:mainfrom
balteravishay:best-practices/april-26
Open

Add 2026 Q2 Best Practices WG quarterly report#598
balteravishay wants to merge 6 commits into
ossf:mainfrom
balteravishay:best-practices/april-26

Conversation

@balteravishay
Copy link
Copy Markdown
Contributor

This pull request adds the 2026 Q2 report for the Best Practices Working Group. Major updates include launching Baseline badges, first release of the Python Secure Coding Guide and publishing the W3C web security guidelines draft.

@balteravishay balteravishay requested a review from a team as a code owner April 13, 2026 17:26
Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated
Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated
Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated

#### Current Status

* Integrated baseline criteria (levels 1–3) into the badge system. Projects can now complete forms and earn baseline badges, with a transition period ending 2026-06-01 for enforcing new criteria.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are there 2 different badges? A baseline one and a best practices one?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes indeed!

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The two different badges have 2 different URLs.

Comment thread TI-reports/2026/2026-Q2-BEST-WG.md
Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated
Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated
Copy link
Copy Markdown
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good overall. Just a few nits.
Thanks.

Comment thread TI-reports/2026/2026-Q2-BEST-WG.md Outdated
balteravishay and others added 5 commits April 14, 2026 15:26
Signed-off-by: balteravishay <avishay.balter@gmail.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: Avishay Balter <avishay.balter@gmail.com>
Signed-off-by: balteravishay <avishay.balter@gmail.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: Avishay Balter <avishay.balter@gmail.com>
Signed-off-by: balteravishay <avishay.balter@gmail.com>
Signed-off-by: balteravishay <avishay.balter@gmail.com>
Signed-off-by: balteravishay <avishay.balter@gmail.com>
@balteravishay balteravishay force-pushed the best-practices/april-26 branch from a9b6131 to 3056a0c Compare April 14, 2026 14:27
@balteravishay balteravishay requested review from gkunz and lehors April 14, 2026 14:27
@lehors
Copy link
Copy Markdown
Contributor

lehors commented Apr 14, 2026

Oh, one more comment: FYI, we have added to the TI report template a question about Funding requests.

Signed-off-by: balteravishay <avishay.balter@gmail.com>
@justaugustus justaugustus added the TI Update Quarterly TI update. Needs 5 approvals, 7d review. label Apr 28, 2026

* Continue working on a threat modelling [guide for web developers](https://github.com/mdn/content/pull/42980).

## Questions/Issues for the TAC
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To @lehors' comment about the missing information regarding funding:

Suggested change
## Questions/Issues for the TAC
## Funding requests and updates
The WG briefly discussed applying for funding of a technical writer to support the group with reviewing, finalizing, and maintaining the various guides we host. However, there currently no concrete funding request in the pipeline.
The WG currently does not receive funding yet.
## Questions/Issues for the TAC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

TI Update Quarterly TI update. Needs 5 approvals, 7d review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants