A Security Practices Evaluation Framework

Source Code Availability


Description

Ross Anderson has claimed that, for sufficiently large software systems, source code availability aids attackers and defenders equally, but the balance shifts based on a variety of project-specific factors. We track the source code availability for each project measured.

Data Collection

Discuss source code availability with the project staff, or infer from the existence of a public repository or other, legal, public distribution of the source code.

Values: Open Source, Closed Source