Skip to content

Add proposals directory, evidence convention, and CONTRIBUTING - #18

Open
m-khan-97 wants to merge 1 commit into
OWASP:mainfrom
m-khan-97:contribution-infrastructure
Open

Add proposals directory, evidence convention, and CONTRIBUTING#18
m-khan-97 wants to merge 1 commit into
OWASP:mainfrom
m-khan-97:contribution-infrastructure

Conversation

@m-khan-97

Copy link
Copy Markdown

Implements two Pre-Sprint 0 activities from the
sprint plan
that do not yet exist in the repository:

  • Distribute the markdown entry template for 2026 entries
  • Publish the evidence and anchor convention: standards, peer-reviewed venues, CVEs, and demonstrated proofs-of-concept
  • Open submission of new entries via pull request to the proposals directory

The wording here is a starting point, not a proposal to change any policy - it
restates what the README and sprint plan already say. Happy to adjust anything to
match how you would rather put it, or to drop any of the three files.

What this adds

proposals/ - the directory the sprint plan routes new entries to. It does
not currently exist, which is why #13 had to place a candidate entry directly in
quantum-top-10/ as QSxx_. The README explains the naming convention, points
at the template, and describes what Sprint 1 does with a proposal, including that
v0.1 entries hold no incumbency so a proposal may displace one.

quantum-top-10/_evidence-convention.md - the demonstrated / emerging /
theoretical definitions plus the anchor hierarchy. The tags are the sprint plan's
headline working principle, but the convention has not been written down and no
entry currently carries a tag, so the principle is not yet visible in the
artefact. Named with a leading underscore to sit alongside _template.md as a
meta file rather than create a new top-level directory.

Two points in it are drawn from what this repository has already run into: cite
primary sources rather than secondary summaries, and keep the verification
comment current when an anchor is superseded. Both are live concerns - the QS08
and QS10 reference comments record earlier mis-citations that had to be
corrected, and draft-ietf-tls-hybrid-design, cited in QS05 and QS06, was
published as RFC 9954 this month.

CONTRIBUTING.md - a routing table for the four contribution paths already
described across the README and sprint plan (proposal, entry feedback, issue,
Google form), the fork-and-PR flow for contributors without write access, the
evidence and vendor-neutrality bar, and the CC BY-SA 4.0 terms.

Notes

  • Nothing under quantum-top-10/ is modified and no existing file is touched, so
    this does not interact with the entry PRs currently open.
  • The evidence convention defers to Proposal: Extend the OWASP Quantum Security Top 10 Entry Template to improve Consistency, Actionability and Verifiability #15: if the template gains a dedicated
    evidence field, that field takes precedence over the convention document.
  • One deliberate open question in the convention, flagged in the text rather than
    silently decided: how to tag a risk whose exploitation depends on a CRQC. It is
    written as "tag by the state of everything except the CRQC", so HNDL collection
    is demonstrated while the decryption step is not. Worth confirming that matches
    how you intend the tags to be read, since it affects most of QS01-QS07.

Implements two Pre-Sprint 0 activities from the sprint plan that do not
yet exist in the repository: the proposals directory that new entries are
routed to, and the published evidence and anchor convention behind the
"evidence over speculation" working principle.

CONTRIBUTING.md consolidates the contribution routes already described
across the README and sprint plan. No existing file is modified.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant