diff --git a/README.md b/README.md index 0ab8c40..4b1c11b 100644 --- a/README.md +++ b/README.md @@ -48,6 +48,7 @@ We plan on addressing this challenge through the following actions: - [OSS-SIRT SIG](https://github.com/ossf/SIRT) (incubating) - SIG dedicated to update of OpenSSF Mobilization Plan Stream 5 working to create upstream open source incident response team. - Vulnerability AutoFix SIG (incubating) - Group dedicated to finding best practices in disclosing open source vulnerabilities and fixes to projects at scale - [OpenVEX SIG](https://github.com/ossf/OpenVEX) (sandbox)- Group dedicated to OpenVEX and VEX industry work. OpenVEX is an implementation of the Vulnerability Exploitability Exchange (VEX for short) that is designed to be minimal, compliant, interoperable, and embeddable. +- [Guide for Open Source Projects to become a CNA}(https://github.com/ossf/wg-vulnerability-disclosures/blob/main/docs/guides/becoming-a-cna-as-an-open-source-org-or-project.md) ## **Past Work**