Outbound Checklists
Our outbound review checklists outlines our process of approving CMS-developed software to be released as open source:
Benefits & Risks
- Evaluate cost savings, extensibility, innovation, and other development benefits
- Evaluate the potential security, financial, and privacy risks
Code Review & Analysis
- Ensure Code Quality
- Detect PII/PHI
- Detect Secrets and Keys
- Detect Security Vulnerabilities
- Identify Licensing and Provenance
Metadata & Hygiene
- Ensure repository files exist and are complete
- Ensure repository metadata exist in a code.json file and are complete
Sign-off
-Acknowledgment and/or Approvals from Technical, Business, and Security Stakeholders
| Tier | Checklist Link |
|---|---|
| Tier 1 | Checklist |
| Tier 2 | Checklist |
| Tier 3 | Checklist |
| Tier 4 | Checklist |
Learn more: