CM-10(1) - Software Usage Restrictions | Open-source Software

Establish the following restrictions on the use of open-source software: [Assignment: organization-defined restrictions].


ID: CM-10(1)
Enhancement of : CM-10

Space Segment Guidance

Public-domain or open-source components can yield SWaP and cost advantages but raise unique assurance issues. Before inclusion, each OSS module should undergo static-code analysis for CWE top 25, license-compliance review, radiation-induced fault tolerance (e.g., exhaustive unit tests with fault injection), and digital signature pinning to a vetted upstream tag. The plan must also define a watch-list process for critical CVE disclosures during the mission; patched versions are validated in the flatsat and uplinked as whole-image refreshes rather than on-orbit package managers.