Skip to content

docs(security): confirm OpenSSF Best Practices Badge tier and publish current score #551

Description

Summary

Re-run the OpenSSF Best Practices Badge questionnaire for project 12195, confirm the current tier (passing / silver / gold), publish the score in README, and file follow-up issues for any unmet criteria.

Background

The badge was added in v0.6.0 (#3). Repository posture has materially improved since then (release-pipeline hardening in #419, Sigstore signing in #7, SECURITY.md, CodeQL, Gitleaks, Scorecard, dependency review). The badge questionnaire likely now qualifies for a higher tier.

Acceptance Criteria

  • Best Practices Badge questionnaire reviewed end to end
  • Current tier confirmed and badge URL updated in README
  • Gap list captured for any criteria still unmet (filed as separate issues if non-trivial)
  • docs/security/ includes a short note describing the tier, the date verified, and a link to the project page
  • CONTRIBUTING.md references the badge requirements for new contributors

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

docsDocumentation improvementssecuritySecurity-related issues or fixes

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions