Skip to content

feat(security): add reproducible OpenSSF badge audit - #1602

Draft
Alexandre Gattiker (algattik) wants to merge 2 commits into
mainfrom
algattik-issue-551-plan
Draft

Alexandre Gattiker (algattik) wants to merge 2 commits into
mainfrom
algattik-issue-551-plan

Conversation

@algattik

Copy link
Copy Markdown
Collaborator

Summary

  • add a canonical .bestpractices.json proposal for OpenSSF project 12195
  • add a deterministic, read-only badge audit skill and collector
  • publish the verified Silver status and correct stale evidence references

Findings

The audit identifies nine confirmed unmet criteria and nine unknown criteria. Issue #1562 tracks the two Silver TLS-verification gaps. No authenticated OpenSSF questionnaire update is included.

Closes #551

- add canonical questionnaire evidence and deterministic collector
- publish current badge status and correct stale references
- document the reusable read-only audit workflow

🛡️ - Generated by Copilot

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 010ed9b5-168d-4893-8bc1-46c4f03099a2
@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA df999e6.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Scanned Files

None

@codecov-commenter

Codecov Comments Bot (codecov-commenter) commented Sep 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.10%. Comparing base (8d49dca) to head (df999e6).
⚠️ Report is 17 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1602   +/-   ##
=======================================
  Coverage   88.10%   88.10%           
=======================================
  Files         279      279           
  Lines       23203    23203           
  Branches     3153     3153           
=======================================
  Hits        20444    20444           
  Misses       2071     2071           
  Partials      688      688           
Flag Coverage Δ *Carryforward flag
go 100.00% <ø> (ø)
pester 86.64% <ø> (ø) Carriedforward from a4359ac
pytest-data-pipeline 100.00% <ø> (ø) Carriedforward from a4359ac
pytest-dataviewer 89.66% <ø> (ø)
pytest-dm-tools 100.00% <ø> (ø) Carriedforward from a4359ac
pytest-evaluation 95.40% <ø> (ø)
pytest-fuzz 3.99% <ø> (ø)
pytest-inference 100.00% <ø> (ø) Carriedforward from a4359ac
pytest-shared-ci 100.00% <ø> (ø) Carriedforward from a4359ac
pytest-training 92.60% <ø> (ø)
vitest 85.66% <ø> (ø) Carriedforward from a4359ac
vitest-app 85.66% <ø> (ø) Carriedforward from a4359ac
vitest-components 85.66% <ø> (ø) Carriedforward from a4359ac
vitest-features 85.66% <ø> (ø) Carriedforward from a4359ac
vitest-lib 85.66% <ø> (ø) Carriedforward from a4359ac
vitest-state 85.66% <ø> (ø) Carriedforward from a4359ac

*This pull request uses carry forward flags. Click here to find out more.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

🔗 - Generated by Copilot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 16904c91-fd21-4efb-9909-c008f45ca45e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(security): confirm OpenSSF Best Practices Badge tier and publish current score

2 participants