Context
Scorecard's CII-Best-Practices check is 0/10 because the repo has no
OpenSSF Best Practices badge at all. Self-certifying the project as
"in progress" is worth 5/10 on the check; earning silver is worth 10/10.
Deferred from the scorecard-gap work (#47) by maintainer decision:
"create an issue to do this later".
What to do
- Sign the project up at https://www.bestpractices.dev (GitHub login,
add project chicks-net/ctm)
- Walk the self-assessment; most silver criteria are already met here:
GPL-2.0 license, security policy, contributing guide, CI tests on every
PR, SAST (CodeQL), secret scanning (gitleaks), dependency updates
(Renovate), signed releases with SLSA provenance
- Fill in the handful of genuinely-missing answers honestly (fuzzing is
now covered; things like "project uses static analysis" check out)
- Link the badge in the README once the project page exists
Why
Roughly an hour of form-filling for +5 on a weight-2 Scorecard check,
plus the badge itself is a useful honest checklist of project hygiene —
the questions that are hard to answer are exactly the ones worth thinking
about.
Context
Scorecard's CII-Best-Practices check is 0/10 because the repo has no
OpenSSF Best Practices badge at all. Self-certifying the project as
"in progress" is worth 5/10 on the check; earning silver is worth 10/10.
Deferred from the scorecard-gap work (#47) by maintainer decision:
"create an issue to do this later".
What to do
add project
chicks-net/ctm)GPL-2.0 license, security policy, contributing guide, CI tests on every
PR, SAST (CodeQL), secret scanning (gitleaks), dependency updates
(Renovate), signed releases with SLSA provenance
now covered; things like "project uses static analysis" check out)
Why
Roughly an hour of form-filling for +5 on a weight-2 Scorecard check,
plus the badge itself is a useful honest checklist of project hygiene —
the questions that are hard to answer are exactly the ones worth thinking
about.