You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

The OpenSSF Best Practices badge program is a way for Free/Libre and Open Source Software (FLOSS) projects to show that they follow best practices.

https://www.bestpractices.dev/en

Projects that already follow ASF policies should generally have no problem achieving a 'passing' grade for the badge, and are encouraged to do so. This page provides some pointers that might be helpful, feel free to add additional information.

Private vulnerability reporting

The "vulnerability_report_private" criterium is somewhat ambiguous, but for now we assume the ASF reporting mechanism is sufficient. In the future we might want to allow GitHub Private Vulnerability Reporting for projects that are using GitHub as well.

  • No labels