OpenSSF / supply-chain readiness (assessment)¶
Not chasing a badge in this sprint.
| Check | State |
|---|---|
| Security policy | Present (SECURITY.md) |
| Releases | v0.1.0 published and archived; v2.x retained as legacy prereleases |
| Workflow permissions | contents: read on Tests |
| Dependabot | Configured |
| Pinned Actions | Uses major tags (@v7); pin-to-SHA is a future hardening |
| Branch protection | One approval, fresh approvals, thread resolution, current branch, Tests, and Documentation required |
| Signed tags | v0.1.0 has a verified ED25519 SSH signature |
| Vulnerability reporting | Private reporting enabled |
| Secret protection | Secret scanning and push protection enabled |
| CodeQL | Not enabled here; evaluate cost vs signal |
| Scorecard | Optional later |
Do not enable noisy workflows solely for a badge.