Skip to content

OpenSSF / supply-chain readiness (assessment)

Not chasing a badge in this sprint.

Check State
Security policy Present (SECURITY.md)
Releases v0.1.0 published and archived; v2.x retained as legacy prereleases
Workflow permissions contents: read on Tests
Dependabot Configured
Pinned Actions Uses major tags (@v7); pin-to-SHA is a future hardening
Branch protection One approval, fresh approvals, thread resolution, current branch, Tests, and Documentation required
Signed tags v0.1.0 has a verified ED25519 SSH signature
Vulnerability reporting Private reporting enabled
Secret protection Secret scanning and push protection enabled
CodeQL Not enabled here; evaluate cost vs signal
Scorecard Optional later

Do not enable noisy workflows solely for a badge.