OWASP / OWASP/openshield

docs: complete OpenSSF Best Practices Silver criteria

Open
#199 1 comment 0 reactions 1 assignee View on GitHub

@TFT444 is already working on this.

Since Jul 16, 2026.

core enhancement
Dominant language
Python
Stars
57
Forks
68
Avg merge
3d 15h
Merged PRs (30d)
17

Description

Goal

Complete the OpenSSF Best Practices Silver assessment and provide clear evidence for every answer.

OpenShield already has the Passing badge. The Silver page currently shows 13% because many criteria are unanswered, although several requirements are already implemented.

Work needed

1. Add evidence for existing work

Use repository links to document existing CI, CodeQL, dependency scanning, SBOM generation, architecture, contribution standards, security reporting, tests, and the Code of Conduct.

2. Add missing project documentation
  • Governance and maintainer responsibilities
  • Access-continuity and bus-factor plan
  • Twelve-month roadmap
  • Security requirements, threat model, trust boundaries, and assurance case
  • Supported-version and upgrade policy
  • Release-signing and verification process
3. Close technical gaps
  • Measure and raise automated statement coverage toward the required 80%
  • Review allowlist-based input validation and security hardening
  • Confirm regression-test and strict-warning policies
  • Sign release artifacts and important version tags where applicable
4. Owner confirmation

Project owners must confirm maintainer access, continuity responsibilities, DCO/CLA approach, release-signing ownership, and any organization-level GitHub settings.

Completion

  • Every Silver criterion is marked Met, N/A, or Unmet with an honest justification
  • Required repository changes are reviewed and merged
  • Evidence URLs point to current public documentation
  • Owner-only actions are confirmed
  • The official assessment awards the Silver badge

No Gold status should be claimed until the official assessment confirms it.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.