Tracking issue for the two Gold criteria that can't be closed by engineering work alone (execution plan: docs/proposals/openssf-best-practices.md, PR #216):
contributors_unassociated (Gold MUST)
Requires two significant contributors not associated with the same organization. Current state: all three maintainers are Infoblox-affiliated; 210 of ~221 human commits are from one person. Candidates exist in the pipeline (IETF draft co-authors, ARD-ecosystem developers).
security_review (Gold MUST)
Decided route: Infoblox product-security team review, with reviewers independent of the dev team. Scope: the assurance case (docs/security/assurance-case.md, PR #217), SSRF/input-validation paths, DNSSEC/DANE trust handling, release pipeline.
Everything else on the Gold list is covered by PRs #217/#218, the coverage push, and org settings (require-2FA, enforce_admins — the latter already enabled).
Tracking issue for the two Gold criteria that can't be closed by engineering work alone (execution plan:
docs/proposals/openssf-best-practices.md, PR #216):contributors_unassociated (Gold MUST)
Requires two significant contributors not associated with the same organization. Current state: all three maintainers are Infoblox-affiliated; 210 of ~221 human commits are from one person. Candidates exist in the pipeline (IETF draft co-authors, ARD-ecosystem developers).
good first issuelabels maintained to feed the pipeline (Goldsmall_tasks)security_review (Gold MUST)
Decided route: Infoblox product-security team review, with reviewers independent of the dev team. Scope: the assurance case (
docs/security/assurance-case.md, PR #217), SSRF/input-validation paths, DNSSEC/DANE trust handling, release pipeline.Everything else on the Gold list is covered by PRs #217/#218, the coverage push, and org settings (require-2FA, enforce_admins — the latter already enabled).