Skip to content

docs: OpenSSF Best Practices proposal — Silver plan, Scorecard fixes, Gold roadmap - #216

Merged
iracic82 merged 3 commits into
mainfrom
docs/openssf-best-practices-proposal
Jul 30, 2026
Merged

docs: OpenSSF Best Practices proposal — Silver plan, Scorecard fixes, Gold roadmap#216
iracic82 merged 3 commits into
mainfrom
docs/openssf-best-practices-proposal

Conversation

@IngmarVG-IB

Copy link
Copy Markdown
Collaborator

Summary

Audit-backed proposal for taking the project from the achieved Passing badge (100%, 2026-04-25) to Silver and Gold, plus Scorecard fixes.

Key findings from the audit:

  • The bestpractices.dev entry (project 12651) still points at the pre-rename infobloxopen org URL — this is why Scorecard's CII-Best-Practices check reports 0/10 despite the badge. @iracic82: updating the entry's repo/homepage URL is the single cheapest score improvement available.
  • Silver (15%) and Gold (22%) are low almost entirely because the questionnaires are unanswered; most Silver criteria are already satisfied by existing artifacts.
  • Maintainer decisions (review policy, coverage pacing, fuzzing scope, security-review route, timeline) are recorded in the doc's §Decisions.

Companion PRs implement the plan: docs set (roadmap/assurance case/policy paragraphs), CI hardening (coverage floor, hash-pinned release deps, repro-build, fuzzing), and the coverage push.

Review notes

  • This PR only adds docs/proposals/openssf-best-practices.md — no behavior changes.

Audit of badge project 12651 against the current repo: Passing is 100%
but every Silver/Gold/OSPS question is unanswered, and the badge entry
still points at the pre-rename infobloxopen org URL, which is why
Scorecard's CII-Best-Practices check reports 0 despite the badge.

Sequence the work into four phases: badge URL fix, questionnaire pass
over already-met criteria, small repo changes (roadmap, assurance case,
coverage gate, signed tags), and Gold items gated on contributor growth.

Signed-off-by: Ingmar Van Glabbeek <ivanglabbeek@infoblox.com>
…proposal

Interview outcomes: 1-approval review policy bound via enforce_admins,
dedicated coverage push to 90/80, repro-build + Atheris + OSS-Fuzz all
in scope, Infoblox internal security review, Gold-ready in 1-2 cycles.

Verified same day: 0 org members lack 2FA (require-2FA is safe to flip),
main already requires 1 review + 8 strict checks, and the uncovered-
statement mass concentrates in cli/main.py and mcp/server.py (~41%).

Signed-off-by: Ingmar Van Glabbeek <ivanglabbeek@infoblox.com>

@iracic82 iracic82 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Solid plan man. Maps out the whole road to Gold really well. Heads up that a chunk of it already landed. Phase 0 badge URL is fixed so CII sits at 5 now. Token-Permissions is 10 after the reusable workflow fix. #218 covers repro-build and fuzzing and pinned deps. And enforce_admins went on this morning. Approving.

@iracic82
iracic82 merged commit cbe6c42 into main Jul 30, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants