Skip to the content.

OpenSSF Gold Checklist

coding-ethos targets the OpenSSF Best Practices Gold badge. The badge is used as a project-improvement checklist: when a criterion is unmet or unknown, the preferred response is to improve the repository, governance, CI, release process, or documentation until the answer is true.

The root .bestpractices.json file is the durable machine-readable source for repo-hosted Best Practices proposals. Keep it aligned with the public project record and ask the Best Practices site to reanalyze the repository when the project is saved with automation enabled. Query-string prefill URLs are not a supported workflow for this repo; they proved too fragile and can silently fail to apply the intended evidence.

Current Repo-Side Remediations

Remaining Gold Gaps

These are intentionally not papered over by repo-local evidence:

The following repo-side gaps were remediated by public docs and .bestpractices.json evidence:

Current Gold count after repo-side remediation:

Baseline Criteria

The public project JSON also includes OSPS Baseline criteria. Track those in .bestpractices.json if they become part of the project target.