OpenSSF Proposal Links
Use these links when updating OpenSSF Best Practices evidence or creating follow-up issues.
Primary links
- OpenSSF Best Practices project: https://www.bestpractices.dev/projects/13378
- OpenSSF Scorecard viewer: https://scorecard.dev/viewer/?uri=github.com/oaslananka/boardreadyops
- Repository: https://github.com/oaslananka/boardreadyops
- Releases: https://github.com/oaslananka/boardreadyops/releases
- npm package: https://www.npmjs.com/package/boardreadyops
- GitHub Marketplace Action: https://github.com/marketplace/actions/boardreadyops
Evidence links
- README: https://github.com/oaslananka/boardreadyops/blob/main/README.md
- License: https://github.com/oaslananka/boardreadyops/blob/main/LICENSE
- Contribution guide: https://github.com/oaslananka/boardreadyops/blob/main/CONTRIBUTING.md
- Code of conduct: https://github.com/oaslananka/boardreadyops/blob/main/CODE_OF_CONDUCT.md
- Security policy: https://github.com/oaslananka/boardreadyops/blob/main/SECURITY.md
- Support policy: https://github.com/oaslananka/boardreadyops/blob/main/SUPPORT.md
- Governance: https://github.com/oaslananka/boardreadyops/blob/main/GOVERNANCE.md
- Maintainers: https://github.com/oaslananka/boardreadyops/blob/main/MAINTAINERS.md
- Maturity report: https://github.com/oaslananka/boardreadyops/blob/main/docs/repo-maturity-report.md
- Release process: https://github.com/oaslananka/boardreadyops/blob/main/docs/development/release-process.md
- Release integrity: https://github.com/oaslananka/boardreadyops/blob/main/docs/security/release-integrity.md
- Testing policy: https://github.com/oaslananka/boardreadyops/blob/main/docs/development/testing-policy.md
- Dependency management: https://github.com/oaslananka/boardreadyops/blob/main/docs/development/dependency-management.md
BadgeApp proposal notes
When updating the BadgeApp project, do not overclaim Gold. Use Passed only for
items with repository evidence or maintainer-confirmed settings. Use Partial or
Needs human confirmation for branch protection details, private vulnerability
reporting, secret scanning/push protection, and independent review until verified
in GitHub settings and recent PR history.