Document OpenSSF Gold remediation evidence#2
Conversation
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
Live badge records were refreshed on 2026-07-24.
The contract checker still matches all 19 public repositories, 127 REST routes, 119 MCP tools, and 118 JSON/text operations. |
July 24 OpenSSF evidence updateThe live badge entries now have complete Silver and Gold assessments.
Authenticated contract verification passed: This evidence does not treat pending branches as default-branch proof. Human continuity, contributor, review, and security-review requirements remain explicitly Unmet. |
Gold
|
|
Verified the published RubyGems artifact independently. The RubyGems Sigstore bundle digest matches x-twitter-scraper-0.5.4.gem, and sigstore-cli validates the Xquik-dev publish workflow identity and transparency proof. Commit a129c32 records the exact consumer verification command and SHA-256 digest. All required checks pass on this head. |
|
Ledger update ce43b29 records the verified Java and Kotlin Maven Central releases. Fourteen projects now have public signed artifacts; C#, Go, and PHP remain. Consumer verification passed in Java run 30076440647 and Kotlin run 30076440671. The public contract checker still matches all 19 repositories: 127 REST routes, 119 MCP tools, and 118 JSON/text operations. This update also records the newly opened independent Haystack contribution and its current post-push review blocker. |
|
Cryptographic 2FA evidence is now recorded in |
|
Forward tag-signing policy added in |
|
Release-tag immutability evidence added in |
|
Maintainer readiness check: a local-only annotated tag signed with the GitHub-registered SSH signing key passed |
|
Organization API verification also confirms |
|
SEO and answer-engine maintenance evidence, 2026-07-24:
This records ongoing GitHub SEO, LLM answerability, and GEO hygiene without treating repetition as optimization. |
Discovery & Answer-Engine UpdateCommit Research and review rules are recorded in the organization discovery policy. This commit adds the organization discovery policy and enforces its anti-spam and answer-engine requirements. The public contract checker passed across 19 repositories with 127 REST, 119 MCP, and 118 JSON/text operations. Hosted checks are rerunning. A different human approval remains required before merge. |
furkanerday
left a comment
There was a problem hiding this comment.
Changes requested for two evidence defects:
-
CONTRIBUTING.md:42-52requires DCO sign-off for every non-trivial contribution, but commit32e67013cb044ad163de228c61e248dcdc6377b3has noSigned-off-by:trailer. Amend and re-push that commit with a valid author sign-off. -
OPENSSF.md:181-184presents post-push approval as the remaining blocker for Haystack #6. Its contributor commitfaf5d270also lacks the required DCO sign-off. The contributor must amend and re-push that commit, and this audit text must record the DCO blocker accurately.
The required check is green and I found no unresolved review threads, but the evidence cannot be approved while these DCO and accuracy issues remain.
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
2b59c1c to
8963b88
Compare
|
Addressed the requested changes.
Re-requesting independent review. |
furkanerday
left a comment
There was a problem hiding this comment.
Re-reviewed the updated head. The previously unsigned maintainer commit was rewritten with an author-matching DCO trailer, and OPENSSF.md now accurately records Haystack #6’s missing contributor sign-off and required amend/re-push. The incremental diff, current commit history, updated conversation, required check, and unresolved-thread state are clean; no actionable blocker remains.
Summary
Primary Guidance
Verification
node scripts/check-public-contract.mjsgit diff --checkThe organization review policy requires approval from a different human before merge.
Note
Document OpenSSF Gold remediation evidence and enforce discoverability policy checks
checkRepoDiscoveryvalidator that requires descriptions to be 70–200 chars, include an independence notice, and have 5–20 topics includingxquikand at least one customer-intent topic.Macroscope summarized 8963b88.