OpenSSF Best Practices badge
Kairon is registered as project
15141 on
OpenSSF Best Practices. Scorecard's
CII-Best-Practices check reads that entry: in progress → 2, passing → 5,
silver → 7, gold → 10.
Where the evidence lives
| Criteria area | Evidence |
|---|---|
| Description, obtain, feedback | README.md, GitHub Issues, Releases |
| Contribution process + requirements | CONTRIBUTING.md (PR process, coding standard, test policy) |
| License | LICENSE (Apache-2.0) |
| Interface docs | docs/CLI.md, docs/guides/, CRDs in charts/kairon |
| Releases / notes | SemVer tags vX.Y.Z, RELEASE_NOTES.md |
| Vulnerability reporting | SECURITY.md (private email + GitHub advisories, 14-day ack) |
| Build / test / CI | make all, .github/workflows/ci.yml |
| Warnings / static analysis | go vet, golangci-lint (.golangci.yml), CodeQL, govulncheck, Trivy |
| Dynamic analysis | go test -race, native Go fuzzing (.github/workflows/fuzz.yml) |
| Signed delivery | cosign keyless signatures + SBOM attestations (release.yml), SHA256SUMS |
Maintained check
Scorecard Maintained stays at 0 until the repository is older than 90
days (created 2026-09-11 → eligible ~2026-12-10), then needs roughly
weekly commits. No code change can advance that calendar.