Skip to main content

OpenSSF Best Practices badge

Kairon is registered as project 15141 on OpenSSF Best Practices. Scorecard's CII-Best-Practices check reads that entry: in progress → 2, passing → 5, silver → 7, gold → 10.

Where the evidence lives​

Criteria areaEvidence
Description, obtain, feedbackREADME.md, GitHub Issues, Releases
Contribution process + requirementsCONTRIBUTING.md (PR process, coding standard, test policy)
LicenseLICENSE (Apache-2.0)
Interface docsdocs/CLI.md, docs/guides/, CRDs in charts/kairon
Releases / notesSemVer tags vX.Y.Z, RELEASE_NOTES.md
Vulnerability reportingSECURITY.md (private email + GitHub advisories, 14-day ack)
Build / test / CImake all, .github/workflows/ci.yml
Warnings / static analysisgo vet, golangci-lint (.golangci.yml), CodeQL, govulncheck, Trivy
Dynamic analysisgo test -race, native Go fuzzing (.github/workflows/fuzz.yml)
Signed deliverycosign keyless signatures + SBOM attestations (release.yml), SHA256SUMS

Maintained check​

Scorecard Maintained stays at 0 until the repository is older than 90 days (created 2026-09-11 → eligible ~2026-12-10), then needs roughly weekly commits. No code change can advance that calendar.