遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/197)
<a href="https://www.bestpractices.dev/projects/197"><img src="https://www.bestpractices.dev/projects/197/badge"></a>
GnuPG is a complete and free implementation of the OpenPGP standard as defined by RFC4880. GnuPG allows to encrypt and sign your data and communication, features a versatile key management system as well as access modules for all kinds of public key directories. GnuPG, also known as GPG, is a command line tool with features for easy integration with other applications.
git
警告:需要更长的理由。
GnuPG defaults to reproducible builds.
警告:需要URL,但找不到URL。
A Jenkins instance is running on one machine. We are planning to make the results public available.
Met for Unix systems.
Only the project site uses HSTS but not bugs.gnupg.org.
On Unix we provide source and thus the user may add all required compiler flags. We are not aware of problems with these compiler flags. (On Windows, we do not use extra protection features right now.)
We don't run them ourself but rely on contributors who do that regulary; in particular using AFL. There is no requirement in the release process, though. However, major releases take place only every couple of years and the current code base has by then been analyzed.
The C files in GnuPG alone have about 770 call to assert and many other explicit checks for unexpected conditions.
后退