遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/3587)
<a href="https://www.bestpractices.dev/projects/3587"><img src="https://www.bestpractices.dev/projects/3587/badge"></a>
An extensible CLI tool responsible for enforcing user-defined rules
https://github.com/gabor-boros/hammurabi/blob/master/CONTRIBUTING.rst
The project uses GitHub issue tracker available at https://github.com/gabor-boros/hammurabi/issues
no vulnerabilities resolved in the last 12 months
https://hammurabi.readthedocs.io/en/latest/vulnerabilities.html
Code must meet PEPs. The linter and CI will ensure that the findings reported by linters are applied. https://github.com/gabor-boros/hammurabi/blob/master/Makefile#L70
https://github.com/gabor-boros/hammurabi/blob/master/Makefile#L70 https://github.com/gabor-boros/hammurabi/blob/master/.travis.yml#L19
no native binaries are being generated
no build or installation system
no building occurs
package can be installed/removed by pip, poetry or similar tools which can install from pypi.org
https://github.com/gabor-boros/hammurabi/blob/master/poetry.lock
GitHub and Dependabot continuously checks it
https://github.com/gabor-boros/hammurabi/network/alerts
https://github.com/gabor-boros/hammurabi/blob/master/CONTRIBUTING.rst#pull-request-guidelines
Python has no concept compiler warning flags. All the warnings are handled by the tools used and can be mitigated through their config
No cryptographic protocols or algorithms are used
Tool used for checking not secure code is bandit, for vulnerability issues we use GitHub's built in solution: https://github.com/gabor-boros/hammurabi/network/alerts
警告:需要更长的理由。
后退