遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/4020)
<a href="https://www.bestpractices.dev/projects/4020"><img src="https://www.bestpractices.dev/projects/4020/badge"></a>
A K8s-native Pipeline resource.
The project has a maintainer team of 10 individuals. We have policies about what it takes to become and remain a maintainer: https://github.com/tektoncd/community/blob/main/process.md#owners We have topical ownership to provide finer granularity as well: https://github.com/tektoncd/pipeline/blob/main/topical-ownership.md I executed the "track-factor" tool against the repository and got a factor of 6.
Repository on GitHub, which uses git. git is distributed.
Unit tests, build tests and integration/e2e are executed via "go test", which is the standard way for golang applications.
警告:需要URL,但找不到URL。
Tekton Pipelines implements continuous integration. Feature branches are shot lived only, we follow the "pull request" model of GitHub. The "main" branch is always in a releasable state.
// X-Content-Type-Options was not set to "nosniff".
Some fuzzing testing was performed as part of Tekton security audit. We may run fuzzing on a regular basis in future: https://github.com/tektoncd/pipeline/issues/5564
We do not run fuzzing tests yet.
后退