遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/9466)
<a href="https://www.bestpractices.dev/projects/9466"><img src="https://www.bestpractices.dev/projects/9466/badge"></a>
Generate a BOFH Excuse for github-cli from the commandline as a gh extension.
https://github.com/AliSajid/gh-bofh-rs/blob/main/CONTRIBUTING.md
https://github.com/AliSajid/gh-bofh-rs/blob/main/GOVERNANCE.md
https://github.com/AliSajid/gh-bofh-rs/blob/main/CODE_OF_CONDUCT.md
There are mechanisms in place to transfer information about this project to a secondary person if I die. https://github.com/AliSajid/gh-bofh-rs/blob/main/GOVERNANCE.md
This is a solo developer project.
https://github.com/AliSajid/gh-bofh-rs/blob/main/ROADMAP.md
https://github.com/AliSajid/gh-bofh-rs/blob/main/ARCHITECTURE.md
https://github.com/AliSajid/gh-bofh-rs/blob/main/SECURITY_REQUIREMENTS.md
https://github.com/AliSajid/gh-bofh-rs/blob/main/README.md
This project outputs a line on the terminal screen. This can be read by a screen reader.
This project is targeted specifically to the English-speaking world.
We do not store any login information
This is a part of the GitHub architecture
This is part of GitHub repo
We have not had any vulnerability reports over the past 12 months.
https://github.com/AliSajid/gh-bofh-rs/blob/main/SECURITY.md
The coding styles are enforced using pre-commit actions and CI
This is a part of the cargo build system.
The builds from rustc are repeatable and generate the exact same file no matter where it's run.
This is a GitHub CLI extension. It can be installed using either through gh CLI or cargo
There is a list of dependencies, and GitHub has those environments.
https://github.com/AliSajid/gh-bofh-rs/blob/main/Cargo.toml
We do that as a matter of policy. This is also auto-implemented with OSSF scorecard and renovate bot
We do both those things.
We use the Rust ecosystem
This is implemented with GitHub Actions
No bugs have been identified over the last 6 months.
We have 87% coverage.
This
This is used with Clippy
We use the minimal information necessary and don't touch the system itself.
All releases are GPG signed
Part of GitHub and release system
We do not take untrusted inputs.
We use whatever hardening mechanism when necessary.
https://github.com/AliSajid/gh-bofh-rs/blob/main/SECURITY_ASSURANCE.md
clippy
We use Rust.
后退