Goal
Complete the human and organizational requirements that automation cannot satisfy.
Current State
- Xquik-dev has one organization member.
- Every standalone project has one significant non-bot contributor.
- Ready remediation pull requests require independent human approval.
- No qualifying human security review is published.
- Silver and Gold badge answers remain explicitly Unmet.
See the public evidence register.
Required Outcomes
Significant Contributor Path
OpenSSF requires 2 unassociated significant contributors per project.
OpenSSF lists these typical significance indicators:
- At least 1,000 lines of code.
- At least 50 commits.
- At least 20 pages of documentation.
These are indicators, not automatic thresholds.
Contribution quality and project impact remain decisive.
Start with an open newcomer issue.
Then follow the selected repository's roadmap and contribution guide.
Useful significant work can span multiple reviewed pull requests.
Small first issues teach project contracts. They do not alone prove significance.
Never split work or inflate commits, pages, or line counts.
Every commit needs the contributor's own DCO sign-off.
Maintainers will link merged evidence here.
Association evidence must be voluntary, public, and privacy-preserving.
Safety Requirements
- Never post credentials, recovery codes, or private reports.
- Never publish private infrastructure details.
- Use least privilege for new maintainers.
- Preserve required checks and independent review.
- Do not count bots or AI systems as human reviewers.
- Do not mark a criterion Met without public evidence.
Completion Evidence
Link role changes, qualifying contributions, merged reviews, and security reviews here.
This tracker coordinates human work. It does not itself satisfy any criterion.
Goal
Complete the human and organizational requirements that automation cannot satisfy.
Current State
See the public evidence register.
Required Outcomes
Significant Contributor Path
OpenSSF requires 2 unassociated significant contributors per project.
OpenSSF lists these typical significance indicators:
These are indicators, not automatic thresholds.
Contribution quality and project impact remain decisive.
Start with an open newcomer issue.
Then follow the selected repository's roadmap and contribution guide.
Useful significant work can span multiple reviewed pull requests.
Small first issues teach project contracts. They do not alone prove significance.
Never split work or inflate commits, pages, or line counts.
Every commit needs the contributor's own DCO sign-off.
Maintainers will link merged evidence here.
Association evidence must be voluntary, public, and privacy-preserving.
Safety Requirements
Completion Evidence
Link role changes, qualifying contributions, merged reviews, and security reviews here.
This tracker coordinates human work. It does not itself satisfy any criterion.