Skip to content

Complete the human prerequisites for OpenSSF Silver and Gold #3

Description

@kriptoburak

Goal

Complete the human and organizational requirements that automation cannot satisfy.

Current State

  • Xquik-dev has one organization member.
  • Every standalone project has one significant non-bot contributor.
  • Ready remediation pull requests require independent human approval.
  • No qualifying human security review is published.
  • Silver and Gold badge answers remain explicitly Unmet.

See the public evidence register.

Required Outcomes

  • Add a second trusted maintainer with review, merge, and release continuity.
  • Document that maintainer's public role and release authority.
  • Accept significant work from 2 unassociated contributors per project.
  • Record independent review for at least 50% of released modifications.
  • Complete a scoped human security review for every standalone project.
  • Publish each review's scope, date, boundary, findings, and remediation status.
  • Recheck every live bestpractices.dev entry after evidence reaches default branches.

Significant Contributor Path

OpenSSF requires 2 unassociated significant contributors per project.

OpenSSF lists these typical significance indicators:

  • At least 1,000 lines of code.
  • At least 50 commits.
  • At least 20 pages of documentation.

These are indicators, not automatic thresholds.

Contribution quality and project impact remain decisive.

Start with an open newcomer issue.

Then follow the selected repository's roadmap and contribution guide.

Useful significant work can span multiple reviewed pull requests.

Small first issues teach project contracts. They do not alone prove significance.

Never split work or inflate commits, pages, or line counts.

Every commit needs the contributor's own DCO sign-off.

Maintainers will link merged evidence here.

Association evidence must be voluntary, public, and privacy-preserving.

Safety Requirements

  • Never post credentials, recovery codes, or private reports.
  • Never publish private infrastructure details.
  • Use least privilege for new maintainers.
  • Preserve required checks and independent review.
  • Do not count bots or AI systems as human reviewers.
  • Do not mark a criterion Met without public evidence.

Completion Evidence

Link role changes, qualifying contributions, merged reviews, and security reviews here.

This tracker coordinates human work. It does not itself satisfy any criterion.

Metadata

Metadata

Assignees

No one assigned

    Labels

    governanceProject roles, access, and decision processeshelp wantedExtra attention is neededopenssfOpenSSF Best Practices evidence and remediation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions