Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
</a>
</td>
This project identifies best practices for Free/Libre and Open Source Software (FLOSS) and implements a badging system for those best practices. The "BadgeApp" badging system is a simple web application that lets projects self-certify that they meet the criteria and show a badge. The real goal of this project is to encourage projects to apply best practices, and to help users determine which FLOSS projects do so. We believe that FLOSS projects that implement best practices are more likely to produce better software, including more secure software. We support both our original "metal" badge criteria and the OpenSSF Baseline criteria.
See the OpenSSF Best Practices badge website if you want to try to actually get a badge.
This is the development site for the criteria and badge application software that runs the website. Feedback is very welcome via the GitHub site as issues or pull (merge) requests. There is also a mailing list for general discussion. This project was originally developed under the CII, but it is now part of the Open Source Security Foundation (OpenSSF) Best Practices Working Group (WG). Its formal name is the OpenSSF Best Practices badge project, formerly named the CII Best Practices badge.
Interesting pages include:
The best practices badge site supports both the OpenSSF Baseline criteria (baseline-1,2,3) and its own "Metal series" of criteria (passing, silver, gold).
The baseline series is a more minimal checklist focusing only on MUST security requirements and is derived in part from global cybersecurity regulations and frameworks. The metal series is a larger set of criteria that includes suggestions and quality issues that impact security, and is derived in part from experiences of secure FLOSS projects. Both focus on security.
We encourage projects to eventually do both. You choose where to start. Once you do one series, it's much easier to do the other.
This is a summary of the passing criteria, with requirements in bold:
Getting a passing badge is a significant achievement; on average only about 10% of pursuing projects have a passing badge. That said, some projects would like to meet even stronger criteria, and many users would like projects to do so. We have established two higher levels beyond passing: silver and gold. The higher levels strengthen some of the passing criteria and add new criteria of their own.
Here is a summary of the silver criteria, with requirements in bold (for details, see the full list of silver criteria):
Here is a summary of the gold criteria, with requirements in bold (for details, see the full list of gold criteria):
If you've used this system in the past, you may have referred to our doc
subdirectory for documentation. We have renamed that to a docs subdirectory.
Years ago we moved our main site to https://www.bestpractices.dev.
For many years the main site previously was at https://bestpractices.coreinfrastructure.org. Ho
No open issues yet, or sync has not completed.