OpenSSF Best Practices Badge (formerly CII)
This document tracks our compliance with the OpenSSF Best Practices Badge.
Status: 100% Passing ✅
| Requirement | Status | Note |
|---|---|---|
| Basic | ✅ Pass | Apache-2.0 License, Documentation, English, Change History. |
| Change Control | ✅ Pass | Git, SemVer 2.0.0, Release Tags (vX.Y.Z). |
| Reporting | ✅ Pass | SECURITY.md, Private Vulnerability Reporting, 48h response SLA. |
| Quality | ✅ Pass | Automated Dart build, CI tests (GitHub Actions), 100% line coverage. |
| Security | ✅ Pass | Continuous Fuzzing (ClusterFuzzLite), SAST (CodeQL), Dependabot, 0 leaks. |
| Analysis | ✅ Pass | Strict static analysis (dart analyze), dynamic assertion testing & fuzzing. |
Action Items
- Register the project at bestpractices.dev.
- Complete the questionnaire with verifiable justifications across all 67 criteria.
- Add the official badge to
README.md.