Skip to main content

OpenSSF Best Practices Badge (formerly CII)

OpenSSF Best Practices

This document tracks our compliance with the OpenSSF Best Practices Badge.

Status: 100% Passing ✅

RequirementStatusNote
Basic✅ PassApache-2.0 License, Documentation, English, Change History.
Change Control✅ PassGit, SemVer 2.0.0, Release Tags (vX.Y.Z).
Reporting✅ PassSECURITY.md, Private Vulnerability Reporting, 48h response SLA.
Quality✅ PassAutomated Dart build, CI tests (GitHub Actions), 100% line coverage.
Security✅ PassContinuous Fuzzing (ClusterFuzzLite), SAST (CodeQL), Dependabot, 0 leaks.
Analysis✅ PassStrict static analysis (dart analyze), dynamic assertion testing & fuzzing.

Action Items

  1. Register the project at bestpractices.dev.
  2. Complete the questionnaire with verifiable justifications across all 67 criteria.
  3. Add the official badge to README.md.