diff --git a/CHANGELOG.md b/CHANGELOG.md index 9bcd884..7992b49 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,8 @@ OpenShield uses [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ### Added +- OpenSSF Best Practices Passing Badge achieved with 100% of applicable Passing-level criteria completed +- Official live OpenSSF badge and verified project record added to project documentation - CBOM endpoints with per-asset quantum risk scoring and migration guidance - NCSC UK and ENISA post-quantum compliance framework mappings - Harvest Now Decrypt Later exposure window calculation per cryptographic asset diff --git a/README.md b/README.md index 4e99c1a..e3f43a5 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,6 @@ # OpenShield +[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/13618/badge)](https://www.bestpractices.dev/projects/13618) [![OpenShield CI](https://github.com/openshield-org/openshield/actions/workflows/ci.yml/badge.svg)](https://github.com/openshield-org/openshield/actions/workflows/ci.yml) [![CodeQL](https://github.com/openshield-org/openshield/actions/workflows/codeql.yml/badge.svg)](https://github.com/openshield-org/openshield/actions/workflows/codeql.yml) [![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT) @@ -57,6 +58,26 @@ Findings map to NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA --- +## Security Assurance + +OpenShield has achieved the **OpenSSF Best Practices Passing Badge**, completing 100% of the applicable Passing-level criteria across project governance, change control, reporting, quality, security, and code analysis. + +

+ + OpenSSF Best Practices Passing Badge + +

+ +

+ OpenSSF Best Practices - Passing +

+ +The project's OpenSSF status is publicly verifiable through the official OpenSSF Best Practices project record. OpenShield continues to strengthen its engineering, security assurance, and open source governance practices as it progresses through the higher-level criteria. + +**[View OpenShield's verified OpenSSF Best Practices record](https://www.bestpractices.dev/projects/13618)** + +--- + ## Architecture ```mermaid diff --git a/docs/assets/openssf-best-practices.svg b/docs/assets/openssf-best-practices.svg new file mode 100644 index 0000000..4fed636 --- /dev/null +++ b/docs/assets/openssf-best-practices.svg @@ -0,0 +1,524 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +