typo3-typoscript-ref-skill

Projects that follow the best practices below can voluntarily self-certify and show that they've achieved an Open Source Security Foundation (OpenSSF) best practices badge.

There is no set of practices that can guarantee that software will never have defects or vulnerabilities; even formal methods can fail if the specifications or assumptions are wrong. Nor is there any set of practices that can guarantee that a project will sustain a healthy and well-functioning development community. However, following best practices can help improve the results of projects. For example, some practices enable multi-person review before release, which can both help find otherwise hard-to-find technical vulnerabilities and help build trust and a desire for repeated interaction among developers from different companies. To earn a badge, all MUST and MUST NOT criteria must be met, all SHOULD criteria must be met OR be unmet with justification, and all SUGGESTED criteria must be met OR unmet (we want them considered at least). If you want to enter justification text as a generic comment, instead of being a rationale that the situation is acceptable, start the text block with '//' followed by a space. Feedback is welcome via the GitHub site as issues or pull requests There is also a mailing list for general discussion.

We gladly provide the information in several locales, however, if there is any conflict or inconsistency between the translations, the English version is the authoritative version.
If this is your project, please show your badge status on your project page! The badge status looks like this: Badge level for project 15074 is in_progress Here is how to embed it:
You can show your badge status by embedding this in your markdown file:
[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/15074/badge)](https://www.bestpractices.dev/projects/15074)
or by embedding this in your HTML:
<a href="https://www.bestpractices.dev/projects/15074"><img src="https://www.bestpractices.dev/projects/15074/badge"></a>


These are the Passing level criteria. You can also view the Silver or Gold level criteria.

Baseline Series: Baseline Level 1 Baseline Level 2 Baseline Level 3

        

 Basics 13/13 ●

 Change Control 8/9 ●

  • Public version-controlled source repository


    The project MUST have a version-controlled source repository that is publicly readable and has a URL. [repo_public]
    The URL MAY be the same as the project URL. The project MAY use private (non-public) branches in specific cases while the change is not publicly released (e.g., for fixing a vulnerability before it is revealed to the public).

    The public Git repository records intermediate development commits with author, timestamp and diff, and exposes pull requests before releases. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/commits/main https://github.com/netresearch/typo3-typoscript-ref-skill/pulls



    The project's source repository MUST track what changes were made, who made the changes, and when the changes were made. [repo_track]

    The public Git repository records intermediate development commits with author, timestamp and diff, and exposes pull requests before releases. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/commits/main https://github.com/netresearch/typo3-typoscript-ref-skill/pulls



    To enable collaborative review, the project's source repository MUST include interim versions for review between releases; it MUST NOT include only final releases. [repo_interim]
    Projects MAY choose to omit specific interim versions from their public source repositories (e.g., ones that fix specific non-public security vulnerabilities, may never be publicly released, or include material that cannot be legally posted and are not in the final release).

    The public Git repository records intermediate development commits with author, timestamp and diff, and exposes pull requests before releases. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/commits/main https://github.com/netresearch/typo3-typoscript-ref-skill/pulls



    It is SUGGESTED that common distributed version control software be used (e.g., git) for the project's source repository. [repo_distributed]
    Git is not specifically required and projects can use centralized version control software (such as subversion) with justification.

    The public Git repository records intermediate development commits with author, timestamp and diff, and exposes pull requests before releases. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/commits/main https://github.com/netresearch/typo3-typoscript-ref-skill/pulls


  • Unique version numbering


    The project results MUST have a unique version identifier for each release intended to be used by users. [version_unique]
    This MAY be met in a variety of ways including a commit IDs (such as git commit id or mercurial changeset id) or a version number (including version numbers that use semantic versioning or date-based schemes like YYYYMMDD).

    Published releases use versioned vMAJOR.MINOR.PATCH identifiers and corresponding Git tags; the reviewed release is v1.6.2. https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2 https://github.com/netresearch/typo3-typoscript-ref-skill/tags



    It is SUGGESTED that the Semantic Versioning (SemVer) or Calendar Versioning (CalVer) version numbering format be used for releases. It is SUGGESTED that those who use CalVer include a micro level value. [version_semver]
    Projects should generally prefer whatever format is expected by their users, e.g., because it is the normal format used by their ecosystem. Many ecosystems prefer SemVer, and SemVer is generally preferred for application programmer interfaces (APIs) and software development kits (SDKs). CalVer tends to be used by projects that are large, have an unusually large number of independently-developed dependencies, have a constantly-changing scope, or are time-sensitive. It is SUGGESTED that those who use CalVer include a micro level value, because including a micro level supports simultaneously-maintained branches whenever that becomes necessary. Other version numbering formats may be used as version numbers, including git commit IDs or mercurial changeset IDs, as long as they uniquely identify versions. However, some alternatives (such as git commit IDs) can cause problems as release identifiers, because users may not be able to easily determine if they are up-to-date. The version ID format may be unimportant for identifying software releases if all recipients only run the latest version (e.g., it is the code for a single website or internet service that is constantly updated via continuous delivery).

    Published releases use versioned vMAJOR.MINOR.PATCH identifiers and corresponding Git tags; the reviewed release is v1.6.2. https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2 https://github.com/netresearch/typo3-typoscript-ref-skill/tags



    It is SUGGESTED that projects identify each release within their version control system. For example, it is SUGGESTED that those using git identify each release using git tags. [version_tags]

    Published releases use versioned vMAJOR.MINOR.PATCH identifiers and corresponding Git tags; the reviewed release is v1.6.2. https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2 https://github.com/netresearch/typo3-typoscript-ref-skill/tags


  • Release notes


    The project MUST provide, in each release, release notes that are a human-readable summary of major changes in that release to help users determine if they should upgrade and what the upgrade impact will be. The release notes MUST NOT be the raw output of a version control log (e.g., the "git log" command results are not release notes). Projects whose results are not intended for reuse in multiple locations (such as the software for a single website or service) AND employ continuous delivery MAY select "N/A". (URL required) [release_notes]
    The release notes MAY be implemented in a variety of ways. Many projects provide them in a file named "NEWS", "CHANGELOG", or "ChangeLog", optionally with extensions such as ".txt", ".md", or ".html". Historically the term "change log" meant a log of every change, but to meet these criteria what is needed is a human-readable summary. The release notes MAY instead be provided by version control system mechanisms such as the GitHub Releases workflow.

    Published GitHub release pages provide human-readable change summaries and linked pull-request descriptions for users; these are the project's release-note channel. https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2 https://github.com/netresearch/typo3-typoscript-ref-skill/releases



    The release notes MUST identify every publicly known run-time vulnerability fixed in this release that already had a CVE assignment or similar when the release was created. This criterion may be marked as not applicable (N/A) if users typically cannot practically update the software themselves (e.g., as is often true for kernel updates). This criterion applies only to the project results, not to its dependencies. If there are no release notes or there have been no publicly known vulnerabilities, choose N/A. [release_notes_vulns]
    This criterion helps users determine if a given update will fix a vulnerability that is publicly known, to help users make an informed decision about updating. If users typically cannot practically update the software themselves on their computers, but must instead depend on one or more intermediaries to perform the update (as is often the case for a kernel and low-level software that is intertwined with a kernel), the project may choose "not applicable" (N/A) instead, since this additional information will not be helpful to those users. Similarly, a project may choose N/A if all recipients only run the latest version (e.g., it is the code for a single website or internet service that is constantly updated via continuous delivery). This criterion only applies to the project results, not its dependencies. Listing the vulnerabilities of all transitive dependencies of a project becomes unwieldy as dependencies increase and vary, and is unnecessary since tools that examine and track dependencies can do this in a more scalable way.

    No complete mapping of historical public vulnerability identifiers to fixed release notes was established. Empty GitHub advisory results alone do not prove no publicly known vulnerability ever existed. https://github.com/netresearch/typo3-typoscript-ref-skill/security/advisories https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2


 Reporting 7/8 ●

 Quality 12/13 ●

 Security 8/16 ●

  • Secure development knowledge


    The project MUST have at least one primary developer who knows how to design secure software. (See ‘details’ for the exact requirements.) [know_secure_design]
    This requires understanding the following design principles, including the 8 principles from Saltzer and Schroeder:
    • economy of mechanism (keep the design as simple and small as practical, e.g., by adopting sweeping simplifications)
    • fail-safe defaults (access decisions should deny by default, and projects' installation should be secure by default)
    • complete mediation (every access that might be limited must be checked for authority and be non-bypassable)
    • open design (security mechanisms should not depend on attacker ignorance of its design, but instead on more easily protected and changed information like keys and passwords)
    • separation of privilege (ideally, access to important objects should depend on more than one condition, so that defeating one protection system won't enable complete access. E.G., multi-factor authentication, such as requiring both a password and a hardware token, is stronger than single-factor authentication)
    • least privilege (processes should operate with the least privilege necessary)
    • least common mechanism (the design should minimize the mechanisms common to more than one user and depended on by all users, e.g., directories for temporary files)
    • psychological acceptability (the human interface must be designed for ease of use - designing for "least astonishment" can help)
    • limited attack surface (the attack surface - the set of the different points where an attacker can try to enter or extract data - should be limited)
    • input validation with allowlists (inputs should typically be checked to determine if they are valid before they are accepted; this validation should use allowlists (which only accept known-good values), not denylists (which attempt to list known-bad values)).
    A "primary developer" in a project is anyone who is familiar with the project's code base, is comfortable making changes to it, and is acknowledged as such by most other participants in the project. A primary developer would typically make a number of contributions over the past year (via code, documentation, or answering questions). Developers would typically be considered primary developers if they initiated the project (and have not left the project more than three years ago), have the option of receiving information on a private vulnerability reporting channel (if there is one), can accept commits on behalf of the project, or perform final releases of the project software. If there is only one developer, that individual is the primary developer. Many books and courses are available to help you understand how to develop more secure software and discuss design. For example, the Secure Software Development Fundamentals course is a free set of three courses that explain how to develop more secure software (it's free if you audit it; for an extra fee you can earn a certificate to prove you learned the material).

    Repository security guidance and automation do not establish the required knowledge of a named primary developer. A maintainer must confirm secure-design principles and common relevant error/mitigation knowledge. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/CONTRIBUTING.md https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md



    At least one of the project's primary developers MUST know of common kinds of errors that lead to vulnerabilities in this kind of software, as well as at least one method to counter or mitigate each of them. [know_common_errors]
    Examples (depending on the type of software) include SQL injection, OS injection, classic buffer overflow, cross-site scripting, missing authentication, and missing authorization. See the CWE/SANS top 25 or OWASP Top 10 for commonly used lists. Many books and courses are available to help you understand how to develop more secure software and discuss common implementation errors that lead to vulnerabilities. For example, the Secure Software Development Fundamentals course is a free set of three courses that explain how to develop more secure software (it's free if you audit it; for an extra fee you can earn a certificate to prove you learned the material).

    Repository security guidance and automation do not establish the required knowledge of a named primary developer. A maintainer must confirm secure-design principles and common relevant error/mitigation knowledge. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/CONTRIBUTING.md https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md


  • Use basic good cryptographic practices

    Note that some software does not need to use cryptographic mechanisms. If your project produces software that (1) includes, activates, or enables encryption functionality, and (2) might be released from the United States (US) to outside the US or to a non-US-citizen, you may be legally required to take a few extra steps. Typically this just involves sending an email. For more information, see the encryption section of Understanding Open Source Technology & US Export Controls.

    The software produced by the project MUST use, by default, only cryptographic protocols and algorithms that are publicly published and reviewed by experts (if cryptographic protocols and algorithms are used). [crypto_published]
    These cryptographic criteria do not always apply because some software has no need to directly use cryptographic capabilities.

    Network/integrity operations delegate to standard GitHub CLI, curl/Git or Python SSL/hash libraries as applicable. No project-defined cryptographic primitive is present in the reviewed helper surface. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    If the software produced by the project is an application or library, and its primary purpose is not to implement cryptography, then it SHOULD only call on software specifically designed to implement cryptographic functions; it SHOULD NOT re-implement its own. [crypto_call]

    Network/integrity operations delegate to standard GitHub CLI, curl/Git or Python SSL/hash libraries as applicable. No project-defined cryptographic primitive is present in the reviewed helper surface. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    All functionality in the software produced by the project that depends on cryptography MUST be implementable using FLOSS. [crypto_floss]

    Network/integrity operations delegate to standard GitHub CLI, curl/Git or Python SSL/hash libraries as applicable. No project-defined cryptographic primitive is present in the reviewed helper surface. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    The security mechanisms within the software produced by the project MUST use default keylengths that at least meet the NIST minimum requirements through the year 2030 (as stated in 2012). It MUST be possible to configure the software so that smaller keylengths are completely disabled. [crypto_keylength]
    These minimum bitlengths are: symmetric key 112, factoring modulus 2048, discrete logarithm key 224, discrete logarithmic group 2048, elliptic curve 224, and hash 224 (password hashing is not covered by this bitlength, more information on password hashing can be found in the crypto_password_storage criterion). See https://www.keylength.com for a comparison of keylength recommendations from various organizations. The software MAY allow smaller keylengths in some configurations (ideally it would not, since this allows downgrade attacks, but shorter keylengths are sometimes necessary for interoperability).

    Helpers delegate transport security to installed system clients/libraries. Supported client versions, every negotiated algorithm/key length and forward-secrecy settings were not established from the project sources. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    The default security mechanisms within the software produced by the project MUST NOT depend on broken cryptographic algorithms (e.g., MD4, MD5, single DES, RC4, Dual_EC_DRBG), or use cipher modes that are inappropriate to the context, unless they are necessary to implement an interoperable protocol (where the protocol implemented is the most recent version of that standard broadly supported by the network ecosystem, that ecosystem requires the use of such an algorithm or mode, and that ecosystem does not offer any more secure alternative). The documentation MUST describe any relevant security risks and any known mitigations if these broken algorithms or modes are necessary for an interoperable protocol. [crypto_working]
    ECB mode is almost never appropriate because it reveals identical blocks within the ciphertext as demonstrated by the ECB penguin, and CTR mode is often inappropriate because it does not perform authentication and causes duplicates if the input state is repeated. In many cases it's best to choose a block cipher algorithm mode designed to combine secrecy and authentication, e.g., Galois/Counter Mode (GCM) and EAX. Projects MAY allow users to enable broken mechanisms (e.g., during configuration) where necessary for compatibility, but then users know they're doing it.

    Helpers delegate transport security to installed system clients/libraries. Supported client versions, every negotiated algorithm/key length and forward-secrecy settings were not established from the project sources. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    The default security mechanisms within the software produced by the project SHOULD NOT depend on cryptographic algorithms or modes with known serious weaknesses (e.g., the SHA-1 cryptographic hash algorithm or the CBC mode in SSH). [crypto_weaknesses]
    Concerns about CBC mode in SSH are discussed in CERT: SSH CBC vulnerability.

    Helpers delegate transport security to installed system clients/libraries. Supported client versions, every negotiated algorithm/key length and forward-secrecy settings were not established from the project sources. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    The security mechanisms within the software produced by the project SHOULD implement perfect forward secrecy for key agreement protocols so a session key derived from a set of long-term keys cannot be compromised if one of the long-term keys is compromised in the future. [crypto_pfs]

    Helpers delegate transport security to installed system clients/libraries. Supported client versions, every negotiated algorithm/key length and forward-secrecy settings were not established from the project sources. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    If the software produced by the project causes the storing of passwords for authentication of external users, the passwords MUST be stored as iterated hashes with a per-user salt by using a key stretching (iterated) algorithm (e.g., Argon2id, Bcrypt, Scrypt, or PBKDF2). See also OWASP Password Storage Cheat Sheet. [crypto_password_storage]
    This criterion applies only when the software is enforcing authentication of users using passwords for external users (aka inbound authentication), such as server-side web applications. It does not apply in cases where the software stores passwords for authenticating into other systems (aka outbound authentication, e.g., the software implements a client for some other system), since at least parts of that software must have often access to the unhashed password.

    The helper tools do not provide inbound password-based authentication for external users or generate authentication keys/nonces. Outbound access uses external clients/credentials. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh



    The security mechanisms within the software produced by the project MUST generate all cryptographic keys and nonces using a cryptographically secure random number generator, and MUST NOT do so using generators that are cryptographically insecure. [crypto_random]
    A cryptographically secure random number generator may be a hardware random number generator, or it may be a cryptographically secure pseudo-random number generator (CSPRNG) using an algorithm such as Hash_DRBG, HMAC_DRBG, CTR_DRBG, Yarrow, or Fortuna. Examples of calls to secure random number generators include Java's java.security.SecureRandom and JavaScript's window.crypto.getRandomValues. Examples of calls to insecure random number generators include Java's java.util.Random and JavaScript's Math.random.

    The helper tools do not provide inbound password-based authentication for external users or generate authentication keys/nonces. Outbound access uses external clients/credentials. https://github.com/netresearch/typo3-typoscript-ref-skill/blob/7158cb39f17336ebca077e4617d753ec4ece14c9/skills/typo3-typoscript-ref/scripts/fetch-docs.sh


  • Secured delivery against man-in-the-middle (MITM) attacks


    The project MUST use a delivery mechanism that counters MITM attacks. Using https or ssh+scp is acceptable. [delivery_mitm]
    An even stronger mechanism is releasing the software with digitally signed packages, since that mitigates attacks on the distribution system, but this only works if the users can be confident that the public keys for signatures are correct and if the users will actually check the signature.

    The official repository, issue tracker, releases and listed package-installation channels use HTTPS. Release checksums and signature bundles are delivered through the same HTTPS GitHub release channel. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2



    A cryptographic hash (e.g., a sha1sum) MUST NOT be retrieved over http and used without checking for a cryptographic signature. [delivery_unsigned]
    These hashes can be modified in transit.

    The official repository, issue tracker, releases and listed package-installation channels use HTTPS. Release checksums and signature bundles are delivered through the same HTTPS GitHub release channel. https://github.com/netresearch/typo3-typoscript-ref-skill https://github.com/netresearch/typo3-typoscript-ref-skill/releases/tag/v1.6.2


  • Publicly known vulnerabilities fixed


    There MUST be no unpatched vulnerabilities of medium or higher severity that have been publicly known for more than 60 days. [vulnerabilities_fixed_60_days]
    The vulnerability must be patched and released by the project itself (patches may be developed elsewhere). A vulnerability becomes publicly known (for this purpose) once it has a CVE with publicly released non-paywalled information (reported, for example, in the National Vulnerability Database) or when the project has been informed and the information has been released to the public (possibly by the project). A vulnerability is considered medium or higher severity if its Common Vulnerability Scoring System (CVSS) base qualitative score is medium or higher. In CVSS versions 2.0 through 3.1, this is equivalent to a CVSS score of 4.0 or higher. Projects may use the CVSS score as published in a widely-used vulnerability database (such as the National Vulnerability Database) using the most-recent version of CVSS reported in that database. Projects may instead calculate the severity themselves using the latest version of CVSS at the time of the vulnerability disclosure, if the calculation inputs are publicly revealed once the vulnerability is publicly known. Note: this means that users might be left vulnerable to all attackers worldwide for up to 60 days. This criterion is often much easier to meet than what Google recommends in Rebooting responsible disclosure, because Google recommends that the 60-day period start when the project is notified even if the report is not public. Also note that this badge criterion, like other criteria, applies to the individual project. Some projects are part of larger umbrella organizations or larger projects, possibly in multiple layers, and many projects feed their results to other organizations and projects as part of a potentially-complex supply chain. An individual project often cannot control the rest, but an individual project can work to release a vulnerability patch in a timely way. Therefore, we focus solely on the individual project's response time. Once a patch is available from the individual project, others can determine how to deal with the patch (e.g., they can update to the newer version or they can apply just the patch as a cherry-picked solution).

    The published vulnerability policy and advisory channel were reviewed, but a complete inventory of reported/known vulnerabilities and actual remediation dates was not available. No assurance of absence or timeliness is inferred from an empty advisory list. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md https://github.com/netresearch/typo3-typoscript-ref-skill/security/advisories



    Projects SHOULD fix all critical vulnerabilities rapidly after they are reported. [vulnerabilities_critical_fixed]

    The published vulnerability policy and advisory channel were reviewed, but a complete inventory of reported/known vulnerabilities and actual remediation dates was not available. No assurance of absence or timeliness is inferred from an empty advisory list. https://github.com/netresearch/.github/blob/535c3130fcb2e508a0720c9b977504a5b6287f50/SECURITY.md https://github.com/netresearch/typo3-typoscript-ref-skill/security/advisories


  • Other security issues


    The public repositories MUST NOT leak a valid private credential (e.g., a working password or private key) that is intended to limit public access. [no_leaked_credentials]
    A project MAY leak "sample" credentials for testing and unimportant databases, as long as they are not intended to limit public access.

    Current authenticated GitHub secret-scanning alert state reports zero open alerts, with secret scanning and push protection enabled. No valid leaked private credential is known from this evidence as of 2026-09-29; this is a current bounded observation, not proof against unknown future findings. https://github.com/netresearch/typo3-typoscript-ref-skill/security/secret-scanning https://api.github.com/repos/netresearch/typo3-typoscript-ref-skill/secret-scanning/alerts?state=open


 Analysis 5/8 ●


You can use tools and AI systems to propose changes via a simple URL, such as https://www.bestpractices.dev/en/projects/15074/choose/edit?osps_ac_01_01_status=Met&osps_ac_01_01_justification=GitHub+enforced. See our automation proposals system for how to do that. This data is available under the Community Data License Agreement – Permissive, Version 2.0 (CDLA-Permissive-2.0). This means that a Data Recipient may share the Data, with or without modifications, so long as the Data Recipient makes available the text of this agreement with the shared Data. Please credit Sebastian Mendel and the OpenSSF Best Practices badge contributors.

Project badge entry owned by: Sebastian Mendel.
Entry created on 2026-09-29 06:09:07 UTC, last updated on 2026-09-29 15:39:25 UTC.