WhitePact

本サイトが提示する下記のベストプラクティスを実行するプロジェクトは、Open Source Security Foundation (OpenSSF) バッジを達成したことを自主的に自己認証し、そのことを外部に示すことができます。

ソフトウェアに欠陥や脆弱性がないことを保証する手立てはありません。形式論的な証明ができたとしても、仕様や前提が間違っていると誤動作の可能性があります。また、プロジェクトが健全で、かつ機能的な開発コミュニティであり続けることを保証する手立てもありません。しかし、ベストプラクティスの採用は、プロジェクトの成果の向上に寄与する可能性があります。たとえば、いくつものベストプラクティスがリリース前の複数人によるレビューを定めていますが、それによりレビュー以外では発見困難な技術的脆弱性を見つけるのを助け、同時に異なる企業の開発者間の信頼を築き、さらに交流を続けることに対する意欲を生んでいます。バッジを獲得するには、すべてのMUSTおよびMUST NOT基準を満たさなければなりません。すべてのSHOULD基準も満たさなければなりませんが、正当な理由がある場合は満たさなくても構いません。そしてすべてのSUGGESTED基準も満たさなければなりませんが、満たさないとしても、少なくとも考慮することが望まれます。フィードバックは、 GitHubサイトのissueまたはpull requestとして提示されれば歓迎します。また、議論のためのメールリストも用意されています。

私たちは多言語で情報を提供していますが、翻訳版に矛盾や意味の不一致がある場合は、英語版を正式な記述とします。
これがあなたのプロジェクトである場合は、プロジェクトページにベースラインバッジステータスを表示してください!ベースラインバッジステータスは次のようになります: プロジェクト14112のベースラインバッジレベルはbaseline-1です ベースラインバッジを埋め込む方法は次のとおりです:
ベースラインバッジステータスを表示するには、マークダウンファイルに以下を埋め込みます:
[![OpenSSF Baseline](https://www.bestpractices.dev/projects/14112/baseline)](https://www.bestpractices.dev/projects/14112)
または、HTMLに以下を埋め込みます:
<a href="https://www.bestpractices.dev/projects/14112"><img src="https://www.bestpractices.dev/projects/14112/baseline"></a>


これらはベースラインレベル2の基準です。 これらは基準バージョン v2026.08.28 の評価項目です。

Baseline Series: ベースラインレベル1 ベースラインレベル2 ベースラインレベル3

        

 基本的情報

  • 一般

    他のプロジェクトが同じ名前を使用していないか注意してください。

    WhitePact is an open-source runtime authority, governance, and assurance layer for autonomous systems. It provides deterministic five-way authorization decisions (ALLOW, ALLOW_WITH_REDACTION, REQUIRE_APPROVAL, DENY, QUARANTINE), policy and risk enforcement, human approval workflows, tamper-evident evidence, MCP governance, trust controls, guardrails, and enterprise integration tooling.

    SPDXライセンスの表現形式を使用してください。 例:「Apache-2.0」、「BSD-2-Clause」、「BSD-3-Clause」、「GPL-2.0+」、「LGPL-3.0+」、「MIT」、「(BSD-2-Clause OR Ruby)」。一重引用符または二重引用符を含めないでください。
    複数の言語がある場合は、コンマを区切り(スペースを入れてもよい)としてリストし、使用頻度の高いものから順に並べます。使用言語が多くある場合は、少なくとも最初の3つの最も多く使われるものをリストアップしてください。言語がない場合(例:ドキュメントだけ、またはテスト専用のプロジェクトの場合)、1文字 " - "を使用します。言語ごとにある大文字・小文字の慣用を踏襲してください(例:「JavaScript」)。
    Common Platform Enumeration(CPE)は、情報技術(IT)システム、ソフトウェア、およびパッケージのための構造化された命名体系です。脆弱性を報告する際に、多くのシステムやデータベースで使用されています。

 管理策 18/19 ●

  • 管理策


    CI/CDタスクが権限を指定せずに実行される場合、CI/CDシステムはパイプラインで付与される最低限の権限をタスクの権限としてデフォルトで設定しなければなりません。 [OSPS-AC-04.01]
    プロジェクトの設定を構成して、デフォルトで新しいパイプラインに利用可能な最低限の権限を割り当て、特定のタスクに必要な場合にのみ追加の権限を付与します。

    STATUS: UNMET
    EVIDENCE: The official current-main OpenSSF Scorecard assessment at commit 9dcdc1bebe0ad856bd399dc627d17c35a2cc5828 reports Token-Permissions 0 and identifies a workflow without top-level default permissions.
    JUSTIFICATION: PR #52 adds least-privilege defaults, but it is still unmerged; branch-only evidence is not represented as current-main compliance.
    URL: https://scorecard.dev/viewer/?uri=github.com/Guruprasath-Annadurai/Whitepact



    公式リリースが作成される場合、そのリリースには一意のバージョン識別子を割り当てなければなりません。 [OSPS-BR-02.01]
    プロジェクトによって生成される各リリースに、一貫した命名規則または番号付けスキームに従って一意のバージョン識別子を割り当てます。例には、SemVer、CalVer、またはgit commit idが含まれます。

    Each WhitePact release uses a unique version identifier. The project version is maintained in pyproject.toml and released versions use distinct semantic version numbers such as v1.0.0, v1.1.0, v1.2.0, v1.2.1, and v1.2.2.

    https://github.com/Guruprasath-Annadurai/Whitepact/releases [version_unique]



    公式リリースが作成される場合、そのリリースには機能的およびセキュリティの変更の記述的なログを含めなければなりません。 [OSPS-BR-04.01]
    すべてのリリースに記述的な変更ログを含めるようにしてください。変更ログが人間が読めるものであり、コミットメッセージだけでなく、セキュリティへの影響や異なるユースケースとの関連性についての説明などの詳細を含めることが推奨されます。機械可読性を確保するために、「## Changelog」などのmarkdownヘッダーの下にコンテンツを配置してください。

    Non-trivial release notes file in repository: https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CHANGELOG.md. [release_notes]



    ビルドとリリースのパイプラインが依存関係を取り込む場合、利用可能な場合は標準化されたツールを使用しなければなりません。 [OSPS-BR-05.01]
    エコシステム用の一般的なツール(パッケージマネージャーや依存関係管理ツールなど)を使用して、ビルド時に依存関係を取り込みます。これには、必要な依存関係を指定するための依存関係ファイル、ロックファイル、またはマニフェストを使用し、ビルドシステムによって取り込まれることが含まれます。

    WhitePact declares its external runtime, optional, and development dependencies in the machine-processable pyproject.toml package configuration.

    Dependencies are separated into the core dependency list and named optional groups for dashboard, PostgreSQL, Redis, telemetry, SSO, model providers, billing, testing, and other integrations.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/pyproject.toml [external_dependencies]



    公式リリースが作成される場合、そのリリースには署名するか、各アセットの暗号ハッシュを含む署名付きマニフェストで説明しなければなりません。 [OSPS-BR-06.01]
    ビルド時にすべてのリリースされたソフトウェア アセットを、GPGまたはPGP署名、Sigstore署名、SLSAプロベナンス、またはSLSA VSAなどの暗号署名または証明で署名します。署名付きマニフェストまたはメタデータファイルに各アセットの暗号ハッシュを含めます。

    WhitePact cryptographically attests its published wheel and source-distribution artifacts using GitHub Artifact Attestations backed by Sigstore and GitHub Actions OIDC.

    The release workflow creates build-provenance attestations for dist/* before publishing to PyPI and uses PyPI Trusted Publishing, so no long-lived private PyPI or signing key is stored on the public distribution service.

    Every GitHub Release includes verification instructions:

    gh attestation verify <artifact> --owner Guruprasath-Annadurai

    This verifies that the artifact was produced by WhitePact's trusted GitHub Actions workflow from the identified repository and commit.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/.github/workflows/publish.yml [signed_releases]



    プロジェクトがリリースを行った場合、プロジェクトのドキュメントには、プロジェクトが依存関係をどのように選択、取得、および追跡するかについての説明を含めなければなりません。 [OSPS-DO-06.01]
    この情報をソースコードリポジトリ、プロジェクトウェブサイト、またはその他のチャネルなどの公開表示可能なリソース上で、プロジェクトの技術および設計ドキュメントと一緒に公開することが推奨されます。

    STATUS: MET
    EVIDENCE: Dependencies are declared and grouped in pyproject.toml; installation and build dependency acquisition use standard Python packaging tooling, and dependency selection/review expectations are documented in CONTRIBUTING.md and docs/CODE_REVIEW.md.
    JUSTIFICATION: The project publicly documents how dependencies are selected, obtained through pip/PyPI-compatible tooling, declared, reviewed, and tracked.
    URL: https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/pyproject.toml https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CONTRIBUTING.md https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/docs/CODE_REVIEW.md



    プロジェクトのドキュメントには、必要なライブラリ、フレームワーク、SDK、および依存関係を含む、ソフトウェアのビルド方法に関する手順が含まれていなければなりません。 [OSPS-DO-07.01]
    この情報は、CONTRIBUTING.mdや他の開発者タスクドキュメントなど、プロジェクトの貢献者ドキュメントと一緒に公開することが推奨されます。これはまた、Makefileターゲットや他の自動化スクリプトを使用して文書化することもできます。

    WhitePact documents a standard development installation using a Python virtual environment and an editable pip installation:

    pip install -e ".[dev]"

    This installs WhitePact together with its development and testing dependencies, including pytest, pytest-cov, Ruff, mypy, and related development tooling.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CONTRIBUTING.md [installation_development_quick]



    プロジェクトの文書には、機密リソースへのアクセス権を持つプロジェクト メンバーの一覧を含めなければなりません(MUST)。 [OSPS-GV-01.01]
    プロジェクトのソースコードリポジトリ内のmembers.md、governance.md、maintainers.md、または同様のファイルなどのアーティファクトを通じて、プロジェクト参加者とその役割を文書化します。これは、メンテナのリストに名前またはアカウントハンドルを含めるだけの簡単なものでも、プロジェクトのガバナンスに応じてより複雑なものでも構いません。

    STATUS: MET
    EVIDENCE: GOVERNANCE.md publicly lists the sole current project member holding maintainer, security-contact, incident-command, risk-owner, merge, and release authority.
    JUSTIFICATION: WhitePact has one person with access to sensitive project resources and names that person plainly; no additional member or committee is implied.
    URL: https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/GOVERNANCE.md



    プロジェクトの文書には、プロジェクト メンバーの役割と責任の説明を含めなければなりません(MUST)。 [OSPS-GV-01.02]
    プロジェクトのソースコードリポジトリ内のmembers.md、governance.md、maintainers.md、または同様のファイルなどのアーティファクトを通じて、プロジェクト参加者とその役割を文書化します。

    WhitePact publicly documents the project's current roles and responsibilities in GOVERNANCE.md, including the founder/maintainer, security contact, incident commander, risk owner, merge/release authority, and responsibility for project decisions.

    The document also clearly identifies who currently holds each role rather than implying roles or committees that do not exist.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/GOVERNANCE.md [roles_responsibilities]



    プロジェクトの文書には、受け入れ可能な貢献の要件を含む、コード貢献者向けのガイドを含めなければなりません(MUST)。 [OSPS-GV-03.02]
    プロジェクトドキュメントのCONTRIBUTING.mdまたはCONTRIBUTING/の内容を拡張して、コーディング標準、テスト要件、コードコントリビューターのための提出ガイドラインを含む、受け入れ可能な貢献の要件を概説します。このガイドがコントリビューターと承認者の両方にとって信頼できる情報源であることが推奨されます。

    The contribution requirements are documented in CONTRIBUTING.md, including development setup, testing requirements, pull request guidelines, CI requirements, Ruff formatting/linting, mypy type checking, public-function typing requirements, and security-related engineering principles.https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CONTRIBUTING.md [contribution_requirements]



    バージョン管理システムは、すべてのコード貢献者に対し、コミットのたびに、関連する貢献を行う法的権限があることを表明するよう要求しなければなりません(MUST)。 [OSPS-LE-01.01]
    プロジェクトのリポジトリにDCOを含め、コードコントリビューターが、すべてのコミットで関連する貢献を行うことが法的に認められていると主張することを要求します。ステータスチェックを使用して、主張が行われたことを確認します。CLAもこの要件を満たします。GitHubなどの一部のバージョン管理システムでは、これがプラットフォームの利用規約に含まれている場合があります。

    WhitePact adopts the Developer Certificate of Origin (DCO) 1.1 for non-trivial contributions. Contributors are required to certify their right to contribute by adding a Signed-off-by trailer to each commit using git commit -s.

    The requirement and contributor instructions are documented in CONTRIBUTING.md, and pull-request commits are automatically checked by CI.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CONTRIBUTING.md [dco]



    プライマリブランチにコミットが行われる場合、コミットの自動ステータスチェックは、合格するか手動でバイパスされる必要があります。 [OSPS-QA-03.01]
    プロジェクトのバージョン管理システムを設定して、すべての自動ステータスチェックが合格するか、コミットがプライマリブランチにマージされる前に手動確認を要求するようにします。オプションのステータスチェックは、承認者がバイパスしたくなるような合格または不合格の要件として設定しないことが推奨されます。

    WhitePact runs its automated test suite through GitHub Actions on every push to main and develop and on pull requests targeting main.

    The CI job installs the project and development dependencies, runs linting and type checking, executes pytest with coverage, and reports success or failure through the GitHub Actions status checks.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/.github/workflows/ci.yml [automated_integration_testing]



    コミットが受け入れられる前に、プロジェクトのCI/CDパイプラインは、変更が期待を満たすことを確認するために少なくとも1つの自動テストスイートを実行する必要があります。 [OSPS-QA-06.01]
    自動テストは、プライマリブランチへのすべてのマージの前に実行される必要があります。テストスイートはCI/CDパイプラインで実行され、結果はすべてのコントリビューターに表示される必要があります。テストスイートは一貫した環境で実行され、コントリビューターがローカルでテストを実行できるような方法で実行される必要があります。テストスイートの例には、ユニットテスト、統合テスト、エンドツーエンドテストが含まれます。

    WhitePact runs its automated test suite through GitHub Actions on every push to main and develop and on pull requests targeting main.

    The CI job installs the project and development dependencies, runs linting and type checking, executes pytest with coverage, and reports success or failure through the GitHub Actions status checks.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/.github/workflows/ci.yml [automated_integration_testing]



    プロジェクトがリリースを行った場合、プロジェクトドキュメントは、システム内のすべてのアクションとアクターを示す設計ドキュメントを含む必要があります。 [OSPS-SA-01.01]
    プロジェクトドキュメントに、アクションとアクターを説明する設計を含めます。アクターには、システム内の別のセグメントに影響を与えることができるサブシステムまたはエンティティが含まれます。これが新機能や破壊的変更のために更新されることを確認してください。

    WhitePact maintains a public architecture specification in SPEC.md describing the system's high-level design, runtime governance pipeline, core entities, identity and authority models, policy and risk evaluation, governance decisions, persistence, evidence, approvals, MCP integration, and implementation boundaries.

    The specification explicitly distinguishes implemented capabilities from target architecture.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/SPEC.md [documentation_architecture]



    プロジェクトがリリースを行った場合、プロジェクトドキュメントは、リリースされたソフトウェアアセットのすべての外部ソフトウェアインターフェースの説明を含む必要があります。 [OSPS-SA-02.01]
    リリースされたソフトウェアアセットのすべてのソフトウェアインターフェース(API)を文書化し、ユーザーがソフトウェアとどのように対話できるか、どのようなデータが期待または生成されるかを説明します。これが新機能や破壊的変更のために更新されることを確認してください。

    WhitePact documents its REST API, Python SDK and MCP external interfaces in README.md and its architecture specification. The FastAPI deployment exposes interactive API reference documentation, while MCP tools have structured input/output schemas and documented usage.
    Evidence URLs:
    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/README.md
    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/SPEC.md [documentation_interface]



    プロジェクトがリリースを行った場合、プロジェクトは、ソフトウェア内で発生する可能性のある最も可能性が高く、影響の大きい潜在的なセキュリティ問題を理解するためにセキュリティ評価を実行する必要があります。 [OSPS-SA-03.01]
    セキュリティ評価を実行することで、プロジェクトメンバーと下流の消費者の両方に、プロジェクトがソフトウェア内で発生する可能性のある問題を理解していることを知らせます。どのような脅威が実現する可能性があるかを理解することは、プロジェクトがリスクを管理および対処するのに役立ちます。この情報は、プロジェクトのセキュリティの能力と実践を示すために、下流の消費者にとって有用です。これが新機能や破壊的変更のために更新されることを確認してください。

    WhitePact cryptographically signs important Git version tags and documents how users can verify those signatures.

    Important release tags are created as annotated cryptographically signed tags using an approved project release-signing identity. The release process verifies that a release tag is annotated, signed, valid, and issued by an approved signer before publication.

    Public verification information is provided so users can independently verify Git tag signatures. This complements, rather than replaces, WhitePact's existing GitHub/Sigstore build-provenance attestations for published release artifacts.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/RELEASING.md [assurance_case]



    プロジェクトの文書には、明確な対応期限を伴う、協調的な脆弱性開示(CVD)のポリシーを含めなければなりません(MUST)。 [OSPS-VM-01.01]
    ディレクトリのルートにSECURITY.mdファイルを作成し、プロジェクトの協調的脆弱性開示のポリシーを概説します。脆弱性を報告する方法を含めます。プロジェクトが報告された問題にどのように対応および対処するかについての期待を設定します。

    WhitePact publishes its vulnerability reporting and responsible-disclosure process in SECURITY.md, including what information reporters should provide, scope, disclosure expectations, and response commitments.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/SECURITY.md [vulnerability_report_process]



    プロジェクトの文書は、プロジェクト内のセキュリティ連絡先に直接、非公開で脆弱性を報告する手段を提供しなければなりません(MUST)。 [OSPS-VM-03.01]
    セキュリティ研究者がプロジェクトに非公開で脆弱性を報告する手段を提供します。これは、専用の電子メールアドレス、ウェブフォーム、VCS専用ツール、セキュリティ連絡先の電子メールアドレス、またはその他の方法である可能性があります。

    Private vulnerability reports are supported by email. SECURITY.md instructs researchers not to create a public GitHub issue and instead send vulnerability details directly to the project's designated security contact.

    https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/SECURITY.md [vulnerability_report_private]



    プロジェクトの文書は、発見された脆弱性に関するデータを公開しなければなりません(MUST)。 [OSPS-VM-04.01]
    CVEエントリ、ブログ投稿、またはその他のメディアなど、予測可能な公開チャネルで既知の脆弱性に関する情報を提供します。可能な限り、この情報には、影響を受けるバージョン、消費者が脆弱かどうかを判断する方法、および緩和または修復の手順が含まれる必要があります。

    STATUS: MET
    EVIDENCE: The public internal security review records discovered SQL-injection-shaped and SSRF issues, their remediation, and regression tests; release changes are published in CHANGELOG.md.
    JUSTIFICATION: Discovered project vulnerabilities and their disposition are publicly documented without claiming an independent penetration test.
    URL: https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/compliance/INTERNAL_SECURITY_REVIEW.md https://github.com/Guruprasath-Annadurai/Whitepact/blob/main/CHANGELOG.md



ツールやAIシステムを使って、https://www.bestpractices.dev/ja/projects/14112/choose/edit?osps_ac_01_01_status=Met&osps_ac_01_01_justification=GitHub+enforcedのような簡単なURLで変更を提案できます。その方法については、自動化提案システムをご覧ください。 このデータは、Community Data License Agreement – Permissive, Version 2.0 (CDLA-Permissive-2.0)のもとで利用可能です。これは、データ受領者が、データ受領者がこの契約のテキストを共有データとともに利用可能にする限り、変更の有無にかかわらずデータを共有できることを意味します。Guruprasath AnnaduraiおよびOpenSSFベストプラクティスバッジのコントリビューターにクレジットを表示してください。

プロジェクト バッジ登録の所有者: Guruprasath Annadurai.
エントリの作成日時 2026-08-17 09:21:34 UTC、 最終更新日 2026-08-29 04:45:45 UTC 最後に2026-08-17 11:38:17 UTCにバッジ合格を達成しました。