{"id":15154,"user_id":48391,"name":"Astetik","description":"Astetik compiles scientific figures, numerical output, and verifiable provenance from declared plot specifications and a centralized design manifest.","homepage_url":"https://github.com/autonomio/astetik","repo_url":"https://github.com/autonomio/astetik","license":"MIT","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"The public repository and source downloads use HTTPS, as do PyPI package downloads. The project does not instruct users to accept unsigned hashes obtained over HTTP. Evidence: https://github.com/autonomio/astetik https://pypi.org/project/astetik/ https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Release-Policy.md","description_good_status":"Met","description_good_justification":"The public README describes scientific figures, numerical output and retained provenance compiled from a declared specification and design manifest. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/README.md","interact_status":"Met","interact_justification":"The README explains source installation and links support and contribution instructions; public issues and PRs accept feedback and contributions. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/README.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/SUPPORT.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md","contribution_status":"Met","contribution_justification":"CONTRIBUTING documents setup, tests, PR/slice process, and coding requirements by reference to the canonical constitution. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CLAUDE.md","contribution_requirements_status":"Met","contribution_requirements_justification":"CONTRIBUTING links canonical constitution and developer setup; the constitution defines acceptable code, testing, documentation and gate requirements. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Astetik is MIT licensed in the standard top-level LICENSE; incorporated third-party MIT material and SIL-OFL font notices are retained. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/LICENSE https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/THIRD_PARTY.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/fonts/OFL.txt","floss_license_status":"Met","floss_license_justification":"Astetik is MIT licensed in the standard top-level LICENSE; incorporated third-party MIT material and SIL-OFL font notices are retained. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/LICENSE https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/THIRD_PARTY.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/fonts/OFL.txt","floss_license_osi_status":"Met","floss_license_osi_justification":"Astetik is MIT licensed in the standard top-level LICENSE; incorporated third-party MIT material and SIL-OFL font notices are retained. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/LICENSE https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/THIRD_PARTY.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/fonts/OFL.txt","documentation_basics_status":"Met","documentation_basics_justification":"Guides cover source installation, first figure, final paper dimensions, scientific input responsibility, publication/evidence boundaries, and replay. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/README.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Guides/First-Figure.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Overview/Boundary.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/SECURITY.md","documentation_interface_status":"Met","documentation_interface_justification":"Public reference pages document CLI, plot specification, manifest, inputs and prepared data, output/evidence, and scientific protocol interfaces. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/CLI.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Plot-Specification.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Manifest.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","repo_public_status":"Met","repo_public_justification":"The public Git repository retains attributable dated commits and interim review branches/PRs between tagged releases. Evidence: https://github.com/autonomio/astetik https://github.com/autonomio/astetik/commits/master https://github.com/autonomio/astetik/pull/62","repo_track_status":"Met","repo_track_justification":"The public Git repository retains attributable dated commits and interim review branches/PRs between tagged releases. Evidence: https://github.com/autonomio/astetik https://github.com/autonomio/astetik/commits/master https://github.com/autonomio/astetik/pull/62","repo_interim_status":"Met","repo_interim_justification":"The public Git repository retains attributable dated commits and interim review branches/PRs between tagged releases. Evidence: https://github.com/autonomio/astetik https://github.com/autonomio/astetik/commits/master https://github.com/autonomio/astetik/pull/62","repo_distributed_status":"Met","repo_distributed_justification":"The public Git repository retains attributable dated commits and interim review branches/PRs between tagged releases. Evidence: https://github.com/autonomio/astetik https://github.com/autonomio/astetik/commits/master https://github.com/autonomio/astetik/pull/62","version_unique_status":"Met","version_unique_justification":"Released results have unique tag/version identities and source commit IDs. Latest published historical release is v1.16; current protected source version 2.0.0 is explicitly unpublished. Evidence: https://github.com/autonomio/astetik/releases/tag/v1.16 https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Release-Policy.md","version_semver_status":"Met","version_semver_justification":"The currently maintained source follows three-component SemVer with a mandatory per-PR bump gate. Historical PyPI versions such as 1.16 followed Python version syntax and were not strict three-component SemVer. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Semantic-Versioning.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/governance/version_gate.py","version_tags_status":"Met","version_tags_justification":"Released historical versions have Git tags, and the configured release process derives a unique v\u003cproject.version\u003e tag for future explicitly authorized releases. Evidence: https://github.com/autonomio/astetik/tags https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Making-Release.md","release_notes_status":"Met","release_notes_justification":"Latest distributed release v1.16 has human-readable notes identifying Hatch migration and minor fixes. Current 2.0 source has a reviewed human-readable changelog; future notes are generated from that reviewed section rather than raw git logs. Evidence: https://github.com/autonomio/astetik/releases/tag/v1.16 https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CHANGELOG.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Release-Policy.md","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"No publicly known Astetik runtime vulnerability with a CVE or comparable advisory was found in GitHub advisories or the OSV PyPI package query. The criterion concerns project vulnerabilities, not transitive dependencies. Evidence: https://github.com/autonomio/astetik/security/advisories https://api.osv.dev/v1/query","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"Live GitHub repository metadata has has_issues=true; issues are the documented bug and contribution tracker. Evidence: https://api.github.com/repos/autonomio/astetik https://github.com/autonomio/astetik/issues https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SUPPORT.md","report_process_status":"Met","report_process_justification":"SUPPORT and issue templates describe how to submit a versioned reproducible report using the public GitHub issue tracker. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/SUPPORT.md https://github.com/autonomio/astetik/issues","report_responses_status":"Met","report_responses_justification":"Complete GitHub issue inventory has no human bug reports or enhancement requests submitted between 2025-10-02 and 2026-08-02, the 2–12 month evaluation window. This does not claim old unanswered historical issues were acknowledged. Evidence: https://github.com/autonomio/astetik/issues?q=is%3Aissue+created%3A2025-10-02..2026-08-02","enhancement_responses_status":"Met","enhancement_responses_justification":"Complete GitHub issue inventory has no human bug reports or enhancement requests submitted between 2025-10-02 and 2026-08-02, the 2–12 month evaluation window. This does not claim old unanswered historical issues were acknowledged. Evidence: https://github.com/autonomio/astetik/issues?q=is%3Aissue+created%3A2025-10-02..2026-08-02","report_archive_status":"Met","report_archive_justification":"GitHub issue and PR discussions are public, searchable, URL-addressable, and accessible through a browser without installing proprietary client software. Evidence: https://github.com/autonomio/astetik/issues https://github.com/autonomio/astetik/pulls","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"SECURITY documents how to report vulnerabilities privately by arranging a channel through the established author contact, warns against public exploitable details, and defines useful report contents. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/SECURITY.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/MAINTAINERS.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"GitHub private vulnerability reporting is enabled for Astetik. Reports are submitted privately over GitHub HTTPS at https://github.com/autonomio/astetik/security/advisories/new . Live repository setting verified 2026-10-02; reporters should not publish exploitable details in public issues. Evidence: https://github.com/autonomio/astetik/security/advisories/new https://github.com/autonomio/astetik/security/policy","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"The primary maintainer confirms no private vulnerability reports were received in the past 12 months as of 2026-10-02. No public Astetik vulnerability report or advisory was found in the last six months. Thus there is no initial-response interval to claim; the official criterion permits N/A when no vulnerabilities were reported in that period. Evidence: https://github.com/autonomio/astetik/security/advisories","build_status":"Met","build_justification":"The source uses the FLOSS Hatchling PEP517 build backend. Public packaging documentation and actual merged PR62 wheel/sdist CI prove source builds and installed-package imports. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Packaging.md https://github.com/autonomio/astetik/actions/runs/36914931308","build_common_tools_status":"Met","build_common_tools_justification":"The source uses the FLOSS Hatchling PEP517 build backend. Public packaging documentation and actual merged PR62 wheel/sdist CI prove source builds and installed-package imports. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Packaging.md https://github.com/autonomio/astetik/actions/runs/36914931308","build_floss_tools_status":"Met","build_floss_tools_justification":"The source uses the FLOSS Hatchling PEP517 build backend. Public packaging documentation and actual merged PR62 wheel/sdist CI prove source builds and installed-package imports. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Packaging.md https://github.com/autonomio/astetik/actions/runs/36914931308","test_status":"Met","test_justification":"Public pytest suites are MIT-licensed project sources, standard python -m pytest invocations are documented, and merged PR62 test CI passed. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/tests https://github.com/autonomio/astetik/actions/runs/36914931313","test_invocation_status":"Met","test_invocation_justification":"Public pytest suites are MIT-licensed project sources, standard python -m pytest invocations are documented, and merged PR62 test CI passed. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/tests https://github.com/autonomio/astetik/actions/runs/36914931313","test_most_status":"Met","test_most_justification":"Actual merged PR62 product coverage was89.9% line and82.0% branch, not merely a configured floor. Evidence: https://github.com/autonomio/astetik/pull/62#issuecomment-5932190379 https://github.com/autonomio/astetik/actions/runs/36914931313","test_policy_status":"Met","test_policy_justification":"Constitution requires changed lines covered and validation against promised capability; contribution instructions document test execution and the slice template requires tests complete. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CLAUDE.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/ISSUE_TEMPLATE/slice.yml","tests_are_added_status":"Met","tests_are_added_justification":"The most recent major functionality merged in PR62 added extensive tests for scientific methods, evidence integrity/replay, publication layouts, typed input and provenance together with those implementations. Evidence: https://github.com/autonomio/astetik/pull/62/files https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/tests/test_paper_catalog.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/tests/test_replay_artifact_bindings.py","tests_documented_added_status":"Met","tests_documented_added_justification":"Contribution instructions route to the constitution and developer workflow, including the capability-tests and regression protection requirement. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/README.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/CONTRIBUTING.md","warnings_status":"Met","warnings_justification":"Pinned Ruff lint and strict Pyright run as required gates. The maintained source has zero retained Ruff diagnostics and zero Pyright error/warning budgets, proven by passing merged PR62 runs. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/budgets.json https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/actions/runs/36914931219","warnings_fixed_status":"Met","warnings_fixed_justification":"Pinned Ruff lint and strict Pyright run as required gates. The maintained source has zero retained Ruff diagnostics and zero Pyright error/warning budgets, proven by passing merged PR62 runs. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/pyproject.toml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/budgets.json https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/actions/runs/36914931219","warnings_strict_status":"Met","warnings_strict_justification":"Python source is checked using pinned Ruff with no retained findings and strict Pyright with an error/warning budget of zero. Docs diagnostics are fatal. There is no native compiler warning surface. Python runtime warnings are not globally ignored by the library; practical third-party exceptions must be explicit. Evidence: https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/budgets.json https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/check_ruff_ratchet.py","know_secure_design_status":"Met","know_secure_design_justification":"Mikko Kotila, Astetik primary maintainer/developer, explicitly confirms understanding all specified secure-design principles: economy of mechanism, fail-safe defaults, complete mediation, open design, separation of privilege, least privilege, least common mechanism, psychological acceptability, limited attack surface, and allowlist input validation. Confirmation given 2026-10-02; implementation controls are documented in the assurance case. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/MAINTAINERS.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Security-Assurance-Case.md","know_common_errors_status":"Met","know_common_errors_justification":"Mikko Kotila, Astetik primary maintainer/developer, explicitly confirms knowing common vulnerability classes relevant to this library and at least one mitigation for each, including injection, unsafe deserialization, path traversal, missing authorization, secret leakage, and vulnerable dependencies. Confirmation given 2026-10-02; the assurance case records the project trust boundaries and relevant controls. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Security-Assurance-Case.md","crypto_published_status":"Met","crypto_published_justification":"The maintained library uses the Python standard-library hashlib SHA-256 primitive for content identity/integrity. SHA-256 is published, 256 bits, and not a broken algorithm. No custom cipher or authentication cryptography is implemented; receipts explicitly do not establish signed authorship. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_source_file.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","crypto_call_status":"Met","crypto_call_justification":"The maintained library uses the Python standard-library hashlib SHA-256 primitive for content identity/integrity. SHA-256 is published, 256 bits, and not a broken algorithm. No custom cipher or authentication cryptography is implemented; receipts explicitly do not establish signed authorship. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_source_file.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","crypto_floss_status":"Met","crypto_floss_justification":"The maintained library uses the Python standard-library hashlib SHA-256 primitive for content identity/integrity. SHA-256 is published, 256 bits, and not a broken algorithm. No custom cipher or authentication cryptography is implemented; receipts explicitly do not establish signed authorship. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_source_file.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","crypto_keylength_status":"Met","crypto_keylength_justification":"The maintained library uses the Python standard-library hashlib SHA-256 primitive for content identity/integrity. SHA-256 is published, 256 bits, and not a broken algorithm. No custom cipher or authentication cryptography is implemented; receipts explicitly do not establish signed authorship. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_source_file.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","crypto_working_status":"Met","crypto_working_justification":"The maintained library uses the Python standard-library hashlib SHA-256 primitive for content identity/integrity. SHA-256 is published, 256 bits, and not a broken algorithm. No custom cipher or authentication cryptography is implemented; receipts explicitly do not establish signed authorship. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_source_file.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Reference/Evidence-Result.md","crypto_pfs_status":"N/A","crypto_pfs_justification":"The installed local scientific library does not implement a network key-agreement protocol or session encryption. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Overview/Boundary.md https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Security-Assurance-Case.md","crypto_password_storage_status":"N/A","crypto_password_storage_justification":"The installed local scientific library does not authenticate external users or store authentication passwords. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Security-Assurance-Case.md","crypto_random_status":"N/A","crypto_random_justification":"Astetik does not generate cryptographic keys or nonces. Scientific determinism/content identities are SHA-256 hashes, not randomly generated secrets. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/_json.py https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Security-Assurance-Case.md","delivery_mitm_status":"Met","delivery_mitm_justification":"The public repository and source downloads use HTTPS, as do PyPI package downloads. The project does not instruct users to accept unsigned hashes obtained over HTTP. Evidence: https://github.com/autonomio/astetik https://pypi.org/project/astetik/ https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Release-Policy.md","delivery_unsigned_status":"Met","delivery_unsigned_justification":"The public repository and source downloads use HTTPS, as do PyPI package downloads. The project does not instruct users to accept unsigned hashes obtained over HTTP. Evidence: https://github.com/autonomio/astetik https://pypi.org/project/astetik/ https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/docs/Developer/Release-Policy.md","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"No publicly known medium-or-higher Astetik runtime vulnerability was found in GitHub advisories or the OSV package database. Live Scorecard configuration findings are separately tracked and do not establish exploitable project vulnerabilities older than 60 days. Evidence: https://github.com/autonomio/astetik/security/advisories https://api.osv.dev/v1/query https://github.com/autonomio/astetik/security/code-scanning","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"No confirmed critical Astetik vulnerability is currently known from the public advisory/OSV audit, and the primary maintainer confirms no private vulnerability reports in the past 12 months. There is no outstanding confirmed critical vulnerability or historical fix interval to misrepresent. Critical reports are prioritized for immediate triage and prompt remediation; this answer does not invent a past response-time result. Evidence: https://github.com/autonomio/astetik/security/advisories https://api.osv.dev/v1/query","static_analysis_status":"Met","static_analysis_justification":"Required CodeQL Python security analysis and strict Pyright run for proposed PRs, with CodeQL on master pushes and weekly. Merged PR62 CodeQL actually passed before the major source entered protected master. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_codeql.yml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_typing.yml https://github.com/autonomio/astetik/actions/runs/36914931349","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"Actual merged-master Python CodeQL run succeeded; its queries analyze security weakness classes. Required PR CodeQL is independently configured with no retained new findings. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583672 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_codeql.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"No open CodeQL Python exploitable vulnerability is reported; open code-scanning alerts are newly generated Scorecard repository-control findings. Required security analysis and lint passed on the merged major implementation. Evidence: https://github.com/autonomio/astetik/security/code-scanning https://github.com/autonomio/astetik/actions/runs/36914931349 https://github.com/autonomio/astetik/actions/runs/36914968410","static_analysis_often_status":"Met","static_analysis_often_justification":"Required CodeQL Python security analysis and strict Pyright run for proposed PRs, with CodeQL on master pushes and weekly. Merged PR62 CodeQL actually passed before the major source entered protected master. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_codeql.yml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_typing.yml https://github.com/autonomio/astetik/actions/runs/36914931349","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Merged PR62 product automated tests have actual 82.0% branch coverage, exceeding this criterion 80% threshold. Governance additionally varies arbitrary user-authored issue text with Hypothesis; this is not a coverage-guided native fuzzing claim. Evidence: https://github.com/autonomio/astetik/pull/62#issuecomment-5932190379 https://github.com/autonomio/astetik/actions/runs/36914931313 https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/governance/tests/test_issue_body_parsers.py https://github.com/autonomio/astetik/actions/runs/36914968410","dynamic_analysis_unsafe_status":"N/A","dynamic_analysis_unsafe_justification":"This project owns Python/JavaScript source and does not produce memory-unsafe C/C++ modules. Third-party native scientific dependencies are separately maintained; no project-native sanitizer/fuzzer claim follows. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Security-Assurance-Case.md","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"Normal pytest/Hypothesis runs retain Python assertions and test invariants; the checked-in CI invocations do not pass -O or disable assertions. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_tests.yml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/governance/tests/test_issue_body_parsers.py","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"No confirmed medium-or-higher exploitable vulnerability from retained test/property-analysis results is open. Dynamic tests and named regression contracts passed on the merged implementation. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931313 https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/security/advisories","general_comments":"","created_at":"2026-10-02T06:55:56.352Z","updated_at":"2026-10-02T09:51:47.855Z","crypto_weaknesses_status":"Met","crypto_weaknesses_justification":"Project integrity digests use hashlib.sha256. No MD5/SHA1 security mechanism or home-grown cipher was found in runtime. Repository delivery uses platform HTTPS/signing primitives. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_json.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_source_file.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_result.py","test_continuous_integration_status":"Met","test_continuous_integration_justification":"Required GitHub workflows run package tests, coverage, static analysis, governance and documentation on proposed PRs; source compatibility runs cover Python 3.11–3.13. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/ci.yml https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/.github/workflows/pr_checks_tests.yml https://github.com/autonomio/astetik/pull/62","cpe":"","discussion_status":"Met","discussion_justification":"GitHub issue and PR discussions are public, searchable, URL-addressable, and accessible through a browser without installing proprietary client software. Evidence: https://github.com/autonomio/astetik/issues https://github.com/autonomio/astetik/pulls","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"GitHub secret-scanning alert 1 is resolved as false_positive after independent analysis: the detected bytes span adjacent WB_A3 country-code and WOE_ID geographic-ID fields in countries.dbf record 184 (North Korea), matching public Natural Earth v4.0.0 attributes. The matched value is geographical metadata, not a credential. No valid private credential is identified in the public repository audit. Evidence: https://github.com/autonomio/astetik/security/secret-scanning/1 https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/astetik/extras/countries.dbf https://raw.githubusercontent.com/nvkelso/natural-earth-vector/v4.0.0/50m_cultural/ne_50m_admin_0_countries.dbf","english_status":"Met","english_justification":"Project documentation and issue templates are in English; existing issue discussions accept English reports. Evidence: https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/CONTRIBUTING.md https://github.com/autonomio/astetik/issues","hardening_status":"N/A","hardening_justification":"Project-owned distributable runtime is memory-managed Python; it builds no native executable and hosts no authentication/web service. Compiler flags/service response headers therefore have no applicable owned runtime surface. Least privilege alone is explicitly not counted as hardening. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SECURITY.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml","crypto_used_network_status":"Met","crypto_used_network_justification":"Scientific runtime does not communicate over a network; project maintenance/publishing tooling uses HTTPS GitHub/PyPI endpoints or GH CLI defaults. No insecure transport bypass was found in audited project source. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/scripts/create_release.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_publish_pypi.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/ruleset_gate.py","crypto_tls12_status":"Met","crypto_tls12_justification":"Runtime does not use TLS. Maintenance/publishing HTTPS uses supported Python3.13 stdlib/GH/PyPI platform TLS stacks rather than implementing SSL/TLS. Its runtime-only answer is N/A. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_publish_pypi.yml","crypto_certificate_verification_status":"Met","crypto_certificate_verification_justification":"Runtime does not use TLS. Publishing code uses urllib.request.urlopen default validating context; GH tools use their ordinary HTTPS defaults. No unverified SSL context, verify=False or CERT_NONE was found. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_publish_pypi.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/ruleset_gate.py","crypto_verification_private_status":"Met","crypto_verification_private_justification":"Runtime sends no HTTP private headers. Maintainer authentication is delegated to GH CLI/GitHub Actions/PyPI OIDC HTTPS clients; project code does not send credentials through an unverified custom TLS context. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_publish_pypi.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/audit_master_ruleset.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/ruleset_gate.py","hardened_site_status":"?","installation_common_status":"Met","installation_common_justification":"Standard pip wheel/source installation and pip uninstall are supported. Actual built-wheel installs/imports outside checkout passed on Python3.11,3.12,3.13. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931308 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Packaging.md","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2026-10-02T09:07:57.546Z","lost_passing_at":null,"implementation_languages":"Python, JavaScript","badge_percentage_1":89,"dco_status":"?","dco_justification":"GitHub Terms of Service D.6 licenses content contributed to a licensed repository under that license and requires contributors to have the right to do so. PR81 CONTRIBUTING identifies this existing legal mechanism and requires equivalent explicit rights assertions for nontrivial contributions received outside GitHub. Do not claim historical signed DCOs. Keep the explicit project policy pending until adopted. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://docs.github.com/en/site-policy/github-terms/github-terms-of-service#6-contributions-under-repository-license https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/CONTRIBUTING.md","governance_status":"Met","governance_justification":"GOVERNANCE and CLAUDE define maintainer decision authority, contribution acceptance, protected checks, independent review and change procedures. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/GOVERNANCE.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md","code_of_conduct_status":"Met","code_of_conduct_justification":"Standard root CODE_OF_CONDUCT.md defines behavior, proportionate enforcement and private maintainer reporting. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CODE_OF_CONDUCT.md","roles_responsibilities_status":"Met","roles_responsibilities_justification":"MAINTAINERS names Mikko Kotila and assigns scope, issue, security, release and merge responsibilities. It identifies mikkokotila and EnergyGuy3 as administrator/code owners. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/MAINTAINERS.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/GOVERNANCE.md","access_continuity_status":"Met","access_continuity_justification":"On 2026-10-02 the user explicitly confirmed EnergyGuy3 can recover Astetik release/PyPI access within one week. Independently audited GitHub permissions show mikkokotila and EnergyGuy3 are administrators. These establish attested operational continuity, separately from a recovery drill or proof of equal technical expertise. PR81 publishes the dated path. Evidence: https://api.github.com/repos/autonomio/astetik/collaborators https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/MAINTAINERS.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SETUP.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/MAINTAINERS.md","bus_factor_status":"Unmet","bus_factor_justification":"Deep compiler knowledge is currently concentrated in the primary maintainer; administrator rights and a backup capable of restoring access do not demonstrate two project experts. The present small maintainer team uses published source, canonical developer documentation, retained regression evidence and a named operational continuation path to reduce interruption. This justified unmet SHOULD transparently preserves that actual staffing boundary. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/MAINTAINERS.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/MAINTAINERS.md","documentation_roadmap_status":"?","documentation_roadmap_justification":"PR81 adds a dated roadmap covering 2026-10-02 through 2027-10-02, with researcher-focused priorities and explicit exclusions. It is publicly reviewable but is not yet adopted on the protected branch. Change to Met only after adoption. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Overview/Boundary.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Overview/Roadmap.md","documentation_architecture_status":"Met","documentation_architecture_justification":"The package page defines the compiler responsibility, component ownership, canonical public flow and dependencies. Boundary and evidence/specification references describe their relationships. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/README.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Overview/Boundary.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Evidence-Result.md","documentation_security_status":"Met","documentation_security_justification":"SECURITY and assurance case identify local library security boundaries, supported source, integrity versus authenticity, dependencies and unproven release/host claims. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SECURITY.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Security-Assurance-Case.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Evidence-Result.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/SECURITY.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Developer/Security-Assurance-Case.md","documentation_quick_start_status":"Met","documentation_quick_start_justification":"The First Figure guide and bundled executable example are exercised by documentation tests; source and installed workflows provide first render, verification, write and replay. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Guides/First-Figure.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/docs/first_figure.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_documentation.py","documentation_current_status":"Met","documentation_current_justification":"Documentation freshness, canonical ownership, links, routes and executable examples are routinely audited. The actual master documentation job passed. Historical usage is separated in Migration. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Documentation-System.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Migration.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/tests/test_installed_documentation.py","documentation_achievements_status":"?","documentation_achievements_justification":"Astetik achieved the actual OpenSSF Best Practices Passing badge on 2026-10-02 at 09:07:57.546Z. PR81 README links the live project 15154 badge and project page, but its protected-branch adoption is still pending. The repository front page must identify and hyperlink achievements within 48 hours of recognition; keep this criterion pending until the reviewed badge link is adopted. Evidence: https://www.bestpractices.dev/projects/15154.json https://www.bestpractices.dev/projects/15154/badge https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/README.md","accessibility_best_practices_status":"Met","accessibility_best_practices_justification":"Master documentation browser/accessibility job passed. Product figures provide readable table/caption/evidence companions and semantic labels; manifests enforce practical contrast. This is bounded evidence, not universal WCAG certification. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Guides/Paper-Figure.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Manifest.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs-site/tests/docs.spec.js https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_colors.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs-site/tests/surfaces.spec.js https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_design.py","internationalization_status":"Unmet","internationalization_justification":"The current scientific Python and agent audience receives stable machine-readable error codes, while researchers control their own Unicode labels. Human diagnostics and project documentation remain English and there is no locale/message catalogue. Full message localization is explicitly deferred from the one-year scope so effort can improve scientific validation, paper output and provenance. This is a justified unmet SHOULD, not a claim that Unicode alone supplies localization. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_errors.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/CLI.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Overview/Roadmap.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Reference/CLI.md","sites_password_security_status":"N/A","sites_password_security_justification":"Astetik has no owned authentication service storing external-user passwords. Repository and publication accounts belong to GitHub/PyPI rather than a project password database. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SECURITY.md","maintenance_or_update_status":"Met","maintenance_or_update_justification":"Migration describes retained argument mappings, breaking behavior, explicit preparation, result/export changes and preserving historical environments. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Migration.md","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"On 2026-10-02 the user confirmed there were no private vulnerability reports in the preceding 12 months. The repository security advisory API returned an empty list. There are therefore no resolved reported vulnerabilities in that period requiring reporter credit. The public advisory result alone would not establish the private history; this answer relies explicitly on the human confirmation. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SECURITY.md https://api.github.com/repos/autonomio/astetik/security-advisories https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/SECURITY.md","vulnerability_response_process_status":"?","vulnerability_response_process_justification":"PR81 SECURITY documents intake, acknowledgment within 14 calendar days, scope and severity triage, immediate priority for critical reports, repair of known medium-or-higher vulnerabilities within 60 calendar days, regression protection and coordinated disclosure/credit. This is a prospective response policy awaiting protected-branch adoption and does not demonstrate historical response performance. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SECURITY.md https://github.com/autonomio/astetik/security/advisories/new https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/SECURITY.md","coding_standards_status":"Met","coding_standards_justification":"CLAUDE and Ruff configuration define Python naming/public API/docstring/style and maintainability standards. Contributions must follow them. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"Actual lint gate passes pinned Ruff with no retained findings and strict ratchets; configuration relaxation is checked against protected base. Evidence: https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_lint.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/check_ruff_ratchet.py","build_standard_variables_status":"N/A","build_standard_variables_justification":"This project builds a pure Python wheel/sdist, not its own native binaries. It does not compile third-party NumPy/SciPy/Pillow binaries. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Packaging.md","build_preserve_debug_status":"Met","build_preserve_debug_justification":"The wheel/sdist retain Python source modules; the package audit checks their contents and no installation strip stage removes debugging source. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931308 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/scripts/package_audit.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml","build_non_recursive_status":"Met","build_non_recursive_justification":"Hatch builds the declared Python package in one graph. No project-owned recursive native build with cross-subdirectory dependencies is present. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931308 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_packaging.yml","build_repeatable_status":"Met","build_repeatable_justification":"Actual packaging run at merged source head5db38b5 reports two artifacts identical across two fixed-epoch builds. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931308 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_packaging.yml","installation_standard_variables_status":"Met","installation_standard_variables_justification":"Standard Python packaging delegates destination choice to pip virtual environments and --target/--prefix conventions; there is no custom installer replacing them. Outside-checkout installation is tested. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931308 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Packaging.md","installation_development_quick_status":"Met","installation_development_quick_justification":"CONTRIBUTING gives conventional virtualenv, pip extras and hashed gate-tool setup; Documentation gives Node/npm/Chromium setup. Actual CI uses those dependencies. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CONTRIBUTING.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Documentation.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/requirements/ci/gate-tools.txt","external_dependencies_status":"Met","external_dependencies_justification":"Python runtime/extras/build requirements and documentation package lock are computer-processable; CI toolchain inputs are hashed requirement files. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs-site/package.json https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs-site/package-lock.json https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/requirements/ci/runtime-env.txt","dependency_monitoring_status":"Met","dependency_monitoring_justification":"Required lint runs pip-audit for declared runtime and docs npm audits; weekly Dependabot update configuration monitors packages/actions. Actual master documentation and lint audit jobs passed. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/actions/runs/36914968410 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/dependabot.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_lint.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/check_dependency_vulnerabilities.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/vuln_exceptions.json","updateable_reused_components_status":"Met","updateable_reused_components_justification":"Externally maintained Python/Node dependencies use standard package managers and declared bounds/locks. There is no mandatory project fork of runtime libraries. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs-site/package.json https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/dependabot.yml","interfaces_current_status":"Met","interfaces_current_justification":"The modern compiler uses supported Python3.11+ APIs and dependency bounds; actual scientific CI passes3.11/3.12/3.13. Deprecated legacy helpers fail explicitly rather than executing old unsafe behavior. This does not certify every upstream API forever. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/pyproject.toml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Migration.md","automated_integration_testing_status":"Met","automated_integration_testing_justification":"Scientific contracts run on each protected master push and PR, reporting pass/fail; actual merged-master run passed. Evidence: https://github.com/autonomio/astetik/actions/runs/36969583737 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/ci.yml","regression_tests_added50_status":"Met","regression_tests_added50_justification":"In origin/master since2026-04-02,15 non-merge fix commits were found.12 add new regression test functions still retained at current master (80%). Deleted test files were not counted as retained coverage. The full suite on their merged source passed1099 tests. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931313 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_replay_source_identity.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_snapshot_json_boundary.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_numeric_option_identity.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_publication.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/governance/tests/test_repository_law.py","test_statement_coverage80_status":"Met","test_statement_coverage80_justification":"Coverage artifact from actual successful merged-source run36914931313 reports4444/4945 covered statements=89.8685540950455%; this meets Silver80%. Its88.120371% combined line/branch percent is a different measure. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931313 https://api.github.com/repos/autonomio/astetik/actions/runs/36914931313/artifacts https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/budgets.json https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_checks_tests.yml","test_policy_mandated_status":"Met","test_policy_mandated_justification":"Slice law requires tests proving every capability assertion and a future regression gate; developer workflow says behavior changes need meaningful regression protection. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/CLAUDE.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/ISSUE_TEMPLATE/slice.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/README.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/CONTRIBUTING.md","implement_secure_design_status":"Met","implement_secure_design_justification":"Actual runtime uses allowlisted declarations, fail-loud error recovery, immutable result sealing, no-overwrite atomic publication, safe YAML and JSON parsing. Runtime has no shell/network authentication privileges. Required CI credentials are bounded. The assurance-case prose should tie these mechanisms to design principles explicitly. The user explicitly confirmed the primary maintainer has secure-design and common coding-security knowledge on 2026-10-02; this is a human attestation, not an audited certificate. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_manifest_load.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_snapshot_parse.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_result_atomic.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_result.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/audit_master_ruleset.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Security-Assurance-Case.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Developer/Security-Assurance-Case.md","input_validation_status":"Met","input_validation_justification":"Runtime allowlists kinds/options/manifests; retained JSON rejects duplicate/nonfinite/invalid schema values; type, source identity, artifact binding and no-overwrite publication are covered by actual passing tests. Evidence: https://github.com/autonomio/astetik/actions/runs/36914931313 https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_spec.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_manifest_load.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_snapshot_parse.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_snapshot_json_boundary.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_replay_artifact_bindings.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/tests/test_numeric_option_identity.py","crypto_algorithm_agility_status":"Unmet","crypto_algorithm_agility_justification":"Receipt v1 deliberately fixes SHA-256 to preserve stable scientific identities. User-selectable digest changes would alter identity and interoperability; a future digest change requires an explicit new receipt schema. Astetik offers no encryption or authentication cipher service. This is a justified unmet SHOULD rather than claiming algorithm agility from schema versioning. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/astetik/_json.py https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Reference/Evidence-Result.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Reference/Evidence-Result.md","crypto_credential_agility_status":"Met","crypto_credential_agility_justification":"Scientific runtime does not process auth credentials or private keys. Maintainer workflows receive replaceable external GitHub Secrets/OIDC credentials separate from source, configuration and artifacts; token rotation needs no compilation. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/SETUP.md https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/audit_master_ruleset.yml https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/.github/workflows/pr_publish_pypi.yml","signed_releases_status":"Unmet","signed_releases_justification":"The published 1.16 wheel and source distribution still lack verified release signatures. Their PyPI SHA-256 values and all 55 package files were checked against tag v1.16; this does not establish historical build provenance. PR81 at 440b2292a527c942787b59a2c09267190d69526e adds a fixed retrospective approval workflow: a read-only runner verifies the exact repository, protected workflow, historical tag/source, stable release, PyPI inventory and unchanged bytes; a separate protected signer uses keyless OIDC/Sigstore to sign only the two fixed reviewed digest subjects; a third protected runner verifies both signatures and the exact approval predicate before attaching unchanged artifacts and their public bundle to the existing release without replacing assets. No local key unlock, new stored signing secret or PyPI reupload is required. The documented verifier retrieves public signing certificates and trust roots and stops on any failed checksum, signature or predicate check. Keep signed_releases Unmet until protected-branch adoption, an approved successful signing/publication run and independent verification of public downloads. This records approval at execution time, not signing in 2024, a signed historical Git tag, a reproducible historical build or completed 2.0 publication. Evidence: https://github.com/autonomio/astetik/blob/440b2292a527c942787b59a2c09267190d69526e/.github/workflows/sign_legacy_release.yml https://github.com/autonomio/astetik/blob/440b2292a527c942787b59a2c09267190d69526e/docs/Developer/Release-Policy.md https://pypi.org/pypi/astetik/1.16/json https://github.com/autonomio/astetik/releases/tag/v1.16","version_tags_signed_status":"Unmet","version_tags_signed_justification":"No cryptographically signed current important version tag was verified. This is SUGGESTED, independent of MUST signed_releases. Evidence: https://api.github.com/repos/autonomio/astetik/git/ref/tags/v1.16","badge_percentage_2":35,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","assurance_case_justification":"PR81 strengthens the canonical assurance case with attacker/threat boundaries, an explicit ten-principle secure-design mapping, eight implementation weakness classes, source/test evidence and residual risks. The argument explains integrity versus authentication, hostile input, resource exhaustion, dependency trust, CI privilege and unsigned artifact limits. It remains pending protected-branch adoption; it does not claim independent security review or signed provenance. Evidence: https://github.com/autonomio/astetik/blob/5db38b5fc054292a2dc3d6e592746f4815e23bf2/docs/Developer/Security-Assurance-Case.md https://github.com/autonomio/astetik/blob/a296fbd7a09e55ca9f002caa4b6499defc74b638/docs/Developer/Security-Assurance-Case.md","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":189,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2026-10-02T09:07:57.546Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"The repository is unarchived, an extensive modern scientific implementation and governance were merged in PR62 on 2026-10-02, and this badge effort is active. Evidence: https://github.com/autonomio/astetik/pull/62 https://github.com/autonomio/astetik/commit/eb829edaca3fc189ff3ea181d0a2a531fd80abe5 https://github.com/autonomio/astetik/blob/eb829edaca3fc189ff3ea181d0a2a531fd80abe5/MAINTAINERS.md","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":0,"OSPS-BR-01.02_justification":null,"OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Mikko Kotila and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"}