× Note: The site will later be briefly unavailable due to database maintenance.

discovery-media-player

Miradi inayofuata mazoea bora hapa chini inaweza kujihakikisha kwa hiari na kuonyesha kuwa wamepata nishani ya mazoea bora ya Open Source Security Foundation (OpenSSF).

Hakuna seti ya mazoea yawezayo kuhakikisha kuwa programu haitakuwa na kasoro au udhaifu; hata mbinu rasmi zinaweza kushindwa ikiwa vipimo au dhana ni sahihi. Wala hakuna seti ya mazoea yawezayo kuhakikisha kuwa mradi utaendelea kuwa na jamii ya maendeleo yenye afya na inayofanya kazi vizuri. Hata hivyo, kufuata mazoea bora kunaweza kusaidia kuboresha matokeo ya miradi. Kwa mfano, baadhi ya mazoea huwezesha ukaguzi wa watu wengi kabla ya kutolewa, ambayo inaweza kusaidia kupata udhaifu wa kiufundi ambao vinginevyo ni vigumu kupata na kusaidia kujenga uaminifu na hamu ya mwingiliano wa kurudia kati ya wasanidi programu kutoka makampuni tofauti. Ili kupata nishani, vigezo vyote vya LAZIMA na LAZIMA WALA USIWAHI lazima vifuatwe, vigezo vyote vya INAPASWA lazima vifuatwe AU visivyo fufufutiliana na thibitisho, na vigezo vyote vya PENDEKEZA lazima vifuatwe AU visivyo fufufutiliana (tunataka vifikiwe angalau). Ikiwa unataka kuingiza maandishi ya thibitisho kama maoni ya jumla, badala ya kuwa maelezo ya busara kwamba hali ni inakubaliwa, anza kifungu cha maandishi na '//' ikifuatiwa na nafasi. Maoni ni karibu kupitia tovuti ya GitHub kama masuala au maombi ya kuvuta Kuna pia orodha ya barua pepe kwa majadiliano ya jumla.

Tunafuraha kutoa habari katika lugha nyingi, hata hivyo, ikiwa kuna mgongano au kutokuwa na usawa kati ya tafsiri, toleo la Kiingereza ni toleo lenye mamlaka.
Ikiwa huu ni mradi wako, tafadhali onyesha hali ya nishani yako ya msingi kwenye ukurasa wa mradi wako! Hali ya nishani ya msingi inaonekana kama hii: Kiwango cha nishani ya msingi kwa mradi 14197 ni baseline-2 Huu ndiyo jinsi ya kuweka nishani ya msingi:
Unaweza kuonyesha hali ya nishani yako ya msingi kwa kuweka hii katika faili yako ya markdown:
[![OpenSSF Baseline](https://www.bestpractices.dev/projects/14197/baseline)](https://www.bestpractices.dev/projects/14197)
au kwa kuweka hii katika HTML yako:
<a href="https://www.bestpractices.dev/projects/14197"><img src="https://www.bestpractices.dev/projects/14197/baseline"></a>


Hizi ni vigezo vya Kiwango cha Msingi 2. Hizi ni vigezo vya toleo v2026.02.19.

Baseline Series: Kiwango cha Msingi 1 Kiwango cha Msingi 2 Kiwango cha Msingi 3

        

 Misingi

  • Jumla

    Kumbuka kwamba miradi mingine inaweza kutumia jina sawa.

    Self-hosted document viewer: per-recipient tracked links, reading analytics, live presentation. The core knows nothing about the app hosting it.

    Tafadhali tumia muundo wa maneno ya leseni ya SPDX; mifano ni pamoja na "Apache-2.0", "BSD-2-Clause", "BSD-3-Clause", "GPL-2.0+", "LGPL-3.0+", "MIT", na "(BSD-2-Clause OR Ruby)". Usitumie alama za nukuu za moja au mbili.
    Ikiwa kuna lugha zaidi ya moja, ziorodhe kama thamani zilizotengwa kwa koma (nafasi ni za hiari) na ziorodhe kuanzia iliyotumiwa zaidi hadi iliyotumiwa kidogo. Ikiwa kuna orodha ndefu, tafadhali orodhesha angalau tatu za kawaida zaidi. Ikiwa hakuna lugha (k.m., huu ni mradi wa nyaraka tu au wa majaribio tu), tumia herufi moja "-". Tafadhali tumia herufi kubwa za kawaida kwa kila lugha, k.m., "JavaScript".
    Common Platform Enumeration (CPE) ni mpango wa kuweka majina yenye muundo kwa mifumo ya teknolojia ya habari, programu, na vifurushi. Inatumika katika mifumo na hifadhidata nyingi wakati wa kuripoti udhaifu.

 Udhibiti 19/19

  • Udhibiti


    Wakati kazi ya CI/CD inatekelezwa bila ruhusa zilizobainishwa, mfumo wa CI/CD LAZIMA uweke chaguomsingi ruhusa za kazi kuwa ruhusa za chini kabisa zinazotolewa katika mfumo wa kuendeshea. [OSPS-AC-04.01]
    Sanidi mipangilio ya mradi ili kupeana ruhusa za chini zaidi zinazopatikana kwa mifumo mipya ya kuendeshea kwa chaguomsingi, ukitoa ruhusa za ziada tu zinapohitajika kwa kazi maalum.

    All eight workflows declare permissions: at the top level, so no job ever runs on an unspecified default. release.yml starts from permissions: {} — no scope at all — and grants each job only what it needs: the build job contents: read, the publish job adding id-token: write for OIDC and nothing more. ci.yml is contents: read throughout and scorecard.yml is read-all. A job needing a write scope names it at job level rather than inheriting one.



    Wakati toleo rasmi linapotengenezwa, toleo hilo LAZIMA lipatiwe kitambulisho cha pekee cha toleo. [OSPS-BR-02.01]
    Peana kitambulisho cha pekee cha toleo kwa kila toleo linalozalishwa na mradi, ukifuata mkondo thabiti wa kutaja au mpango wa nambari. Mifano ni pamoja na SemVer, CalVer, au kitambulisho cha kuwasilisha cha git.

    Each release carries a unique identifier: package.json declares it, npm publishes under that exact version and refuses to republish it, git carries a matching vX.Y.Z tag, and a running instance reports the same string through GET /api/doc?contract=1 so an operator can tell what is serving. The current release is v0.1.128. A release preflight guard refuses a tag whose version does not match what the repository declares, and another refuses a tag pointing at a commit that does not belong to main.



    Wakati toleo rasmi linapotengenezwa, toleo hilo LAZIMA liwe na kumbukumbu ya maelezo ya marekebisho ya utendakazi na usalama. [OSPS-BR-04.01]
    Hakikisha kuwa matoleo yote yanajumuisha kumbukumbu ya mabadiliko ya maelezo. Inashauriwa kuhakikisha kuwa kumbukumbu ya mabadiliko inaweza kusomwa na binadamu na inajumuisha maelezo zaidi ya ujumbe wa ahadi, kama vile maelezo ya athari za usalama au uhusiano na matumizi tofauti. Ili kuhakikisha kusomwa kwa mashine, weka maudhui chini ya kichwa cha markdown kama "## Changelog".

    Every release ships notes covering functional and security-relevant changes. CHANGELOG.md carries a dated section per version in Keep a Changelog form — including, by name and date, the findings of the three external assessments of August 2026 and the version that fixed each — and the same content is published as the GitHub Release for that tag. tools/changelog.mjs fails CI when the version being released has no matching section, so a release cannot ship without a log.



    Wakati mfululizo wa ujenzi na toleo unaingia utegemezi, LAZIMA utumie zana zilizowekwa viwango ambapo zinapatikana. [OSPS-BR-05.01]
    Tumia zana za kawaida kwa ikolojia yako, kama vile wasimamizi wa vifurushi au zana za usimamizi wa utegemezi kuingia utegemezi wakati wa ujenzi. Hii inaweza kujumuisha kutumia faili ya utegemezi, faili ya kufuli, au orodha ya kudhibitisha utegemezi unaohitajika, ambayo kisha unavutwa na mfumo wa ujenzi.

    npm is the dependency manager, driven exclusively through npm ci; no workflow runs npm install. package-lock.json is committed and carries a Subresource-Integrity hash for every package in the transitive graph, so CI installs the graph the lockfile describes rather than whatever the registry served that morning. Build inputs outside npm are pinned by digest rather than tag — container base images by sha256, GitHub Actions by 40-character commit SHA — each enforced by a CI guard that refuses a floating reference. The policy is written down in docs/DEPENDENCIES.md.



    Wakati toleo rasmi linapotengenezwa, toleo hilo LAZIMA liwe na saini au kuhesabiwa kwenye orodha iliyosainiwa ikiwa ni pamoja na hashes za usimbuaji za mali kila moja. [OSPS-BR-06.01]
    Saini mali zote za programu zilizotolewa wakati wa ujenzi kwa saini ya usimbuaji au uthibitisho, kama vile saini ya GPG au PGP, saini za Sigstore, utokeo wa SLSA, au SLSA VSAs. Jumuisha hashes za usimbuaji za mali kila moja katika orodha iliyosainiwa au faili ya metadata.

    Released assets are signed at build time. The npm package is published with npm publish --provenance under OIDC trusted publishing, producing a Sigstore-signed SLSA provenance attestation that names the tarball's cryptographic digest and binds it to the workflow, repository and commit that built it; a consumer verifies it with npm audit signatures. The container image is built with provenance: mode=max and an SBOM, and pushed to GHCR with build attestations under id-token: write. No long-lived signing credential exists to hold or to leak — the signature is obtained from the platform's identity at the moment of publication.



    Wakati mradi umefanya toleo, nyaraka za mradi LAZIMA zijumuishe maelezo ya jinsi mradi unavyochagua, kupata, na kufuatilia utegemezi wake. [OSPS-DO-06.01]
    Inashauriwa kuchapisha habari hii pamoja na nyaraka za kiufundi na muundo wa mradi kwenye rasilimali inayoweza kuonwa hadharani kama vile hifadhi ya msimbo wa chanzo, tovuti ya mradi, au kituo kingine.

    docs/DEPENDENCIES.md describes selection, acquisition and tracking. Selection: the bar a new dependency must clear, and why it is high for a component that runs beside an operator's commercial documents — the runtime tree is one package, pdfjs-dist, pinned exactly because it is the rendering engine and its upgrade is a decision rather than a bump. Acquisition: npm ci only, against a committed lockfile with integrity hashes, with digest pinning for images and commit-SHA pinning for actions. Tracking: the Dependabot policy — monthly, tooling grouped, an action's major arriving alone so it cannot hide in a batch — including the two upgrades deliberately held back, the reason for each, and why majors are not frozen elsewhere.



    Nyaraka za mradi LAZIMA zijumuishe maelekezo ya jinsi ya kujenga programu, ikiwa ni pamoja na maktaba zinazohitajika, mifumo, SDK, na utegemezi. [OSPS-DO-07.01]
    Inashauriwa kuchapisha taarifa hii pamoja na nyaraka za wachangiaji wa mradi, kama vile katika CONTRIBUTING.md au nyaraka nyingine za kazi za msanidi. Hii inaweza pia kuandikwa kwa kutumia malengo ya Makefile au hati nyingine za uendeshaji.

    CONTRIBUTING.md opens with the build: npm install, npm test, npm run lint, npm run typecheck, npm run build. It states the only prerequisite — Node 22 or later — and adds that there is nothing else to install, because the tests spin the player up in-process against a temporary folder and run offline. The browser bench and its single extra requirement are documented beside it: a Chrome already present on the machine, driven by playwright-core with no browser download, and PLAYER_E2E_CHROME to point at it if it lives somewhere unusual. README.md gives the same path for a fresh clone.



    Wakati ikiwa hai, nyaraka za mradi LAZIMA zijumuishe orodha ya wanachama wa mradi walio na ufikiaji wa rasilimali nyeti. [OSPS-GV-01.01]
    Andika washiriki wa mradi na majukumu yao kupitia vitu kama members.md, governance.md, maintainers.md, au faili sawa ndani ya hifadhi ya msimbo wa chanzo wa mradi. Hii inaweza kuwa rahisi kama kujumuisha majina au alama za akaunti katika orodha ya watunzaji, au changamano zaidi kulingana na utawala wa mradi.

    MAINTAINERS.md lists the project members and, in a dedicated table, exactly which sensitive resources each holds: repository admin, merge rights on main, GitHub Actions configuration, npm publishing, the GHCR image, and the security mailbox. There is currently one maintainer and no other account holds write access to the repository, which the file states explicitly rather than leaving to be inferred. It also records that no release credential is stored anywhere — publication authenticates through OIDC at the moment it runs, so there is no secret to hold, rotate, or lose.



    Wakati ikiwa hai, nyaraka za mradi LAZIMA zijumuishe maelezo ya majukumu na wajibu wa wanachama wa mradi. [OSPS-GV-01.02]
    Andika washiriki wa mradi na majukumu yao kupitia vitu kama members.md, governance.md, maintainers.md, au faili sawa ndani ya hifadhi ya msimbo wa chanzo wa mradi.

    MAINTAINERS.md describes the roles and what each answers for. The maintainer: review and merge, what the host contract may promise and when it may break, cutting releases and being answerable for what a published version contains, and triaging vulnerability reports within the timeline SECURITY.md commits to. Contributors: no invitation to wait for, the CLA that a workflow checks on every pull request, and the project's rule on tests. Operators: no access here, but asked to report a boundary the documentation did not predict. A Bus factor section states plainly what one maintainer costs and what it does not.



    Wakati ikiwa hai, nyaraka za mradi LAZIMA zijumuishe mwongozo kwa wachangiaji wa msimbo ambao unajumuisha mahitaji ya michango inayokubalika. [OSPS-GV-03.02]
    Panua yaliyomo ya CONTRIBUTING.md au CONTRIBUTING/ katika nyaraka za mradi ili kuorodhesha mahitaji ya michango inayokubalika, ikiwa ni pamoja na viwango vya kuandika msimbo, mahitaji ya majaribio, na miongozo ya kuwasilisha kwa wachangiaji wa msimbo. Inashauriwa kuwa mwongozo huu ni chanzo cha ukweli kwa wachangiaji na waidhinishaji.

    CONTRIBUTING.md states the requirements for an acceptable contribution. The project's one rule is that a behaviour worth keeping is worth a test that fails without it, and the requirement extends to the test's name: it must say which failure it prevents, not that it tests the happy path, and one that does not will be asked about in review. The same document covers what review looks for, how generated files are handled, commit and branch conventions, the language rule and the CLA; AGENTS.md records which conventions a CI guard enforces and which only review catches.



    Wakati ikiwa hai, mfumo wa kudhibiti toleo LAZIMA uhitaji wachangiaji wote wa msimbo kudai kuwa wanaruhusiwa kisheria kufanya michango husika kwenye ahadi kila moja. [OSPS-LE-01.01]
    Jumuisha DCO katika hifadhi ya mradi, kuhitaji wachangiaji wa msimbo kudai kuwa wanaruhusiwa kisheria kuwasilisha michango husika kwenye ahadi kila moja. Tumia ukaguzi wa hali kuhakikisha dai linafanywa. CLA pia inakidhi mahitaji haya. Mifumo fulani ya kudhibiti toleo, kama vile GitHub, inaweza kujumuisha hii katika masharti ya huduma ya jukwaa.

    Every code contributor asserts their legal right to contribute through the CLA in CLA.md, and the assertion is enforced rather than assumed: .github/workflows/cla.yml checks it on every pull request, posts and updates a comment when a signature is missing, and records signatures on a dedicated branch. An unsigned pull request does not merge, and because branch protection makes pull requests the only route into main, no contribution reaches released code without the assertion having been made and recorded. The OSPS recommendation for this control names a CLA as satisfying it.



    Wakati ahadi inafanywa kwenye tawi kuu, ukaguzi wowote wa kiotomatiki wa hali za ahadi LAZIMA upite au upuuzwe kwa mikono. [OSPS-QA-03.01]
    Sanidi mfumo wa kudhibiti toleo wa mradi kuhitaji kuwa ukaguzi wote wa kiotomatiki wa hali upite au kuhitaji thibitisho la mikono kabla ya ahadi kuweza kuunganishwa kwenye tawi kuu. Inashauriwa kuwa ukaguzi wowote wa hiari HAUPASWI kusanidiwa kama mahitaji ya kupita au kushindwa ambayo waidhinishaji wanaweza kuwa na msukumo wa kupuuza.

    main is protected and its status checks must pass before a pull request can merge. The required set covers lint, typecheck and the full 1515-test suite on Node 22 and 24, CodeQL, and the repository's own guards: every GitHub Action pinned to a commit SHA, the version comment beside each SHA telling the truth, container base images pinned to a digest, the committed browser bundles still matching their TypeScript sources, the published tarball shipping compiled JavaScript rather than raw TypeScript, and no plaintext credential in any tracked file. Direct pushes, which would bypass all of it, are refused.



    Kabla ya ahadi kukubalika, mifululizo ya CI/CD ya mradi LAZIMA iendeshe angalau seti moja ya majaribio ya kiotomatiki kuhakikisha mabadiliko yanakidhi matarajio. [OSPS-QA-06.01]
    Majaribio ya kiotomatiki yanapaswa kuendeshwa kabla ya kuunganisha kila moja kwenye tawi kuu. Seti ya majaribio inapaswa kuendeshwa katika mfululizo wa CI/CD na matokeo yanapaswa kuonekana kwa wachangiaji wote. Seti ya majaribio inapaswa kuendeshwa katika mazingira thabiti na inapaswa kuendeshwa kwa njia inayoruhusu wachangiaji kuendesha majaribio kienyeji. Mifano ya seti za majaribio ni pamoja na majaribio ya kitengo, majaribio ya uunganishaji, na majaribio ya mwisho-hadi-mwisho.

    ci.yml runs on every pull request and every push to main, executing the full vitest suite — 1515 tests across 144 files — on Node 22 and 24, alongside lint and typecheck. Three further benches run in the same workflow rather than on a schedule: a browser bench driving a real Chromium including an axe-core accessibility pass, a bench against a real PostgREST and Postgres instead of a stub, and a cost bench that asserts on the number of database round trips per gesture, so a performance regression fails the build instead of surfacing on an invoice.



    Mradi ulipotoa toleo, nyaraka za mradi LAZIMA zijumuishe nyaraka za muundo zinazoonyesha matendo yote na watendaji ndani ya mfumo. [OSPS-SA-01.01]
    Jumuisha miundo katika nyaraka za mradi inayoeleza matendo na watendaji. Watendaji ni pamoja na mfumo wowote mdogo au kipengele ambacho kinaweza kuathiri sehemu nyingine katika mfumo. Hakikisha hii inasasishwa kwa vipengele vipya au mabadiliko ya kuvunja.

    docs/ARCHITECTURE.md includes an Actors and actions section: a table of every actor — link recipient, internal reader, presenter, live attendee, host application, operator, maintainer — giving the actions each may perform and, in the column that matters most, where the decision is actually made. A second table covers the three non-human systems the design turns on: the file source and the SSRF guard that confines it to allow-listed origins, the database reached only from the server with no anonymous read policy on any table, and the host route behind PLAYER_HOST_FETCH_SECRET. The rest of the document explains the seam that makes those the only decision points.



    Mradi ulipotoa toleo, nyaraka za mradi LAZIMA zijumuishe maelezo ya kiolesura vyote vya nje vya programu vya mali za programu zilizotolewa. [OSPS-SA-02.01]
    Eleza kiolesura vyote vya programu (APIs) vya mali za programu zilizotolewa, ukieleza jinsi watumiaji wanaweza kuingiliana na programu na data gani inatarajiwa au inazalishwa. Hakikisha hii inasasishwa kwa vipengele vipya au mabadiliko ya kuvunja.

    docs/API.md is the English reference for what a host can call and what it must implement. docs/HOST-CONTRACT.md is the binding version of the same surface, carrying a dated journal of every boundary change, and it ships inside the published package — resolvable by a consumer as discovery-media-player/contrat. TypeScript declarations in types/ describe the interface to a compiler, and src/bridge.ts is the MIT-licensed postMessage contract a host application imports to talk to the player. A CI guard compares the declared public surface against what the package actually exports, so the documentation cannot drift from the code.



    Mradi ulipotoa toleo, mradi LAZIMA ufanye tathmini ya usalama ili kuelewa matatizo ya uwezekano wa usalama ambayo ni ya uwezekano zaidi na yenye athari kubwa ambayo yangeweza kutokea ndani ya programu. [OSPS-SA-03.01]
    Kufanya tathmini ya usalama huwaelimisha wajumbe wa mradi na pia watumiaji wa chini kwamba mradi unaelewa matatizo ambayo yangeweza kutokea ndani ya programu. Kuelewa vitisho ambavyo vingeweza kutambuliwa husaidia mradi kudhibiti na kushughulikia hatari. Habari hii ni muhimu kwa watumiaji wa chini ili kuonyesha ujuzi wa usalama na mazoea ya mradi. Hakikisha hii inasasishwa kwa vipengele vipya au mabadiliko ya kuvunja.

    SECURITY.md is the assessment. It names the file proxy as the highest-value target in the codebase, precisely because it takes a URL from a caller and fetches it server-side, and enumerates the outcomes treated as vulnerabilities: reaching a file outside an allow-listed storage origin, reading a document without the right link through slug guessing or a revoked link that still opens, taking a live presentation without its control token, escalating across the host boundary or leaking PLAYER_HOST_FETCH_SECRET into a URL or a log, and XSS against a nonce-based CSP. It also states what is out of scope and why. Three external assessments were carried out in August 2026 and are published unedited in docs/, with a follow-up ledger recording what was fixed, what was decided against, and the reason.



    Ikiwa iko hai, nyaraka za mradi LAZIMA zijumuishe sera ya ufichuaji wa udhaifu wa pamoja (CVD), yenye muda maalum wa kujibu. [OSPS-VM-01.01]
    Unda faili ya SECURITY.md mzizini mwa saraka, ikielezea sera ya mradi ya ufichuaji wa udhaifu wa pamoja. Jumuisha njia ya kuripoti udhaifu. Weka matarajio ya jinsi mradi utajibu na kushughulikia masuala yaliyoripotiwa.

    SECURITY.md publishes the coordinated disclosure policy with explicit timeframes: acknowledgement within 72 hours, an assessment within 7 days, then a disclosure date agreed with the reporter, and credit in the changelog unless the reporter would rather not be named. It states which versions are supported, what is and is not treated as a vulnerability, and the design notes a tester needs before starting. .github/ISSUE_TEMPLATE/config.yml links the policy from the issue chooser, so a reporter meets it before opening a public issue.



    Ikiwa iko hai, nyaraka za mradi LAZIMA zitoe njia ya kuripoti udhaifu wa faragha moja kwa moja kwa mawasiliano ya usalama ndani ya mradi. [OSPS-VM-03.01]
    Toa njia kwa watafiti wa usalama kuripoti udhaifu kwa faragha kwa mradi. Hii inaweza kuwa anwani ya barua pepe mahususi, fomu ya wavuti, zana maalum za VCS, anwani za barua pepe kwa mawasiliano ya usalama, au mbinu nyingine.

    Private reporting is the required channel rather than an option, and there are two: GitHub private vulnerability reporting and security@3d-discovery.fr. SECURITY.md directs reporters to them instead of opening an issue, and the issue-template configuration puts the private form first, with the reason written: instances of this player serve commercial documents, and a public report would expose every operator before a fix exists. https://github.com/Juli1artha/discovery-media-player/blob/main/SECURITY.md



    Ikiwa iko hai, nyaraka za mradi LAZIMA zichapisha hadharani data kuhusu udhaifu uliogundulika. [OSPS-VM-04.01]
    Toa habari kuhusu udhaifu unaojulikana katika kituo cha hadharani kinachoweza kutabirika, kama vile ingizo la CVE, chapisho la blogi, au njia nyingine. Kwa kiwango kinachowezekana, habari hii inapaswa kujumuisha toleo(matoleo) lililoathirika, jinsi mtumiaji anavyoweza kubaini kama wanaathirika, na maelekezo ya kuzuia au kurekebisha.

    Discovered issues are published in a predictable public channel. CHANGELOG.md carries a dated section per version naming security-relevant fixes and the version carrying each, so a consumer can tell from a version number whether they are affected and what to upgrade to; the same content is published as the GitHub Release for that tag. The findings of the three external assessments of August 2026 are published in full in docs/, kept in the state they were received because an assessment rewritten afterwards is no longer a trace, alongside a ledger of what was fixed and what was deliberately not. SECURITY.md commits to crediting reporters there. No CVE has been assigned to date; that changelog section is where one would appear.



Data hii inapatikana chini ya Community Data License Agreement – Permissive, Version 2.0 (CDLA-Permissive-2.0). Hii inamaanisha kuwa Mpokeaji wa Data anaweza kushiriki Data, na au bila marekebisho, mradi Mpokeaji wa Data anapatanisha maandishi ya mkataba huu na Data iliyoshirikiwa. Tafadhali tambua Julien Arthapignet na wachangiaji wa nishani ya Mazoea Bora ya OpenSSF.

Ingizo la nishani ya mradi linamilikiwa na: Julien Arthapignet.
Ingizo liliundwa siku 2026-08-22 00:19:58 UTC, iliyosasishwa mara ya mwisho siku 2026-08-25 12:37:10 UTC. Ilipata mara ya mwisho nishani ya kupita siku 2026-08-22 07:59:01 UTC.