Talos

遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。

没有一套可以保证软件永远不会有缺陷或漏洞的做法;如果规范或假设是错误的,即使合适的方法也可能失败。也没有哪些做法可以保证一个项目能够维持健康和运作良好的开发者社区。但是,遵循最佳做法可以帮助改善项目的成果。例如,一些做法可以在发布之前进行多人评估,这可以帮助您找到其他难以找到的技术漏洞,并帮助建立信任,并希望不同公司的开发人员之间进行重复的交互。要获得徽章,必须满足所有“必须”和“禁止”的条款,满足所有“应该”条款或有合适的理由,和所有“建议”条款必须满足或未满足(至少希望考虑)。欢迎通过 GitHub网站创建问题或提出请求进行反馈。另外还有一个一般讨论邮件列表。

如果这是您的项目,请在您的项目页面上显示您的徽章状态!徽章状态如下所示: 项目15140的徽章级别为in_progress 这里是如何嵌入它:
您可以通过将其嵌入在您的Markdown文件中:
[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/15140/badge)](https://www.bestpractices.dev/projects/15140)
或将其嵌入到HTML中来显示您的徽章状态:
<a href="https://www.bestpractices.dev/projects/15140"><img src="https://www.bestpractices.dev/projects/15140/badge"></a>


这些是通过级别条款。您还可以查看白银或黄金级别条款。

Baseline Series: 基准等级1 基准等级2 基准等级3

        

 基本 13/13 ●

 变更控制 9/9 ●

 报告 8/8 ●

  • 错误报告流程


    项目必须为用户提交错误报告(例如,使用问题跟踪器或邮件列表)提供相关流程。 (需要网址) [report_process]

    Public Git repository with interim reviewed candidate, issue tracker, searchable permanent URLs and browser participation.

    https://github.com/autonomio/talos/issues
    https://github.com/autonomio/talos/pull/608



    项目必须使用问题跟踪器来跟踪每个问题。 [report_tracker]

    Public GitHub tracker exists.

    https://github.com/autonomio/talos/issues



    该项目必须响应过去2-12个月内(含)提交的大多数错误报告;响应不需要包括修复。 [report_responses]

    The only eligible bug report in the 2–12-month window is #605, created2025-10-29. On2026-08-20 community participant bbogart acknowledged the same installation error and documented a working Python3.11 workaround in two public comments:1/1eligible reports acknowledged. The official criterion does not require maintainer authorship or a response deadline; this is community acknowledgement, not a claim that a maintainer replied.

    https://github.com/autonomio/talos/issues/605
    https://www.bestpractices.dev/en/criteria/0?details=true#report_responses



    该项目应该对过去2-12个月内(包括)的大部分(> 50%)的增强请求作出回应。 [enhancement_responses]
    答复可能是“不”或有关其价值的讨论。目的只是对某些请求有一些回应,这表明项目还活着。为了该条款的目的,项目不需要计数无效请求(例如,来自垃圾邮件发送者或自动系统)。如果项目不再进行增强,请选择“未满足”,并将介绍此情况的URL包含在内。如果一个项目有超出处理能力的增强需求数量,请选择“未满足”并解释。

    No eligible enhancement request was identified in the observed 2–12-month issue window. This SHOULD criterion is considered, but there is no measured response-rate denominator; an unmet justification is used because this criterion does not offer N/A.



    该项目必须有一个公开的报告和回复的档案供后续搜索。 (需要网址) [report_archive]

    Public Git repository with interim reviewed candidate, issue tracker, searchable permanent URLs and browser participation.

    https://github.com/autonomio/talos/issues
    https://github.com/autonomio/talos/pull/608


  • 漏洞报告流程


    项目必须在项目网站上发布报告漏洞的流程。 (需要网址) [vulnerability_report_process]
    例如,https://PROJECTSITE/security 上的一个明确指定的邮箱地址,通常以 security@example.org 的形式。这可能与其错误报告流程相同。漏洞报告可能一直是公开的,但是许多项目都有一个私密漏洞报告机制。

    SECURITY.md gives GitHub private advisory and maintainer email routes. Private vulnerability reporting was verified enabled.

    https://github.com/autonomio/talos/blob/9783406eafd0c9d72d00010aeffb379a534a5349/SECURITY.md



    如果支持私有漏洞报告,项目必须包括如何以保密的方式发送信息。 (需要网址) [vulnerability_report_private]
    示例包括使用HTTPS(TLS)或使用OpenPGP加密的电子邮件在网络上提交的私密缺陷报告。如果漏洞报告总是公开的(从来没有私密漏洞报告),请选择“不适用”(N/A)。

    SECURITY.md gives GitHub private advisory and maintainer email routes. Private vulnerability reporting was verified enabled.

    https://github.com/autonomio/talos/blob/9783406eafd0c9d72d00010aeffb379a534a5349/SECURITY.md



    该项目在过去6个月收到的任何漏洞报告的初始响应时间必须小于或等于14天。 [vulnerability_report_response]
    如果过去6个月没有报告漏洞,请选择“不适用”(N/A)。

    The maintainer confirms there were no private/email vulnerability reports in the preceding six months. The official detail instructs N/A when no vulnerabilities were reported in that period. No response-time denominator or fabricated acknowledgement timestamps are asserted.

    https://www.bestpractices.dev/en/criteria/0?details=true#vulnerability_report_response
    https://github.com/autonomio/talos/security


 质量 13/13 ●

 安全 14/16 ●

 分析 8/8 ●


您可以使用工具和AI系统通过简单的URL提交变更建议,例如 https://www.bestpractices.dev/zh-CN/projects/15140/choose/edit?osps_ac_01_01_status=Met&osps_ac_01_01_justification=GitHub+enforced。请参阅我们的自动化提案系统,了解具体操作方法。 该数据可在社区数据许可协议 – 许可性,版本 2.0 (CDLA-Permissive-2.0)下获取。这意味着数据接收方可以共享数据,无论是否经过修改,只要数据接收方在共享数据时提供本协议文本。请注明Mikko Kotila和OpenSSF最佳实践徽章贡献者。

项目徽章条目拥有者: Mikko Kotila.
最后更新于 2026-10-01 16:30:01 UTC, 最后更新于 2026-10-01 19:11:47 UTC。