Talos

遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。

没有一套可以保证软件永远不会有缺陷或漏洞的做法;如果规范或假设是错误的,即使合适的方法也可能失败。也没有哪些做法可以保证一个项目能够维持健康和运作良好的开发者社区。但是,遵循最佳做法可以帮助改善项目的成果。例如,一些做法可以在发布之前进行多人评估,这可以帮助您找到其他难以找到的技术漏洞,并帮助建立信任,并希望不同公司的开发人员之间进行重复的交互。要获得徽章,必须满足所有“必须”和“禁止”的条款,满足所有“应该”条款或有合适的理由,和所有“建议”条款必须满足或未满足(至少希望考虑)。欢迎通过 GitHub网站创建问题或提出请求进行反馈。另外还有一个一般讨论邮件列表。

如果这是您的项目,请在您的项目页面上显示您的徽章状态!徽章状态如下所示: 项目15140的徽章级别为in_progress 这里是如何嵌入它:
您可以通过将其嵌入在您的Markdown文件中:
[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/15140/badge)](https://www.bestpractices.dev/projects/15140)
或将其嵌入到HTML中来显示您的徽章状态:
<a href="https://www.bestpractices.dev/projects/15140"><img src="https://www.bestpractices.dev/projects/15140/badge"></a>


这些是白银级别条款。您还可以查看通过或黄金级别条款。

Baseline Series: 基准等级1 基准等级2 基准等级3

        

 基本 11/17 ●

 变更控制 1/1 ●

 报告 2/3 ●

  • 错误报告流程


    项目必须使用问题跟踪器来跟踪每个问题。 [report_tracker]

    Public GitHub tracker exists.

    https://github.com/autonomio/talos/issues


  • 漏洞报告流程


    除了要求匿名的报告者外,该项目必须对过去12个月内解决的所有漏洞报告的报告者表示感谢。如果过去12个月没有修复漏洞,请选择“不适用”(N/A)。 (需要网址) [vulnerability_report_credit]

    The maintainer confirms compliance with crediting reporters of vulnerability reports resolved during the preceding12months, except those requesting anonymity. No report count, individual report, private narrative or response timestamp is invented. If a separately confirmed zero-resolution denominator is supplied, the official N/A option can instead be used.

    https://github.com/autonomio/talos/blob/9783406eafd0c9d72d00010aeffb379a534a5349/SECURITY.md
    https://www.bestpractices.dev/en/criteria/1?details=true#vulnerability_report_credit



    该项目必须有一个书面的流程来响应漏洞报告。 (需要网址) [vulnerability_response_process]
    这与security_report_process有很强的相关性,它需要有一个书面的流程来报告漏洞。它还涉及到spam_report_response,它需要在一定时间内响应漏洞报告。

    Reporting routes and reporter-credit policy exist, but a complete documented acknowledgement, triage, remediation, coordinated disclosure and closure process is absent from the merged source. Root prepares that process on the next branch; historic compliance remains a separate fact.

    https://github.com/autonomio/talos/blob/9783406eafd0c9d72d00010aeffb379a534a5349/SECURITY.md


 质量 12/19 ●

 安全 4/13 ●

 分析 2/2 ●


您可以使用工具和AI系统通过简单的URL提交变更建议,例如 https://www.bestpractices.dev/zh-CN/projects/15140/choose/edit?osps_ac_01_01_status=Met&osps_ac_01_01_justification=GitHub+enforced。请参阅我们的自动化提案系统,了解具体操作方法。 该数据可在社区数据许可协议 – 许可性,版本 2.0 (CDLA-Permissive-2.0)下获取。这意味着数据接收方可以共享数据,无论是否经过修改,只要数据接收方在共享数据时提供本协议文本。请注明Mikko Kotila和OpenSSF最佳实践徽章贡献者。

项目徽章条目拥有者: Mikko Kotila.
最后更新于 2026-10-01 16:30:01 UTC, 最后更新于 2026-10-01 19:11:47 UTC。