遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/4681)
<a href="https://www.bestpractices.dev/projects/4681"><img src="https://www.bestpractices.dev/projects/4681/badge"></a>
Open source platform for X.509 certificate based service authentication and fine grained access control in dynamic infrastructures. Athenz supports provisioning and configuration (centralized authorization) use cases as well as serving/runtime (decentralized authorization) use cases.
https://github.com/AthenZ/athenz/blob/master/CONTRIBUTING.md
Athenz uses DCO https://github.com/AthenZ/athenz/blob/master/CONTRIBUTING.md#sign-your-work
Athenz has adopted open governance model, details documented at https://github.com/AthenZ/athenz/blob/master/GOVERNANCE.md
Athenz is a CNCF sandbox project and follows CNCF code of conduct. https://github.com/AthenZ/athenz/blob/master/CODE_OF_CONDUCT.md
https://github.com/AthenZ/athenz/blob/master/GOVERNANCE.md
https://github.com/AthenZ/athenz/blob/master/GOVERNANCE.md Since Athenz is a CNCF project, CNCF is the owner of AthenZ github organization and owner of athenz.io DNS.
Athenz has 3 core maintainers as mentioned at https://github.com/AthenZ/athenz/blob/master/MAINTAINERS in addition to that individual non-core sub-projects have its own separate maintainers.
Athenz maintains Quarterly roadmap in GitHub, https://github.com/AthenZ/athenz/blob/master/roadmap.md
Detailed documentation is available at https://athenz.github.io/athenz/
警告:需要URL,但找不到URL。
Athenz documentation describes a quick way to get started using pre-built docker images and helper scripts. https://athenz.github.io/athenz/how_to_sample_identity_from_local_athenz/
Athenz documentation is maintained periodically to keep current with latest features and changes.
Athenz github readme page contains relevant badges including best practices badge https://github.com/AthenZ/athenz/blob/master/README.md
Athenz site follows Accessibility best practices.
Efforts are underway to make localization of Athenz UI possible.
Athenz does not store any passwords.
Athenz versions are generally backward compatible, when not, its clearly called out in release notes.
https://github.com/AthenZ/athenz/issues
No vulnerabilities have been reported in last 12 months by reporters.
Athenz has a security policy as mentioned at https://github.com/AthenZ/athenz/security/policy
Athenz uses standard oss tools for coding styles and those are enforced by pull requests builds https://github.com/AthenZ/athenz/pulls
Pull requests created at https://github.com/AthenZ/athenz/pulls will fail if not complied with coding standards.
警告:需要更长的理由。
sub-module POMs enforce minimum required code coverage and PR builds will fail if the new code does not satisfy the conditions.
Main maven build is set to fail on warnings.
Athenz is not dependent on cryptographic algorithms or modes with known serious weaknesses like SHA-1
https://sonarcloud.io/dashboard?id=AthenzSonar-com.yahoo.athenz%3Aathenz
Athenz uses Java, Go and JavaScript which are memory-safe languages.
后退