遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/6374)
<a href="https://www.bestpractices.dev/projects/6374"><img src="https://www.bestpractices.dev/projects/6374/badge"></a>
A high performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar
The project is maintained by Okta and has a team assigned to it, with more than two developers working on it https://github.com/openfga/openfga/graphs/contributors
Repository on GitHub, which uses git. git is distributed.
https://github.com/openfga/openfga/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22good%20first%20issue%22 https://github.com/openfga/openfga/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22help%20wanted%22
All maintainers have MFA enabled in Github
Maintainers are required to use Yubikeys, Passkeys or authenticator apps when configuring MFA
https://github.com/openfga/openfga/blob/main/Makefile
https://github.com/openfga/openfga/blob/main/Makefile#L46
https://github.com/openfga/openfga/blob/main/.github/workflows/pull_request.yaml
https://app.codecov.io/gh/openfga/openfga Code Coverage is in > 89%
The software can be run using HTTPs with TLS 1.2 or later.
// One or more of the required security hardening headers is missing. // X-Content-Type-Options was not set to "nosniff". // One or more of the required security hardening headers is missing.
Project performs static and dynamic code analysis through Github Actions. Every release also pays attention to latest list of CVEs that may impact OpenFGA.
警告:需要URL,但找不到URL。
We use Web Application Scanner (Detectify) for Auth0 FGA, which uses OpenFGA as a library. We don't have dynamic analysis on OpenFGA yet.
Our test suite has 89% code coverage.
警告:需要更长的理由。
后退