遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/804)
<a href="https://www.bestpractices.dev/projects/804"><img src="https://www.bestpractices.dev/projects/804/badge"></a>
Social server with an ActivityStreams API
Repository on GitHub, which uses git. git is distributed.
https://github.com/pump-io/pump.io/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+pr%22, https://github.com/pump-io/pump.io/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+second+pr%22, https://github.com/pump-io/pump.io/blob/master/doc/CONTRIBUTING_CODE.md#finding-an-issue
https://github.com/pump-io/pump.io/blob/master/package.json
https://travis-ci.org/pump-io/pump.io
HTTP will be used if the admin does not configure HTTPS or if activities are distributed to remote nodes whose admins haven't configured HTTPS. There are plans to automatically manage HTTPS and to disallow HTTP activity distribution, and to turn these options on by default.
警告:需要更长的理由。
GitHub meets this criteria. npm downloads do not require these headers. X-Content-Type-Options was not set to "nosniff". // X-Content-Type-Options was not set to "nosniff".
pump.io uses Content Security Policy and several other security-related HTTP headers. It also ships with a systemd service which disallows many harmful behaviors in case of compromise. There are plans to make it run in a chroot jail and to improve the Content Security Policy.
警告:需要URL,但找不到URL。
后退