diff --git a/README.md b/README.md index 5f61570..092e6c1 100644 --- a/README.md +++ b/README.md @@ -5,6 +5,7 @@ [![Python](https://img.shields.io/pypi/pyversions/csaf-check.svg)](https://pypi.org/project/csaf-check/) [![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/gexiro-global/csaf-check/badge)](https://scorecard.dev/viewer/?uri=github.com/gexiro-global/csaf-check) [Security and trust evidence](docs/SECURITY-TRUST.md) documents the project's policies and automated checks. No certification or badge level is claimed. Validate CSAF 2.0 advisories from Python, using the same validator Secvisogram runs — and get an diff --git a/docs/SECURITY-TRUST.md b/docs/SECURITY-TRUST.md index 4d50cb4..ae60c01 100644 --- a/docs/SECURITY-TRUST.md +++ b/docs/SECURITY-TRUST.md @@ -8,4 +8,4 @@ This page is an evidence index, not a certification. The evidence does not prove - CodeQL, dependency review, Dependabot and OpenSSF Scorecard are configured in `.github/`. - Third-party actions are pinned to immutable commit SHAs with version comments. -The Scorecard badge is intentionally withheld until a successful default-branch run has produced a public API result. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission. +The official public Scorecard result is 6.3, generated 2026-09-04T13:38:43Z for commit `4156d852e4a1738953d3cf95b366e1dd846db55e`; see the [official public viewer](https://scorecard.dev/viewer/?uri=github.com/gexiro-global/csaf-check). This numeric result is point-in-time posture evidence, not a certification. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission.