diff --git a/_data/openssf/10611.json b/_data/openssf/10611.json index c2df393..8f6bc6c 100644 --- a/_data/openssf/10611.json +++ b/_data/openssf/10611.json @@ -1 +1 @@ -{"id":10611,"user_id":44336,"name":"MPICH","description":"MPICH is a high performance and widely portable implementation of the Message Passing Interface (MPI) standard.","homepage_url":"https://www.mpich.org","repo_url":"https://github.com/pmodels/mpich","license":"OTHER","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","interact_status":"Met","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/pmodels/mpich/blob/main/CONTRIBUTING\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"http://github.com/pmodels/mpich/blob/main/doc/wiki/Index.md","license_location_status":"Met","license_location_justification":"https://github.com/pmodels/mpich/blob/main/COPYRIGHT","floss_license_status":"Met","floss_license_osi_status":"Unmet","floss_license_osi_justification":"Released under mpich2 license (https://spdx.org/licenses/mpich2.html). It is a BSD-2 compatible license.","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"N/A","documentation_interface_justification":"The project is an implementation of the standardized Message Passing Interface (MPI). The standardized interface reference can be found at https://www.mpi-forum.org/docs/mpi-4.1/mpi41-report.pdf.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Each release (including beta and rc releases) can be found at https://github.com/pmodels/mpich/releases","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/pmodels/mpich/tags","release_notes_status":"Met","release_notes_justification":"https://github.com/pmodels/mpich/blob/main/CHANGES","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"MPI libraries are usually not updated by the end users. Usually, the system administrator would manage the version installed on the cluster to ensure the stability and optimal performance.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/pmodels/mpich/issues","report_process_status":"Met","report_process_justification":"https://github.com/pmodels/mpich/issues","report_responses_status":"Met","enhancement_responses_status":"Met","report_archive_status":"Met","report_archive_justification":"https://github.com/pmodels/mpich/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/pmodels/mpich/issues","vulnerability_report_private_status":"N/A","vulnerability_report_response_status":"N/A","build_status":"Met","build_common_tools_status":"Met","build_floss_tools_status":"Met","test_status":"Met","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_justification":"The project has configuration for \"strict\". CI included \"warning\" and \"strict\" test configs.","warnings_fixed_status":"Met","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Does not apply to this project.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Does not apply to this project.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"Does not apply to this project.","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"Does not apply to this project.","static_analysis_status":"Met","static_analysis_justification":"Coverity Scan","static_analysis_common_vulnerabilities_status":"Met","static_analysis_fixed_status":"N/A","static_analysis_often_status":"Met","static_analysis_often_justification":"Coverity Scan triggered nightly by CI.","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Clang Address Sanitizer and Undefined Behavior Sanitizer\r\n","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Clang Address Sanitizer and Undefined Behavior Sanitizer\r\n","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"Triggered by nightly test via CI.","dynamic_analysis_fixed_status":"N/A","general_comments":"","created_at":"2025-05-26T12:43:36.418Z","updated_at":"2025-09-11T17:15:19.694Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\". Required security hardening headers missing: https://www.mpich.org: content-security-policy, x-content-type-options, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-05-26T13:21:22.909Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C, M4, Fortran, Python, Perl, Makefile, C++, Shell, TeX","lock_version":12,"badge_percentage_1":9,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":109,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-05-26T13:21:22.909Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":false,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Yanfei Guo and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":10611,"user_id":44336,"name":"MPICH","description":"MPICH is a high performance and widely portable implementation of the Message Passing Interface (MPI) standard.","homepage_url":"https://www.mpich.org","repo_url":"https://github.com/pmodels/mpich","license":"OTHER","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","interact_status":"Met","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/pmodels/mpich/blob/main/CONTRIBUTING\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"http://github.com/pmodels/mpich/blob/main/doc/wiki/Index.md","license_location_status":"Met","license_location_justification":"https://github.com/pmodels/mpich/blob/main/COPYRIGHT","floss_license_status":"Met","floss_license_osi_status":"Unmet","floss_license_osi_justification":"Released under mpich2 license (https://spdx.org/licenses/mpich2.html). It is a BSD-2 compatible license.","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"N/A","documentation_interface_justification":"The project is an implementation of the standardized Message Passing Interface (MPI). The standardized interface reference can be found at https://www.mpi-forum.org/docs/mpi-4.1/mpi41-report.pdf.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Each release (including beta and rc releases) can be found at https://github.com/pmodels/mpich/releases","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/pmodels/mpich/tags","release_notes_status":"Met","release_notes_justification":"https://github.com/pmodels/mpich/blob/main/CHANGES","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"MPI libraries are usually not updated by the end users. Usually, the system administrator would manage the version installed on the cluster to ensure the stability and optimal performance.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/pmodels/mpich/issues","report_process_status":"Met","report_process_justification":"https://github.com/pmodels/mpich/issues","report_responses_status":"Met","enhancement_responses_status":"Met","report_archive_status":"Met","report_archive_justification":"https://github.com/pmodels/mpich/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/pmodels/mpich/issues","vulnerability_report_private_status":"N/A","vulnerability_report_response_status":"N/A","build_status":"Met","build_common_tools_status":"Met","build_floss_tools_status":"Met","test_status":"Met","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_justification":"The project has configuration for \"strict\". CI included \"warning\" and \"strict\" test configs.","warnings_fixed_status":"Met","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Does not apply to this project.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Does not apply to this project.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"Does not apply to this project.","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"Does not apply to this project.","static_analysis_status":"Met","static_analysis_justification":"Coverity Scan","static_analysis_common_vulnerabilities_status":"Met","static_analysis_fixed_status":"N/A","static_analysis_often_status":"Met","static_analysis_often_justification":"Coverity Scan triggered nightly by CI.","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Clang Address Sanitizer and Undefined Behavior Sanitizer\r\n","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Clang Address Sanitizer and Undefined Behavior Sanitizer\r\n","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"Triggered by nightly test via CI.","dynamic_analysis_fixed_status":"N/A","general_comments":"","created_at":"2025-05-26T12:43:36.418Z","updated_at":"2025-09-11T17:15:19.694Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\". Required security hardening headers missing: https://www.mpich.org: content-security-policy, x-content-type-options, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-05-26T13:21:22.909Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C, M4, Fortran, Python, Perl, Makefile, C++, Shell, TeX","lock_version":12,"badge_percentage_1":9,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":109,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-05-26T13:21:22.909Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":false,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Yanfei Guo and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/11410.json b/_data/openssf/11410.json index b4641af..279b22b 100644 --- a/_data/openssf/11410.json +++ b/_data/openssf/11410.json @@ -1 +1 @@ -{"id":11410,"user_id":45892,"name":"ADIOS2","description":"Next generation of ADIOS developed in the Exascale Computing Program","homepage_url":"https://adios2.readthedocs.io","repo_url":"https://github.com/ornladios/ADIOS2","license":"Apache-2.0","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"This is explained in the introduction section","interact_status":"Met","interact_justification":"There is extensive information on how to install and where is the issue tracker and repository.","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/Contributing.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"This is explained at the projects wiki: https://github.com/ornladios/ADIOS2/wiki","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The Apache-2.0 license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"The Apache-2.0 license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"Met","documentation_interface_justification":"This is explained in the readthedocs site in detail in the API section.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"This partially achieve through the use of release candidates before final releases","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"This is achieve by using semantic versioning","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"We use git tags","release_notes_status":"Met","release_notes_justification":"We provide release notes in all the recent releases as shown here: https://github.com/ornladios/ADIOS2/releases/tag/v2.10.2","release_notes_vulns_status":"Met","release_notes_vulns_justification":"This has been the case in the past releases","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/ornladios/ADIOS2/issues","report_process_status":"Met","report_process_justification":"We provide github issues templates for bug reports https://github.com/ornladios/ADIOS2/blob/master/.github/ISSUE_TEMPLATE/bug_report.md","report_responses_status":"Met","enhancement_responses_status":"Met","enhancement_responses_justification":"We have responded to the majority (+50%) of the issues in the past year.","report_archive_status":"Met","report_archive_justification":"Close section in: https://github.com/ornladios/ADIOS2/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"This has been addressed in the security policy file https://github.com/ornladios/ADIOS2/blob/master/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"This has been addressed in the security policy file https://github.com/ornladios/ADIOS2/blob/master/SECURITY.md","vulnerability_report_response_status":"Met","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"We test this in our CI that builds ADIOS2 in Linux distro such as almalinux 8 and debian.","test_status":"Met","test_justification":"We use GTest + cmake. How to run the test is described in adios2 readthedocs","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","test_policy_justification":"This is heavily expected.","tests_are_added_status":"Met","tests_are_added_justification":"Our contribute.md file partially covers this","tests_documented_added_status":"Unmet","warnings_status":"Met","warnings_justification":"We use sanitize and code SAST","warnings_fixed_status":"Met","warnings_fixed_justification":"We treat warnings as errors.","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"Met","crypto_call_status":"Met","crypto_floss_status":"Met","crypto_floss_justification":"We use OpenSSL in parts and libsodium","crypto_keylength_status":"Met","crypto_working_status":"Met","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"clang-tidy and codeql","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"clang-tidy and codeql","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"We have done it","static_analysis_often_status":"Met","static_analysis_often_justification":"In every commit","dynamic_analysis_status":"Met","dynamic_analysis_justification":"We use clang sanitizers ASAN MSAN TSAN and UBSAN","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Just in case we use clang sanitizers ASAN MSAN TSAN and UBSAN","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"We disable things like assert in release builds","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"We on average address sanitizer issues in timely manner","general_comments":"","created_at":"2025-10-30T00:07:38.432Z","updated_at":"2025-11-06T22:09:28.675Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"We do it.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"The documentation is written in English and hosted in the readthedocs, the projects accepts bug reports and comments in the github pull requests and issues","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"Required security hardening headers missing: https://adios2.readthedocs.io/: content-security-policy, x-frame-options Required security hardening headers missing: https://adios2.readthedocs.io: content-security-policy, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-11-03T20:21:00.077Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, C, CMake, Fortran, Python, Shell, MATLAB, Dockerfile, Makefile, Lex, Yacc, Cuda, PowerShell","lock_version":14,"badge_percentage_1":11,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":111,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-11-03T20:21:00.077Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Vicente Adolfo Bolea Sanchez and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":11410,"user_id":45892,"name":"ADIOS2","description":"Next generation of ADIOS developed in the Exascale Computing Program","homepage_url":"https://adios2.readthedocs.io","repo_url":"https://github.com/ornladios/ADIOS2","license":"Apache-2.0","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"This is explained in the introduction section","interact_status":"Met","interact_justification":"There is extensive information on how to install and where is the issue tracker and repository.","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/Contributing.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"This is explained at the projects wiki: https://github.com/ornladios/ADIOS2/wiki","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The Apache-2.0 license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"The Apache-2.0 license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"Met","documentation_interface_justification":"This is explained in the readthedocs site in detail in the API section.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"This partially achieve through the use of release candidates before final releases","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"This is achieve by using semantic versioning","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"We use git tags","release_notes_status":"Met","release_notes_justification":"We provide release notes in all the recent releases as shown here: https://github.com/ornladios/ADIOS2/releases/tag/v2.10.2","release_notes_vulns_status":"Met","release_notes_vulns_justification":"This has been the case in the past releases","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/ornladios/ADIOS2/issues","report_process_status":"Met","report_process_justification":"We provide github issues templates for bug reports https://github.com/ornladios/ADIOS2/blob/master/.github/ISSUE_TEMPLATE/bug_report.md","report_responses_status":"Met","enhancement_responses_status":"Met","enhancement_responses_justification":"We have responded to the majority (+50%) of the issues in the past year.","report_archive_status":"Met","report_archive_justification":"Close section in: https://github.com/ornladios/ADIOS2/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"This has been addressed in the security policy file https://github.com/ornladios/ADIOS2/blob/master/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"This has been addressed in the security policy file https://github.com/ornladios/ADIOS2/blob/master/SECURITY.md","vulnerability_report_response_status":"Met","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/ornladios/ADIOS2/blob/master/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"We test this in our CI that builds ADIOS2 in Linux distro such as almalinux 8 and debian.","test_status":"Met","test_justification":"We use GTest + cmake. How to run the test is described in adios2 readthedocs","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","test_policy_justification":"This is heavily expected.","tests_are_added_status":"Met","tests_are_added_justification":"Our contribute.md file partially covers this","tests_documented_added_status":"Unmet","warnings_status":"Met","warnings_justification":"We use sanitize and code SAST","warnings_fixed_status":"Met","warnings_fixed_justification":"We treat warnings as errors.","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"Met","crypto_call_status":"Met","crypto_floss_status":"Met","crypto_floss_justification":"We use OpenSSL in parts and libsodium","crypto_keylength_status":"Met","crypto_working_status":"Met","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"clang-tidy and codeql","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"clang-tidy and codeql","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"We have done it","static_analysis_often_status":"Met","static_analysis_often_justification":"In every commit","dynamic_analysis_status":"Met","dynamic_analysis_justification":"We use clang sanitizers ASAN MSAN TSAN and UBSAN","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Just in case we use clang sanitizers ASAN MSAN TSAN and UBSAN","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"We disable things like assert in release builds","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"We on average address sanitizer issues in timely manner","general_comments":"","created_at":"2025-10-30T00:07:38.432Z","updated_at":"2025-11-06T22:09:28.675Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"We do it.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"The documentation is written in English and hosted in the readthedocs, the projects accepts bug reports and comments in the github pull requests and issues","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"Required security hardening headers missing: https://adios2.readthedocs.io/: content-security-policy, x-frame-options Required security hardening headers missing: https://adios2.readthedocs.io: content-security-policy, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-11-03T20:21:00.077Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, C, CMake, Fortran, Python, Shell, MATLAB, Dockerfile, Makefile, Lex, Yacc, Cuda, PowerShell","lock_version":14,"badge_percentage_1":11,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":111,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-11-03T20:21:00.077Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Vicente Adolfo Bolea Sanchez and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/7802.json b/_data/openssf/7802.json index b735125..00e2d92 100644 --- a/_data/openssf/7802.json +++ b/_data/openssf/7802.json @@ -1 +1 @@ -{"id":7802,"user_id":45373,"name":"HDF5 Library and File Format","description":"Official HDF5® Library Repository","homepage_url":"https://github.com/HDFGroup/hdf5","repo_url":"https://github.com/HDFGroup/hdf5","license":"BSD-3-Clause","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"All project sites support HTTPS using TLS:\r\n\r\n**1 Project Website**\r\n\r\n* The HDF Group website uses HTTPS: https://www.hdfgroup.org/\r\n\r\nReference from README.md and CONTRIBUTING.md\r\n\r\n**2 Source Code Repository**\r\n\r\nThe GitHub repository uses HTTPS:\r\n\r\n * https://github.com/HDFGroup/hdf5\r\n * https://github.com/HDFGroup/hdf5.git\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**3 Download URLs**\r\n\r\nAll download locations use HTTPS:\r\n\r\n * Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * Current releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n * Archived releases: https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n * Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Maven artifacts: https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\nReference: README.md\r\n\r\n**4 Help and Support URLs**\r\n\r\nSupport sites use HTTPS:\r\n\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md#help-and-support\r\n\r\n**5 License URL**\r\n\r\nLicense information uses HTTPS:\r\n\r\n * https://www.hdfgroup.org/licenses\r\n\r\nReferenced throughout source code files and CONTRIBUTING.md URL: All project URLs use HTTPS (see above) All project sites, repositories, and download locations exclusively use HTTPS with TLS encryption.","description_good_status":"Met","description_good_justification":"The README.md file succinctly describes what HDF5 does and what problem it solves:\r\n\r\n**1 Primary Description**\r\n\r\nThe README states:\r\n\r\n * \"This repository contains a high-performance library's source code and a file format specification that implements the HDF5® data model. The model has been adopted across many industries, and this implementation has become a de facto data management standard in science, engineering, and research communities worldwide.\"\r\n\r\n**2 This clearly describes**:\r\n\r\n * What it does: Provides a high-performance library and file format for data management\r\n * What problem it solves: Data management and storage needs in science, engineering, and research\r\n * Its significance: De facto standard adopted across many industries\r\n\r\nReference: README.md\r\n\r\n**3 Additional Context**\r\n\r\nThe README also directs users to The HDF Group's website for more information:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md","interact_status":"Met","interact_justification":"**1 How to Obtain the Software**\r\n\r\nThe README includes multiple sources for obtaining HDF5:\r\n\r\n* Source code repository: https://github.com/HDFGroup/hdf5.git\r\n* Current releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n* Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n* Archived releases: https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n* Maven artifacts: https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\n Reference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**2 How to Provide Feedback (Bug Reports and Enhancements)**\r\n\r\nThe README provides clear channels for feedback:\r\n\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org (for technical questions and discussions)\r\n * HDF5 Topics Forum: https://forum.hdfgroup.org/c/hdf5 (specifically for HDF5-related discussions)\r\n\r\nReference: README.md#help-and-support and README.md#forum-and-news\r\n\r\n**3 How to Contribute**\r\n\r\nWhile not detailed in README.md itself, the repository contains a comprehensive CONTRIBUTING.md file that explains the contribution process in detail. URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project website (accessible through the links in README.md) provides all necessary information for obtaining, providing feedback, and contributing to the software.","contribution_status":"Met","contribution_justification":"Reference: https://github.com/HDFGroup/hdf5/blob/develop/CONTRIBUTING.md The file clearly explains that pull requests are the mechanism for contributions and provides comprehensive process documentation.","contribution_requirements_status":"Met","contribution_requirements_justification":"Reference: CONTRIBUTING.md#checklist-for-contributors URL: https://github.com/HDFGroup/hdf5/blob/develop/CONTRIBUTING.md \r\n\r\nThe file comprehensively addresses coding standards, development conventions, and contribution requirements throughout multiple sections. Specifically:\r\n\r\n**1 Development Conventions Section**\r\n\r\nThis section documents required coding standards, including:\r\n\r\n * Code organization (public, private, package visibility levels)\r\n * Function naming conventions (H5Xfoo(), H5X_foo(), H5X__foo())\r\n * Function structure requirements (entry/exit macros, error handling)\r\n * Error handling conventions\r\n * Platform independence requirements\r\n * Memory management standards\r\n\r\n Reference: CONTRIBUTING.md#development-conventions\r\n\r\n**2 Acceptance Criteria Section**\r\n\r\nThis section explicitly lists requirements for pull requests:\r\n\r\n * Clear purpose\r\n * Proper documentation\r\n * Testing requirements\r\n * Compatibility requirements (100% backward compatibility, machine independence, binary compatibility)\r\n * Documentation standards (Doxygen, CHANGELOG.md)\r\n\r\nReference: CONTRIBUTING.md#acceptance-criteria\r\n\r\n**3 Checklist for Contributors Section**\r\n\r\nProvides a verification checklist covering:\r\n\r\n* Code conventions (naming, portability, structure)\r\n* Documentation requirements\r\n* Testing requirements","license_location_status":"Met","license_location_justification":"The project posts its license in the standard location:\r\n\r\n* LICENSE File in Repository Root URL: https://github.com/HDFGroup/hdf5/blob/develop/LICENSE","floss_license_status":"Met","floss_license_justification":"https://github.com/HDFGroup/hdf5/blob/develop/LICENSE The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"https://opensource.org/license/bsd-3-clause The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"The project provides comprehensive basic documentation through multiple channels:\r\n\r\n * README.md - Quick Start Documentation\r\n\r\n**1 The README.md file in the repository root provides essential documentation, including:**\r\n\r\n * What the software does (high-performance data management library)\r\n * How to obtain the software\r\n * Where to get help and support\r\n * Release information\r\n * Reference: README.md\r\n\r\n**2 Installation Documentation**\r\n\r\nThe release_docs/ directory contains detailed installation and usage instructions:\r\n\r\n * INSTALL - General compilation and installation instructions\r\n * INSTALL_CMAKE - CMake-specific build instructions\r\n * INSTALL_Windows and INSTALL_Cygwin - Platform-specific installation\r\n * README_HPC.md - HPC system configuration\r\n * USING_HDF5_CMake - Building applications with HDF5\r\n * USING_CMake_Examples - Building and testing examples\r\n \r\nReference: release_docs/\r\n\r\n**3 CONTRIBUTING.md - Development Documentation**\r\n\r\nComprehensive guide for developers covering:\r\n\r\n * How to build for development\r\n * Source code organization\r\n * Development conventions and coding standards\r\n * Testing procedures\r\n\r\n Reference: CONTRIBUTING.md\r\n\r\n**4 Online Documentation**\r\n\r\nThe README.md directs users to comprehensive online documentation:\r\n\r\n * All HDF software documentation: https://support.hdfgroup.org/documentation/index.html\r\n * Latest HDF5 library documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n\r\n**5 API Documentation**\r\n\r\n* Doxygen documentation: The project includes Doxygen markup in public headers for API documentation\r\n* The doxygen/ directory contains Doxygen build files for generating API documentation\r\n\r\n**6 CHANGELOG.md**\r\n\r\nThe release_docs/CHANGELOG.md file documents:\r\n\r\n * Changes from release to release\r\n * New features\r\n * Bug fixes\r\n * Known problems\r\n \r\nReference: release_docs/CHANGELOG.md URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project provides extensive basic documentation both in the repository (README, INSTALL files, CONTRIBUTING guide) and online (comprehensive API documentation and user guides).","documentation_interface_status":"Met","documentation_interface_justification":"The project provides comprehensive reference documentation describing the external interface (both input and output):\r\n\r\n**1 Doxygen-Documented Public API Headers**\r\n\r\nAll public API functions are documented with Doxygen markup in the public header files.\r\nThese include detailed descriptions of:\r\n\r\n * Input parameters: Each parameter is documented with \\param[in], \\param[out], or \\param[in,out] tags\r\n * Return values: Documented with \\return tags\r\n * Detailed descriptions: Comprehensive \\details sections explaining function behavior\r\n * Code examples: Many functions include \\par Example sections\r\n * Version information: \\since tags indicating when functions were introduced\r\n\r\n**2 Online Reference Documentation**\r\n\r\nThe README.md directs users to comprehensive online API reference documentation:\r\n\r\n * Latest HDF5 API Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * This is generated from the Doxygen markup in the source code\r\n\r\nReference: README.md#documentation\r\n\r\n**3 Complete API Coverage**\r\n\r\nPublic API headers covering all major functionality\r\n\r\n**4 Doxygen Build System**\r\n\r\nThe project includes a complete Doxygen build system in the doxygen/ directory for generating reference documentation from the annotated source code. URL: https://support.hdfgroup.org/documentation/hdf5/latest The project provides extensive reference documentation with detailed input/output specifications for all public API functions, both in the source code (Doxygen comments) and in published online documentation.","repo_public_status":"Met","repo_public_justification":"The project has a version-controlled source repository that is publicly readable with a URL:\r\n\r\n**1 Version Control System**\r\n\r\nThe project uses Git for version control:\r\n\r\n * The environment information shows: \"Is directory a git repo: Yes\"\r\n * Git commit history is available, showing recent commits with hashes (bd76ec789a, b986a34474, 5e2a73d542, etc.)\r\n\r\n**2 Publicly Readable Repository**\r\n\r\nThe repository is hosted on GitHub and is publicly accessible:\r\n\r\n * Repository URL: https://github.com/HDFGroup/hdf5\r\n * Clone URL: https://github.com/HDFGroup/hdf5.git\r\n * Anyone can read, browse, and clone the repository without authentication\r\n\r\nReference: README.md#getting-the-source-code states \"Development code is available at our Github location: https://github.com/HDFGroup/hdf5.git\" Reference: CONTRIBUTING.md#getting-the-source-code provides instructions: \"git clone https://github.com/HDFGroup/hdf5.git cd hdf5\"\r\n\r\n**3 Public Access to All Branches**\r\n\r\nMultiple branches are publicly accessible:\r\n\r\n * develop branch (main development branch)\r\n * Various release branches (hdf5_1_14, etc.)\r\n * All commit history is publicly visible\r\n\r\nReference: Git status shows \"Current branch: develop\" and \"Main branch (you will usually use this for PRs): develop\"\r\n\r\n**4 Web Interface**\r\n\r\nGitHub provides a web interface for browsing the repository:\r\n\r\n * Code browser: https://github.com/HDFGroup/hdf5\r\n * File viewing: Individual files can be accessed via URLs like https://github.com/HDFGroup/hdf5/blob/develop/README.md\r\n * Commit history: https://github.com/HDFGroup/hdf5/commits/develop\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project has a publicly readable Git repository hosted on GitHub with full version control history accessible to everyone.","repo_track_status":"Met","repo_track_justification":"The project's Git repository tracks what changes were made, who made the changes, and when the changes were made:\r\n\r\n**1 What Changes Were Made**\r\n\r\nGit tracks all file modifications, additions, and deletions:\r\n\r\n * Commit messages describe changes (e.g., \"Improved usage information (#6070)\", \"Minor optimizations of r-tree implementation (#6039)\")\r\n * Diff information shows exact code changes\r\n * Git log shows complete history of modifications\r\n\r\n**2 Who Made the Changes**\r\n\r\nGit tracks author information for every commit:\r\n\r\n * CONTRIBUTING.md references git log command to see commit authorship\r\n * Git commit format includes author name and email\r\n * CONTRIBUTING.md mentions checking authorship with: \"git log -1 --format='%an %ae'\"\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git states \"Before amending: ALWAYS check authorship (git log -1 --format='%an %ae')\"\r\n\r\n**3 When Changes Were Made**\r\n\r\nGit tracks timestamps for all commits:\r\n\r\n * Each commit has a timestamp\r\n * File listing shows modification dates (e.g., \"Nov 11 22:02\" for LICENSE file)\r\n * Git log shows the complete temporal history\r\n * CONTRIBUTING.md describes using git log to see recent commit history\r\n\r\nReference: The bash output showed \"Nov 11 22:02\" timestamp for the LICENSE file\r\n\r\n**4 Version Control Best Practices**\r\n\r\nThe project follows Git best practices:\r\n\r\n * Detailed commit messages with issue references (#6070, #6075, etc.)\r\n * Pull request workflow that preserves change history\r\n * Branch strategy documented in CONTRIBUTING.md\r\n * Co-authored commits supported (CONTRIBUTING.md shows \"Co-Authored-By: Claude noreply@anthropic.com\" format)\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git provides detailed Git workflow instructions\r\n\r\n**5 Public Access to History**\r\n\r\nAll change history is publicly accessible:\r\n\r\n * https://github.com/HDFGroup/hdf5/commits/develop\r\n * Each commit shows what changed, who made it, and when\r\n\r\nURL: https://github.com/HDFGroup/hdf5/commits/develop The Git repository fully tracks what changes were made (commit diffs and messages), who made them (author information), and when they were made (commit timestamps). Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"The project's source repository includes interim versions for review between releases, not only final releases:\r\n\r\n**1 Active Development Branch**\r\n\r\nThe repository has an active development branch with interim commits:\r\n\r\n* Current branch: develop\r\n* Recent interim commits visible:\r\n * bd76ec789a \"Improved usage information (#6070)\"\r\n * b986a34474 \"Bump the github-actions group with 6 updates (#6075)\"\r\n * 5e2a73d542 \"Minor optimizations of r-tree implementation (#6039)\"\r\n\r\nThese are work-in-progress commits, not final releases.\r\n\r\n**2 Pull Request Workflow**\r\n\r\nCONTRIBUTING.md describes a collaborative review process using pull requests:\r\n\r\n * \"Submit a pull request (PR)\"\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * \"Work with HDF Group developers to meet acceptance criteria\"\r\n\r\nThis workflow requires interim code to be visible in the repository for review before merging. Reference: CONTRIBUTING.md#contributing-changes\r\n\r\n3. Development Version in Repository\r\nREADME.md states:\r\n \"HDF5 version 2.0.1 currently under development\"\r\nThis shows the repository contains work-in-progress code, not just released versions.\r\n\r\n4. Development Snapshots\r\nThe project provides periodic development snapshots:\r\n\"Periodically development code snapshots are provided at the following URL: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\"\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n5. Branching Strategy for Collaboration\r\nCONTRIBUTING.md describes branching strategy enabling interim review:\r\n \"Target the develop branch for new features and bug fixes\"\r\n \"Small features: Develop in forks of the main repository\"\r\n \"Large collaborative work: Use feature branches named feature/\u003cfeature\u003e\"\r\nReference: CONTRIBUTING.md#branching-strategy\r\n\r\n6. Unmerged Work Visible\r\nThe git status shows numerous untracked and modified files, indicating ongoing development work:\r\n Multiple Makefile.in files\r\n Test files (a.out, object files)\r\n Patch files (hdf5_subfiling_mapping.patch, subfiling_mapping.patch, subfiling_mapping2.patch)\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The repository contains interim development versions on the develop branch and feature branches for collaborative review, not just final releases.","repo_distributed_status":"Met","repo_distributed_justification":"The project uses Git, a common distributed version control software:\r\n\r\n **1 Git Repository Confirmed**\r\n\r\nThe environment information confirms Git usage:\r\n * \"Is directory a git repo: Yes\"\r\n\r\n**2 Hosted on GitHub**\r\n\r\nThe repository is hosted on GitHub, which uses Git:\r\n\r\n * Repository URL: https://github.com/HDFGroup/hdf5\r\n * Clone URL: https://github.com/HDFGroup/hdf5.git\r\n\r\nReference: README.md#getting-the-source-code states \"Development code is available at our Github location: https://github.com/HDFGroup/hdf5.git\" Reference: CONTRIBUTING.md#getting-the-source-code provides Git clone instructions: \"git clone https://github.com/HDFGroup/hdf5.git cd hdf5\"\r\n\r\n**3 Git Prerequisites**\r\n\r\nCONTRIBUTING.md lists Git as a required tool:\r\n\r\n * \"Git: For version control.\"\r\n * \"If you are new to Git and GitHub, we encourage you to check out the GitHub tutorial\"\r\n\r\nReference: CONTRIBUTING.md#prerequisites\r\n\r\n**4 Git Workflow Documentation**\r\n\r\nCONTRIBUTING.md extensively documents Git workflows:\r\n\r\n * Git commit procedures\r\n * Git branch strategy (develop branch, feature branches)\r\n * Git commands for commits, status, diff, log, push\r\n * Pull request workflow using Git\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git and CONTRIBUTING.md#branching-strategy\r\n\r\n**5 Git Commit History**\r\n\r\nThe repository shows a typical Git commit history:\r\n\r\n * Commit hashes (bd76ec789a, b986a34474, etc.)\r\n * Git status shows branch information (\"Current branch: develop\")\r\n * Recent commits log available\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project uses Git, which is one of the most common distributed version control systems and is the de facto standard for modern software development.on GitHub, which uses git. Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The project uses unique version identifiers for each release:\r\n\r\n**1 Current Version Identifier**\r\n\r\nREADME.md shows the current development version:\r\n\r\n* \"HDF5 version 2.0.1 currently under development\"\r\n* This follows semantic versioning (major.minor.patch).\r\n\r\n**2 Release Version Examples**\r\n\r\nREADME.md references specific versioned releases:\r\n\r\n * \"hdf5 1.14 releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\"\r\n * Version 2.0.0 mentioned in release schedule table\r\n * Historical versions referenced: \"1.10.0-1.12.0\" in HISTORY files\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**3 Version Numbering System**\r\nREADME.md describes the versioning approach:\r\n\r\n * Major versions for significant changes (2.0.0)\r\n * Maintenance branches for each major.minor version\r\n * Release schedule shows specific version numbers\r\n\r\nReference: README.md#release-schedule states \"we aim to have at least one annual release for each maintenance branch\"\r\n\r\n**4 Branching by Version**\r\n\r\nCONTRIBUTING.md references version-specific branches:\r\n\r\n * \"hdf5_X_Y\" format for release support branches\r\n * \"hdf5_X_Y_Z\" format for release preparation branches\r\n * Example: \"hdf5_1_14\" branch\r\n\r\nReference: CONTRIBUTING.md mentions maintenance branches and release_docs/RELEASE_PROCESS.md references version-specific branches\r\n\r\n**5 Maven Artifact Versioning**\r\n\r\nREADME.md shows versioned Maven artifacts:\r\n\r\n * \"org.hdfgroup:hdf5-java\" with version identifiers\r\n * Snapshot versions with \"-SNAPSHOT\" suffix\r\n * Maven Central releases with specific versions\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**6 GitHub Releases**\r\n\r\nThe project uses GitHub releases with version tags:\r\n\r\n * Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Tagged releases for each version\r\n\r\nReference: README.md URL: https://github.com/HDFGroup/hdf5/releases Each release has a unique version identifier following the format major.minor.patch (e.g., 2.0.1, 1.14.x), ensuring users can identify and reference specific releases.","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"The project identifies releases within the version control system using tags:\r\n\r\n**1 GitHub Release Tags**\r\n\r\nREADME.md references GitHub releases with tags:\r\n\r\n * \"Periodically, development code snapshots are provided at the following URL: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\"\r\n\r\nThis shows the project uses Git tags for releases (the \"tag/snapshot\" URL pattern indicates Git tags). Reference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**2 Version-Specific Release Branches**\r\n\r\nThe project uses version-specific branches for releases:\r\n\r\n * \"hdf5_X_Y\" format for release support branches\r\n * \"hdf5_X_Y_Z\" format for release preparation branches\r\n * Example: \"hdf5_1_14\" branch for 1.14 releases\r\n\r\nReference: RELEASE_PROCESS.md and CONTRIBUTING.md mention version-specific branches\r\n\r\n**3 GitHub Releases Infrastructure**\r\n\r\nThe project uses GitHub's release system, which is built on Git tags:\r\n\r\n * https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Source packages available through GitHub releases\r\n * Each release on GitHub corresponds to a Git tag\r\n\r\n**4 Release Documentation Process**\r\n\r\nRELEASE_PROCESS.md describes the release workflow which includes version control system operations:\r\n\r\n * References to branches like \"hdf5_X_Y\" and \"hdf5_X_Y_Z\"\r\n * Mentions lifting code freeze on release branches\r\n * Describes version-specific branch management\r\n\r\nReference: release_docs/RELEASE_PROCESS.md\r\n\r\n**5 Maven Release Tags**\r\n\r\nThe project uses versioned releases for Maven artifacts:\r\n\r\n * Snapshot builds with version identifiers\r\n * Release workflows that create tagged versions\r\n\r\nReference: CONTRIBUTING.md mentions Maven snapshot and release builds URL: https://github.com/HDFGroup/hdf5/releases The project uses Git tags to identify releases, as evidenced by the GitHub releases system (which uses Git tags) and the documented release process with version-specific branches and tags.","release_notes_status":"Met","release_notes_justification":"The project provides human-readable release notes that are not raw version control logs:\r\n\r\n**1 CHANGELOG.md File**\r\n\r\nThe project maintains a comprehensive CHANGELOG.md file with curated release notes:\r\n\r\n * Located at: release_docs/CHANGELOG.md\r\n * Human-readable summaries organized by category\r\n * Not raw git log output, but structured documentation\r\n\r\nReference: README.md states \"See the CHANGELOG.md file in the release_docs/ directory for information specific to the features and updates included in this release of the library.\"\r\n\r\n**2 Well-Structured Release Notes**\r\n\r\nThe CHANGELOG.md includes:\r\n\r\n * Executive Summary with key highlights\r\n * Performance Enhancements (specific improvements like \"2500% faster\" Virtual Dataset operations)\r\n * Breaking Changes section (e.g., \"Updated default file format to 1.8\")\r\n * New Features \u0026 Improvements organized by category\r\n * Bug Fixes section\r\n * Support for new platforms\r\n * Platforms Tested\r\n * Known Problems\r\n\r\nThis format helps users determine whether to upgrade and understand the impact of the upgrade.\r\n\r\n**3 Release Note Format Requirements**\r\n\r\nCONTRIBUTING.md documents the release note format requirements:\r\n\r\n * \"Title/Problem - Problem description paragraph explaining the issue and conditions where it occurs\"\r\n * \"Solution paragraph describing what was done to resolve the issue and any functional impact or workarounds\"\r\n * When to write release notes: \"Required: User-visible changes in functionality or behavior\"\r\n * When not to write: \"Not required: Internal code changes, comments, or build process changes\"\r\n\r\nReference: CONTRIBUTING.md#release-notes\r\n\r\n4. Historical Release Notes\r\nThe project maintains release notes for older versions:\r\n HISTORY-1_10_0-1_12_0.txt for historical releases\r\n release.txt referenced for pre-2.0.0 releases\r\nReference: CHANGELOG.md states \"For releases prior to version 2.0.0, please see the release.txt file\"\r\n\r\n5. Upgrade Impact Information\r\nThe CHANGELOG provides clear upgrade impact guidance:\r\n Breaking changes clearly marked with warning symbol\r\n Compatibility issues documented (e.g., family driver changes)\r\n Migration guidance (e.g., CMake options replacing Autotools)\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/release_docs/CHANGELOG.md The project provides comprehensive, human-readable release notes in CHANGELOG.md that help users understand major changes and their upgrade impact, not raw version-control logs.","release_notes_vulns_status":"Met","release_notes_vulns_justification":"The release notes identify every publicly known run-time vulnerability fixed in releases with CVE assignments:\r\n\r\n**1 CVE Vulnerabilities Documented in CHANGELOG.md**\r\n\r\nThe current CHANGELOG.md for version 2.0.1 identifies multiple CVE fixes with detailed descriptions:\r\n\r\n* CVE-2025-7067 - Heap buffer overflow in H5FS__sinfo_serialize_node_cb()\r\n* CVE-2025-2915 - Heap-based buffer overflow in H5F__accum_free\r\n* CVE-2025-7068 - Resource leaks during metadata cache entry discard\r\n* CVE-2025-6816, CVE-2025-6818, CVE-2025-6856, CVE-2025-2923 - Corrupted object header issues\r\n* CVE-2025-6750 - Heap buffer overflow in mtime message decoding\r\n* CVE-2025-6269 - Security vulnerabilities in H5C__reconstruct_cache_entry()\r\n* CVE-2025-2153 - Message flags field modification issue\r\n* CVE-2025-2925 - Double-free vulnerability in H5C__load_entry()\r\n\r\nReference: release_docs/CHANGELOG.md Bug Fixes section\r\n\r\n**2 CVE Information Includes Links**\r\n\r\nMany CVE entries include direct links to the National Vulnerability Database:\r\n\r\n * Example: CVE-2025-2915\r\n * Example: CVE-2025-7068\r\n\r\n3. CVEs in Historical Release Notes\r\n\r\nHistorical release documentation also identifies CVEs:\r\n\r\n* HISTORY-1_12_0-1_14_0.txt documents CVE-2019-8396, CVE-2021-37501, CVE-2018-13867, CVE-2021-46244, and many others\r\n* HISTORY-1_10_0-1_12_0.txt documents CVE-2018-11202, CVE-2018-11203, CVE-2018-11204, and others\r\n* HISTORY-1_14_0-2_0_0.txt documents numerous CVEs from 2023-2024\r\n\r\n**4 GitHub Issue References**\r\n\r\nEach CVE fix includes references to the specific GitHub issues:\r\n\r\n * Example: \"Fixes GitHub issue #5577\" for CVE-2025-7067\r\n * Example: \"Fixes GitHub issue #5380\" for CVE-2025-2915\r\n\r\n**5 CVE Regression Testing**\r\n\r\n* README.md shows active CVE regression testing:\r\n* \"CVE regression\" CI badge indicating continuous testing for CVE vulnerabilities\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/release_docs/CHANGELOG.md The project consistently identifies all publicly known vulnerabilities with CVE assignments in their release notes, with detailed descriptions, links to CVE databases, and references to GitHub issues.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"The project uses GitHub Issues as an issue tracker for tracking individual issues:\r\n\r\n**1 GitHub Issues Used for Issue Tracking**\r\n\r\nThe project uses GitHub's built-in issue tracker:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states: \"1. Open a GitHub issue (HDF5 Issues) - Required unless the change is minor (e.g., typo fix). - Describe the problem or feature request clearly.\"\r\n\r\n**2 Individual Issue Tracking**\r\n\r\nEach bug report and feature request gets its own individual issue with:\r\n\r\n * Unique issue number (e.g., #5577, #5380, #5578)\r\n * Individual URL for each issue\r\n * Status tracking (open/closed)\r\n * Labels and assignments\r\n\r\nReference: CHANGELOG.md references specific GitHub issues.\r\n\r\n**3 Pull Requests Reference Issues**\r\n\r\nCONTRIBUTING.md requires pull requests to reference issues:\r\n\r\n * \"Make sure to include the issue that the PR addresses in the description\"\r\n\r\nThis creates traceability between code changes and individual issues. Reference: CONTRIBUTING.md#contributing-changes\r\n\r\n**4 Evidence of Active Issue Tracking**\r\n\r\nRecent commits reference issue numbers:\r\n\r\n* \"#6070\" in commit \"Improved usage information (#6070)\"\r\n* \"#6075\" in commit \"Bump the github-actions group with 6 updates (#6075)\"\r\n\" #6039\" in commit \"Minor optimizations of r-tree implementation (#6039)\"\r\n\r\n**5 Issue Tracker Features**\r\n\r\nGitHub Issues provides:\r\n\r\n * Individual issue URLs (e.g., https://github.com/HDFGroup/hdf5/issues/5577)\r\n * Search functionality\r\n * Labels and milestones\r\n * Assignment to developers\r\n * Discussion threads\r\n * Status tracking\r\n\r\nURL: https://github.com/HDFGroup/hdf5/issues The project actively uses GitHub Issues as an issue tracker for tracking individual bugs, feature requests, and security vulnerabilities.","report_process_status":"Met","report_process_justification":"The project provides multiple processes for users to submit bug reports:\r\n\r\n**1 GitHub Issues (Primary Bug Reporting Mechanism)**\r\n\r\nThe project uses GitHub Issues as the primary bug reporting system:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states: \"1. Open a GitHub issue (HDF5 Issues) - Required unless the change is minor (e.g., typo fix). - Describe the problem or feature request clearly.\"\r\nReference: README.md#help-and-support mentions GitHub Issues as a reporting mechanism\r\n\r\n**2 Help Desk**\r\n\r\nThe HDF Group provides a free Help Desk for bug reports and support:\r\n\r\n * URL: https://help.hdfgroup.org\r\n\r\nReference: README.md#help-and-support states: \"The HDF Group staffs a free Help Desk accessible at https://help.hdfgroup.org and also monitors the Forum. Our free support service is community-based and handled as time allows.\"\r\n\r\n**3 HDF Forum**\r\n\r\nUsers can report bugs and discuss issues on the HDF Forum:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n\r\nReference: README.md#forum-and-news states: \"The HDF Forum is provided for public announcements, technical questions, and discussions of interest to the general HDF5 Community.\"\r\n\r\n**4 Issue Tracker is Searchable and Public**\r\n\r\nThe GitHub issue tracker is:\r\n\r\n * Publicly accessible\r\n * Searchable\r\n * Does not require proprietary software\r\n * Allows new users to participate\r\n\r\nReference: CONTRIBUTING.md confirms GitHub Issues are used for bug reports and feature requests\r\n\r\n**5 Bug Report Requirements**\r\n\r\nCONTRIBUTING.md describes when to open issues:\r\n\r\n * \"Required unless the change is minor (e.g., typo fix)\"\r\n * \"Describe the problem or feature request clearly\"\r\n\r\nURL: https://github.com/HDFGroup/hdf5/issues The project provides a clear process for users to submit bug reports through GitHub Issues (primary), Help Desk, and the HDF Forum.","report_responses_status":"Met","report_responses_justification":"The project has a triage procedure for issues as they come in:\r\n\r\n**1 GitHub Project for Triage**\r\n\r\nThe project uses GitHub Projects for issue triage:\r\n\r\n * URL: https://github.com/orgs/HDFGroup/projects/39\r\n\r\nThis is the project management board where issues are triaged and tracked.\r\n\r\n**2 Release Progress Tracking**\r\n\r\nREADME.md references this project board:\r\n\r\n * \"Release Progress\" badge links to: https://github.com/orgs/HDFGroup/projects/39/views/24\r\n * The badge shows current progress of release-blocking issues\r\n\r\nReference: README.md#release-progress states: \"The badge above shows the current progress of release-blocking issues with colors that reflect completion status\" \"Click the badge to view the detailed project board with current release-blocking issues.\"\r\n\r\n**3 Active Project Management**\r\n\r\nThe project board indicates:\r\n\r\n * Issues are categorized and tracked\r\n * Release-blocking issues are identified\r\n * Progress is monitored with completion percentages\r\n * Multiple views available (view/24 suggests different perspectives on the same issues)\r\n\r\n**4 Organizational Structure**\r\n\r\nThe project board is at the organization level (orgs/HDFGroup/projects/39):\r\n\r\n * Centralized issue management\r\n * Visible to the community\r\n * Integrated with GitHub Issues workflow\r\n\r\n**5 Triage Indicators**\r\n\r\nThe existence of this project board suggests:\r\n\r\n * Issues are reviewed and categorized as they come in\r\n * Release-blocking vs non-blocking issues are identified\r\n * Priority and status are tracked\r\n * Progress is publicly visible\r\n\r\nURL: https://github.com/orgs/HDFGroup/projects/39 The project has an active triage procedure using GitHub Projects (project #39) to manage and categorize issues as they are submitted.","enhancement_responses_status":"Met","enhancement_responses_justification":"Enhancement requests are responded to through a weekly triage procedure:\r\n\r\n**1 Weekly Triage Procedure**\r\n\r\n Enhancement requests are responded to weekly through the triage procedure using the GitHub Projects board:\r\n\r\n * URL: https://github.com/orgs/HDFGroup/projects/39\r\n\r\nThis ensures regular review and response to incoming enhancement requests.","report_archive_status":"Met","report_archive_justification":"The project has publicly available archives for reports and responses that are searchable:\r\n\r\n**1 GitHub Issues Archive**\r\n\r\nGitHub Issues provides a permanent, publicly searchable archive:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n * All issues (open and closed) are archived\r\n * Searchable by keyword, label, date, author, etc.\r\n * Includes all comments and responses\r\n * Accessible without authentication for reading\r\n\r\nReference: CONTRIBUTING.md states \"Open a GitHub issue (https://github.com/HDFGroup/hdf5/issues)\"\r\n\r\n**2 GitHub Pull Requests Archive**\r\n\r\nPull requests and their discussions are archived:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/pulls\r\n * Searchable history of all pull requests\r\n * Includes code review comments and discussions\r\n * Linked to related issues\r\n\r\n**3 HDF Forum Archive**\r\n\r\nThe HDF Forum provides searchable archives:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n\r\nReference: README.md#forum-and-news states: \"These forums are provided as an open and public service for searching and reading.\"\r\n\r\n**4 Permanent Record in Git History**\r\n\r\nAll changes and their associated discussions are permanently recorded:\r\n\r\n * Commit messages reference issues (e.g., \"#5577\", \"#5380\")\r\n * Git history: https://github.com/HDFGroup/hdf5/commits/develop\r\n * Publicly accessible and searchable\r\n \r\n**5 CHANGELOG and Historical Documentation**\r\n\r\nRelease notes archive historical issues:\r\n\r\n * CHANGELOG.md archives bug fixes and enhancements\r\n * HISTORY-*.txt files contain historical issue records\r\n * References to GitHub issues and CVE numbers\r\n\r\nReference: release_docs/CHANGELOG.md contains archived issue references URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nThe project maintains publicly available, searchable archives for bug reports and responses through GitHub Issues, Pull Requests, the HDF Forum, and documentation files.","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"The project publishes the process for reporting vulnerabilities on the project site:\r\n\r\n**1 SECURITY.md File in Repository**\r\n\r\nThe project has a SECURITY.md file in the repository root that documents the vulnerability reporting process:\r\n\r\n * File location: /SECURITY.md\r\n * Publicly accessible in the repository\r\n \r\n**2 Vulnerability Reporting Process Documented**\r\n\r\nSECURITY.md clearly describes how to report vulnerabilities:\r\n\r\n * \"If you have discovered a security vulnerability in this project, please report it privately.\"\r\n * \"Do not disclose it as a public issue.\"\r\n * Provides rationale: \"This gives us time to work with you to fix the issue before public exposure\"\r\n\r\n**3 Reporting Mechanism Specified**\r\n\r\nThe document provides the specific method for reporting:\r\n\r\n * \"Please disclose it at security advisory\"\r\n * URL: https://github.com/HDFGroup/hdf5/security/advisories/new\r\n\r\nThis uses GitHub's private security advisory feature.\r\n\r\n**4 Supported Versions Documented**\r\n\r\nSECURITY.md specifies which versions receive security updates:\r\n\r\n * \"Security updates are applied only to the latest release.\"\r\n\r\nThis helps reporters understand which versions are supported.\r\n\r\n**5 GitHub Security Advisory Integration**\r\n\r\nGitHub automatically surfaces SECURITY.md to users:\r\n\r\n * Visible in the repository's \"Security\" tab\r\n * Linked from GitHub's security reporting interface\r\n * Standard location for security policies\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/SECURITY.md \r\nThe project publishes its vulnerability reporting process in SECURITY.md, instructing users to report vulnerabilities privately via GitHub Security Advisories at https://github.com/HDFGroup/hdf5/security/advisories/new.","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"The SECURITY.md file specifies how to send vulnerability information privately:\r\n\r\n**1 Private Reporting Method Specified**\r\nSECURITY.md states:\r\n * \"If you have discovered a security vulnerability in this project, please report it privately.\"\r\n * \"Do not disclose it as a public issue.\"\r\n * \"Please disclose it at security advisory\"\r\nURL provided: https://github.com/HDFGroup/hdf5/security/advisories/new\r\n\r\n**2 GitHub Security Advisories Keep Reports Private**\r\n\r\nThe specified method (GitHub Security Advisories) is a private reporting channel:\r\n\r\n * Reports submitted through this URL are private by default\r\n * Only visible to project maintainers\r\n * Not disclosed publicly until a fix is ready\r\n * Explanation Provided\r\n\r\nSECURITY.md explains why private reporting is important:\r\n * \"This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.\"\r\n\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/SECURITY.md \r\nThe project includes instructions for sending vulnerability information privately via GitHub Security Advisories at https://github.com/HDFGroup/hdf5/security/advisories/new.","vulnerability_report_response_status":"Unmet","vulnerability_report_response_justification":"There is no current procedure in place to meet this requirement. It is under advisement to add one.","build_status":"Met","build_justification":"The project provides a working build system that automatically rebuilds the software from source code:\r\n\r\n**1 CMake Build System**\r\n\r\nThe project uses CMake as its build system:\r\n\r\n * CMake minimum version: 3.26\r\n * Supports automated building from source\r\n\r\nReference: CONTRIBUTING.md#building-for-development states: \"CMake is the required build system for all platforms\" Reference: CHANGELOG.md states: \"CMake minimum version is now 3.26\"\r\n\r\n**2 Build Instructions Provided**\r\n\r\nCONTRIBUTING.md provides clear build instructions.\r\n\r\n**3 Installation Documentation**\r\n\r\nREADME.md and release_docs/ directory contain build documentation:\r\n\r\n * INSTALL - General compilation and installation instructions\r\n * INSTALL_CMAKE - CMake-specific build instructions\r\n * Platform-specific instructions (INSTALL_Windows, INSTALL_Cygwin)\r\n\r\nReference: README.md#documentation\r\n\r\n**4 Automated CI/CD Builds**\r\n\r\nThe project has automated builds in CI/CD:\r\n\r\n * Multiple CI workflows shown in README.md badges\r\n * Daily builds\r\n * Platform-specific builds (Linux, Windows, macOS)\r\n \r\n**5 CMake-Only Since 2025**\r\n\r\nREADME.md confirms:\r\n\r\n * \"Starting with HDF5 2.0, only the CMake build system is supported.\"\r\n * Autotools was removed March 10, 2025\r\n\r\nThe project provides CMake as a working build system that automatically rebuilds the software from source code.","build_common_tools_status":"Met","build_common_tools_justification":"The project uses CMake, which is a common and widely used build tool:\r\n\r\n**1 CMake is a Common Build Tool**\r\n\r\nCMake is one of the most widely-used cross-platform build systems:\r\n\r\n * Industry standard for C/C++ projects\r\n * Used by thousands of open-source and commercial projects\r\n * Supported on all major platforms (Linux, Windows, macOS)\r\n\r\n**2 Required Build Tool**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"CMake is required\"\r\n * \"CMake is the required build system for all platforms\"\r\n\r\nThe project uses CMake, a common and widely adopted build tool.","build_floss_tools_status":"Met","build_floss_tools_justification":"The project can be built using only FLOSS (Free/Libre and Open Source Software) tools:\r\n\r\n**1 Build System - CMake**\r\n\r\nCMake is FLOSS:\r\n\r\n * License: BSD 3-Clause\r\n * Open source and freely available\r\n\r\n**2 Compilers - GCC and Clang**\r\n\r\nThe project supports FLOSS compilers:\r\n\r\n * GCC (GNU Compiler Collection) - GPL licensed\r\n * Clang/LLVM - Apache 2.0/NCSA licensed\r\n \r\nBoth are fully open source\r\nNote: MSVC (Microsoft Visual C++) is also supported on Windows, but is not required. Reference: CONTRIBUTING.md states \"A C11-compatible C compiler (MSVC on Windows is supported)\" - indicating MSVC is optional, not required.\r\n\r\n**3 Version Control - Git**\r\n\r\nGit is FLOSS:\r\n\r\n * License: GPL v2\r\n * Open source\r\n\r\n**4 Other Required Tools are FLOSS**\r\n\r\nCONTRIBUTING.md lists required tools, all FLOSS:\r\n * Perl - Artistic License/GPL\r\n * Make (Unix Makefiles) - GPL (For older versions of HDF5)\r\n\r\n**5 Recommended Tools are FLOSS**\r\n\r\nAll recommended tools are FLOSS:\r\n\r\n * clang-format - Apache 2.0/NCSA\r\n * Doxygen - GPL\r\n * codespell - GPL\r\n\r\nThe project can be built entirely using FLOSS tools (CMake, GCC/Clang, Git, Perl, Make) without requiring any proprietary software.","test_status":"Met","test_justification":"**1 Automated Test Suite Exists**\r\n\r\nThe project has test suites in the repository:\r\n\r\n * test/ directory - C library tests\r\n * testpar/ directory - Parallel C library tests\r\n * c++/test/ - C++ wrapper tests\r\n * fortran/test/ - Fortran wrapper tests\r\n\r\n**2 Test Suite is FLOSS**\r\n\r\nThe test suite is part of the HDF5 repository:\r\n\r\n * Licensed under BSD 3-Clause (same as main project)\r\n * Publicly available in the repository\r\n\r\n**3 Documentation on Running Tests**\r\n\r\nCONTRIBUTING.md documents testing:\r\n\r\n * \"Build and test thoroughly\"\r\n * \"Ensure all tests pass\"\r\n * \"All new functionality and bug fixes must include tests\"\r\n * Test structure documented with examples using h5test.h macros\r\n\r\nReference: CONTRIBUTING.md#testing\r\n\r\n**4 CI System Shows Test Execution**\r\n\r\n README.md shows active CI with automated tests:\r\n * Multiple CI badges indicating automated testing\r\n * Daily builds with tests\r\n * Platform-specific test runs\r\n\r\n**5 CMake Test Integration**\r\n\r\nTests run via CMake:\r\n\r\n * CMakeLists.txt files in test directories\r\n * Standard CMake test commands (ctest)\r\n\r\nThe project uses automated test suites (in test/ and testpar/ directories) that are FLOSS-licensed and documented in CONTRIBUTING.md, with execution shown via CI badges in README.md.","test_invocation_status":"Met","test_invocation_justification":"The project uses CMake with CTest, which is the standard way to invoke tests for CMake-based C/C++ projects:\r\n\r\n * Standard command: ctest or make test\r\n * CMakeLists.txt files in test directories configure tests\r\n * Standard CMake test infrastructure\r\n\r\nReference: CONTRIBUTING.md mentions \"Ensure tests run and pass under CMake\" and \"Update CMakeLists.txt in the test/ directory\" The test suite is invocable using standard CMake/CTest commands.","test_most_status":"Met","test_most_justification":"Minimum automated testing is performed on branches, as features, bug fixes, and enhancements are derived from forks rather than the central HDF5 repository. Branches associated with releases are tested automatically.\r\n\r\n**1 Coverage Reporting to CDash**\r\n\r\nREADME.md provides link to coverage results:\r\n\r\n* \"HPC configure/build/test results\" at https://my.cdash.org/index.php?project=HDF5\r\n* CDash provides centralized test and coverage reporting\r\n* Public visibility of coverage metrics\r\n\r\n**2 Automated Coverage Analysis**\r\n\r\n.github/workflows/analysis.yml runs coverage testing:\r\n\r\n* Coverage test job: \"Ubuntu GCC Coverage\"\r\n* Uses lcov for coverage collection\r\n* DHDF5_ENABLE_COVERAGE:BOOL=ON\r\n* CODE_COVERAGE:BOOL=ON\r\n* Automated coverage generation and reporting\r\n\r\n**3 Code Coverage Infrastructure**\r\n\r\nconfig/sanitizer/code-coverage.cmake provides coverage support:\r\n\r\n* GCC/LCOV support\r\n* Clang/llvm-cov support\r\n* Multiple coverage targets for different granularity\r\n* HTML coverage reports generated\r\n\r\nReference: config/sanitizer/README.md documents extensive code coverage capabilities\r\n\r\n**4 Extensive Test Suite**\r\n\r\nThe project has comprehensive tests across multiple directories:\r\n\r\n* test/ - C library tests\r\n* testpar/ - Parallel C library tests\r\n* c++/test/ - C++ wrapper tests\r\n* fortran/test/ - Fortran wrapper tests\r\n* tools/test/ - Command-line tools tests\r\n\r\n**5 Test Policy Requires Tests for New Code**\r\n\r\nCONTRIBUTING.md mandates:\r\n\r\n* \"All new functionality and bug fixes must include tests\"\r\n* Ensures ongoing coverage improvement\r\n* Tests must be added for all code changes\r\n\r\n**6 Multiple Sanitizers Provide Branch Coverage**\r\n\r\n.github/workflows/analysis.yml runs multiple sanitizers:\r\n\r\n* AddressSanitizer\r\n* LeakSanitizer\r\n* UndefinedBehaviorSanitizer\r\n\r\nThese dynamic analysis tools exercise code paths to detect issues and provide functional coverage verification.\r\n\r\n**7 CVE Regression Tests**\r\n\r\nREADME.md shows CVE regression testing:\r\n\r\n* Tests for previously fixed vulnerabilities\r\n* Ensures critical code paths are covered\r\n* Validates security-sensitive functionality\r\n\r\n**8 OSS-Fuzz for Input Coverage**\r\n\r\nOSS-Fuzz integration provides:\r\n\r\n* Automated fuzzing of input handling code\r\n* Explores different input combinations\r\n* Discovers edge cases and boundary conditions\r\n\r\nThe project has comprehensive test coverage tracked through CDash, with automated coverage analysis in CI/CD, extensive test suites across all components, and mandatory testing requirements for new code.","test_policy_status":"Met","test_policy_justification":"CONTRIBUTING.md explicitly states the policy:\r\n\r\n * \"All new functionality and bug fixes must include tests.\"\r\n\r\nThis is a clear, mandatory policy requiring tests for new functionality. Reference: CONTRIBUTING.md#adding-new-tests states:\r\n\r\n * \"All new functionality and bug fixes must include tests.\"\r\n * \"Add tests to existing test files when appropriate.\"\r\n * \"Create new test programs using h5test.h macros.\"\r\n\r\nThe project has a formal policy requiring tests for all new functionality.","tests_are_added_status":"Met","tests_are_added_justification":"**1 Recent Major Changes Include Tests**\r\n\r\nThe CHANGELOG.md for version 2.0.1 documents extensive major changes with corresponding test evidence:\r\n\r\n * Bug fixes reference GitHub issues that include test cases\r\n * Security fixes (CVEs) have regression tests\r\n * CI badge shows \"CVE regression\" testing\r\n\r\n**2 CVE Regression Testing**\r\n\r\nREADME.md shows active CVE regression testing:\r\n\r\n * CVE regression CI badge indicates automated testing of security fixes\r\n * Multiple CVEs fixed in recent release with tests\r\n\r\n**3 Test Requirements Enforced in CI**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * CI system validates that tests pass before merging\r\n\r\n**4 Maven Testing for Java Changes**\r\n\r\nRecent major Java enhancements include comprehensive testing:\r\n\r\n * \"Complete Java examples Maven integration with cross-platform CI/CD testing\"\r\n * Maven artifact validation scripts\r\n * Multi-platform testing workflows\r\n\r\nReference: CHANGELOG.md#java-enhancements\r\n\r\n**5 Pull Request References Show Test Integration**\r\n\r\nRecent commits reference pull requests (#6070, #6075, #6039, #6049, #6066), which go through CI testing before merge. The project demonstrates adherence to its test policy through CI enforcement, CVE regression testing, and documented test requirements for recent major changes.","tests_documented_added_status":"Met","tests_documented_added_justification":"CONTRIBUTING.md documents the test policy in the instructions for change proposals:\r\n\r\n**1 In the Workflow Section**\r\n\r\nStep 3 under \"Make your changes\":\r\n * \"Add tests for new functionality or bug fixes.\"\r\n\r\n**2 In the Adding New Tests Section**\r\n\r\nExplicit documentation:\r\n * \"All new functionality and bug fixes must include tests.\"\r\n\r\n**3 In the Checklist for Contributors**\r\n\r\nTesting checklist item:\r\n\r\n * \"Pull request includes tests.\"\r\n\r\n**4 In the Acceptance Criteria Section**\r\n\r\nTesting requirement for pull request acceptance:\r\n\r\n * \"Testing: Must pass HDF5 regression testing and include appropriate tests.\"\r\n\r\nReference: CONTRIBUTING.md#contributing-changes, CONTRIBUTING.md#adding-new-tests, and CONTRIBUTING.md#checklist-for-contributors The test policy is documented in multiple sections of CONTRIBUTING.md where change proposals and pull requests are described.","warnings_status":"Met","warnings_justification":"**1 Compiler Warning Flags Enabled**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"The CI system builds with -Werror\"\r\n * \"HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\" option available for extra warnings\r\n * \"fix all compiler warnings before submitting pull requests\"\r\n\r\n**2 Developer Mode Warnings**\r\n\r\nCONTRIBUTING.md documents developer build options:\r\n * \"HDF5_ENABLE_DEVELOPER_MODE=ON\" enables \"warnings as errors\"\r\n * \"Developer Warnings: Enable extra warnings with HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\"\r\n\r\n**3 Linter Tool - clang-format**\r\n\r\nCONTRIBUTING.md lists clang-format as a recommended tool:\r\n\r\n * \"clang-format: For code formatting. The CI system will automatically format pull requests if needed.\"\r\n\r\n**4 CI Enforcement**\r\n\r\nThe CI system enforces code quality:\r\n\r\n * Builds with -Werror (warnings treated as errors)\r\n * Automatic code formatting\r\n * Must pass before pull request acceptance\r\n\r\nReference: CONTRIBUTING.md#prerequisites and CONTRIBUTING.md#developer-build-tips The project enables compiler warning flags (-Werror), uses clang-format for linting, and enforces these in CI.","warnings_fixed_status":"Met","warnings_fixed_justification":"CONTRIBUTING.md explicitly requires addressing warnings:\r\n\r\n * \"The CI system builds with -Werror, so fix all compiler warnings before submitting pull requests.\"\r\n\r\nThis policy ensures:\r\n\r\n * Warnings are treated as errors in CI builds\r\n * All warnings must be fixed before code can be merged\r\n * Pull requests cannot be accepted with warnings\r\n\r\nReference: CONTRIBUTING.md#developer-build-tips The project requires all compiler warnings to be addressed before pull request submission.","warnings_strict_status":"Met","warnings_strict_justification":"CONTRIBUTING.md shows the project is maximally strict with warnings:\r\n\r\n**1 Warnings as Errors Required**\r\n\r\n * \"The CI system builds with -Werror\" (treats all warnings as errors)\r\n * Mandatory for all pull requests\r\n\r\n**2 Additional Developer Warnings Available**\r\n * \"HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\" enables extra warnings\r\n * \"generates significant output but can be useful\"\r\n\r\n**3 Developer Mode Strictness**\r\n * \"HDF5_ENABLE_DEVELOPER_MODE=ON\" enables \"warnings as errors\"\r\n * Recommended for development builds\r\n\r\nReference: CONTRIBUTING.md#developer-build-tips The project uses the strictest possible warning level with -Werror in CI and optional extra warnings for developers.","know_secure_design_status":"Met","know_secure_design_justification":"Evidence that primary developers understand secure software design principles:\r\n\r\n**1 Economy of Mechanism**\r\n\r\nCONTRIBUTING.md enforces simplicity:\r\n\r\n * \"Avoid over-engineering. Only make changes that are directly requested or clearly necessary.\"\r\n * \"Don't create helpers, utilities, or abstractions for one-time operations.\"\r\n * \"The right amount of complexity is the minimum needed for the current task\"\r\n\r\n**2 Fail-Safe Defaults**\r\n\r\nSecurity fixes show fail-safe approach:\r\n\r\n * CVE-2025-2915: \"Added validation in H5O__mdci_decode to detect and reject invalid values early\"\r\n * CVE-2025-6750: \"allow invalid message size to be detected\"\r\n * Default error handling with HGOTO_ERROR macro\r\n\r\n**3 Complete Mediation**\r\n\r\nCONTRIBUTING.md shows validation practices:\r\n\r\n * \"Always check return values of functions that can fail\"\r\n * Function structure includes parameter checks: \"HDassert(/parameter check/)\"\r\n\r\n**4 Open Design**\r\n\r\nThe project is fully open source:\r\n\r\n * All security mechanisms in public repository\r\n * Security fixes documented in CHANGELOG.md\r\n * No security through obscurity\r\n\r\n**5 Least Privilege**\r\n\r\nCONTRIBUTING.md describes function visibility levels:\r\n\r\n * Public, Private, and Package scopes\r\n * \"Package: Used only within the defining package\"\r\n * Minimizes exposure of internal APIs\r\n\r\n**6 Input Validation with Allowlists**\r\n\r\nMultiple CVE fixes demonstrate input validation:\r\n\r\n * CVE-2025-2915: \"Added validation...to detect and reject invalid values early, preventing the overflow condition\"\r\n * CVE-2025-6816 series: \"checking the expected number of object header chunks against the actual value\"\r\n * CVE-2025-2925: \"checks for an image buffer length of 0 before calling H5MM_realloc\"\r\n * \"Check for overflow in decoded heap block addresses\"\r\n\r\n**7 Limited Attack Surface**\r\n\r\nCONTRIBUTING.md enforces minimalism:\r\n\r\n * Three-tier API (Public/Private/Package) limits attack surface\r\n * \"Don't add features...beyond what was asked\"\r\n\r\n**8 OWASP Awareness**\r\n\r\nCONTRIBUTING.md explicitly mentions security:\r\n\r\n * \"Be careful not to introduce security vulnerabilities such as command injection, XSS, SQL injection, and other OWASP top 10 vulnerabilities.\"\r\n\r\n**9 Professional Security Practices**\r\n\r\n * Private vulnerability disclosure (SECURITY.md)\r\n * CVE regression testing\r\n * 15+ CVEs fixed in recent release with detailed technical understanding\r\n * Bounds checking, input validation, safe cleanup practices\r\n\r\nThe project demonstrates knowledge of secure design principles through documented policies, extensive security fixes showing deep understanding, and explicit security requirements in the contribution guidelines.","know_common_errors_status":"Met","know_common_errors_justification":"Evidence that primary developers know common vulnerability types and mitigations:\r\n\r\n**1 Buffer Overflows - Known and Mitigated**\r\n\r\nMultiple CVE fixes demonstrate understanding:\r\n\r\n * CVE-2025-7067: \"Fixed a heap buffer overflow in H5FS__sinfo_serialize_node_cb()\" - Mitigation: \"discarding file free space sections...when they are found to be invalid\"\r\n * CVE-2025-2915: \"Fixed a heap-based buffer overflow...caused by an integer overflow\" - Mitigation: \"Added validation...to detect and reject invalid values early\"\r\n * CVE-2025-6750: \"A heap buffer overflow occurred because an mtime message was not properly decoded\" - Mitigation: \"decoding old and new mtime messages which will allow invalid message size to be detected\"\r\n\r\n**2 Integer Overflows - Known and Mitigated**\r\n\r\n * CVE-2025-2915: \"integer overflow when calculating new_accum_size\" - Mitigation: validation to prevent overflow\r\n * \"Check for overflow in decoded heap block addresses\" - Mitigation: \"added a check in H5HL__fl_deserialize to ensure no overflow can occur\"\r\n\r\n**3 Memory Leaks and Resource Management - Known and Mitigated**\r\n\r\n * CVE-2025-7068: \"could cause the library to skip calling the callback to free the cache entry. This could result in resource leaks\" - Mitigation: \"attempting to fully free a cache entry before signalling that an error has occurred\"\r\n * CVE-2025-6269: \"memory leaks\" - Mitigation: \"safe cleanup\"\r\n\r\n**4 Double-Free Vulnerabilities - Known and Mitigated**\r\n\r\n * CVE-2025-2925: \"it was freed again in done, causing a double-free vulnerability\" - Mitigation: \"H5C__load_entry() now checks for an image buffer length of 0 before calling H5MM_realloc\"\r\n\r\n**5 Stack Overflows - Known and Mitigated**\r\n\r\n * CVE-2025-6857: \"An HDF5 file had a corrupted v1 B-tree that would result in a stack overflow\" - Mitigation: \"additional integrity checks\"\r\n\r\n**6 Input Validation Failures - Known and Mitigated**\r\n\r\n * CVE-2025-2913, CVE-2025-2926: \"The size of a continuation message was decoded as 0, causing multiple vulnerabilities\" - Mitigation: \"An error check was added to return failure to prevent further processing of invalid data\"\r\n * CVE-2025-6816 series: \"corrupted object header with a continuation message that points back to itself\" - Mitigation: \"checking the expected number of object header chunks against the actual value\"\r\n\r\n**7 OWASP Top 10 Awareness**\r\n\r\nCONTRIBUTING.md explicitly requires:\r\n\r\n * \"Be careful not to introduce security vulnerabilities such as command injection, XSS, SQL injection, and other OWASP top 10 vulnerabilities.\"\r\n\r\n**8 Bounds Checking**\r\n\r\n * CVE-2025-6269: \"buffer overflows\" - Mitigation: \"bounds checks, input validation\"\r\n\r\n**9 Common Mitigation Techniques Used**\r\n\r\n * Early validation and rejection of invalid input\r\n * Bounds checking before operations\r\n * Safe cleanup and error handling\r\n * Integer overflow detection\r\n * Resource leak prevention\r\n\r\nThe project demonstrates comprehensive knowledge of common vulnerability types (buffer overflows, integer overflows, memory leaks, double-frees, stack overflows) and proper mitigation techniques through extensive CVE remediation and explicit security requirements.","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"The project uses delivery mechanisms that counter MITM attacks:\r\n\r\n**1 HTTPS for Downloads**\r\n\r\nAll download URLs use HTTPS:\r\n\r\n * https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n * https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n * https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n\r\n**2 HTTPS for Git Repository**\r\n\r\nSource code repository uses HTTPS:\r\n\r\n * https://github.com/HDFGroup/hdf5.git\r\n\r\nGit also supports SSH:\r\n\r\n * git@github.com:HDFGroup/hdf5.git\r\n\r\n**3 HTTPS for Maven Artifacts**\r\n\r\nMaven package repository uses HTTPS:\r\n\r\n * https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\n**4 All Project URLs Use HTTPS**\r\n\r\nPreviously verified that all project sites use HTTPS:\r\n\r\n * Website: https://www.hdfgroup.org/\r\n * Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md and earlier analysis The project uses HTTPS for all delivery mechanisms (downloads, Git repository, Maven artifacts), which counters MITM attacks.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"**1 No HTTP Hash Retrieval Found**\r\n\r\n**2 All Downloads Use HTTPS**\r\n\r\nExternal downloads in CI workflows use HTTPS, not HTTP\r\n\r\n**3 HTTP Timestamp Server Not Hash Retrieval**\r\n\r\nThe only HTTP usage is:\r\n\r\n * ctest.yml line 190: timestamp-rfc3161: http://timestamp.acs.microsoft.com\r\n * This is for code signing timestamp, not retrieving cryptographic hashes\r\n\r\nThe project does NOT retrieve cryptographic hashes over HTTP.","vulnerabilities_fixed_60_days_status":"Unmet","vulnerabilities_critical_fixed_status":"?","static_analysis_status":"Unmet","static_analysis_common_vulnerabilities_status":"Unmet","static_analysis_fixed_status":"Unmet","static_analysis_often_status":"Unmet","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Evidence that dynamic analysis tools are applied before major production releases:\r\n\r\n**1 Multiple Sanitizers in Analysis Workflow**\r\n\r\n * .github/workflows/analysis.yml runs dynamic analysis before releases:\r\n * LeakSanitizer: \"detects memory leaks\"\r\n * AddressSanitizer: \"fast memory error detector\" for buffer overflows, use-after-free, etc.\r\n * UndefinedBehaviorSanitizer: detects undefined behavior at runtime\r\n\r\n**2 Analysis Workflow Integrated into Release Process**\r\n\r\nFrom .github/workflows/daily-build.yml:\r\n * uses: ./.github/workflows/analysis.yml\r\n * This calls the analysis workflow as part of the build process\r\n\r\n**3 Sanitizer Infrastructure Available**\r\n\r\nFrom config/sanitizer/sanitizers.cmake and config/sanitizer/README.md document:\r\n\r\n * HDF5_USE_SANITIZER CMake variable\r\n * Support for Address, Memory, Undefined, Thread, Leak, and CFI sanitizers\r\n * All are FLOSS dynamic analysis tools from LLVM/Clang\r\n\r\nReference: config/sanitizer/README.md states: \"Sanitizers are tools that perform checks during a program's runtime\"\r\n\r\n**4 Coverage Analysis**\r\n\r\nFrom .github/workflows/analysis.yml:\r\n\r\n * Code coverage testing with gcov/lcov\r\n * While primarily for coverage metrics, it requires executing tests (dynamic analysis)\r\n\r\n**5 OSS-Fuzz Integration**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n * Continuous fuzzing (dynamic analysis for vulnerability detection)\r\n * Indicates ongoing dynamic analysis\r\n\r\n**6 Sanitizers Run on Multiple Configurations**\r\n\r\nanalysis.yml shows sanitizers run with:\r\n\r\n * Different compilers (Clang)\r\n * Different configurations\r\n * Automated in CI/CD pipeline\r\n\r\nThe project applies multiple FLOSS dynamic analysis tools (LeakSanitizer, AddressSanitizer, UndefinedBehaviorSanitizer, and fuzzing) before releases through automated workflows.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Evidence that dynamic tools are routinely used with memory safety detection for C/C++ code:\r\n\r\n**1 HDF5 is Written in Memory-Unsafe Languages**\r\n\r\nThe project is primarily written in C (with C++ and Fortran wrappers):\r\n\r\n * CONTRIBUTING.md requires \"A C11-compatible C compiler\"\r\n * Source code in src/ is C code\r\n * This is a memory-unsafe language\r\n\r\n**2 AddressSanitizer Detects Memory Safety Problems**\r\n\r\n.github/workflows/analysis.yml runs AddressSanitizer:\r\n * CTEST_MEMORYCHECK_TYPE \"AddressSanitizer\"\r\n * HDF5_USE_SANITIZER:STRING=Address\r\n\r\nAddressSanitizer detects:\r\n\r\n * Buffer overflows (overwrites)\r\n * Use-after-free\r\n * Double-free\r\n * Out-of-bounds accesses\r\n\r\nReference: config/sanitizer/README.md states AddressSanitizer \"is useful for detecting most issues dealing with memory, such as: Out of bounds accesses to heap, stack, global\"\r\n\r\n**3 LeakSanitizer for Memory Leaks**\r\n\r\n.github/workflows/analysis.yml runs LeakSanitizer:\r\n\r\n * CTEST_MEMORYCHECK_TYPE \"LeakSanitizer\"\r\n * HDF5_USE_SANITIZER:STRING=Leak\r\n\r\n**4 OSS-Fuzz for Fuzzing**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n * Active fuzzing integration\r\n * Fuzzing is a dynamic tool that generates test inputs\r\n * Combined with sanitizers to detect memory safety issues\r\n\r\n**5 Routine Use Through CI/CD**\r\n\r\nThe sanitizers run automatically:\r\n\r\n * .github/workflows/daily-build.yml calls analysis.yml\r\n * Runs on daily schedule\r\n * Integrated into continuous testing\r\n\r\n**6 Multiple Memory Safety Mechanisms**\r\n\r\nThe project combines:\r\n\r\n * Fuzzing (OSS-Fuzz) - dynamic input generation\r\n * AddressSanitizer - detects buffer overwrites and memory errors\r\n * LeakSanitizer - detects memory leaks\r\n * UndefinedBehaviorSanitizer - detects undefined behavior\r\n\r\nThe project routinely uses fuzzing (OSS-Fuzz) combined with AddressSanitizer to detect memory safety problems including buffer overwrites in its C/C++ code.","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"The project uses configurations with assertions enabled for dynamic analysis:\r\n\r\n**1 Developer Mode Enables Assertions**\r\n\r\nCONTRIBUTING.md documents developer build options:\r\n\r\n* HDF5_ENABLE_DEVELOPER_MODE=ON enables developer-friendly settings\r\n* Developer mode is recommended for development builds\r\n\r\n**2 Sanitizer Builds Use Debug Configuration**\r\n\r\n.github/workflows/analysis.yml runs sanitizers with Debug configuration:\r\n\r\n* Coverage test: ctest -S HDF5config.cmake...CTEST_SOURCE_NAME=${{ steps.set-file-base.outputs.SOURCE_BASE }} -C Debug\r\n* LeakSanitizer runs with -C Debug\r\n* AddressSanitizer runs with -C Debug\r\n* UndefinedBehaviorSanitizer runs with -C Debug\r\n\r\nDebug builds typically enable assertions that are disabled in release builds.\r\n\r\n**3 Assertion Macros in Code**\r\n\r\nCONTRIBUTING.md shows assertion usage in function structure:\r\n\r\n* FUNC_ENTER_NOAPI(FAIL)\r\n\r\nHDassert(/*parameter check*/);\r\n\r\nThe HDassert macro is used throughout the codebase for parameter checking.\r\n\r\n**4 Memory Checker Configuration**\r\n\r\nCONTRIBUTING.md documents memory checking option:\r\n\r\n* HDF5_ENABLE_USING_MEMCHECKER:BOOL=ON when using tools like Valgrind\r\n* This disables internal memory pools to enable better error detection\r\n\r\nReference: \"Use HDF5_ENABLE_USING_MEMCHECKER:BOOL=ON when using tools like Valgrind. This disables internal memory pools that can hide memory issues.\"\r\n\r\n**5 Sanitizer Configuration Separate from Production**\r\n\r\n.github/workflows/analysis.yml shows sanitizer builds are separate:\r\n\r\n* Different workflow from production builds\r\n* Uses specific build options not used in production\r\n* Runs in \"Sanitize\" group/model\r\n\r\n**6 Coverage Build Uses Debug Settings**\r\n\r\n.github/workflows/analysis.yml coverage test:\r\n\r\n* LOCAL_COVERAGE_TEST \"TRUE\"\r\n* DHDF5_ENABLE_COVERAGE:BOOL=ON\r\n* Coverage builds run with instrumentation not suitable for production\r\n\r\nThe project uses Debug configuration with assertions enabled for dynamic analysis (sanitizers, fuzzing, testing), which are separate from production builds.","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"**1 Extensive CVE Fixes Documented**\r\n\r\nCHANGELOG.md shows that numerous security vulnerabilities have been fixed:\r\n\r\n* CVE-2025-7067 - Heap buffer overflow in H5FS__sinfo_serialize_node_cb()\r\n* CVE-2025-2915 - Heap-based buffer overflow in H5F__accum_free\r\n* CVE-2025-7068 - Resource leaks in metadata cache\r\n* CVE-2025-6816, CVE-2025-6818, CVE-2025-6856, CVE-2025-2923 - Object header vulnerabilities\r\n\r\nAnd many more...\r\n\r\n**2 OSS-Fuzz Integration for Discovery**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n* Continuous fuzzing (dynamic analysis) for vulnerability detection\r\n* OSS-Fuzz reports vulnerabilities that are then fixed\r\n\r\nReference: OSS-Fuzz badge indicates active participation in continuous fuzzing program\r\n\r\n**3 CVE Regression Testing**\r\n\r\nREADME.md shows CVE regression CI badge:\r\n\r\n* Automated testing to ensure CVE fixes remain effective\r\n* Prevents reintroduction of vulnerabilities\r\n\r\n**4 Security Advisory Process**\r\n\r\nSECURITY.md documents vulnerability handling:\r\n\r\n* Private disclosure process for security vulnerabilities\r\n* \"This gives us time to work with you to fix the issue before public exposure\"\r\n* Shows commitment to fixing vulnerabilities before disclosure\r\n\r\n**5 GitHub Issues Track Vulnerabilities**\r\n\r\nCHANGELOG.md references GitHub issues for each CVE:\r\n\r\n* \"Fixes GitHub issue #5577\" (CVE-2025-7067)\r\n* \"Fixes GitHub issue #5380\" (CVE-2025-2915)\r\n* \"Fixes GitHub issue #5578\" (CVE-2025-7068)\r\n\r\nShows systematic tracking and resolution\r\n\r\n**6 Multiple Fixes in Single Release**\r\n\r\nVersion 2.0.0 includes fixes for 10+ CVEs, demonstrating:\r\n\r\n* Active vulnerability remediation\r\n* Timely response to discovered issues\r\n* Comprehensive fixes are released together\r\n\r\n**7 Sanitizer Findings Are Addressed**\r\n\r\nThe project runs sanitizers routinely:\r\n\r\n* AddressSanitizer, LeakSanitizer, UndefinedBehaviorSanitizer\r\n* Findings from these tools are used to fix memory safety issues\r\n* Many CVE fixes mention sanitizer-detectable issues (buffer overflows, use-after-free, memory leaks)\r\n\r\nThe project demonstrates timely fixing of exploitable vulnerabilities discovered through dynamic analysis (fuzzing, sanitizers), with extensive CVE fixes documented in CHANGELOG.md and systematic tracking through GitHub issues.","general_comments":"","created_at":"2023-09-05T17:54:26.295Z","updated_at":"2025-12-03T17:51:05.305Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"**1 Multiple CI Workflows**\r\n\r\nREADME.md displays numerous CI badges showing active continuous integration:\r\n\r\n * develop cmake build status\r\n * HDF5 develop daily build\r\n * netCDF build status\r\n * h5py build status\r\n * CVE regression\r\n * HDF5 VOL connectors build status\r\n * HDF5 VFD build status\r\n * Link checker status\r\n\r\n**2 GitHub Actions**\r\n\r\nThe project uses GitHub Actions for CI:\r\n\r\n * .github/workflows/ directory contains CI workflows\r\n * Automated testing on pull requests\r\n * Daily scheduled builds\r\n\r\n**3 CI Requirements in CONTRIBUTING.md**\r\n\r\nCONTRIBUTING.md mentions CI integration:\r\n\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * \"The CI system will automatically format pull requests if needed\"\r\n * \"The CI system builds with -Werror\"\r\n\r\n**4 CDash Integration**\r\n\r\nTest results reported to CDash:\r\n\r\n * URL: https://my.cdash.org/index.php?project=HDF5\r\n\r\nThe project implements continuous integration with multiple automated workflows, daily builds, and automated testing on code changes.","cpe":"cpe:hdf5","discussion_status":"Met","discussion_justification":"The project has multiple mechanisms for discussion that meet all the requirements:\r\n\r\n**1 GitHub Issues**\r\n\r\nThe project uses GitHub Issues for bug reports, feature requests, and discussions:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n * Searchable: Yes, GitHub provides full search functionality\r\n * Addressable by URL: Yes, each issue has a unique URL\r\n * Open participation: Yes, anyone with a GitHub account can participate\r\n * No proprietary software: GitHub is accessible via web browser\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states \"Open a GitHub issue (https://github.com/HDFGroup/hdf5/issues)\"\r\n\r\n**2 HDF Forum**\r\n\r\nThe project provides a public forum for discussions:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n * News and Announcements: https://forum.hdfgroup.org/c/news-and-announcements-from-the-hdf-group\r\n * Searchable: Yes, described as \"open and public service for searching and reading\"\r\n * Addressable by URL: Yes, topics have unique URLs\r\n * Open participation: Yes, \"Posting requires completing a simple registration\"\r\n * No proprietary software: Web-based, accessible via browser\r\n\r\nReference: README.md#forum-and-news states \"The HDF Forum is provided for public announcements, technical questions, and discussions of interest to the general HDF5 Community.\"\r\n\r\n**3 GitHub Pull Request Discussions**\r\n\r\nPull requests enable threaded discussions about proposed changes:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/pulls\r\n * Searchable: Yes\r\n * Addressable by URL: Yes, each PR has a unique URL\r\n * Open participation: Yes, anyone can comment on public PRs\r\n * No proprietary software: Web browser access only\r\n\r\nReference: CONTRIBUTING.md#contributing-changes describes the pull request workflow URL: https://github.com/HDFGroup/hdf5/issues and https://forum.hdfgroup.org All mechanisms are searchable, URL-addressable, open to new participants, and accessible via web browsers without proprietary software installation.","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"**1 All Credentials Use GitHub Secrets**\r\n\r\nWorkflow files properly use GitHub Secrets for sensitive credentials:\r\n\r\n * ${{ secrets.AZURE_CODE_SIGNING_NAME }}\r\n * ${{ secrets.AZURE_CERT_PROFILE_NAME }}\r\n * ${{ secrets.GPG_PRIVATE_KEY }}\r\n * MAVEN_PASSWORD referenced as environment variable, not hardcoded\r\n\r\nReference: .github/workflows/ctest.yml, release.yml, maven-deploy.yml\r\n\r\n**2 Test Credentials Are Clearly Fake**\r\n\r\nThe AWS-looking credential found (AKIAIMC3D3XLYXLN5COA) is in a test file:\r\n\r\n * File: tools/libtest/h5tools_test_utils.c\r\n * Purpose: \"unit-test functionality of the routines in tools/lib/h5tools_utils\"\r\n * Context: \"real-world use case\" test case for tuple parsing\r\n * This is test data for parsing AWS credential format, not an actual working credential\r\n\r\n**3 No Private Key Files Found**\r\n\r\n * No BEGIN PRIVATE KEY blocks\r\n * No .pem, .key, id_rsa, id_dsa files\r\n * No GitHub tokens (ghp_, gho_, ghu_ patterns)\r\n * No Slack tokens (xox patterns)\r\n\r\n**4 Test Secrets Are Placeholder Values**\r\n\r\nTest code uses obviously fake values:\r\n\r\n * test/vfd.c: secret_key = \"plugh\" (Adventure game reference)\r\n * tools/libtest: Various single-character test values (\"w\", \"c\", \"z\")\r\n\r\n** 5 .gitignore Does Not Exclude Credential Files**\r\n\r\nThe .gitignore doesn't exclude .env, .pem, or credential files, suggesting no such files exist or need to be excluded. The public repository does NOT leak valid private credentials. All sensitive credentials use GitHub Secrets, and AWS-format strings found are test data for parsing functionality. \r\n\r\nGitHub provides automatic secret scanning for public repositories, alerting maintainers when known credential patterns are detected. The project uses proper secret management practices (GitHub Secrets).\r\n","english_status":"Met","english_justification":"The project provides documentation in English and accepts bug reports and comments in English:\r\n\r\n**1 Documentation in English**\r\nAll project documentation is written in English:\r\n\r\n * README.md - Written in English\r\n * CONTRIBUTING.md - Written in English\r\n * LICENSE - Written in English\r\n * INSTALL files in release_docs/ - Written in English\r\n * CHANGELOG.md - Written in English\r\n * API documentation at https://support.hdfgroup.org/documentation/hdf5/latest - Written in English\r\n * Code comments and Doxygen documentation in source files - Written in English\r\n\r\nReference: All documentation files in the repository\r\n\r\n**2 Bug Reports in English**\r\n\r\nThe project accepts bug reports in English through multiple channels:\r\n\r\n * GitHub Issues: https://github.com/HDFGroup/hdf5/issues - English language platform\r\n * Help Desk: https://help.hdfgroup.org - English language support\r\n * HDF Forum: https://forum.hdfgroup.org - Primary language is English\r\n\r\nReference: README.md#help-and-support states \"The HDF Group staffs a free Help Desk accessible at https://help.hdfgroup.org\" Reference: CONTRIBUTING.md#contributing-changes states \"Open a GitHub issue\" for reporting bugs\r\n\r\n**3 Code Comments in English**\r\n\r\nAll code comments, function documentation, and discussions in pull requests are conducted in English:\r\n\r\n * Source code comments - English\r\n * Doxygen annotations in header files - English\r\n * Pull request discussions - English\r\n * Commit messages - English\r\n\r\nReference: Source code files like src/H5Dpublic.h contain English documentation URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project provides comprehensive documentation in English and accepts bug reports and code comments in English through GitHub Issues, the Help Desk, and the HDF Forum.","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Met","hardened_site_justification":"Found all required security hardening headers.","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":93,"achieved_passing_at":null,"lost_passing_at":null,"last_reminder_at":"2026-01-02T23:00:13.597Z","disabled_reminders":false,"implementation_languages":"C, Java, Fortran, CMake, C++, Shell, PLSQL, M4, LiveScript, Makefile, Perl, Yacc, Scilab, JavaScript, Lex","lock_version":61,"badge_percentage_1":11,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":17,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Unmet","achieve_silver_status":"Unmet","tiered_percentage":93,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":null,"first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"The project is actively maintained:\r\n\r\n**1 Recent Commit Activity**\r\n\r\nThe git status shows recent commits to the develop branch (as of 12/25):\r\n\r\n**2 Active CI/CD System**\r\n\r\nREADME.md shows multiple active CI/CD badges indicating continuous testing:\r\n\r\n * develop cmake build status\r\n * HDF5 develop daily build\r\n * netCDF build status\r\n * h5py build status\r\n * CVE regression testing\r\n * HDF5 VOL connectors build status\r\n * HDF5 VFD build status\r\n * Link checker status\r\n\r\nReference: README.md displays active build status badges\r\n\r\n**3 Active Issue and Pull Request System**\r\n\r\nThe project uses GitHub Issues and Pull Requests for ongoing maintenance:\r\n\r\n * GitHub Issues: https://github.com/HDFGroup/hdf5/issues\r\n * Pull Requests referenced in recent commits (e.g., #6070, #6075, #6039, #6049, #6066)\r\n \r\n**4 Ongoing Development Roadmap**\r\n\r\nREADME.md shows active development with planned features:\r\n\r\n * Major update on March 10, 2025 (CMake-only builds)\r\n * Future roadmap includes: Multi-threaded HDF5, crashproofing, Full SWMR, encryption, etc.\r\n\r\nReference: README.md states \"HDF5 version 2.0.1 currently under development\"\r\n\r\n**5 Dedicated Maintainer**\r\n\r\nThe HDF Group is the official maintainer:\r\n\r\n * Website: https://www.hdfgroup.org/\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md states \"The HDF Group is the developer, maintainer, and steward of HDF5 software\"\r\n\r\n**6 Regular Release Schedule**\r\n\r\nREADME.md describes the release approach:\r\n\r\n * \"HDF5 does not follow a regular release schedule. Instead, updates are based on the introduction of new features and the resolution of bugs. However, we aim to have at least one annual release for each maintenance branch.\"\r\n * Release progress badge shows active release planning\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project is actively maintained by The HDF Group with recent commits, active CI/CD, ongoing issue resolution, and planned future development.","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"in_progress","additional_rights":[],"project_entry_attribution":"Please credit Scot Breitenfeld and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":7802,"user_id":45373,"name":"HDF5 Library and File Format","description":"Official HDF5® Library Repository","homepage_url":"https://github.com/HDFGroup/hdf5","repo_url":"https://github.com/HDFGroup/hdf5","license":"BSD-3-Clause","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"All project sites support HTTPS using TLS:\r\n\r\n**1 Project Website**\r\n\r\n* The HDF Group website uses HTTPS: https://www.hdfgroup.org/\r\n\r\nReference from README.md and CONTRIBUTING.md\r\n\r\n**2 Source Code Repository**\r\n\r\nThe GitHub repository uses HTTPS:\r\n\r\n * https://github.com/HDFGroup/hdf5\r\n * https://github.com/HDFGroup/hdf5.git\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**3 Download URLs**\r\n\r\nAll download locations use HTTPS:\r\n\r\n * Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * Current releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n * Archived releases: https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n * Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Maven artifacts: https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\nReference: README.md\r\n\r\n**4 Help and Support URLs**\r\n\r\nSupport sites use HTTPS:\r\n\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md#help-and-support\r\n\r\n**5 License URL**\r\n\r\nLicense information uses HTTPS:\r\n\r\n * https://www.hdfgroup.org/licenses\r\n\r\nReferenced throughout source code files and CONTRIBUTING.md URL: All project URLs use HTTPS (see above) All project sites, repositories, and download locations exclusively use HTTPS with TLS encryption.","description_good_status":"Met","description_good_justification":"The README.md file succinctly describes what HDF5 does and what problem it solves:\r\n\r\n**1 Primary Description**\r\n\r\nThe README states:\r\n\r\n * \"This repository contains a high-performance library's source code and a file format specification that implements the HDF5® data model. The model has been adopted across many industries, and this implementation has become a de facto data management standard in science, engineering, and research communities worldwide.\"\r\n\r\n**2 This clearly describes**:\r\n\r\n * What it does: Provides a high-performance library and file format for data management\r\n * What problem it solves: Data management and storage needs in science, engineering, and research\r\n * Its significance: De facto standard adopted across many industries\r\n\r\nReference: README.md\r\n\r\n**3 Additional Context**\r\n\r\nThe README also directs users to The HDF Group's website for more information:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md","interact_status":"Met","interact_justification":"**1 How to Obtain the Software**\r\n\r\nThe README includes multiple sources for obtaining HDF5:\r\n\r\n* Source code repository: https://github.com/HDFGroup/hdf5.git\r\n* Current releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n* Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n* Archived releases: https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n* Maven artifacts: https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\n Reference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**2 How to Provide Feedback (Bug Reports and Enhancements)**\r\n\r\nThe README provides clear channels for feedback:\r\n\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org (for technical questions and discussions)\r\n * HDF5 Topics Forum: https://forum.hdfgroup.org/c/hdf5 (specifically for HDF5-related discussions)\r\n\r\nReference: README.md#help-and-support and README.md#forum-and-news\r\n\r\n**3 How to Contribute**\r\n\r\nWhile not detailed in README.md itself, the repository contains a comprehensive CONTRIBUTING.md file that explains the contribution process in detail. URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project website (accessible through the links in README.md) provides all necessary information for obtaining, providing feedback, and contributing to the software.","contribution_status":"Met","contribution_justification":"Reference: https://github.com/HDFGroup/hdf5/blob/develop/CONTRIBUTING.md The file clearly explains that pull requests are the mechanism for contributions and provides comprehensive process documentation.","contribution_requirements_status":"Met","contribution_requirements_justification":"Reference: CONTRIBUTING.md#checklist-for-contributors URL: https://github.com/HDFGroup/hdf5/blob/develop/CONTRIBUTING.md \r\n\r\nThe file comprehensively addresses coding standards, development conventions, and contribution requirements throughout multiple sections. Specifically:\r\n\r\n**1 Development Conventions Section**\r\n\r\nThis section documents required coding standards, including:\r\n\r\n * Code organization (public, private, package visibility levels)\r\n * Function naming conventions (H5Xfoo(), H5X_foo(), H5X__foo())\r\n * Function structure requirements (entry/exit macros, error handling)\r\n * Error handling conventions\r\n * Platform independence requirements\r\n * Memory management standards\r\n\r\n Reference: CONTRIBUTING.md#development-conventions\r\n\r\n**2 Acceptance Criteria Section**\r\n\r\nThis section explicitly lists requirements for pull requests:\r\n\r\n * Clear purpose\r\n * Proper documentation\r\n * Testing requirements\r\n * Compatibility requirements (100% backward compatibility, machine independence, binary compatibility)\r\n * Documentation standards (Doxygen, CHANGELOG.md)\r\n\r\nReference: CONTRIBUTING.md#acceptance-criteria\r\n\r\n**3 Checklist for Contributors Section**\r\n\r\nProvides a verification checklist covering:\r\n\r\n* Code conventions (naming, portability, structure)\r\n* Documentation requirements\r\n* Testing requirements","license_location_status":"Met","license_location_justification":"The project posts its license in the standard location:\r\n\r\n* LICENSE File in Repository Root URL: https://github.com/HDFGroup/hdf5/blob/develop/LICENSE","floss_license_status":"Met","floss_license_justification":"https://github.com/HDFGroup/hdf5/blob/develop/LICENSE The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"https://opensource.org/license/bsd-3-clause The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"The project provides comprehensive basic documentation through multiple channels:\r\n\r\n * README.md - Quick Start Documentation\r\n\r\n**1 The README.md file in the repository root provides essential documentation, including:**\r\n\r\n * What the software does (high-performance data management library)\r\n * How to obtain the software\r\n * Where to get help and support\r\n * Release information\r\n * Reference: README.md\r\n\r\n**2 Installation Documentation**\r\n\r\nThe release_docs/ directory contains detailed installation and usage instructions:\r\n\r\n * INSTALL - General compilation and installation instructions\r\n * INSTALL_CMAKE - CMake-specific build instructions\r\n * INSTALL_Windows and INSTALL_Cygwin - Platform-specific installation\r\n * README_HPC.md - HPC system configuration\r\n * USING_HDF5_CMake - Building applications with HDF5\r\n * USING_CMake_Examples - Building and testing examples\r\n \r\nReference: release_docs/\r\n\r\n**3 CONTRIBUTING.md - Development Documentation**\r\n\r\nComprehensive guide for developers covering:\r\n\r\n * How to build for development\r\n * Source code organization\r\n * Development conventions and coding standards\r\n * Testing procedures\r\n\r\n Reference: CONTRIBUTING.md\r\n\r\n**4 Online Documentation**\r\n\r\nThe README.md directs users to comprehensive online documentation:\r\n\r\n * All HDF software documentation: https://support.hdfgroup.org/documentation/index.html\r\n * Latest HDF5 library documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n\r\n**5 API Documentation**\r\n\r\n* Doxygen documentation: The project includes Doxygen markup in public headers for API documentation\r\n* The doxygen/ directory contains Doxygen build files for generating API documentation\r\n\r\n**6 CHANGELOG.md**\r\n\r\nThe release_docs/CHANGELOG.md file documents:\r\n\r\n * Changes from release to release\r\n * New features\r\n * Bug fixes\r\n * Known problems\r\n \r\nReference: release_docs/CHANGELOG.md URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project provides extensive basic documentation both in the repository (README, INSTALL files, CONTRIBUTING guide) and online (comprehensive API documentation and user guides).","documentation_interface_status":"Met","documentation_interface_justification":"The project provides comprehensive reference documentation describing the external interface (both input and output):\r\n\r\n**1 Doxygen-Documented Public API Headers**\r\n\r\nAll public API functions are documented with Doxygen markup in the public header files.\r\nThese include detailed descriptions of:\r\n\r\n * Input parameters: Each parameter is documented with \\param[in], \\param[out], or \\param[in,out] tags\r\n * Return values: Documented with \\return tags\r\n * Detailed descriptions: Comprehensive \\details sections explaining function behavior\r\n * Code examples: Many functions include \\par Example sections\r\n * Version information: \\since tags indicating when functions were introduced\r\n\r\n**2 Online Reference Documentation**\r\n\r\nThe README.md directs users to comprehensive online API reference documentation:\r\n\r\n * Latest HDF5 API Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * This is generated from the Doxygen markup in the source code\r\n\r\nReference: README.md#documentation\r\n\r\n**3 Complete API Coverage**\r\n\r\nPublic API headers covering all major functionality\r\n\r\n**4 Doxygen Build System**\r\n\r\nThe project includes a complete Doxygen build system in the doxygen/ directory for generating reference documentation from the annotated source code. URL: https://support.hdfgroup.org/documentation/hdf5/latest The project provides extensive reference documentation with detailed input/output specifications for all public API functions, both in the source code (Doxygen comments) and in published online documentation.","repo_public_status":"Met","repo_public_justification":"The project has a version-controlled source repository that is publicly readable with a URL:\r\n\r\n**1 Version Control System**\r\n\r\nThe project uses Git for version control:\r\n\r\n * The environment information shows: \"Is directory a git repo: Yes\"\r\n * Git commit history is available, showing recent commits with hashes (bd76ec789a, b986a34474, 5e2a73d542, etc.)\r\n\r\n**2 Publicly Readable Repository**\r\n\r\nThe repository is hosted on GitHub and is publicly accessible:\r\n\r\n * Repository URL: https://github.com/HDFGroup/hdf5\r\n * Clone URL: https://github.com/HDFGroup/hdf5.git\r\n * Anyone can read, browse, and clone the repository without authentication\r\n\r\nReference: README.md#getting-the-source-code states \"Development code is available at our Github location: https://github.com/HDFGroup/hdf5.git\" Reference: CONTRIBUTING.md#getting-the-source-code provides instructions: \"git clone https://github.com/HDFGroup/hdf5.git cd hdf5\"\r\n\r\n**3 Public Access to All Branches**\r\n\r\nMultiple branches are publicly accessible:\r\n\r\n * develop branch (main development branch)\r\n * Various release branches (hdf5_1_14, etc.)\r\n * All commit history is publicly visible\r\n\r\nReference: Git status shows \"Current branch: develop\" and \"Main branch (you will usually use this for PRs): develop\"\r\n\r\n**4 Web Interface**\r\n\r\nGitHub provides a web interface for browsing the repository:\r\n\r\n * Code browser: https://github.com/HDFGroup/hdf5\r\n * File viewing: Individual files can be accessed via URLs like https://github.com/HDFGroup/hdf5/blob/develop/README.md\r\n * Commit history: https://github.com/HDFGroup/hdf5/commits/develop\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project has a publicly readable Git repository hosted on GitHub with full version control history accessible to everyone.","repo_track_status":"Met","repo_track_justification":"The project's Git repository tracks what changes were made, who made the changes, and when the changes were made:\r\n\r\n**1 What Changes Were Made**\r\n\r\nGit tracks all file modifications, additions, and deletions:\r\n\r\n * Commit messages describe changes (e.g., \"Improved usage information (#6070)\", \"Minor optimizations of r-tree implementation (#6039)\")\r\n * Diff information shows exact code changes\r\n * Git log shows complete history of modifications\r\n\r\n**2 Who Made the Changes**\r\n\r\nGit tracks author information for every commit:\r\n\r\n * CONTRIBUTING.md references git log command to see commit authorship\r\n * Git commit format includes author name and email\r\n * CONTRIBUTING.md mentions checking authorship with: \"git log -1 --format='%an %ae'\"\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git states \"Before amending: ALWAYS check authorship (git log -1 --format='%an %ae')\"\r\n\r\n**3 When Changes Were Made**\r\n\r\nGit tracks timestamps for all commits:\r\n\r\n * Each commit has a timestamp\r\n * File listing shows modification dates (e.g., \"Nov 11 22:02\" for LICENSE file)\r\n * Git log shows the complete temporal history\r\n * CONTRIBUTING.md describes using git log to see recent commit history\r\n\r\nReference: The bash output showed \"Nov 11 22:02\" timestamp for the LICENSE file\r\n\r\n**4 Version Control Best Practices**\r\n\r\nThe project follows Git best practices:\r\n\r\n * Detailed commit messages with issue references (#6070, #6075, etc.)\r\n * Pull request workflow that preserves change history\r\n * Branch strategy documented in CONTRIBUTING.md\r\n * Co-authored commits supported (CONTRIBUTING.md shows \"Co-Authored-By: Claude noreply@anthropic.com\" format)\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git provides detailed Git workflow instructions\r\n\r\n**5 Public Access to History**\r\n\r\nAll change history is publicly accessible:\r\n\r\n * https://github.com/HDFGroup/hdf5/commits/develop\r\n * Each commit shows what changed, who made it, and when\r\n\r\nURL: https://github.com/HDFGroup/hdf5/commits/develop The Git repository fully tracks what changes were made (commit diffs and messages), who made them (author information), and when they were made (commit timestamps). Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"The project's source repository includes interim versions for review between releases, not only final releases:\r\n\r\n**1 Active Development Branch**\r\n\r\nThe repository has an active development branch with interim commits:\r\n\r\n* Current branch: develop\r\n* Recent interim commits visible:\r\n * bd76ec789a \"Improved usage information (#6070)\"\r\n * b986a34474 \"Bump the github-actions group with 6 updates (#6075)\"\r\n * 5e2a73d542 \"Minor optimizations of r-tree implementation (#6039)\"\r\n\r\nThese are work-in-progress commits, not final releases.\r\n\r\n**2 Pull Request Workflow**\r\n\r\nCONTRIBUTING.md describes a collaborative review process using pull requests:\r\n\r\n * \"Submit a pull request (PR)\"\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * \"Work with HDF Group developers to meet acceptance criteria\"\r\n\r\nThis workflow requires interim code to be visible in the repository for review before merging. Reference: CONTRIBUTING.md#contributing-changes\r\n\r\n3. Development Version in Repository\r\nREADME.md states:\r\n \"HDF5 version 2.0.1 currently under development\"\r\nThis shows the repository contains work-in-progress code, not just released versions.\r\n\r\n4. Development Snapshots\r\nThe project provides periodic development snapshots:\r\n\"Periodically development code snapshots are provided at the following URL: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\"\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n5. Branching Strategy for Collaboration\r\nCONTRIBUTING.md describes branching strategy enabling interim review:\r\n \"Target the develop branch for new features and bug fixes\"\r\n \"Small features: Develop in forks of the main repository\"\r\n \"Large collaborative work: Use feature branches named feature/\u003cfeature\u003e\"\r\nReference: CONTRIBUTING.md#branching-strategy\r\n\r\n6. Unmerged Work Visible\r\nThe git status shows numerous untracked and modified files, indicating ongoing development work:\r\n Multiple Makefile.in files\r\n Test files (a.out, object files)\r\n Patch files (hdf5_subfiling_mapping.patch, subfiling_mapping.patch, subfiling_mapping2.patch)\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The repository contains interim development versions on the develop branch and feature branches for collaborative review, not just final releases.","repo_distributed_status":"Met","repo_distributed_justification":"The project uses Git, a common distributed version control software:\r\n\r\n **1 Git Repository Confirmed**\r\n\r\nThe environment information confirms Git usage:\r\n * \"Is directory a git repo: Yes\"\r\n\r\n**2 Hosted on GitHub**\r\n\r\nThe repository is hosted on GitHub, which uses Git:\r\n\r\n * Repository URL: https://github.com/HDFGroup/hdf5\r\n * Clone URL: https://github.com/HDFGroup/hdf5.git\r\n\r\nReference: README.md#getting-the-source-code states \"Development code is available at our Github location: https://github.com/HDFGroup/hdf5.git\" Reference: CONTRIBUTING.md#getting-the-source-code provides Git clone instructions: \"git clone https://github.com/HDFGroup/hdf5.git cd hdf5\"\r\n\r\n**3 Git Prerequisites**\r\n\r\nCONTRIBUTING.md lists Git as a required tool:\r\n\r\n * \"Git: For version control.\"\r\n * \"If you are new to Git and GitHub, we encourage you to check out the GitHub tutorial\"\r\n\r\nReference: CONTRIBUTING.md#prerequisites\r\n\r\n**4 Git Workflow Documentation**\r\n\r\nCONTRIBUTING.md extensively documents Git workflows:\r\n\r\n * Git commit procedures\r\n * Git branch strategy (develop branch, feature branches)\r\n * Git commands for commits, status, diff, log, push\r\n * Pull request workflow using Git\r\n\r\nReference: CONTRIBUTING.md#committing-changes-with-git and CONTRIBUTING.md#branching-strategy\r\n\r\n**5 Git Commit History**\r\n\r\nThe repository shows a typical Git commit history:\r\n\r\n * Commit hashes (bd76ec789a, b986a34474, etc.)\r\n * Git status shows branch information (\"Current branch: develop\")\r\n * Recent commits log available\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project uses Git, which is one of the most common distributed version control systems and is the de facto standard for modern software development.on GitHub, which uses git. Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The project uses unique version identifiers for each release:\r\n\r\n**1 Current Version Identifier**\r\n\r\nREADME.md shows the current development version:\r\n\r\n* \"HDF5 version 2.0.1 currently under development\"\r\n* This follows semantic versioning (major.minor.patch).\r\n\r\n**2 Release Version Examples**\r\n\r\nREADME.md references specific versioned releases:\r\n\r\n * \"hdf5 1.14 releases: https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\"\r\n * Version 2.0.0 mentioned in release schedule table\r\n * Historical versions referenced: \"1.10.0-1.12.0\" in HISTORY files\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**3 Version Numbering System**\r\nREADME.md describes the versioning approach:\r\n\r\n * Major versions for significant changes (2.0.0)\r\n * Maintenance branches for each major.minor version\r\n * Release schedule shows specific version numbers\r\n\r\nReference: README.md#release-schedule states \"we aim to have at least one annual release for each maintenance branch\"\r\n\r\n**4 Branching by Version**\r\n\r\nCONTRIBUTING.md references version-specific branches:\r\n\r\n * \"hdf5_X_Y\" format for release support branches\r\n * \"hdf5_X_Y_Z\" format for release preparation branches\r\n * Example: \"hdf5_1_14\" branch\r\n\r\nReference: CONTRIBUTING.md mentions maintenance branches and release_docs/RELEASE_PROCESS.md references version-specific branches\r\n\r\n**5 Maven Artifact Versioning**\r\n\r\nREADME.md shows versioned Maven artifacts:\r\n\r\n * \"org.hdfgroup:hdf5-java\" with version identifiers\r\n * Snapshot versions with \"-SNAPSHOT\" suffix\r\n * Maven Central releases with specific versions\r\n\r\nReference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**6 GitHub Releases**\r\n\r\nThe project uses GitHub releases with version tags:\r\n\r\n * Development snapshots: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Tagged releases for each version\r\n\r\nReference: README.md URL: https://github.com/HDFGroup/hdf5/releases Each release has a unique version identifier following the format major.minor.patch (e.g., 2.0.1, 1.14.x), ensuring users can identify and reference specific releases.","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"The project identifies releases within the version control system using tags:\r\n\r\n**1 GitHub Release Tags**\r\n\r\nREADME.md references GitHub releases with tags:\r\n\r\n * \"Periodically, development code snapshots are provided at the following URL: https://github.com/HDFGroup/hdf5/releases/tag/snapshot\"\r\n\r\nThis shows the project uses Git tags for releases (the \"tag/snapshot\" URL pattern indicates Git tags). Reference: README.md#snapshots-previous-releases-and-source-code\r\n\r\n**2 Version-Specific Release Branches**\r\n\r\nThe project uses version-specific branches for releases:\r\n\r\n * \"hdf5_X_Y\" format for release support branches\r\n * \"hdf5_X_Y_Z\" format for release preparation branches\r\n * Example: \"hdf5_1_14\" branch for 1.14 releases\r\n\r\nReference: RELEASE_PROCESS.md and CONTRIBUTING.md mention version-specific branches\r\n\r\n**3 GitHub Releases Infrastructure**\r\n\r\nThe project uses GitHub's release system, which is built on Git tags:\r\n\r\n * https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n * Source packages available through GitHub releases\r\n * Each release on GitHub corresponds to a Git tag\r\n\r\n**4 Release Documentation Process**\r\n\r\nRELEASE_PROCESS.md describes the release workflow which includes version control system operations:\r\n\r\n * References to branches like \"hdf5_X_Y\" and \"hdf5_X_Y_Z\"\r\n * Mentions lifting code freeze on release branches\r\n * Describes version-specific branch management\r\n\r\nReference: release_docs/RELEASE_PROCESS.md\r\n\r\n**5 Maven Release Tags**\r\n\r\nThe project uses versioned releases for Maven artifacts:\r\n\r\n * Snapshot builds with version identifiers\r\n * Release workflows that create tagged versions\r\n\r\nReference: CONTRIBUTING.md mentions Maven snapshot and release builds URL: https://github.com/HDFGroup/hdf5/releases The project uses Git tags to identify releases, as evidenced by the GitHub releases system (which uses Git tags) and the documented release process with version-specific branches and tags.","release_notes_status":"Met","release_notes_justification":"The project provides human-readable release notes that are not raw version control logs:\r\n\r\n**1 CHANGELOG.md File**\r\n\r\nThe project maintains a comprehensive CHANGELOG.md file with curated release notes:\r\n\r\n * Located at: release_docs/CHANGELOG.md\r\n * Human-readable summaries organized by category\r\n * Not raw git log output, but structured documentation\r\n\r\nReference: README.md states \"See the CHANGELOG.md file in the release_docs/ directory for information specific to the features and updates included in this release of the library.\"\r\n\r\n**2 Well-Structured Release Notes**\r\n\r\nThe CHANGELOG.md includes:\r\n\r\n * Executive Summary with key highlights\r\n * Performance Enhancements (specific improvements like \"2500% faster\" Virtual Dataset operations)\r\n * Breaking Changes section (e.g., \"Updated default file format to 1.8\")\r\n * New Features \u0026 Improvements organized by category\r\n * Bug Fixes section\r\n * Support for new platforms\r\n * Platforms Tested\r\n * Known Problems\r\n\r\nThis format helps users determine whether to upgrade and understand the impact of the upgrade.\r\n\r\n**3 Release Note Format Requirements**\r\n\r\nCONTRIBUTING.md documents the release note format requirements:\r\n\r\n * \"Title/Problem - Problem description paragraph explaining the issue and conditions where it occurs\"\r\n * \"Solution paragraph describing what was done to resolve the issue and any functional impact or workarounds\"\r\n * When to write release notes: \"Required: User-visible changes in functionality or behavior\"\r\n * When not to write: \"Not required: Internal code changes, comments, or build process changes\"\r\n\r\nReference: CONTRIBUTING.md#release-notes\r\n\r\n4. Historical Release Notes\r\nThe project maintains release notes for older versions:\r\n HISTORY-1_10_0-1_12_0.txt for historical releases\r\n release.txt referenced for pre-2.0.0 releases\r\nReference: CHANGELOG.md states \"For releases prior to version 2.0.0, please see the release.txt file\"\r\n\r\n5. Upgrade Impact Information\r\nThe CHANGELOG provides clear upgrade impact guidance:\r\n Breaking changes clearly marked with warning symbol\r\n Compatibility issues documented (e.g., family driver changes)\r\n Migration guidance (e.g., CMake options replacing Autotools)\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/release_docs/CHANGELOG.md The project provides comprehensive, human-readable release notes in CHANGELOG.md that help users understand major changes and their upgrade impact, not raw version-control logs.","release_notes_vulns_status":"Met","release_notes_vulns_justification":"The release notes identify every publicly known run-time vulnerability fixed in releases with CVE assignments:\r\n\r\n**1 CVE Vulnerabilities Documented in CHANGELOG.md**\r\n\r\nThe current CHANGELOG.md for version 2.0.1 identifies multiple CVE fixes with detailed descriptions:\r\n\r\n* CVE-2025-7067 - Heap buffer overflow in H5FS__sinfo_serialize_node_cb()\r\n* CVE-2025-2915 - Heap-based buffer overflow in H5F__accum_free\r\n* CVE-2025-7068 - Resource leaks during metadata cache entry discard\r\n* CVE-2025-6816, CVE-2025-6818, CVE-2025-6856, CVE-2025-2923 - Corrupted object header issues\r\n* CVE-2025-6750 - Heap buffer overflow in mtime message decoding\r\n* CVE-2025-6269 - Security vulnerabilities in H5C__reconstruct_cache_entry()\r\n* CVE-2025-2153 - Message flags field modification issue\r\n* CVE-2025-2925 - Double-free vulnerability in H5C__load_entry()\r\n\r\nReference: release_docs/CHANGELOG.md Bug Fixes section\r\n\r\n**2 CVE Information Includes Links**\r\n\r\nMany CVE entries include direct links to the National Vulnerability Database:\r\n\r\n * Example: CVE-2025-2915\r\n * Example: CVE-2025-7068\r\n\r\n3. CVEs in Historical Release Notes\r\n\r\nHistorical release documentation also identifies CVEs:\r\n\r\n* HISTORY-1_12_0-1_14_0.txt documents CVE-2019-8396, CVE-2021-37501, CVE-2018-13867, CVE-2021-46244, and many others\r\n* HISTORY-1_10_0-1_12_0.txt documents CVE-2018-11202, CVE-2018-11203, CVE-2018-11204, and others\r\n* HISTORY-1_14_0-2_0_0.txt documents numerous CVEs from 2023-2024\r\n\r\n**4 GitHub Issue References**\r\n\r\nEach CVE fix includes references to the specific GitHub issues:\r\n\r\n * Example: \"Fixes GitHub issue #5577\" for CVE-2025-7067\r\n * Example: \"Fixes GitHub issue #5380\" for CVE-2025-2915\r\n\r\n**5 CVE Regression Testing**\r\n\r\n* README.md shows active CVE regression testing:\r\n* \"CVE regression\" CI badge indicating continuous testing for CVE vulnerabilities\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/release_docs/CHANGELOG.md The project consistently identifies all publicly known vulnerabilities with CVE assignments in their release notes, with detailed descriptions, links to CVE databases, and references to GitHub issues.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"The project uses GitHub Issues as an issue tracker for tracking individual issues:\r\n\r\n**1 GitHub Issues Used for Issue Tracking**\r\n\r\nThe project uses GitHub's built-in issue tracker:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states: \"1. Open a GitHub issue (HDF5 Issues) - Required unless the change is minor (e.g., typo fix). - Describe the problem or feature request clearly.\"\r\n\r\n**2 Individual Issue Tracking**\r\n\r\nEach bug report and feature request gets its own individual issue with:\r\n\r\n * Unique issue number (e.g., #5577, #5380, #5578)\r\n * Individual URL for each issue\r\n * Status tracking (open/closed)\r\n * Labels and assignments\r\n\r\nReference: CHANGELOG.md references specific GitHub issues.\r\n\r\n**3 Pull Requests Reference Issues**\r\n\r\nCONTRIBUTING.md requires pull requests to reference issues:\r\n\r\n * \"Make sure to include the issue that the PR addresses in the description\"\r\n\r\nThis creates traceability between code changes and individual issues. Reference: CONTRIBUTING.md#contributing-changes\r\n\r\n**4 Evidence of Active Issue Tracking**\r\n\r\nRecent commits reference issue numbers:\r\n\r\n* \"#6070\" in commit \"Improved usage information (#6070)\"\r\n* \"#6075\" in commit \"Bump the github-actions group with 6 updates (#6075)\"\r\n\" #6039\" in commit \"Minor optimizations of r-tree implementation (#6039)\"\r\n\r\n**5 Issue Tracker Features**\r\n\r\nGitHub Issues provides:\r\n\r\n * Individual issue URLs (e.g., https://github.com/HDFGroup/hdf5/issues/5577)\r\n * Search functionality\r\n * Labels and milestones\r\n * Assignment to developers\r\n * Discussion threads\r\n * Status tracking\r\n\r\nURL: https://github.com/HDFGroup/hdf5/issues The project actively uses GitHub Issues as an issue tracker for tracking individual bugs, feature requests, and security vulnerabilities.","report_process_status":"Met","report_process_justification":"The project provides multiple processes for users to submit bug reports:\r\n\r\n**1 GitHub Issues (Primary Bug Reporting Mechanism)**\r\n\r\nThe project uses GitHub Issues as the primary bug reporting system:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states: \"1. Open a GitHub issue (HDF5 Issues) - Required unless the change is minor (e.g., typo fix). - Describe the problem or feature request clearly.\"\r\nReference: README.md#help-and-support mentions GitHub Issues as a reporting mechanism\r\n\r\n**2 Help Desk**\r\n\r\nThe HDF Group provides a free Help Desk for bug reports and support:\r\n\r\n * URL: https://help.hdfgroup.org\r\n\r\nReference: README.md#help-and-support states: \"The HDF Group staffs a free Help Desk accessible at https://help.hdfgroup.org and also monitors the Forum. Our free support service is community-based and handled as time allows.\"\r\n\r\n**3 HDF Forum**\r\n\r\nUsers can report bugs and discuss issues on the HDF Forum:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n\r\nReference: README.md#forum-and-news states: \"The HDF Forum is provided for public announcements, technical questions, and discussions of interest to the general HDF5 Community.\"\r\n\r\n**4 Issue Tracker is Searchable and Public**\r\n\r\nThe GitHub issue tracker is:\r\n\r\n * Publicly accessible\r\n * Searchable\r\n * Does not require proprietary software\r\n * Allows new users to participate\r\n\r\nReference: CONTRIBUTING.md confirms GitHub Issues are used for bug reports and feature requests\r\n\r\n**5 Bug Report Requirements**\r\n\r\nCONTRIBUTING.md describes when to open issues:\r\n\r\n * \"Required unless the change is minor (e.g., typo fix)\"\r\n * \"Describe the problem or feature request clearly\"\r\n\r\nURL: https://github.com/HDFGroup/hdf5/issues The project provides a clear process for users to submit bug reports through GitHub Issues (primary), Help Desk, and the HDF Forum.","report_responses_status":"Met","report_responses_justification":"The project has a triage procedure for issues as they come in:\r\n\r\n**1 GitHub Project for Triage**\r\n\r\nThe project uses GitHub Projects for issue triage:\r\n\r\n * URL: https://github.com/orgs/HDFGroup/projects/39\r\n\r\nThis is the project management board where issues are triaged and tracked.\r\n\r\n**2 Release Progress Tracking**\r\n\r\nREADME.md references this project board:\r\n\r\n * \"Release Progress\" badge links to: https://github.com/orgs/HDFGroup/projects/39/views/24\r\n * The badge shows current progress of release-blocking issues\r\n\r\nReference: README.md#release-progress states: \"The badge above shows the current progress of release-blocking issues with colors that reflect completion status\" \"Click the badge to view the detailed project board with current release-blocking issues.\"\r\n\r\n**3 Active Project Management**\r\n\r\nThe project board indicates:\r\n\r\n * Issues are categorized and tracked\r\n * Release-blocking issues are identified\r\n * Progress is monitored with completion percentages\r\n * Multiple views available (view/24 suggests different perspectives on the same issues)\r\n\r\n**4 Organizational Structure**\r\n\r\nThe project board is at the organization level (orgs/HDFGroup/projects/39):\r\n\r\n * Centralized issue management\r\n * Visible to the community\r\n * Integrated with GitHub Issues workflow\r\n\r\n**5 Triage Indicators**\r\n\r\nThe existence of this project board suggests:\r\n\r\n * Issues are reviewed and categorized as they come in\r\n * Release-blocking vs non-blocking issues are identified\r\n * Priority and status are tracked\r\n * Progress is publicly visible\r\n\r\nURL: https://github.com/orgs/HDFGroup/projects/39 The project has an active triage procedure using GitHub Projects (project #39) to manage and categorize issues as they are submitted.","enhancement_responses_status":"Met","enhancement_responses_justification":"Enhancement requests are responded to through a weekly triage procedure:\r\n\r\n**1 Weekly Triage Procedure**\r\n\r\n Enhancement requests are responded to weekly through the triage procedure using the GitHub Projects board:\r\n\r\n * URL: https://github.com/orgs/HDFGroup/projects/39\r\n\r\nThis ensures regular review and response to incoming enhancement requests.","report_archive_status":"Met","report_archive_justification":"The project has publicly available archives for reports and responses that are searchable:\r\n\r\n**1 GitHub Issues Archive**\r\n\r\nGitHub Issues provides a permanent, publicly searchable archive:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n * All issues (open and closed) are archived\r\n * Searchable by keyword, label, date, author, etc.\r\n * Includes all comments and responses\r\n * Accessible without authentication for reading\r\n\r\nReference: CONTRIBUTING.md states \"Open a GitHub issue (https://github.com/HDFGroup/hdf5/issues)\"\r\n\r\n**2 GitHub Pull Requests Archive**\r\n\r\nPull requests and their discussions are archived:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/pulls\r\n * Searchable history of all pull requests\r\n * Includes code review comments and discussions\r\n * Linked to related issues\r\n\r\n**3 HDF Forum Archive**\r\n\r\nThe HDF Forum provides searchable archives:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n\r\nReference: README.md#forum-and-news states: \"These forums are provided as an open and public service for searching and reading.\"\r\n\r\n**4 Permanent Record in Git History**\r\n\r\nAll changes and their associated discussions are permanently recorded:\r\n\r\n * Commit messages reference issues (e.g., \"#5577\", \"#5380\")\r\n * Git history: https://github.com/HDFGroup/hdf5/commits/develop\r\n * Publicly accessible and searchable\r\n \r\n**5 CHANGELOG and Historical Documentation**\r\n\r\nRelease notes archive historical issues:\r\n\r\n * CHANGELOG.md archives bug fixes and enhancements\r\n * HISTORY-*.txt files contain historical issue records\r\n * References to GitHub issues and CVE numbers\r\n\r\nReference: release_docs/CHANGELOG.md contains archived issue references URL: https://github.com/HDFGroup/hdf5/issues\r\n\r\nThe project maintains publicly available, searchable archives for bug reports and responses through GitHub Issues, Pull Requests, the HDF Forum, and documentation files.","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"The project publishes the process for reporting vulnerabilities on the project site:\r\n\r\n**1 SECURITY.md File in Repository**\r\n\r\nThe project has a SECURITY.md file in the repository root that documents the vulnerability reporting process:\r\n\r\n * File location: /SECURITY.md\r\n * Publicly accessible in the repository\r\n \r\n**2 Vulnerability Reporting Process Documented**\r\n\r\nSECURITY.md clearly describes how to report vulnerabilities:\r\n\r\n * \"If you have discovered a security vulnerability in this project, please report it privately.\"\r\n * \"Do not disclose it as a public issue.\"\r\n * Provides rationale: \"This gives us time to work with you to fix the issue before public exposure\"\r\n\r\n**3 Reporting Mechanism Specified**\r\n\r\nThe document provides the specific method for reporting:\r\n\r\n * \"Please disclose it at security advisory\"\r\n * URL: https://github.com/HDFGroup/hdf5/security/advisories/new\r\n\r\nThis uses GitHub's private security advisory feature.\r\n\r\n**4 Supported Versions Documented**\r\n\r\nSECURITY.md specifies which versions receive security updates:\r\n\r\n * \"Security updates are applied only to the latest release.\"\r\n\r\nThis helps reporters understand which versions are supported.\r\n\r\n**5 GitHub Security Advisory Integration**\r\n\r\nGitHub automatically surfaces SECURITY.md to users:\r\n\r\n * Visible in the repository's \"Security\" tab\r\n * Linked from GitHub's security reporting interface\r\n * Standard location for security policies\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/SECURITY.md \r\nThe project publishes its vulnerability reporting process in SECURITY.md, instructing users to report vulnerabilities privately via GitHub Security Advisories at https://github.com/HDFGroup/hdf5/security/advisories/new.","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"The SECURITY.md file specifies how to send vulnerability information privately:\r\n\r\n**1 Private Reporting Method Specified**\r\nSECURITY.md states:\r\n * \"If you have discovered a security vulnerability in this project, please report it privately.\"\r\n * \"Do not disclose it as a public issue.\"\r\n * \"Please disclose it at security advisory\"\r\nURL provided: https://github.com/HDFGroup/hdf5/security/advisories/new\r\n\r\n**2 GitHub Security Advisories Keep Reports Private**\r\n\r\nThe specified method (GitHub Security Advisories) is a private reporting channel:\r\n\r\n * Reports submitted through this URL are private by default\r\n * Only visible to project maintainers\r\n * Not disclosed publicly until a fix is ready\r\n * Explanation Provided\r\n\r\nSECURITY.md explains why private reporting is important:\r\n * \"This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.\"\r\n\r\n\r\nURL: https://github.com/HDFGroup/hdf5/blob/develop/SECURITY.md \r\nThe project includes instructions for sending vulnerability information privately via GitHub Security Advisories at https://github.com/HDFGroup/hdf5/security/advisories/new.","vulnerability_report_response_status":"Met","vulnerability_report_response_justification":"There is SECURITY.md which directs reporters to the Vulnerability Disclosure Policy for triage timelines.\r\n\r\nThe SSP Vulnerability Disclosure Policy commits to:\r\n\r\nStandard track: Acknowledge report within 3 business days\r\nAccelerated track: Acknowledge report within 1 business day (for actively exploited vulnerabilities)\r\nBoth are well under the ≤ 14 day requirement.","build_status":"Met","build_justification":"The project provides a working build system that automatically rebuilds the software from source code:\r\n\r\n**1 CMake Build System**\r\n\r\nThe project uses CMake as its build system:\r\n\r\n * CMake minimum version: 3.26\r\n * Supports automated building from source\r\n\r\nReference: CONTRIBUTING.md#building-for-development states: \"CMake is the required build system for all platforms\" Reference: CHANGELOG.md states: \"CMake minimum version is now 3.26\"\r\n\r\n**2 Build Instructions Provided**\r\n\r\nCONTRIBUTING.md provides clear build instructions.\r\n\r\n**3 Installation Documentation**\r\n\r\nREADME.md and release_docs/ directory contain build documentation:\r\n\r\n * INSTALL - General compilation and installation instructions\r\n * INSTALL_CMAKE - CMake-specific build instructions\r\n * Platform-specific instructions (INSTALL_Windows, INSTALL_Cygwin)\r\n\r\nReference: README.md#documentation\r\n\r\n**4 Automated CI/CD Builds**\r\n\r\nThe project has automated builds in CI/CD:\r\n\r\n * Multiple CI workflows shown in README.md badges\r\n * Daily builds\r\n * Platform-specific builds (Linux, Windows, macOS)\r\n \r\n**5 CMake-Only Since 2025**\r\n\r\nREADME.md confirms:\r\n\r\n * \"Starting with HDF5 2.0, only the CMake build system is supported.\"\r\n * Autotools was removed March 10, 2025\r\n\r\nThe project provides CMake as a working build system that automatically rebuilds the software from source code.","build_common_tools_status":"Met","build_common_tools_justification":"The project uses CMake, which is a common and widely used build tool:\r\n\r\n**1 CMake is a Common Build Tool**\r\n\r\nCMake is one of the most widely-used cross-platform build systems:\r\n\r\n * Industry standard for C/C++ projects\r\n * Used by thousands of open-source and commercial projects\r\n * Supported on all major platforms (Linux, Windows, macOS)\r\n\r\n**2 Required Build Tool**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"CMake is required\"\r\n * \"CMake is the required build system for all platforms\"\r\n\r\nThe project uses CMake, a common and widely adopted build tool.","build_floss_tools_status":"Met","build_floss_tools_justification":"The project can be built using only FLOSS (Free/Libre and Open Source Software) tools:\r\n\r\n**1 Build System - CMake**\r\n\r\nCMake is FLOSS:\r\n\r\n * License: BSD 3-Clause\r\n * Open source and freely available\r\n\r\n**2 Compilers - GCC and Clang**\r\n\r\nThe project supports FLOSS compilers:\r\n\r\n * GCC (GNU Compiler Collection) - GPL licensed\r\n * Clang/LLVM - Apache 2.0/NCSA licensed\r\n \r\nBoth are fully open source\r\nNote: MSVC (Microsoft Visual C++) is also supported on Windows, but is not required. Reference: CONTRIBUTING.md states \"A C11-compatible C compiler (MSVC on Windows is supported)\" - indicating MSVC is optional, not required.\r\n\r\n**3 Version Control - Git**\r\n\r\nGit is FLOSS:\r\n\r\n * License: GPL v2\r\n * Open source\r\n\r\n**4 Other Required Tools are FLOSS**\r\n\r\nCONTRIBUTING.md lists required tools, all FLOSS:\r\n * Perl - Artistic License/GPL\r\n * Make (Unix Makefiles) - GPL (For older versions of HDF5)\r\n\r\n**5 Recommended Tools are FLOSS**\r\n\r\nAll recommended tools are FLOSS:\r\n\r\n * clang-format - Apache 2.0/NCSA\r\n * Doxygen - GPL\r\n * codespell - GPL\r\n\r\nThe project can be built entirely using FLOSS tools (CMake, GCC/Clang, Git, Perl, Make) without requiring any proprietary software.","test_status":"Met","test_justification":"**1 Automated Test Suite Exists**\r\n\r\nThe project has test suites in the repository:\r\n\r\n * test/ directory - C library tests\r\n * testpar/ directory - Parallel C library tests\r\n * c++/test/ - C++ wrapper tests\r\n * fortran/test/ - Fortran wrapper tests\r\n\r\n**2 Test Suite is FLOSS**\r\n\r\nThe test suite is part of the HDF5 repository:\r\n\r\n * Licensed under BSD 3-Clause (same as main project)\r\n * Publicly available in the repository\r\n\r\n**3 Documentation on Running Tests**\r\n\r\nCONTRIBUTING.md documents testing:\r\n\r\n * \"Build and test thoroughly\"\r\n * \"Ensure all tests pass\"\r\n * \"All new functionality and bug fixes must include tests\"\r\n * Test structure documented with examples using h5test.h macros\r\n\r\nReference: CONTRIBUTING.md#testing\r\n\r\n**4 CI System Shows Test Execution**\r\n\r\n README.md shows active CI with automated tests:\r\n * Multiple CI badges indicating automated testing\r\n * Daily builds with tests\r\n * Platform-specific test runs\r\n\r\n**5 CMake Test Integration**\r\n\r\nTests run via CMake:\r\n\r\n * CMakeLists.txt files in test directories\r\n * Standard CMake test commands (ctest)\r\n\r\nThe project uses automated test suites (in test/ and testpar/ directories) that are FLOSS-licensed and documented in CONTRIBUTING.md, with execution shown via CI badges in README.md.","test_invocation_status":"Met","test_invocation_justification":"The project uses CMake with CTest, which is the standard way to invoke tests for CMake-based C/C++ projects:\r\n\r\n * Standard command: ctest or make test\r\n * CMakeLists.txt files in test directories configure tests\r\n * Standard CMake test infrastructure\r\n\r\nReference: CONTRIBUTING.md mentions \"Ensure tests run and pass under CMake\" and \"Update CMakeLists.txt in the test/ directory\" The test suite is invocable using standard CMake/CTest commands.","test_most_status":"Met","test_most_justification":"Minimum automated testing is performed on branches, as features, bug fixes, and enhancements are derived from forks rather than the central HDF5 repository. Branches associated with releases are tested automatically.\r\n\r\n**1 Coverage Reporting to CDash**\r\n\r\nREADME.md provides link to coverage results:\r\n\r\n* \"HPC configure/build/test results\" at https://my.cdash.org/index.php?project=HDF5\r\n* CDash provides centralized test and coverage reporting\r\n* Public visibility of coverage metrics\r\n\r\n**2 Automated Coverage Analysis**\r\n\r\n.github/workflows/analysis.yml runs coverage testing:\r\n\r\n* Coverage test job: \"Ubuntu GCC Coverage\"\r\n* Uses lcov for coverage collection\r\n* DHDF5_ENABLE_COVERAGE:BOOL=ON\r\n* CODE_COVERAGE:BOOL=ON\r\n* Automated coverage generation and reporting\r\n\r\n**3 Code Coverage Infrastructure**\r\n\r\nconfig/sanitizer/code-coverage.cmake provides coverage support:\r\n\r\n* GCC/LCOV support\r\n* Clang/llvm-cov support\r\n* Multiple coverage targets for different granularity\r\n* HTML coverage reports generated\r\n\r\nReference: config/sanitizer/README.md documents extensive code coverage capabilities\r\n\r\n**4 Extensive Test Suite**\r\n\r\nThe project has comprehensive tests across multiple directories:\r\n\r\n* test/ - C library tests\r\n* testpar/ - Parallel C library tests\r\n* c++/test/ - C++ wrapper tests\r\n* fortran/test/ - Fortran wrapper tests\r\n* tools/test/ - Command-line tools tests\r\n\r\n**5 Test Policy Requires Tests for New Code**\r\n\r\nCONTRIBUTING.md mandates:\r\n\r\n* \"All new functionality and bug fixes must include tests\"\r\n* Ensures ongoing coverage improvement\r\n* Tests must be added for all code changes\r\n\r\n**6 Multiple Sanitizers Provide Branch Coverage**\r\n\r\n.github/workflows/analysis.yml runs multiple sanitizers:\r\n\r\n* AddressSanitizer\r\n* LeakSanitizer\r\n* UndefinedBehaviorSanitizer\r\n\r\nThese dynamic analysis tools exercise code paths to detect issues and provide functional coverage verification.\r\n\r\n**7 CVE Regression Tests**\r\n\r\nREADME.md shows CVE regression testing:\r\n\r\n* Tests for previously fixed vulnerabilities\r\n* Ensures critical code paths are covered\r\n* Validates security-sensitive functionality\r\n\r\n**8 OSS-Fuzz for Input Coverage**\r\n\r\nOSS-Fuzz integration provides:\r\n\r\n* Automated fuzzing of input handling code\r\n* Explores different input combinations\r\n* Discovers edge cases and boundary conditions\r\n\r\nThe project has comprehensive test coverage tracked through CDash, with automated coverage analysis in CI/CD, extensive test suites across all components, and mandatory testing requirements for new code.","test_policy_status":"Met","test_policy_justification":"CONTRIBUTING.md explicitly states the policy:\r\n\r\n * \"All new functionality and bug fixes must include tests.\"\r\n\r\nThis is a clear, mandatory policy requiring tests for new functionality. Reference: CONTRIBUTING.md#adding-new-tests states:\r\n\r\n * \"All new functionality and bug fixes must include tests.\"\r\n * \"Add tests to existing test files when appropriate.\"\r\n * \"Create new test programs using h5test.h macros.\"\r\n\r\nThe project has a formal policy requiring tests for all new functionality.","tests_are_added_status":"Met","tests_are_added_justification":"**1 Recent Major Changes Include Tests**\r\n\r\nThe CHANGELOG.md for version 2.0.1 documents extensive major changes with corresponding test evidence:\r\n\r\n * Bug fixes reference GitHub issues that include test cases\r\n * Security fixes (CVEs) have regression tests\r\n * CI badge shows \"CVE regression\" testing\r\n\r\n**2 CVE Regression Testing**\r\n\r\nREADME.md shows active CVE regression testing:\r\n\r\n * CVE regression CI badge indicates automated testing of security fixes\r\n * Multiple CVEs fixed in recent release with tests\r\n\r\n**3 Test Requirements Enforced in CI**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * CI system validates that tests pass before merging\r\n\r\n**4 Maven Testing for Java Changes**\r\n\r\nRecent major Java enhancements include comprehensive testing:\r\n\r\n * \"Complete Java examples Maven integration with cross-platform CI/CD testing\"\r\n * Maven artifact validation scripts\r\n * Multi-platform testing workflows\r\n\r\nReference: CHANGELOG.md#java-enhancements\r\n\r\n**5 Pull Request References Show Test Integration**\r\n\r\nRecent commits reference pull requests (#6070, #6075, #6039, #6049, #6066), which go through CI testing before merge. The project demonstrates adherence to its test policy through CI enforcement, CVE regression testing, and documented test requirements for recent major changes.","tests_documented_added_status":"Met","tests_documented_added_justification":"CONTRIBUTING.md documents the test policy in the instructions for change proposals:\r\n\r\n**1 In the Workflow Section**\r\n\r\nStep 3 under \"Make your changes\":\r\n * \"Add tests for new functionality or bug fixes.\"\r\n\r\n**2 In the Adding New Tests Section**\r\n\r\nExplicit documentation:\r\n * \"All new functionality and bug fixes must include tests.\"\r\n\r\n**3 In the Checklist for Contributors**\r\n\r\nTesting checklist item:\r\n\r\n * \"Pull request includes tests.\"\r\n\r\n**4 In the Acceptance Criteria Section**\r\n\r\nTesting requirement for pull request acceptance:\r\n\r\n * \"Testing: Must pass HDF5 regression testing and include appropriate tests.\"\r\n\r\nReference: CONTRIBUTING.md#contributing-changes, CONTRIBUTING.md#adding-new-tests, and CONTRIBUTING.md#checklist-for-contributors The test policy is documented in multiple sections of CONTRIBUTING.md where change proposals and pull requests are described.","warnings_status":"Met","warnings_justification":"**1 Compiler Warning Flags Enabled**\r\n\r\nCONTRIBUTING.md states:\r\n\r\n * \"The CI system builds with -Werror\"\r\n * \"HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\" option available for extra warnings\r\n * \"fix all compiler warnings before submitting pull requests\"\r\n\r\n**2 Developer Mode Warnings**\r\n\r\nCONTRIBUTING.md documents developer build options:\r\n * \"HDF5_ENABLE_DEVELOPER_MODE=ON\" enables \"warnings as errors\"\r\n * \"Developer Warnings: Enable extra warnings with HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\"\r\n\r\n**3 Linter Tool - clang-format**\r\n\r\nCONTRIBUTING.md lists clang-format as a recommended tool:\r\n\r\n * \"clang-format: For code formatting. The CI system will automatically format pull requests if needed.\"\r\n\r\n**4 CI Enforcement**\r\n\r\nThe CI system enforces code quality:\r\n\r\n * Builds with -Werror (warnings treated as errors)\r\n * Automatic code formatting\r\n * Must pass before pull request acceptance\r\n\r\nReference: CONTRIBUTING.md#prerequisites and CONTRIBUTING.md#developer-build-tips The project enables compiler warning flags (-Werror), uses clang-format for linting, and enforces these in CI.","warnings_fixed_status":"Met","warnings_fixed_justification":"CONTRIBUTING.md explicitly requires addressing warnings:\r\n\r\n * \"The CI system builds with -Werror, so fix all compiler warnings before submitting pull requests.\"\r\n\r\nThis policy ensures:\r\n\r\n * Warnings are treated as errors in CI builds\r\n * All warnings must be fixed before code can be merged\r\n * Pull requests cannot be accepted with warnings\r\n\r\nReference: CONTRIBUTING.md#developer-build-tips The project requires all compiler warnings to be addressed before pull request submission.","warnings_strict_status":"Met","warnings_strict_justification":"CONTRIBUTING.md shows the project is maximally strict with warnings:\r\n\r\n**1 Warnings as Errors Required**\r\n\r\n * \"The CI system builds with -Werror\" (treats all warnings as errors)\r\n * Mandatory for all pull requests\r\n\r\n**2 Additional Developer Warnings Available**\r\n * \"HDF5_ENABLE_DEV_WARNINGS:BOOL=ON\" enables extra warnings\r\n * \"generates significant output but can be useful\"\r\n\r\n**3 Developer Mode Strictness**\r\n * \"HDF5_ENABLE_DEVELOPER_MODE=ON\" enables \"warnings as errors\"\r\n * Recommended for development builds\r\n\r\nReference: CONTRIBUTING.md#developer-build-tips The project uses the strictest possible warning level with -Werror in CI and optional extra warnings for developers.","know_secure_design_status":"Met","know_secure_design_justification":"Evidence that primary developers understand secure software design principles:\r\n\r\n**1 Economy of Mechanism**\r\n\r\nCONTRIBUTING.md enforces simplicity:\r\n\r\n * \"Avoid over-engineering. Only make changes that are directly requested or clearly necessary.\"\r\n * \"Don't create helpers, utilities, or abstractions for one-time operations.\"\r\n * \"The right amount of complexity is the minimum needed for the current task\"\r\n\r\n**2 Fail-Safe Defaults**\r\n\r\nSecurity fixes show fail-safe approach:\r\n\r\n * CVE-2025-2915: \"Added validation in H5O__mdci_decode to detect and reject invalid values early\"\r\n * CVE-2025-6750: \"allow invalid message size to be detected\"\r\n * Default error handling with HGOTO_ERROR macro\r\n\r\n**3 Complete Mediation**\r\n\r\nCONTRIBUTING.md shows validation practices:\r\n\r\n * \"Always check return values of functions that can fail\"\r\n * Function structure includes parameter checks: \"HDassert(/parameter check/)\"\r\n\r\n**4 Open Design**\r\n\r\nThe project is fully open source:\r\n\r\n * All security mechanisms in public repository\r\n * Security fixes documented in CHANGELOG.md\r\n * No security through obscurity\r\n\r\n**5 Least Privilege**\r\n\r\nCONTRIBUTING.md describes function visibility levels:\r\n\r\n * Public, Private, and Package scopes\r\n * \"Package: Used only within the defining package\"\r\n * Minimizes exposure of internal APIs\r\n\r\n**6 Input Validation with Allowlists**\r\n\r\nMultiple CVE fixes demonstrate input validation:\r\n\r\n * CVE-2025-2915: \"Added validation...to detect and reject invalid values early, preventing the overflow condition\"\r\n * CVE-2025-6816 series: \"checking the expected number of object header chunks against the actual value\"\r\n * CVE-2025-2925: \"checks for an image buffer length of 0 before calling H5MM_realloc\"\r\n * \"Check for overflow in decoded heap block addresses\"\r\n\r\n**7 Limited Attack Surface**\r\n\r\nCONTRIBUTING.md enforces minimalism:\r\n\r\n * Three-tier API (Public/Private/Package) limits attack surface\r\n * \"Don't add features...beyond what was asked\"\r\n\r\n**8 OWASP Awareness**\r\n\r\nCONTRIBUTING.md explicitly mentions security:\r\n\r\n * \"Be careful not to introduce security vulnerabilities such as command injection, XSS, SQL injection, and other OWASP top 10 vulnerabilities.\"\r\n\r\n**9 Professional Security Practices**\r\n\r\n * Private vulnerability disclosure (SECURITY.md)\r\n * CVE regression testing\r\n * 15+ CVEs fixed in recent release with detailed technical understanding\r\n * Bounds checking, input validation, safe cleanup practices\r\n\r\nThe project demonstrates knowledge of secure design principles through documented policies, extensive security fixes showing deep understanding, and explicit security requirements in the contribution guidelines.","know_common_errors_status":"Met","know_common_errors_justification":"Evidence that primary developers know common vulnerability types and mitigations:\r\n\r\n**1 Buffer Overflows - Known and Mitigated**\r\n\r\nMultiple CVE fixes demonstrate understanding:\r\n\r\n * CVE-2025-7067: \"Fixed a heap buffer overflow in H5FS__sinfo_serialize_node_cb()\" - Mitigation: \"discarding file free space sections...when they are found to be invalid\"\r\n * CVE-2025-2915: \"Fixed a heap-based buffer overflow...caused by an integer overflow\" - Mitigation: \"Added validation...to detect and reject invalid values early\"\r\n * CVE-2025-6750: \"A heap buffer overflow occurred because an mtime message was not properly decoded\" - Mitigation: \"decoding old and new mtime messages which will allow invalid message size to be detected\"\r\n\r\n**2 Integer Overflows - Known and Mitigated**\r\n\r\n * CVE-2025-2915: \"integer overflow when calculating new_accum_size\" - Mitigation: validation to prevent overflow\r\n * \"Check for overflow in decoded heap block addresses\" - Mitigation: \"added a check in H5HL__fl_deserialize to ensure no overflow can occur\"\r\n\r\n**3 Memory Leaks and Resource Management - Known and Mitigated**\r\n\r\n * CVE-2025-7068: \"could cause the library to skip calling the callback to free the cache entry. This could result in resource leaks\" - Mitigation: \"attempting to fully free a cache entry before signalling that an error has occurred\"\r\n * CVE-2025-6269: \"memory leaks\" - Mitigation: \"safe cleanup\"\r\n\r\n**4 Double-Free Vulnerabilities - Known and Mitigated**\r\n\r\n * CVE-2025-2925: \"it was freed again in done, causing a double-free vulnerability\" - Mitigation: \"H5C__load_entry() now checks for an image buffer length of 0 before calling H5MM_realloc\"\r\n\r\n**5 Stack Overflows - Known and Mitigated**\r\n\r\n * CVE-2025-6857: \"An HDF5 file had a corrupted v1 B-tree that would result in a stack overflow\" - Mitigation: \"additional integrity checks\"\r\n\r\n**6 Input Validation Failures - Known and Mitigated**\r\n\r\n * CVE-2025-2913, CVE-2025-2926: \"The size of a continuation message was decoded as 0, causing multiple vulnerabilities\" - Mitigation: \"An error check was added to return failure to prevent further processing of invalid data\"\r\n * CVE-2025-6816 series: \"corrupted object header with a continuation message that points back to itself\" - Mitigation: \"checking the expected number of object header chunks against the actual value\"\r\n\r\n**7 OWASP Top 10 Awareness**\r\n\r\nCONTRIBUTING.md explicitly requires:\r\n\r\n * \"Be careful not to introduce security vulnerabilities such as command injection, XSS, SQL injection, and other OWASP top 10 vulnerabilities.\"\r\n\r\n**8 Bounds Checking**\r\n\r\n * CVE-2025-6269: \"buffer overflows\" - Mitigation: \"bounds checks, input validation\"\r\n\r\n**9 Common Mitigation Techniques Used**\r\n\r\n * Early validation and rejection of invalid input\r\n * Bounds checking before operations\r\n * Safe cleanup and error handling\r\n * Integer overflow detection\r\n * Resource leak prevention\r\n\r\nThe project demonstrates comprehensive knowledge of common vulnerability types (buffer overflows, integer overflows, memory leaks, double-frees, stack overflows) and proper mitigation techniques through extensive CVE remediation and explicit security requirements.","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"The project uses delivery mechanisms that counter MITM attacks:\r\n\r\n**1 HTTPS for Downloads**\r\n\r\nAll download URLs use HTTPS:\r\n\r\n * https://support.hdfgroup.org/releases/hdf5/v1_14/index.html\r\n * https://support.hdfgroup.org/archive/support/ftp/HDF5/releases/index.html\r\n * https://github.com/HDFGroup/hdf5/releases/tag/snapshot\r\n\r\n**2 HTTPS for Git Repository**\r\n\r\nSource code repository uses HTTPS:\r\n\r\n * https://github.com/HDFGroup/hdf5.git\r\n\r\nGit also supports SSH:\r\n\r\n * git@github.com:HDFGroup/hdf5.git\r\n\r\n**3 HTTPS for Maven Artifacts**\r\n\r\nMaven package repository uses HTTPS:\r\n\r\n * https://maven.pkg.github.com/HDFGroup/hdf5\r\n\r\n**4 All Project URLs Use HTTPS**\r\n\r\nPreviously verified that all project sites use HTTPS:\r\n\r\n * Website: https://www.hdfgroup.org/\r\n * Documentation: https://support.hdfgroup.org/documentation/hdf5/latest\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md and earlier analysis The project uses HTTPS for all delivery mechanisms (downloads, Git repository, Maven artifacts), which counters MITM attacks.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"**1 No HTTP Hash Retrieval Found**\r\n\r\n**2 All Downloads Use HTTPS**\r\n\r\nExternal downloads in CI workflows use HTTPS, not HTTP\r\n\r\n**3 HTTP Timestamp Server Not Hash Retrieval**\r\n\r\nThe only HTTP usage is:\r\n\r\n * ctest.yml line 190: timestamp-rfc3161: http://timestamp.acs.microsoft.com\r\n * This is for code signing timestamp, not retrieving cryptographic hashes\r\n\r\nThe project does NOT retrieve cryptographic hashes over HTTP.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"For published (publicly known) advisories, we currently satisfy this criterion. \r\nNone of the published medium+ advisories are unpatched and older than 60 days.","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"Policy commitment: The SSP Vulnerability Disclosure Policy defines two tracks:\r\n\r\nAccelerated track (actively exploited): Fix within 7-10 days\r\nStandard track: Fix within 90 days\r\n\r\nIn practice, published advisories look good:\r\nFor past history, the 3 published advisories were all handled within reasonable timeframes, and the one real critical/high item (GHSA-5p2m-j456-9mr2, high severity) was published with a patch already available.","static_analysis_status":"Met","static_analysis_justification":"CodeQL— it's a FLOSS static analysis tool that goes well beyond compiler warnings\r\nIt runs automatically in CI via .github/workflows/codeql.yml on every push/PR to develop, which is the branch from which releases are cut\r\nUses the security-and-quality query suite covering CWEs specific to C/C++","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"Primary: CodeQL (.github/workflows/codeql.yml)\r\n\r\nRuns the security-and-quality query set on C/C++, which explicitly includes rules for common vulnerabilities: buffer overflows, SQL injection, command injection, TOCTOU races, null dereferences, etc.","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"satisfies the criterion because medium- and high-severity issues are triaged and confirmed as non-exploitable or exploitable, and fixed.","static_analysis_often_status":"Met","static_analysis_often_justification":"Yes, met. The CodeQL workflow in .github/workflows/codeql.yml runs on:\r\n\r\n*Every push to develop\r\n*Every pull request targeting develop\r\n*Weekly scheduled run (Sundays at 7:16 UTC)","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Evidence that dynamic analysis tools are applied before major production releases:\r\n\r\n**1 Multiple Sanitizers in Analysis Workflow**\r\n\r\n * .github/workflows/analysis.yml runs dynamic analysis before releases:\r\n * LeakSanitizer: \"detects memory leaks\"\r\n * AddressSanitizer: \"fast memory error detector\" for buffer overflows, use-after-free, etc.\r\n * UndefinedBehaviorSanitizer: detects undefined behavior at runtime\r\n\r\n**2 Analysis Workflow Integrated into Release Process**\r\n\r\nFrom .github/workflows/daily-build.yml:\r\n * uses: ./.github/workflows/analysis.yml\r\n * This calls the analysis workflow as part of the build process\r\n\r\n**3 Sanitizer Infrastructure Available**\r\n\r\nFrom config/sanitizer/sanitizers.cmake and config/sanitizer/README.md document:\r\n\r\n * HDF5_USE_SANITIZER CMake variable\r\n * Support for Address, Memory, Undefined, Thread, Leak, and CFI sanitizers\r\n * All are FLOSS dynamic analysis tools from LLVM/Clang\r\n\r\nReference: config/sanitizer/README.md states: \"Sanitizers are tools that perform checks during a program's runtime\"\r\n\r\n**4 Coverage Analysis**\r\n\r\nFrom .github/workflows/analysis.yml:\r\n\r\n * Code coverage testing with gcov/lcov\r\n * While primarily for coverage metrics, it requires executing tests (dynamic analysis)\r\n\r\n**5 OSS-Fuzz Integration**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n * Continuous fuzzing (dynamic analysis for vulnerability detection)\r\n * Indicates ongoing dynamic analysis\r\n\r\n**6 Sanitizers Run on Multiple Configurations**\r\n\r\nanalysis.yml shows sanitizers run with:\r\n\r\n * Different compilers (Clang)\r\n * Different configurations\r\n * Automated in CI/CD pipeline\r\n\r\nThe project applies multiple FLOSS dynamic analysis tools (LeakSanitizer, AddressSanitizer, UndefinedBehaviorSanitizer, and fuzzing) before releases through automated workflows.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Evidence that dynamic tools are routinely used with memory safety detection for C/C++ code:\r\n\r\n**1 HDF5 is Written in Memory-Unsafe Languages**\r\n\r\nThe project is primarily written in C (with C++ and Fortran wrappers):\r\n\r\n * CONTRIBUTING.md requires \"A C11-compatible C compiler\"\r\n * Source code in src/ is C code\r\n * This is a memory-unsafe language\r\n\r\n**2 AddressSanitizer Detects Memory Safety Problems**\r\n\r\n.github/workflows/analysis.yml runs AddressSanitizer:\r\n * CTEST_MEMORYCHECK_TYPE \"AddressSanitizer\"\r\n * HDF5_USE_SANITIZER:STRING=Address\r\n\r\nAddressSanitizer detects:\r\n\r\n * Buffer overflows (overwrites)\r\n * Use-after-free\r\n * Double-free\r\n * Out-of-bounds accesses\r\n\r\nReference: config/sanitizer/README.md states AddressSanitizer \"is useful for detecting most issues dealing with memory, such as: Out of bounds accesses to heap, stack, global\"\r\n\r\n**3 LeakSanitizer for Memory Leaks**\r\n\r\n.github/workflows/analysis.yml runs LeakSanitizer:\r\n\r\n * CTEST_MEMORYCHECK_TYPE \"LeakSanitizer\"\r\n * HDF5_USE_SANITIZER:STRING=Leak\r\n\r\n**4 OSS-Fuzz for Fuzzing**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n * Active fuzzing integration\r\n * Fuzzing is a dynamic tool that generates test inputs\r\n * Combined with sanitizers to detect memory safety issues\r\n\r\n**5 Routine Use Through CI/CD**\r\n\r\nThe sanitizers run automatically:\r\n\r\n * .github/workflows/daily-build.yml calls analysis.yml\r\n * Runs on daily schedule\r\n * Integrated into continuous testing\r\n\r\n**6 Multiple Memory Safety Mechanisms**\r\n\r\nThe project combines:\r\n\r\n * Fuzzing (OSS-Fuzz) - dynamic input generation\r\n * AddressSanitizer - detects buffer overwrites and memory errors\r\n * LeakSanitizer - detects memory leaks\r\n * UndefinedBehaviorSanitizer - detects undefined behavior\r\n\r\nThe project routinely uses fuzzing (OSS-Fuzz) combined with AddressSanitizer to detect memory safety problems including buffer overwrites in its C/C++ code.","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"The project uses configurations with assertions enabled for dynamic analysis:\r\n\r\n**1 Developer Mode Enables Assertions**\r\n\r\nCONTRIBUTING.md documents developer build options:\r\n\r\n* HDF5_ENABLE_DEVELOPER_MODE=ON enables developer-friendly settings\r\n* Developer mode is recommended for development builds\r\n\r\n**2 Sanitizer Builds Use Debug Configuration**\r\n\r\n.github/workflows/analysis.yml runs sanitizers with Debug configuration:\r\n\r\n* Coverage test: ctest -S HDF5config.cmake...CTEST_SOURCE_NAME=${{ steps.set-file-base.outputs.SOURCE_BASE }} -C Debug\r\n* LeakSanitizer runs with -C Debug\r\n* AddressSanitizer runs with -C Debug\r\n* UndefinedBehaviorSanitizer runs with -C Debug\r\n\r\nDebug builds typically enable assertions that are disabled in release builds.\r\n\r\n**3 Assertion Macros in Code**\r\n\r\nCONTRIBUTING.md shows assertion usage in function structure:\r\n\r\n* FUNC_ENTER_NOAPI(FAIL)\r\n\r\nHDassert(/*parameter check*/);\r\n\r\nThe HDassert macro is used throughout the codebase for parameter checking.\r\n\r\n**4 Memory Checker Configuration**\r\n\r\nCONTRIBUTING.md documents memory checking option:\r\n\r\n* HDF5_ENABLE_USING_MEMCHECKER:BOOL=ON when using tools like Valgrind\r\n* This disables internal memory pools to enable better error detection\r\n\r\nReference: \"Use HDF5_ENABLE_USING_MEMCHECKER:BOOL=ON when using tools like Valgrind. This disables internal memory pools that can hide memory issues.\"\r\n\r\n**5 Sanitizer Configuration Separate from Production**\r\n\r\n.github/workflows/analysis.yml shows sanitizer builds are separate:\r\n\r\n* Different workflow from production builds\r\n* Uses specific build options not used in production\r\n* Runs in \"Sanitize\" group/model\r\n\r\n**6 Coverage Build Uses Debug Settings**\r\n\r\n.github/workflows/analysis.yml coverage test:\r\n\r\n* LOCAL_COVERAGE_TEST \"TRUE\"\r\n* DHDF5_ENABLE_COVERAGE:BOOL=ON\r\n* Coverage builds run with instrumentation not suitable for production\r\n\r\nThe project uses Debug configuration with assertions enabled for dynamic analysis (sanitizers, fuzzing, testing), which are separate from production builds.","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"**1 Extensive CVE Fixes Documented**\r\n\r\nCHANGELOG.md shows that numerous security vulnerabilities have been fixed:\r\n\r\n* CVE-2025-7067 - Heap buffer overflow in H5FS__sinfo_serialize_node_cb()\r\n* CVE-2025-2915 - Heap-based buffer overflow in H5F__accum_free\r\n* CVE-2025-7068 - Resource leaks in metadata cache\r\n* CVE-2025-6816, CVE-2025-6818, CVE-2025-6856, CVE-2025-2923 - Object header vulnerabilities\r\n\r\nAnd many more...\r\n\r\n**2 OSS-Fuzz Integration for Discovery**\r\n\r\nREADME.md shows OSS-Fuzz badge:\r\n\r\n* Continuous fuzzing (dynamic analysis) for vulnerability detection\r\n* OSS-Fuzz reports vulnerabilities that are then fixed\r\n\r\nReference: OSS-Fuzz badge indicates active participation in continuous fuzzing program\r\n\r\n**3 CVE Regression Testing**\r\n\r\nREADME.md shows CVE regression CI badge:\r\n\r\n* Automated testing to ensure CVE fixes remain effective\r\n* Prevents reintroduction of vulnerabilities\r\n\r\n**4 Security Advisory Process**\r\n\r\nSECURITY.md documents vulnerability handling:\r\n\r\n* Private disclosure process for security vulnerabilities\r\n* \"This gives us time to work with you to fix the issue before public exposure\"\r\n* Shows commitment to fixing vulnerabilities before disclosure\r\n\r\n**5 GitHub Issues Track Vulnerabilities**\r\n\r\nCHANGELOG.md references GitHub issues for each CVE:\r\n\r\n* \"Fixes GitHub issue #5577\" (CVE-2025-7067)\r\n* \"Fixes GitHub issue #5380\" (CVE-2025-2915)\r\n* \"Fixes GitHub issue #5578\" (CVE-2025-7068)\r\n\r\nShows systematic tracking and resolution\r\n\r\n**6 Multiple Fixes in Single Release**\r\n\r\nVersion 2.0.0 includes fixes for 10+ CVEs, demonstrating:\r\n\r\n* Active vulnerability remediation\r\n* Timely response to discovered issues\r\n* Comprehensive fixes are released together\r\n\r\n**7 Sanitizer Findings Are Addressed**\r\n\r\nThe project runs sanitizers routinely:\r\n\r\n* AddressSanitizer, LeakSanitizer, UndefinedBehaviorSanitizer\r\n* Findings from these tools are used to fix memory safety issues\r\n* Many CVE fixes mention sanitizer-detectable issues (buffer overflows, use-after-free, memory leaks)\r\n\r\nThe project demonstrates timely fixing of exploitable vulnerabilities discovered through dynamic analysis (fuzzing, sanitizers), with extensive CVE fixes documented in CHANGELOG.md and systematic tracking through GitHub issues.","general_comments":"","created_at":"2023-09-05T17:54:26.295Z","updated_at":"2026-03-19T04:36:25.542Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"**1 Multiple CI Workflows**\r\n\r\nREADME.md displays numerous CI badges showing active continuous integration:\r\n\r\n * develop cmake build status\r\n * HDF5 develop daily build\r\n * netCDF build status\r\n * h5py build status\r\n * CVE regression\r\n * HDF5 VOL connectors build status\r\n * HDF5 VFD build status\r\n * Link checker status\r\n\r\n**2 GitHub Actions**\r\n\r\nThe project uses GitHub Actions for CI:\r\n\r\n * .github/workflows/ directory contains CI workflows\r\n * Automated testing on pull requests\r\n * Daily scheduled builds\r\n\r\n**3 CI Requirements in CONTRIBUTING.md**\r\n\r\nCONTRIBUTING.md mentions CI integration:\r\n\r\n * \"Address any formatting or testing issues reported by CI\"\r\n * \"The CI system will automatically format pull requests if needed\"\r\n * \"The CI system builds with -Werror\"\r\n\r\n**4 CDash Integration**\r\n\r\nTest results reported to CDash:\r\n\r\n * URL: https://my.cdash.org/index.php?project=HDF5\r\n\r\nThe project implements continuous integration with multiple automated workflows, daily builds, and automated testing on code changes.","cpe":"cpe:hdf5","discussion_status":"Met","discussion_justification":"The project has multiple mechanisms for discussion that meet all the requirements:\r\n\r\n**1 GitHub Issues**\r\n\r\nThe project uses GitHub Issues for bug reports, feature requests, and discussions:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/issues\r\n * Searchable: Yes, GitHub provides full search functionality\r\n * Addressable by URL: Yes, each issue has a unique URL\r\n * Open participation: Yes, anyone with a GitHub account can participate\r\n * No proprietary software: GitHub is accessible via web browser\r\n\r\nReference: CONTRIBUTING.md#contributing-changes states \"Open a GitHub issue (https://github.com/HDFGroup/hdf5/issues)\"\r\n\r\n**2 HDF Forum**\r\n\r\nThe project provides a public forum for discussions:\r\n\r\n * URL: https://forum.hdfgroup.org\r\n * HDF5 Topics: https://forum.hdfgroup.org/c/hdf5\r\n * News and Announcements: https://forum.hdfgroup.org/c/news-and-announcements-from-the-hdf-group\r\n * Searchable: Yes, described as \"open and public service for searching and reading\"\r\n * Addressable by URL: Yes, topics have unique URLs\r\n * Open participation: Yes, \"Posting requires completing a simple registration\"\r\n * No proprietary software: Web-based, accessible via browser\r\n\r\nReference: README.md#forum-and-news states \"The HDF Forum is provided for public announcements, technical questions, and discussions of interest to the general HDF5 Community.\"\r\n\r\n**3 GitHub Pull Request Discussions**\r\n\r\nPull requests enable threaded discussions about proposed changes:\r\n\r\n * URL: https://github.com/HDFGroup/hdf5/pulls\r\n * Searchable: Yes\r\n * Addressable by URL: Yes, each PR has a unique URL\r\n * Open participation: Yes, anyone can comment on public PRs\r\n * No proprietary software: Web browser access only\r\n\r\nReference: CONTRIBUTING.md#contributing-changes describes the pull request workflow URL: https://github.com/HDFGroup/hdf5/issues and https://forum.hdfgroup.org All mechanisms are searchable, URL-addressable, open to new participants, and accessible via web browsers without proprietary software installation.","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"**1 All Credentials Use GitHub Secrets**\r\n\r\nWorkflow files properly use GitHub Secrets for sensitive credentials:\r\n\r\n * ${{ secrets.AZURE_CODE_SIGNING_NAME }}\r\n * ${{ secrets.AZURE_CERT_PROFILE_NAME }}\r\n * ${{ secrets.GPG_PRIVATE_KEY }}\r\n * MAVEN_PASSWORD referenced as environment variable, not hardcoded\r\n\r\nReference: .github/workflows/ctest.yml, release.yml, maven-deploy.yml\r\n\r\n**2 Test Credentials Are Clearly Fake**\r\n\r\nThe AWS-looking credential found (AKIAIMC3D3XLYXLN5COA) is in a test file:\r\n\r\n * File: tools/libtest/h5tools_test_utils.c\r\n * Purpose: \"unit-test functionality of the routines in tools/lib/h5tools_utils\"\r\n * Context: \"real-world use case\" test case for tuple parsing\r\n * This is test data for parsing AWS credential format, not an actual working credential\r\n\r\n**3 No Private Key Files Found**\r\n\r\n * No BEGIN PRIVATE KEY blocks\r\n * No .pem, .key, id_rsa, id_dsa files\r\n * No GitHub tokens (ghp_, gho_, ghu_ patterns)\r\n * No Slack tokens (xox patterns)\r\n\r\n**4 Test Secrets Are Placeholder Values**\r\n\r\nTest code uses obviously fake values:\r\n\r\n * test/vfd.c: secret_key = \"plugh\" (Adventure game reference)\r\n * tools/libtest: Various single-character test values (\"w\", \"c\", \"z\")\r\n\r\n** 5 .gitignore Does Not Exclude Credential Files**\r\n\r\nThe .gitignore doesn't exclude .env, .pem, or credential files, suggesting no such files exist or need to be excluded. The public repository does NOT leak valid private credentials. All sensitive credentials use GitHub Secrets, and AWS-format strings found are test data for parsing functionality. \r\n\r\nGitHub provides automatic secret scanning for public repositories, alerting maintainers when known credential patterns are detected. The project uses proper secret management practices (GitHub Secrets).\r\n","english_status":"Met","english_justification":"The project provides documentation in English and accepts bug reports and comments in English:\r\n\r\n**1 Documentation in English**\r\nAll project documentation is written in English:\r\n\r\n * README.md - Written in English\r\n * CONTRIBUTING.md - Written in English\r\n * LICENSE - Written in English\r\n * INSTALL files in release_docs/ - Written in English\r\n * CHANGELOG.md - Written in English\r\n * API documentation at https://support.hdfgroup.org/documentation/hdf5/latest - Written in English\r\n * Code comments and Doxygen documentation in source files - Written in English\r\n\r\nReference: All documentation files in the repository\r\n\r\n**2 Bug Reports in English**\r\n\r\nThe project accepts bug reports in English through multiple channels:\r\n\r\n * GitHub Issues: https://github.com/HDFGroup/hdf5/issues - English language platform\r\n * Help Desk: https://help.hdfgroup.org - English language support\r\n * HDF Forum: https://forum.hdfgroup.org - Primary language is English\r\n\r\nReference: README.md#help-and-support states \"The HDF Group staffs a free Help Desk accessible at https://help.hdfgroup.org\" Reference: CONTRIBUTING.md#contributing-changes states \"Open a GitHub issue\" for reporting bugs\r\n\r\n**3 Code Comments in English**\r\n\r\nAll code comments, function documentation, and discussions in pull requests are conducted in English:\r\n\r\n * Source code comments - English\r\n * Doxygen annotations in header files - English\r\n * Pull request discussions - English\r\n * Commit messages - English\r\n\r\nReference: Source code files like src/H5Dpublic.h contain English documentation URL: https://github.com/HDFGroup/hdf5/blob/develop/README.md The project provides comprehensive documentation in English and accepts bug reports and code comments in English through GitHub Issues, the Help Desk, and the HDF Forum.","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Met","hardened_site_justification":"Found all required security hardening headers.","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2026-03-19T04:36:25.540Z","lost_passing_at":null,"last_reminder_at":"2026-01-02T23:00:13.597Z","disabled_reminders":false,"implementation_languages":"C, Java, Fortran, CMake, C++, Shell, PLSQL, M4, LiveScript, Makefile, Perl, Yacc, Scilab, JavaScript, Lex","lock_version":65,"badge_percentage_1":15,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":17,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":115,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2026-03-19T04:36:25.540Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"The project is actively maintained:\r\n\r\n**1 Recent Commit Activity**\r\n\r\nThe git status shows recent commits to the develop branch (as of 12/25):\r\n\r\n**2 Active CI/CD System**\r\n\r\nREADME.md shows multiple active CI/CD badges indicating continuous testing:\r\n\r\n * develop cmake build status\r\n * HDF5 develop daily build\r\n * netCDF build status\r\n * h5py build status\r\n * CVE regression testing\r\n * HDF5 VOL connectors build status\r\n * HDF5 VFD build status\r\n * Link checker status\r\n\r\nReference: README.md displays active build status badges\r\n\r\n**3 Active Issue and Pull Request System**\r\n\r\nThe project uses GitHub Issues and Pull Requests for ongoing maintenance:\r\n\r\n * GitHub Issues: https://github.com/HDFGroup/hdf5/issues\r\n * Pull Requests referenced in recent commits (e.g., #6070, #6075, #6039, #6049, #6066)\r\n \r\n**4 Ongoing Development Roadmap**\r\n\r\nREADME.md shows active development with planned features:\r\n\r\n * Major update on March 10, 2025 (CMake-only builds)\r\n * Future roadmap includes: Multi-threaded HDF5, crashproofing, Full SWMR, encryption, etc.\r\n\r\nReference: README.md states \"HDF5 version 2.0.1 currently under development\"\r\n\r\n**5 Dedicated Maintainer**\r\n\r\nThe HDF Group is the official maintainer:\r\n\r\n * Website: https://www.hdfgroup.org/\r\n * Help Desk: https://help.hdfgroup.org\r\n * Forum: https://forum.hdfgroup.org\r\n\r\nReference: README.md states \"The HDF Group is the developer, maintainer, and steward of HDF5 software\"\r\n\r\n**6 Regular Release Schedule**\r\n\r\nREADME.md describes the release approach:\r\n\r\n * \"HDF5 does not follow a regular release schedule. Instead, updates are based on the introduction of new features and the resolution of bugs. However, we aim to have at least one annual release for each maintenance branch.\"\r\n * Release progress badge shows active release planning\r\n\r\nURL: https://github.com/HDFGroup/hdf5 The project is actively maintained by The HDF Group with recent commits, active CI/CD, ongoing issue resolution, and planned future development.","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Scot Breitenfeld and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/8037.json b/_data/openssf/8037.json index 3db0f73..bf6a1de 100644 --- a/_data/openssf/8037.json +++ b/_data/openssf/8037.json @@ -1 +1 @@ -{"id":8037,"user_id":29406,"name":"ginkgo","description":"Numerical linear algebra software package","homepage_url":"https://ginkgo-project.github.io","repo_url":"https://github.com/ginkgo-project/ginkgo","license":"BSD-3-Clause","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://ginkgo-project.github.io/","interact_status":"Met","interact_justification":"https://github.com/ginkgo-project/ginkgo/issues","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CONTRIBUTING.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"https://github.com/ginkgo-project/ginkgo/blob/develop/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"Met","documentation_interface_justification":"https://ginkgo-project.github.io/ginkgo-generated-documentation/doc/develop/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"Sematic versioning used, https://github.com/ginkgo-project/ginkgo/releases","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/ginkgo-project/ginkgo/releases","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"this software has not yet encountered a specific CVE","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_process_status":"Met","report_process_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_responses_status":"Met","report_responses_justification":"https://github.com/ginkgo-project/ginkgo/issues","enhancement_responses_status":"Met","enhancement_responses_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_archive_status":"Met","report_archive_justification":"https://github.com/ginkgo-project/ginkgo/issues and https://github.com/ginkgo-project/ginkgo/discussions","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/ginkgo-project/ginkgo/issues","vulnerability_report_private_status":"N/A","vulnerability_report_response_status":"N/A","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","test_status":"Met","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_justification":"Through sonarcloud, code coverage, and other memory leak tools","warnings_fixed_status":"Met","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"sonarcloud","static_analysis_common_vulnerabilities_status":"Met","static_analysis_fixed_status":"Met","static_analysis_often_status":"Met","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Unmet","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_fixed_status":"N/A","general_comments":"","created_at":"2023-11-04T13:09:00.535Z","updated_at":"2023-11-04T13:27:36.951Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"https://ginkgo-project.github.io/ginkgo-generated-documentation/doc/develop/","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"Found all required security hardening headers. // X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2023-11-04T13:27:36.950Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, Cuda, CMake, Shell, Python, R","lock_version":7,"badge_percentage_1":7,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":4,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":107,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2023-11-04T13:27:36.950Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":false,"gold_saved":false,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Pratik Nayak and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":8037,"user_id":29406,"name":"ginkgo","description":"Numerical linear algebra software package","homepage_url":"https://ginkgo-project.github.io","repo_url":"https://github.com/ginkgo-project/ginkgo","license":"BSD-3-Clause","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://ginkgo-project.github.io/","interact_status":"Met","interact_justification":"https://github.com/ginkgo-project/ginkgo/issues","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CONTRIBUTING.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"https://github.com/ginkgo-project/ginkgo/blob/develop/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"The BSD-3-Clause license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"Met","documentation_interface_justification":"https://ginkgo-project.github.io/ginkgo-generated-documentation/doc/develop/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"Sematic versioning used, https://github.com/ginkgo-project/ginkgo/releases","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/ginkgo-project/ginkgo/releases","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"this software has not yet encountered a specific CVE","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_process_status":"Met","report_process_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_responses_status":"Met","report_responses_justification":"https://github.com/ginkgo-project/ginkgo/issues","enhancement_responses_status":"Met","enhancement_responses_justification":"https://github.com/ginkgo-project/ginkgo/issues","report_archive_status":"Met","report_archive_justification":"https://github.com/ginkgo-project/ginkgo/issues and https://github.com/ginkgo-project/ginkgo/discussions","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/ginkgo-project/ginkgo/issues","vulnerability_report_private_status":"N/A","vulnerability_report_response_status":"N/A","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/ginkgo-project/ginkgo/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","test_status":"Met","test_invocation_status":"Met","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_justification":"Through sonarcloud, code coverage, and other memory leak tools","warnings_fixed_status":"Met","warnings_strict_status":"Met","know_secure_design_status":"Met","know_common_errors_status":"Met","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"sonarcloud","static_analysis_common_vulnerabilities_status":"Met","static_analysis_fixed_status":"Met","static_analysis_often_status":"Met","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Unmet","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_fixed_status":"N/A","general_comments":"","created_at":"2023-11-04T13:09:00.535Z","updated_at":"2023-11-04T13:27:36.951Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"https://ginkgo-project.github.io/ginkgo-generated-documentation/doc/develop/","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"?","hardened_site_status":"Unmet","hardened_site_justification":"Found all required security hardening headers. // X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2023-11-04T13:27:36.950Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, Cuda, CMake, Shell, Python, R","lock_version":7,"badge_percentage_1":7,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"?","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":4,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":107,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2023-11-04T13:27:36.950Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":false,"gold_saved":false,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Pratik Nayak and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/8273.json b/_data/openssf/8273.json index d3188dd..676cfcc 100644 --- a/_data/openssf/8273.json +++ b/_data/openssf/8273.json @@ -1 +1 @@ -{"id":8273,"user_id":29717,"name":"LLVM","description":"The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.","homepage_url":"https://llvm.org","repo_url":"https://github.com/llvm/llvm-project","license":"OTHER","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://llvm.org/ First paragraph at the top of the page.","interact_status":"Met","interact_justification":"https://llvm.org\r\n* Links to download the software is on the top left side of the website.\r\n* LInk to bug tracker is on the top left side of the website.\r\n* The last paragraph on the main page has a 'getting involved' link.","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/llvm/llvm-project/blob/main/CONTRIBUTING.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"https://llvm.org/docs/DeveloperPolicy.html\r\n","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/llvm/llvm-project/blob/main/LICENSE.TXT\u003e.","floss_license_status":"Met","floss_license_justification":"The majority of the project is licensed under: Apache-2.0 WITH LLVM-exception OR NCSA. It is packaged for both Debian and Fedora when means the licenses meets their requirements.","floss_license_osi_status":"Met","floss_license_osi_justification":"The majority of the project is licensed under: Apache-2.0 WITH LLVM-exception OR NCSA. There are small sections of code that are licensed under other licenses (e.g. MIT, Unicode, and others), but those are all NCSA approved.","documentation_basics_status":"Met","documentation_basics_justification":"There are several different documentation pages for the various sub-projects, but here is the main documentation page for LLVM: https://llvm.org/docs/","documentation_interface_status":"Met","documentation_interface_justification":"The full LLVM and clang API is published via doxygen at: https://llvm.org/doxygen/ and https://clang.llvm.org/doxygen/\r\n\r\nThere are a large number of binary tools distributed by this project, the command line options for these are documented on web pages, like this: https://clang.llvm.org/docs/ClangCommandLineReference.html and/or in man pages distributed with the software.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Every commit included in our releases is in the public git repository: https://github.com/llvm/llvm-project. We also do release candidate releases prior to final versions e.g.:\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc4","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The current project policy is to release a new major release every six months with bug fix releases every two weeks afterwards for 10 to 12 weeks. Example of a year's worth of releases:\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.0\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.5\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.6\r\n* Note due to a packaging mistake, we withdrew the 17.0.0 release and replaced it with 17.0.1.\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.4\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.5\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.6","version_semver_status":"Unmet","version_semver_justification":"What we use is similar to Semantic Versioning, except that when we update the minor release number, that release is not backwards compatible with the previous release. We use the minor version to indicate the ABI has changed.","version_tags_status":"Met","version_tags_justification":"We use git tags to identify each release. e.g. https://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.6","release_notes_status":"Met","release_notes_justification":"We have started doing individual release notes for each bug fix release now:\r\n\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-18.1.3","release_notes_vulns_status":"Met","release_notes_vulns_justification":"We added a note about the most recent CVE to our release notes:\r\n\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-18.1.3","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/llvm/llvm-project/issues","report_process_status":"Met","report_process_justification":"https://github.com/llvm/llvm-project/issues","report_responses_status":"Met","report_responses_justification":"On March 28, 2024, I ran a query looking at all the issues in the last 12 months:\r\n\r\n87.2% of the bugs had at least one person other than the reporter 'participate' in the bug.\r\n49.9% of the bugs has at least two people other than the reporter 'participate' in the bug.\r\n\r\nFrom what I can tell 'participate' means someone added a comment, a label, or a reaction to a bug.","enhancement_responses_status":"Unmet","enhancement_responses_justification":"We don't have a formal way to make feature requests.\r\nTODO: See if we can determine if there are any feature requests by looking at github labels and measure our response rate.","report_archive_status":"Met","report_archive_justification":"https://github.com/llvm/llvm-project/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"Security Reporting Process: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"The instructions here are for reporting a vulnerability privately: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","vulnerability_report_response_status":"Met","vulnerability_report_response_justification":"We aim to respond in 2 business days: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","build_status":"Met","build_justification":"We provide a CMake build system for general use. In addition, there is a GN and also a Bazel build system that can be used as an alternative to CMake in some configurations.","build_common_tools_status":"Met","build_common_tools_justification":"You can build the software using CMake, which is a very common tool.","build_floss_tools_status":"Met","build_floss_tools_justification":"CMake is a FLOSS tool you can build the project with.","test_status":"Met","test_justification":"The main test suites are integrated into the https://github.com/llvm/llvm-project repository. Instructions for how to run the tests can be found in our testing guide: https://llvm.org/docs/TestingGuide.html We have buildbots that automatically build and test the new code when it is committed: https://lab.llvm.org/buildbot/#/console","test_invocation_status":"Met","test_invocation_justification":"You can run the test suite using `make check-all` or `ninja check-all` depending on which tool you are using. See https://llvm.org/docs/TestingGuide.html","test_most_status":"Met","test_most_justification":"As of November 2023, our tests suite covered ~85% of the clang, llvm, and lldb sub-projects. See https://lab.llvm.org/coverage/coverage-reports/coverage/Users/buildslave/jenkins/workspace/coverage/llvm-project/index.html","test_policy_status":"Met","test_policy_justification":"We have a policy of requiring tests for bug fixes and new features: https://llvm.org/docs/DeveloperPolicy.html#test-cases","tests_are_added_status":"Met","tests_are_added_justification":"Commit logs for some of our test directories:\r\nhttps://github.com/llvm/llvm-project/commits/main/llvm/test\r\nhttps://github.com/llvm/llvm-project/commits/main/clang/test\r\n\r\nThis is a smaller feature, but this patch for new functionality added tests: https://github.com/llvm/llvm-project/commit/8186e1500b1d9709f10199b7c599274f8a6f8e3a","tests_documented_added_status":"Met","tests_documented_added_justification":"We don't really have an official change proposal policy, but we do mention n the developer policy that tests should be added for new features: https://llvm.org/docs/DeveloperPolicy.html#test-cases","warnings_status":"Met","warnings_justification":"The project enables -Wextra and other warnings by default and also enables -Wall except when compiling with clang-cl: https://github.com/llvm/llvm-project/blob/e07a2f49e3d3c13b6e9b89e0f6118652f2b2d3ac/llvm/cmake/modules/HandleLLVMOptions.cmake#L774","warnings_fixed_status":"Met","warnings_fixed_justification":"Our latest release (17.0.6) had 9,636,137 lines of code ( cloc --include-lang=\"C,C++,C/C++ Header\" compiler-rt/ clang-tools-extra/ libcxx libcxxabi/ libunwind/ openmp/ lld lldb polly mlir flang llvm/ bolt clang/). In our official release builds, there were 110 warnings: https://github.com/llvm/llvm-project/actions/runs/7017442066/job/19094022079. This is less that 1 per 100 lines.","warnings_strict_status":"Met","warnings_strict_justification":"The project enables -Wall (in most configurations) and -Wextra by default.\r\nhttps://github.com/llvm/llvm-project/blob/e07a2f49e3d3c13b6e9b89e0f6118652f2b2d3ac/llvm/cmake/modules/HandleLLVMOptions.cmake#L774","know_secure_design_status":"Met","know_secure_design_justification":"As of 4/23/2024, we have at least 2 developers how meet this criteria, see the discussion here: https://discourse.llvm.org/t/do-you-have-secure-development-knowledge/78429/4","know_common_errors_status":"Met","know_common_errors_justification":"As of 4/23/2024, we have at least 2 developers how meet this criteria, see the discussion here: https://discourse.llvm.org/t/do-you-have-secure-development-knowledge/78429/4","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Releases are hosted on https://github.com/llvm/llvm-project/releases\r\n\r\nWe sign our source tarballs, but not our release binaries.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"All our release assets are hosted at https://github.com/llvm/llvm-project/releases which uses https.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"As of May 9, 2024, all medium or higher CVEs listed here have been fixed: https://nvd.nist.gov/vuln/search/results?form_type=Advanced\u0026results_type=overview\u0026search_type=all\u0026isCpeNameSearch=false\u0026cpe_vendor=cpe%3A%2F%3Allvm","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"As of May 9, 2024, according to https://nvd.nist.gov/vuln/search/results?form_type=Advanced\u0026results_type=overview\u0026search_type=all\u0026isCpeNameSearch=false\u0026cpe_vendor=cpe%3A%2F%3Allvm there have been no critical CVEs assigned to the project.","static_analysis_status":"Met","static_analysis_justification":"We are running the clang static analyzer against our main branch one per day, and we will be running it for every commit the release branches going forward.\r\nhttps://github.com/llvm/llvm-project/actions/workflows/ci-post-commit-analyzer.yml\r\n","static_analysis_common_vulnerabilities_status":"N/A","static_analysis_common_vulnerabilities_justification":"We don't currently use a static analysis tool.","static_analysis_fixed_status":"N/A","static_analysis_fixed_justification":"We don't currently use a static analysis tool.","static_analysis_often_status":"N/A","static_analysis_often_justification":"We don't currently use a static analysis tool.","dynamic_analysis_status":"Unmet","dynamic_analysis_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"We have several buildbots that run tests with the sanitizers enabled: https://lab.llvm.org","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_enable_assertions_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","dynamic_analysis_fixed_status":"N/A","dynamic_analysis_fixed_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","general_comments":"","created_at":"2024-01-05T00:45:31.701Z","updated_at":"2024-09-16T23:03:47.234Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"When code is merged to the main branch, there is an automated buildbot system that tests the result: https://lab.llvm.org/buildbot/#/console","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"We use https://www.passwordstore.org/ to encrypt and store our project credentials in a private git repository.","english_status":"Met","english_justification":"* Documentation in English: https://llvm.org/docs/\r\n* Bug Reports in English: https://github.com/llvm/llvm-project/issues\r\n* Code comments in English: https://github.com/llvm/llvm-project/blob/release/17.x/clang/lib/Driver/Driver.cpp#L2524","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"Unmet","installation_common_justification":"TODO: Fix ninja uninstall\r\nThe project use CMake to configure the build system. Ninja install works, but ninja uninstall does not.","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2024-06-10T14:10:02.503Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++","lock_version":80,"badge_percentage_1":56,"dco_status":"Unmet","dco_justification":"TODO: Need to clarify why we don't have one of these.","governance_status":"Met","governance_justification":"LLVM decision making process: https://github.com/llvm/llvm-www/blob/main/proposals/LP0001-LLVMDecisionMaking.md\r\nCode Owners: https://www.llvm.org/docs/DeveloperPolicy.html#code-owners\r\nRelease Managers: https://llvm.org/docs/HowToReleaseLLVM.html","code_of_conduct_status":"Met","code_of_conduct_justification":"https://llvm.org/docs/CodeOfConduct.html","roles_responsibilities_status":"Unmet","roles_responsibilities_justification":"Code Owners are the only real defined role for the project:\r\nhttps://llvm.org/docs/DeveloperPolicy.html#code-owners\r\nhttps://clang.llvm.org/docs/CodeOwners.html\r\n\r\nWe also have project admins, but no documentation for that. TODO: Document project admin responsibilities.","access_continuity_status":"?","bus_factor_status":"Met","bus_factor_justification":"As of June 11, 2024, we have a truck factor of 71 according to https://github.com/mtov/truck-factor.","documentation_roadmap_status":"Unmet","documentation_roadmap_justification":"TODO: Create one.","documentation_architecture_status":"Unmet","documentation_architecture_justification":"TODO: Find the links for this. I think we have this for some areas of the project.","documentation_security_status":"Met","documentation_security_justification":"https://llvm.org/docs/Security.html#what-is-considered-a-security-issue\r\n","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://llvm.org/docs/GettingStarted.html\r\n\r\nThis provides the basics for how to build and use llvm/clang. ","documentation_current_status":"Met","documentation_current_justification":"We generate and host the documentation directly from the main branch in git: https://llvm.org/docs/ ","documentation_achievements_status":"Met","documentation_achievements_justification":"There are OpenSSF ScoreCard and OpenSSF Best Practices badges in the README file: https://github.com/llvm/llvm-project","accessibility_best_practices_status":"Unmet","accessibility_best_practices_justification":"TODO: We need to check if our websites meet this criteria.","internationalization_status":"Unmet","internationalization_justification":"We don't translate the error or warning messages.","sites_password_security_status":"Met","sites_password_security_justification":"This project uses GitHub: https://github.com/llvm/llvm-project","maintenance_or_update_status":"Met","maintenance_or_update_justification":"It's easy to download and build a new version of the compiler. You can even install new versions along side old versions.","vulnerability_report_credit_status":"Unmet","vulnerability_report_credit_justification":"TODO: I'm not sure what giving credit means. I need to check with the security team.","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"https://llvm.org/docs/Security.html#process","coding_standards_status":"Met","coding_standards_justification":"Coding style is documented here: https://www.llvm.org/docs/CodingStandards.html","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"Coding style is enforced with a GitHub actions job: https://github.com/llvm/llvm-project/actions/workflows/pr-code-format.yml","build_standard_variables_status":"Met","build_standard_variables_justification":"You can specify your own flags using the CMAKE_*_FLAGS variable. These will be added to the list of internal language flags.","build_preserve_debug_status":"Met","build_preserve_debug_justification":"Debug information is preserved on install.","build_non_recursive_status":"Met","build_non_recursive_justification":"The CMake build system correctly computes dependencies and builds the objects in the correct order.","build_repeatable_status":"Unmet","build_repeatable_justification":"TODO: Investigate how well we support reproducible builds.","installation_standard_variables_status":"Unmet","installation_standard_variables_justification":"TODO: Investigate if DESTDIR is supported.","installation_development_quick_status":"Met","installation_development_quick_justification":"I think we meet this. There really aren't a lot of prerequisites for building the llvm-project. For the most part, you can just download the source and build it without needing to set anything else up.","external_dependencies_status":"Unmet","external_dependencies_justification":"TODO: Investigate this.","dependency_monitoring_status":"Unmet","dependency_monitoring_justification":"TODO: Start checking external dependencies","updateable_reused_components_status":"Unmet","updateable_reused_components_justification":"TODO: We bundle a few things, we need to create a process for keeping them up-to-date.","interfaces_current_status":"?","automated_integration_testing_status":"Met","automated_integration_testing_justification":"We run the test suite on every change submitted to the release/* branches. ","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"N/A","crypto_credential_agility_justification":"LLVM doesn't process passwords or other sensitive information.","signed_releases_status":"?","version_tags_signed_status":"Met","version_tags_signed_justification":"The project release tags are signed: https://github.com/llvm/llvm-project/tags","badge_percentage_2":22,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":156,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2024-06-10T14:10:02.503Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Tom Stellard and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":8273,"user_id":29717,"name":"LLVM","description":"The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.","homepage_url":"https://llvm.org","repo_url":"https://github.com/llvm/llvm-project","license":"OTHER","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://llvm.org/ First paragraph at the top of the page.","interact_status":"Met","interact_justification":"https://llvm.org\r\n* Links to download the software is on the top left side of the website.\r\n* LInk to bug tracker is on the top left side of the website.\r\n* The last paragraph on the main page has a 'getting involved' link.","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/llvm/llvm-project/blob/main/CONTRIBUTING.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"https://llvm.org/docs/DeveloperPolicy.html\r\n","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/llvm/llvm-project/blob/main/LICENSE.TXT\u003e.","floss_license_status":"Met","floss_license_justification":"The majority of the project is licensed under: Apache-2.0 WITH LLVM-exception OR NCSA. It is packaged for both Debian and Fedora when means the licenses meets their requirements.","floss_license_osi_status":"Met","floss_license_osi_justification":"The majority of the project is licensed under: Apache-2.0 WITH LLVM-exception OR NCSA. There are small sections of code that are licensed under other licenses (e.g. MIT, Unicode, and others), but those are all NCSA approved.","documentation_basics_status":"Met","documentation_basics_justification":"There are several different documentation pages for the various sub-projects, but here is the main documentation page for LLVM: https://llvm.org/docs/","documentation_interface_status":"Met","documentation_interface_justification":"The full LLVM and clang API is published via doxygen at: https://llvm.org/doxygen/ and https://clang.llvm.org/doxygen/\r\n\r\nThere are a large number of binary tools distributed by this project, the command line options for these are documented on web pages, like this: https://clang.llvm.org/docs/ClangCommandLineReference.html and/or in man pages distributed with the software.","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Every commit included in our releases is in the public git repository: https://github.com/llvm/llvm-project. We also do release candidate releases prior to final versions e.g.:\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.0-rc4","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The current project policy is to release a new major release every six months with bug fix releases every two weeks afterwards for 10 to 12 weeks. Example of a year's worth of releases:\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.0\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.5\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-16.0.6\r\n* Note due to a packaging mistake, we withdrew the 17.0.0 release and replaced it with 17.0.1.\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.1\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.2\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.3\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.4\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.5\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.6","version_semver_status":"Unmet","version_semver_justification":"What we use is similar to Semantic Versioning, except that when we update the minor release number, that release is not backwards compatible with the previous release. We use the minor version to indicate the ABI has changed.","version_tags_status":"Met","version_tags_justification":"We use git tags to identify each release. e.g. https://github.com/llvm/llvm-project/releases/tag/llvmorg-17.0.6","release_notes_status":"Met","release_notes_justification":"We have started doing individual release notes for each bug fix release now:\r\n\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-18.1.3","release_notes_vulns_status":"Met","release_notes_vulns_justification":"We added a note about the most recent CVE to our release notes:\r\n\r\nhttps://github.com/llvm/llvm-project/releases/tag/llvmorg-18.1.3","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/llvm/llvm-project/issues","report_process_status":"Met","report_process_justification":"https://github.com/llvm/llvm-project/issues","report_responses_status":"Met","report_responses_justification":"On March 28, 2024, I ran a query looking at all the issues in the last 12 months:\r\n\r\n87.2% of the bugs had at least one person other than the reporter 'participate' in the bug.\r\n49.9% of the bugs has at least two people other than the reporter 'participate' in the bug.\r\n\r\nFrom what I can tell 'participate' means someone added a comment, a label, or a reaction to a bug.","enhancement_responses_status":"Unmet","enhancement_responses_justification":"We don't have a formal way to make feature requests.\r\nTODO: See if we can determine if there are any feature requests by looking at github labels and measure our response rate.","report_archive_status":"Met","report_archive_justification":"https://github.com/llvm/llvm-project/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"Security Reporting Process: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"The instructions here are for reporting a vulnerability privately: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","vulnerability_report_response_status":"Met","vulnerability_report_response_justification":"We aim to respond in 2 business days: https://llvm.org/docs/Security.html#how-to-report-a-security-issue","build_status":"Met","build_justification":"We provide a CMake build system for general use. In addition, there is a GN and also a Bazel build system that can be used as an alternative to CMake in some configurations.","build_common_tools_status":"Met","build_common_tools_justification":"You can build the software using CMake, which is a very common tool.","build_floss_tools_status":"Met","build_floss_tools_justification":"CMake is a FLOSS tool you can build the project with.","test_status":"Met","test_justification":"The main test suites are integrated into the https://github.com/llvm/llvm-project repository. Instructions for how to run the tests can be found in our testing guide: https://llvm.org/docs/TestingGuide.html We have buildbots that automatically build and test the new code when it is committed: https://lab.llvm.org/buildbot/#/console","test_invocation_status":"Met","test_invocation_justification":"You can run the test suite using `make check-all` or `ninja check-all` depending on which tool you are using. See https://llvm.org/docs/TestingGuide.html","test_most_status":"Met","test_most_justification":"As of November 2023, our tests suite covered ~85% of the clang, llvm, and lldb sub-projects. See https://lab.llvm.org/coverage/coverage-reports/coverage/Users/buildslave/jenkins/workspace/coverage/llvm-project/index.html","test_policy_status":"Met","test_policy_justification":"We have a policy of requiring tests for bug fixes and new features: https://llvm.org/docs/DeveloperPolicy.html#test-cases","tests_are_added_status":"Met","tests_are_added_justification":"Commit logs for some of our test directories:\r\nhttps://github.com/llvm/llvm-project/commits/main/llvm/test\r\nhttps://github.com/llvm/llvm-project/commits/main/clang/test\r\n\r\nThis is a smaller feature, but this patch for new functionality added tests: https://github.com/llvm/llvm-project/commit/8186e1500b1d9709f10199b7c599274f8a6f8e3a","tests_documented_added_status":"Met","tests_documented_added_justification":"We don't really have an official change proposal policy, but we do mention n the developer policy that tests should be added for new features: https://llvm.org/docs/DeveloperPolicy.html#test-cases","warnings_status":"Met","warnings_justification":"The project enables -Wextra and other warnings by default and also enables -Wall except when compiling with clang-cl: https://github.com/llvm/llvm-project/blob/e07a2f49e3d3c13b6e9b89e0f6118652f2b2d3ac/llvm/cmake/modules/HandleLLVMOptions.cmake#L774","warnings_fixed_status":"Met","warnings_fixed_justification":"Our latest release (17.0.6) had 9,636,137 lines of code ( cloc --include-lang=\"C,C++,C/C++ Header\" compiler-rt/ clang-tools-extra/ libcxx libcxxabi/ libunwind/ openmp/ lld lldb polly mlir flang llvm/ bolt clang/). In our official release builds, there were 110 warnings: https://github.com/llvm/llvm-project/actions/runs/7017442066/job/19094022079. This is less that 1 per 100 lines.","warnings_strict_status":"Met","warnings_strict_justification":"The project enables -Wall (in most configurations) and -Wextra by default.\r\nhttps://github.com/llvm/llvm-project/blob/e07a2f49e3d3c13b6e9b89e0f6118652f2b2d3ac/llvm/cmake/modules/HandleLLVMOptions.cmake#L774","know_secure_design_status":"Met","know_secure_design_justification":"As of 4/23/2024, we have at least 2 developers how meet this criteria, see the discussion here: https://discourse.llvm.org/t/do-you-have-secure-development-knowledge/78429/4","know_common_errors_status":"Met","know_common_errors_justification":"As of 4/23/2024, we have at least 2 developers how meet this criteria, see the discussion here: https://discourse.llvm.org/t/do-you-have-secure-development-knowledge/78429/4","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Releases are hosted on https://github.com/llvm/llvm-project/releases\r\n\r\nWe sign our source tarballs, but not our release binaries.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"All our release assets are hosted at https://github.com/llvm/llvm-project/releases which uses https.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"As of May 9, 2024, all medium or higher CVEs listed here have been fixed: https://nvd.nist.gov/vuln/search/results?form_type=Advanced\u0026results_type=overview\u0026search_type=all\u0026isCpeNameSearch=false\u0026cpe_vendor=cpe%3A%2F%3Allvm","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"As of May 9, 2024, according to https://nvd.nist.gov/vuln/search/results?form_type=Advanced\u0026results_type=overview\u0026search_type=all\u0026isCpeNameSearch=false\u0026cpe_vendor=cpe%3A%2F%3Allvm there have been no critical CVEs assigned to the project.","static_analysis_status":"Met","static_analysis_justification":"We are running the clang static analyzer against our main branch one per day, and we will be running it for every commit the release branches going forward.\r\nhttps://github.com/llvm/llvm-project/actions/workflows/ci-post-commit-analyzer.yml\r\n","static_analysis_common_vulnerabilities_status":"N/A","static_analysis_common_vulnerabilities_justification":"We don't currently use a static analysis tool.","static_analysis_fixed_status":"N/A","static_analysis_fixed_justification":"We don't currently use a static analysis tool.","static_analysis_often_status":"N/A","static_analysis_often_justification":"We don't currently use a static analysis tool.","dynamic_analysis_status":"Unmet","dynamic_analysis_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"We have several buildbots that run tests with the sanitizers enabled: https://lab.llvm.org","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_enable_assertions_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","dynamic_analysis_fixed_status":"N/A","dynamic_analysis_fixed_justification":"We generally don't really much on fuzzing, because we assume that all inputs are trusted.","general_comments":"","created_at":"2024-01-05T00:45:31.701Z","updated_at":"2024-09-16T23:03:47.234Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"When code is merged to the main branch, there is an automated buildbot system that tests the result: https://lab.llvm.org/buildbot/#/console","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"We use https://www.passwordstore.org/ to encrypt and store our project credentials in a private git repository.","english_status":"Met","english_justification":"* Documentation in English: https://llvm.org/docs/\r\n* Bug Reports in English: https://github.com/llvm/llvm-project/issues\r\n* Code comments in English: https://github.com/llvm/llvm-project/blob/release/17.x/clang/lib/Driver/Driver.cpp#L2524","hardening_status":"?","crypto_used_network_status":"?","crypto_tls12_status":"?","crypto_certificate_verification_status":"?","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"Unmet","installation_common_justification":"TODO: Fix ninja uninstall\r\nThe project use CMake to configure the build system. Ninja install works, but ninja uninstall does not.","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2024-06-10T14:10:02.503Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++","lock_version":80,"badge_percentage_1":56,"dco_status":"Unmet","dco_justification":"TODO: Need to clarify why we don't have one of these.","governance_status":"Met","governance_justification":"LLVM decision making process: https://github.com/llvm/llvm-www/blob/main/proposals/LP0001-LLVMDecisionMaking.md\r\nCode Owners: https://www.llvm.org/docs/DeveloperPolicy.html#code-owners\r\nRelease Managers: https://llvm.org/docs/HowToReleaseLLVM.html","code_of_conduct_status":"Met","code_of_conduct_justification":"https://llvm.org/docs/CodeOfConduct.html","roles_responsibilities_status":"Unmet","roles_responsibilities_justification":"Code Owners are the only real defined role for the project:\r\nhttps://llvm.org/docs/DeveloperPolicy.html#code-owners\r\nhttps://clang.llvm.org/docs/CodeOwners.html\r\n\r\nWe also have project admins, but no documentation for that. TODO: Document project admin responsibilities.","access_continuity_status":"?","bus_factor_status":"Met","bus_factor_justification":"As of June 11, 2024, we have a truck factor of 71 according to https://github.com/mtov/truck-factor.","documentation_roadmap_status":"Unmet","documentation_roadmap_justification":"TODO: Create one.","documentation_architecture_status":"Unmet","documentation_architecture_justification":"TODO: Find the links for this. I think we have this for some areas of the project.","documentation_security_status":"Met","documentation_security_justification":"https://llvm.org/docs/Security.html#what-is-considered-a-security-issue\r\n","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://llvm.org/docs/GettingStarted.html\r\n\r\nThis provides the basics for how to build and use llvm/clang. ","documentation_current_status":"Met","documentation_current_justification":"We generate and host the documentation directly from the main branch in git: https://llvm.org/docs/ ","documentation_achievements_status":"Met","documentation_achievements_justification":"There are OpenSSF ScoreCard and OpenSSF Best Practices badges in the README file: https://github.com/llvm/llvm-project","accessibility_best_practices_status":"Unmet","accessibility_best_practices_justification":"TODO: We need to check if our websites meet this criteria.","internationalization_status":"Unmet","internationalization_justification":"We don't translate the error or warning messages.","sites_password_security_status":"Met","sites_password_security_justification":"This project uses GitHub: https://github.com/llvm/llvm-project","maintenance_or_update_status":"Met","maintenance_or_update_justification":"It's easy to download and build a new version of the compiler. You can even install new versions along side old versions.","vulnerability_report_credit_status":"Unmet","vulnerability_report_credit_justification":"TODO: I'm not sure what giving credit means. I need to check with the security team.","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"https://llvm.org/docs/Security.html#process","coding_standards_status":"Met","coding_standards_justification":"Coding style is documented here: https://www.llvm.org/docs/CodingStandards.html","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"Coding style is enforced with a GitHub actions job: https://github.com/llvm/llvm-project/actions/workflows/pr-code-format.yml","build_standard_variables_status":"Met","build_standard_variables_justification":"You can specify your own flags using the CMAKE_*_FLAGS variable. These will be added to the list of internal language flags.","build_preserve_debug_status":"Met","build_preserve_debug_justification":"Debug information is preserved on install.","build_non_recursive_status":"Met","build_non_recursive_justification":"The CMake build system correctly computes dependencies and builds the objects in the correct order.","build_repeatable_status":"Unmet","build_repeatable_justification":"TODO: Investigate how well we support reproducible builds.","installation_standard_variables_status":"Unmet","installation_standard_variables_justification":"TODO: Investigate if DESTDIR is supported.","installation_development_quick_status":"Met","installation_development_quick_justification":"I think we meet this. There really aren't a lot of prerequisites for building the llvm-project. For the most part, you can just download the source and build it without needing to set anything else up.","external_dependencies_status":"Unmet","external_dependencies_justification":"TODO: Investigate this.","dependency_monitoring_status":"Unmet","dependency_monitoring_justification":"TODO: Start checking external dependencies","updateable_reused_components_status":"Unmet","updateable_reused_components_justification":"TODO: We bundle a few things, we need to create a process for keeping them up-to-date.","interfaces_current_status":"?","automated_integration_testing_status":"Met","automated_integration_testing_justification":"We run the test suite on every change submitted to the release/* branches. ","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"?","crypto_credential_agility_status":"N/A","crypto_credential_agility_justification":"LLVM doesn't process passwords or other sensitive information.","signed_releases_status":"?","version_tags_signed_status":"Met","version_tags_signed_justification":"The project release tags are signed: https://github.com/llvm/llvm-project/tags","badge_percentage_2":22,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":156,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2024-06-10T14:10:02.503Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Tom Stellard and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/9344.json b/_data/openssf/9344.json index cc7581c..200e291 100644 --- a/_data/openssf/9344.json +++ b/_data/openssf/9344.json @@ -1 +1 @@ -{"id":9344,"user_id":37713,"name":"Kokkos","description":"Kokkos C++ Performance Portability Programming Ecosystem: The Programming Model - Parallel Execution and Memory Abstraction","homepage_url":"https://kokkos.org","repo_url":"https://github.com/kokkos/kokkos","license":"Apache-2.0 WITH LLVM-exception","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://github.com/kokkos/kokkos/","interact_status":"Met","interact_justification":"https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","contribution_status":"Met","contribution_justification":"Contribution process is explained in https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","contribution_requirements_status":"Met","contribution_requirements_justification":"Requirements for acceptable contributions are covered by https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The project is licensed under the Apache-2.0 license WITH LLVM-exception. The Apache-2.0 license is approved by the Open Source Initiative (OSI). Kokkos is packaged for Fedora which means the license meets their requirement.","floss_license_osi_status":"Met","floss_license_osi_justification":"The Apache-2.0 license WITH LLVM-exception is approved by OSI, see https://opensource.org/license/apache-2-0 and https://spdx.org/licenses/LLVM-exception.html.","documentation_basics_status":"Met","documentation_basics_justification":"https://kokkos.org/kokkos-core-wiki/","documentation_interface_status":"Met","documentation_interface_justification":"https://kokkos.org/kokkos-core-wiki/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"All code development happens on GitHub using pull requests","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_semver_status":"Met","version_tags_status":"Met","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"no known vulnerabilities","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","report_process_status":"Met","report_process_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","report_responses_status":"Met","enhancement_responses_status":"Met","report_archive_status":"Met","report_archive_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/kokkos/kokkos/blob/develop/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"https://github.com/kokkos/kokkos/blob/develop/SECURITY.md encourages to send e-mails.","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"No known vulnerabilities.","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"The primary build system is CMake.","test_status":"Met","test_justification":"We are using CTest with Github Workflows.","test_invocation_status":"Met","test_invocation_justification":"We are using CTest with Github Workflows.","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_fixed_status":"Met","warnings_strict_status":"Met","warnings_strict_justification":"We treat warnings as error in our CI builds.","know_secure_design_status":"Met","know_secure_design_justification":"@dalg24 completed LFD121 course on 2025/02/11","know_common_errors_status":"Met","know_common_errors_justification":"@dalg24 completed LFD121 course on 2025/02/11","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"MemorySanitizer, UnderfinedBehaviorSanitizer, clang-tidy, CodeQL","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"The project uses CodeQL and the Clang Static Analyzer as part of the CI.","static_analysis_fixed_status":"Met","static_analysis_often_status":"Met","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Unmet","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_fixed_status":"Met","general_comments":"","created_at":"2024-08-08T21:13:55.697Z","updated_at":"2025-11-15T03:02:51.105Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"We are using CTest with Github Workflows and jenkins.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"https://kokkos.org/kokkos-core-wiki/","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\". Required security hardening headers missing: https://kokkos.org: content-security-policy, strict-transport-security, x-content-type-options, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-02-12T12:50:31.943Z","lost_passing_at":null,"last_reminder_at":"2024-12-28T23:00:29.819Z","disabled_reminders":false,"implementation_languages":"C++","lock_version":28,"badge_percentage_1":53,"dco_status":"Met","dco_justification":"We use a DCO and enforce it on all contributions via GitHub action.","governance_status":"Met","governance_justification":"Our governance model is detailed in https://github.com/kokkos/governance in the GOVERNANCE.md file.","code_of_conduct_status":"Met","code_of_conduct_justification":"https://kokkos.org/community/code-of-conduct/","roles_responsibilities_status":"Met","roles_responsibilities_justification":"Key roles in the project are documented in https://github.com/kokkos/governance in the GOVERNANCE.md file under the \"Project Leads\" section.","access_continuity_status":"Met","access_continuity_justification":"Kokkos is a Linux Foundation project. LF co-owns the organization on GH and holds our assets including the domain name for our website.\r\nhttps://insights.linuxfoundation.org/project/kokkos-project/repository/kokkos-kokkos","bus_factor_status":"Met","bus_factor_justification":"The project has a bus factor of 3.\r\nhttps://insights.linuxfoundation.org/project/kokkos-project/repository/kokkos-kokkos/contributors","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://kokkos.org/kokkos-core-wiki/get-started/quick-start.html","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"N/A","sites_password_security_justification":"We do not store password, we connect to GitHub identity using OAuth.","maintenance_or_update_status":"Met","maintenance_or_update_justification":"We maintain last minor release and provide patches as necessary.\r\nWe support the last minor release of the previous major release series for a year.","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"There have been no vulnerabilities reported in the last 12 months.","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"https://github.com/kokkos/kokkos?tab=security-ov-file#reporting-security-issues","coding_standards_status":"?","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"We enforce proper formatting (clang-format and cmake-format amongst other things) in our pre-commit testing.","build_standard_variables_status":"Met","build_standard_variables_justification":"We follow CMake best practices.","build_preserve_debug_status":"Met","build_preserve_debug_justification":"Debugging information are preserved when requested at configuration time.","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"Met","installation_standard_variables_justification":"Our build system honor standard conventions for selecting the location where built artifacts are written to at installation time.","installation_development_quick_status":"Met","installation_development_quick_justification":"Potential developers can download the project source code, configure and build using CMake.","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"N/A","input_validation_justification":"Kokkos is a programming model. The only inputs it takes are command-line arguments and environment variables to control the runtime. When provided, all variables are validated and bad formats cause immediate abnormal program termination.","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"?","version_tags_signed_status":"Met","version_tags_signed_justification":"Release tags are signed by the maintainers, so are the cryptographic hashes for the release archives.","badge_percentage_2":17,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":153,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-02-12T12:50:31.943Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Daniel Arndt and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":9344,"user_id":37713,"name":"Kokkos","description":"Kokkos C++ Performance Portability Programming Ecosystem: The Programming Model - Parallel Execution and Memory Abstraction","homepage_url":"https://kokkos.org","repo_url":"https://github.com/kokkos/kokkos","license":"Apache-2.0 WITH LLVM-exception","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"https://github.com/kokkos/kokkos/","interact_status":"Met","interact_justification":"https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","contribution_status":"Met","contribution_justification":"Contribution process is explained in https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","contribution_requirements_status":"Met","contribution_requirements_justification":"Requirements for acceptable contributions are covered by https://github.com/kokkos/kokkos/blob/develop/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Non-trivial license location file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The project is licensed under the Apache-2.0 license WITH LLVM-exception. The Apache-2.0 license is approved by the Open Source Initiative (OSI). Kokkos is packaged for Fedora which means the license meets their requirement.","floss_license_osi_status":"Met","floss_license_osi_justification":"The Apache-2.0 license WITH LLVM-exception is approved by OSI, see https://opensource.org/license/apache-2-0 and https://spdx.org/licenses/LLVM-exception.html.","documentation_basics_status":"Met","documentation_basics_justification":"https://kokkos.org/kokkos-core-wiki/","documentation_interface_status":"Met","documentation_interface_justification":"https://kokkos.org/kokkos-core-wiki/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"All code development happens on GitHub using pull requests","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_semver_status":"Met","version_tags_status":"Met","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"no known vulnerabilities","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","report_process_status":"Met","report_process_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","report_responses_status":"Met","enhancement_responses_status":"Met","report_archive_status":"Met","report_archive_justification":"GitHub issues https://github.com/kokkos/kokkos/issues.","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/kokkos/kokkos/blob/develop/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"https://github.com/kokkos/kokkos/blob/develop/SECURITY.md encourages to send e-mails.","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"No known vulnerabilities.","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"The primary build system is CMake.","test_status":"Met","test_justification":"We are using CTest with Github Workflows.","test_invocation_status":"Met","test_invocation_justification":"We are using CTest with Github Workflows.","test_most_status":"Met","test_policy_status":"Met","tests_are_added_status":"Met","tests_documented_added_status":"Met","warnings_status":"Met","warnings_fixed_status":"Met","warnings_strict_status":"Met","warnings_strict_justification":"We treat warnings as error in our CI builds.","know_secure_design_status":"Met","know_secure_design_justification":"@dalg24 completed LFD121 course on 2025/02/11","know_common_errors_status":"Met","know_common_errors_justification":"@dalg24 completed LFD121 course on 2025/02/11","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_unsigned_status":"Met","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_critical_fixed_status":"Met","static_analysis_status":"Met","static_analysis_justification":"MemorySanitizer, UnderfinedBehaviorSanitizer, clang-tidy, CodeQL","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"The project uses CodeQL and the Clang Static Analyzer as part of the CI.","static_analysis_fixed_status":"Met","static_analysis_often_status":"Met","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Unmet","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_fixed_status":"Met","general_comments":"","created_at":"2024-08-08T21:13:55.697Z","updated_at":"2025-11-15T03:02:51.105Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"We are using CTest with Github Workflows and jenkins.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","english_status":"Met","english_justification":"https://kokkos.org/kokkos-core-wiki/","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\". Required security hardening headers missing: https://kokkos.org: content-security-policy, strict-transport-security, x-content-type-options, x-frame-options","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-02-12T12:50:31.943Z","lost_passing_at":null,"last_reminder_at":"2024-12-28T23:00:29.819Z","disabled_reminders":false,"implementation_languages":"C++","lock_version":28,"badge_percentage_1":53,"dco_status":"Met","dco_justification":"We use a DCO and enforce it on all contributions via GitHub action.","governance_status":"Met","governance_justification":"Our governance model is detailed in https://github.com/kokkos/governance in the GOVERNANCE.md file.","code_of_conduct_status":"Met","code_of_conduct_justification":"https://kokkos.org/community/code-of-conduct/","roles_responsibilities_status":"Met","roles_responsibilities_justification":"Key roles in the project are documented in https://github.com/kokkos/governance in the GOVERNANCE.md file under the \"Project Leads\" section.","access_continuity_status":"Met","access_continuity_justification":"Kokkos is a Linux Foundation project. LF co-owns the organization on GH and holds our assets including the domain name for our website.\r\nhttps://insights.linuxfoundation.org/project/kokkos-project/repository/kokkos-kokkos","bus_factor_status":"Met","bus_factor_justification":"The project has a bus factor of 3.\r\nhttps://insights.linuxfoundation.org/project/kokkos-project/repository/kokkos-kokkos/contributors","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://kokkos.org/kokkos-core-wiki/get-started/quick-start.html","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"N/A","sites_password_security_justification":"We do not store password, we connect to GitHub identity using OAuth.","maintenance_or_update_status":"Met","maintenance_or_update_justification":"We maintain last minor release and provide patches as necessary.\r\nWe support the last minor release of the previous major release series for a year.","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"There have been no vulnerabilities reported in the last 12 months.","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"https://github.com/kokkos/kokkos?tab=security-ov-file#reporting-security-issues","coding_standards_status":"?","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"We enforce proper formatting (clang-format and cmake-format amongst other things) in our pre-commit testing.","build_standard_variables_status":"Met","build_standard_variables_justification":"We follow CMake best practices.","build_preserve_debug_status":"Met","build_preserve_debug_justification":"Debugging information are preserved when requested at configuration time.","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"Met","installation_standard_variables_justification":"Our build system honor standard conventions for selecting the location where built artifacts are written to at installation time.","installation_development_quick_status":"Met","installation_development_quick_justification":"Potential developers can download the project source code, configure and build using CMake.","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"N/A","input_validation_justification":"Kokkos is a programming model. The only inputs it takes are command-line arguments and environment variables to control the runtime. When provided, all variables are validated and bad formats cause immediate abnormal program termination.","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"?","version_tags_signed_status":"Met","version_tags_signed_justification":"Release tags are signed by the maintainers, so are the cryptographic hashes for the release archives.","badge_percentage_2":17,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":153,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-02-12T12:50:31.943Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Daniel Arndt and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/9452.json b/_data/openssf/9452.json index 115aa73..542a47d 100644 --- a/_data/openssf/9452.json +++ b/_data/openssf/9452.json @@ -1 +1 @@ -{"id":9452,"user_id":32662,"name":"Trilinos","description":"TheTrilinos Project is an effort to develop algorithms and enabling technologies within an object-oriented software framework for the solution of large-scale, complex multi-physics engineering and scientific problems on new and emerging high-performance computing (HPC) architectures.\r\n","homepage_url":"https://trilinos.org","repo_url":"https://github.com/trilinos/Trilinos","license":"BSD-3-Clause, LGPL","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"https://github.com/trilinos/Trilinos.git","description_good_status":"Met","description_good_justification":"https://github.com/trilinos/Trilinos/blob/master/README.md","interact_status":"Met","interact_justification":"https://github.com/trilinos/Trilinos/blob/master/README.md","contribution_status":"Met","contribution_justification":"https://github.com/trilinos/Trilinos/wiki/Managing-Trilinos-Project-Issues","contribution_requirements_status":"Met","contribution_requirements_justification":"https://github.com/trilinos/Trilinos/wiki/Managing-Trilinos-Project-Issues\r\nhttps://github.com/trilinos/Trilinos/wiki/PR-Creation-\u0026-Approval-Guidelines-for-Tpetra,-Ifpack2,-\r\nand-MueLu-Developers","license_location_status":"Met","license_location_justification":"https://github.com/trilinos/Trilinos/blob/master/LICENSE","floss_license_status":"Met","floss_license_justification":"https://trilinos.github.io/license.html","floss_license_osi_status":"Met","documentation_basics_status":"Met","documentation_basics_justification":"https://trilinos.github.io/","documentation_interface_status":"Met","documentation_interface_justification":"https://trilinos.github.io/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Primary development is done on github.","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"https://github.com/trilinos/Trilinos/releases","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/trilinos/Trilinos/releases","release_notes_status":"Met","release_notes_justification":"Release notes provided since version 14.2.0 https://github.com/trilinos/Trilinos/releases","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"There have not been any CVE or similar run-time vulnerabilities identified in Trilinos.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/trilinos/Trilinos/issues","report_process_status":"Met","report_process_justification":"https://github.com/trilinos/Trilinos/issues. Trilinos uses github issues.","report_responses_status":"Met","report_responses_justification":"https://github.com/trilinos/Trilinos/issues","enhancement_responses_status":"Met","enhancement_responses_justification":"https://github.com/trilinos/Trilinos/issues","report_archive_status":"Met","report_archive_justification":"https://github.com/trilinos/Trilinos/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/trilinos/Trilinos/issues","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"https://github.com/trilinos/Trilinos/security","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"Trilinos has not received any vulnerability reports in the last 6 months.","build_status":"Met","build_justification":"Trilinos uses cmake.","build_common_tools_status":"Met","build_common_tools_justification":"Trilinos uses cmake.","build_floss_tools_status":"Met","build_floss_tools_justification":"Trilinos uses cmake.","test_status":"Met","test_justification":"Trilinos uses cmake.","test_invocation_status":"Met","test_invocation_justification":"Trilinos uses cmake.","test_most_status":"Met","test_most_justification":"Trilinos' test suite covers most code branches.","test_policy_status":"Met","test_policy_justification":"See our testing policy: https://github.com/trilinos/Trilinos/wiki/Trilinos-Testing-Policy","tests_are_added_status":"Met","tests_are_added_justification":"See issue https://github.com/trilinos/Trilinos/pull/12728 which is cited in the 15.0.0 release notes, in which added functionality also includes tests.","tests_documented_added_status":"Met","tests_documented_added_justification":"See https://github.com/trilinos/Trilinos/blob/master/CONTRIBUTING.md","warnings_status":"Met","warnings_justification":"A gcc -Werror build is included as part of the testing process.","warnings_fixed_status":"Met","warnings_fixed_justification":"A gcc -Werror build is included as part of the testing process. Code cannot be merged if this test fails.","warnings_strict_status":"Met","warnings_strict_justification":"Werror cannot be enabled for legacy packages which are scheduled for deprecation in FY25. Once they are removed then stricter use of -Werror is possible.","know_secure_design_status":"Met","know_secure_design_justification":"The #4 developer by commits has completed Linux Foundation's Developing Secure Software LFD121 course.","know_common_errors_status":"Met","know_common_errors_justification":"Memory errors are the major issue in scientific software like Trilinos. Most developers are familiar with preventing this type of errors.","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Github uses https / ssh for checkouts.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Github uses https / ssh for checkouts, not http","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"There are no publicly known vulnerabilities in Trilinos","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"There are have not to date been critical vulnerabilities reported for Trilinos.","static_analysis_status":"Met","static_analysis_justification":"CodeQL is used as part of the PR testing process.","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"CodeQL does this.","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"CodeQL is run on every PR.","static_analysis_often_status":"Met","static_analysis_often_justification":"CodeQL is run on every PR.","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Valgrind is used as part of regular nightly testing.","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"We have not identified any vulnerabilities with dynamic analysis at this time.","general_comments":"","created_at":"2024-09-16T20:00:07.681Z","updated_at":"2024-10-08T17:37:08.095Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"CI is run via github as part of the testing process.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests. https://github.com/trilinos/Trilinos\r\n/issues","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"There are no credentials stored in the Trilinos repo.","english_status":"Met","english_justification":"https://github.com/trilinos/Trilinos/issues, https://trilinos.github.io/","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2024-10-08T16:26:20.006Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, Python","lock_version":11,"badge_percentage_1":25,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":125,"repo_url_updated_at":"2024-10-08T16:18:42.960Z","achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2024-10-08T16:26:20.006Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"https://github.com/trilinos/Trilinos/pulls","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Chris Siefert and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":9452,"user_id":32662,"name":"Trilinos","description":"TheTrilinos Project is an effort to develop algorithms and enabling technologies within an object-oriented software framework for the solution of large-scale, complex multi-physics engineering and scientific problems on new and emerging high-performance computing (HPC) architectures.\r\n","homepage_url":"https://trilinos.org","repo_url":"https://github.com/trilinos/Trilinos","license":"BSD-3-Clause, LGPL","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"https://github.com/trilinos/Trilinos.git","description_good_status":"Met","description_good_justification":"https://github.com/trilinos/Trilinos/blob/master/README.md","interact_status":"Met","interact_justification":"https://github.com/trilinos/Trilinos/blob/master/README.md","contribution_status":"Met","contribution_justification":"https://github.com/trilinos/Trilinos/wiki/Managing-Trilinos-Project-Issues","contribution_requirements_status":"Met","contribution_requirements_justification":"https://github.com/trilinos/Trilinos/wiki/Managing-Trilinos-Project-Issues\r\nhttps://github.com/trilinos/Trilinos/wiki/PR-Creation-\u0026-Approval-Guidelines-for-Tpetra,-Ifpack2,-\r\nand-MueLu-Developers","license_location_status":"Met","license_location_justification":"https://github.com/trilinos/Trilinos/blob/master/LICENSE","floss_license_status":"Met","floss_license_justification":"https://trilinos.github.io/license.html","floss_license_osi_status":"Met","documentation_basics_status":"Met","documentation_basics_justification":"https://trilinos.github.io/","documentation_interface_status":"Met","documentation_interface_justification":"https://trilinos.github.io/","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Primary development is done on github.","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"https://github.com/trilinos/Trilinos/releases","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"https://github.com/trilinos/Trilinos/releases","release_notes_status":"Met","release_notes_justification":"Release notes provided since version 14.2.0 https://github.com/trilinos/Trilinos/releases","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"There have not been any CVE or similar run-time vulnerabilities identified in Trilinos.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"https://github.com/trilinos/Trilinos/issues","report_process_status":"Met","report_process_justification":"https://github.com/trilinos/Trilinos/issues. Trilinos uses github issues.","report_responses_status":"Met","report_responses_justification":"https://github.com/trilinos/Trilinos/issues","enhancement_responses_status":"Met","enhancement_responses_justification":"https://github.com/trilinos/Trilinos/issues","report_archive_status":"Met","report_archive_justification":"https://github.com/trilinos/Trilinos/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"https://github.com/trilinos/Trilinos/issues","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"https://github.com/trilinos/Trilinos/security","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"Trilinos has not received any vulnerability reports in the last 6 months.","build_status":"Met","build_justification":"Trilinos uses cmake.","build_common_tools_status":"Met","build_common_tools_justification":"Trilinos uses cmake.","build_floss_tools_status":"Met","build_floss_tools_justification":"Trilinos uses cmake.","test_status":"Met","test_justification":"Trilinos uses cmake.","test_invocation_status":"Met","test_invocation_justification":"Trilinos uses cmake.","test_most_status":"Met","test_most_justification":"Trilinos' test suite covers most code branches.","test_policy_status":"Met","test_policy_justification":"See our testing policy: https://github.com/trilinos/Trilinos/wiki/Trilinos-Testing-Policy","tests_are_added_status":"Met","tests_are_added_justification":"See issue https://github.com/trilinos/Trilinos/pull/12728 which is cited in the 15.0.0 release notes, in which added functionality also includes tests.","tests_documented_added_status":"Met","tests_documented_added_justification":"See https://github.com/trilinos/Trilinos/blob/master/CONTRIBUTING.md","warnings_status":"Met","warnings_justification":"A gcc -Werror build is included as part of the testing process.","warnings_fixed_status":"Met","warnings_fixed_justification":"A gcc -Werror build is included as part of the testing process. Code cannot be merged if this test fails.","warnings_strict_status":"Met","warnings_strict_justification":"Werror cannot be enabled for legacy packages which are scheduled for deprecation in FY25. Once they are removed then stricter use of -Werror is possible.","know_secure_design_status":"Met","know_secure_design_justification":"The #4 developer by commits has completed Linux Foundation's Developing Secure Software LFD121 course.","know_common_errors_status":"Met","know_common_errors_justification":"Memory errors are the major issue in scientific software like Trilinos. Most developers are familiar with preventing this type of errors.","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"Github uses https / ssh for checkouts.","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Github uses https / ssh for checkouts, not http","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"There are no publicly known vulnerabilities in Trilinos","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"There are have not to date been critical vulnerabilities reported for Trilinos.","static_analysis_status":"Met","static_analysis_justification":"CodeQL is used as part of the PR testing process.","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"CodeQL does this.","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"CodeQL is run on every PR.","static_analysis_often_status":"Met","static_analysis_often_justification":"CodeQL is run on every PR.","dynamic_analysis_status":"Unmet","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"Valgrind is used as part of regular nightly testing.","dynamic_analysis_enable_assertions_status":"Unmet","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"We have not identified any vulnerabilities with dynamic analysis at this time.","general_comments":"","created_at":"2024-09-16T20:00:07.681Z","updated_at":"2024-10-08T17:37:08.095Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"CI is run via github as part of the testing process.","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests. https://github.com/trilinos/Trilinos\r\n/issues","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"There are no credentials stored in the Trilinos repo.","english_status":"Met","english_justification":"https://github.com/trilinos/Trilinos/issues, https://trilinos.github.io/","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Unmet","hardened_site_justification":"// X-Content-Type-Options was not set to \"nosniff\".","installation_common_status":"?","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2024-10-08T16:26:20.006Z","lost_passing_at":null,"last_reminder_at":null,"disabled_reminders":false,"implementation_languages":"C++, Python","lock_version":11,"badge_percentage_1":25,"dco_status":"?","governance_status":"?","code_of_conduct_status":"?","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"?","documentation_current_status":"?","documentation_achievements_status":"?","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"?","maintenance_or_update_status":"?","vulnerability_report_credit_status":"?","vulnerability_response_process_status":"?","coding_standards_status":"?","coding_standards_enforced_status":"?","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"?","build_repeatable_status":"?","installation_standard_variables_status":"?","installation_development_quick_status":"?","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"?","automated_integration_testing_status":"?","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"?","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"?","version_tags_signed_status":"?","badge_percentage_2":13,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":125,"repo_url_updated_at":"2024-10-08T16:18:42.960Z","achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2024-10-08T16:26:20.006Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"https://github.com/trilinos/Trilinos/pulls","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":null,"badge_percentage_baseline_2":null,"badge_percentage_baseline_3":null,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Chris Siefert and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file diff --git a/_data/openssf/9534.json b/_data/openssf/9534.json index 97f1bb7..ae62517 100644 --- a/_data/openssf/9534.json +++ b/_data/openssf/9534.json @@ -1 +1 @@ -{"id":9534,"user_id":39990,"name":"kokkos-kernels","description":"Kokkos C++ Performance Portability Programming Ecosystem: Math Kernels - Provides BLAS, Sparse BLAS and Graph Kernels","homepage_url":"https://github.com/kokkos/kokkos-kernels","repo_url":"https://github.com/kokkos/kokkos-kernels","license":"Apache-2.0","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"Our main website and the documentation both provide overview of what the library does and provides.\r\nhttps://kokkos.org/about/overview and https://kokkos.org/kokkos-kernels/docs/","interact_status":"Met","interact_justification":"The project has a release page on github (https://github.com/kokkos/kokkos-kernels/releases) and our website (https://kokkos.org/about/releases/). We also provide information on how to contribute to the project here: https://kokkos.org/kokkos-kernels/docs/Contributing.html","contribution_status":"Met","contribution_justification":"The process on how to submit code changes by pull request to Kokkos Kernels is documented here: https://kokkos.org/kokkos-kernels/docs/Contributing.html ","contribution_requirements_status":"Met","contribution_requirements_justification":"The requirement for change submissions is detailed here: https://kokkos.org/kokkos-kernels/docs/Contributing.html, various aspect of the required testing and format are explained.","license_location_status":"Met","license_location_justification":"License location file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The library is license under Apache 2.0 with LLVM exception, the license is available here: https://github.com/kokkos/kokkos-kernels/blob/develop/LICENSE The Apache-2.0 license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"While Apache 2.0 is approved by OSI, the specific LLVM exception is not even though it derives from the OSI approved license. The Apache-2.0 license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"The documentation is developed within the code repository and is built and published automatically with our CI.\r\nDocumentation source: https://github.com/kokkos/kokkos-kernels/tree/develop/docs\r\nDocumentation website: https://kokkos.org/kokkos-kernels/docs/index.html","documentation_interface_status":"Met","documentation_interface_justification":"The API documentation can be found in the following sections of the documentation:\r\nhttps://kokkos.org/kokkos-kernels/docs/API/blas-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/batched-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/lapack-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/sparse-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/graph-index.html","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs, https://github.com/kokkos/kokkos-kernels","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Every pull request on github is subject to a review process which is open and public. The release process itself is independent from the individual pull request submitted to the repository.","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The project uses SemVer 2.0.0, we had a blog post on the topic recently: https://kokkos.org/blog/2025-07-08-aligning-with-semver/ and the version numbers of the current release can be seen on our release page: https://kokkos.org/about/releases/","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"We are using tags to identify each release and actually use the GitHub feature that associate tags and releases to maintain the list of releases on github, see https://github.com/kokkos/kokkos-kernels/releases","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"There are no publicly none vulnerabilities so far.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"The project uses github issues track individual issues: https://github.com/kokkos/kokkos-kernels/issues","report_process_status":"Met","report_process_justification":"The project uses github issues for bug submissions from users: https://github.com/kokkos/kokkos-kernels/issues","report_responses_status":"Met","report_responses_justification":"Project members add the label: \"bug\" on issues that contain a bug report, this makes it easy for anyone to filter the issues to see all bug reports: https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug","enhancement_responses_status":"Met","enhancement_responses_justification":"Enhancement and feature requests are tracked with label in github issues and are responded to in timely manner more than 50% of the time: https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue%20state%3Aopen%20label%3Aenhancement%20label%3A%22feature%20request%22","report_archive_status":"Met","report_archive_justification":"Github provides various filters to show open, closed or all issues allowing users to search in past issues and see the associated discussions. https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"Kokkos Kernels has a security.md file in the repository under .github/ which is the standard location for this file and it is automatically picked up by the github API and displayed under the security tab of the repository's main page. https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"We recommend submitting vulnerability report via github's mechanism for privacy or directly to the library leads. https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md ","vulnerability_report_response_status":"Met","vulnerability_report_response_justification":"Any vulnerability report submit to the project gets a response within 5 business days see: https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md ","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"The build system is based on CMake which is distributed under BSD-3: https://github.com/Kitware/CMake","test_status":"Met","test_justification":"The project uses a combination of gtest and ctest for automated testing. The build and test process are described in the documentation: https://kokkos.org/kokkos-kernels/docs/building.html","test_invocation_status":"Met","test_invocation_justification":"Once the library and its tests are built, executable are generated that can be run without any argument to run all the test. Passing the `--help` option on the command line prints an explanation to run only selected subset of tests.","test_most_status":"Met","test_most_justification":"Our tests are as extensive as possible and attempt to cover all code path in the library: https://kokkos.org/kokkos-kernels/docs/Contributing.html#testing-policy","test_policy_status":"Met","test_policy_justification":"All new features and their associated APIs are required to be tested with associated unit-tests, ideally simple usage example are also created. https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","tests_are_added_status":"Met","tests_are_added_justification":"One can observed the status of the CI after each Pull Request was merged, additionally our scorecard how many pull requests are merged without proper reviews: https://github.com/kokkos/kokkos-kernels/security/code-scanning","tests_documented_added_status":"Met","tests_documented_added_justification":"This policy is documented clearly in the pull request section of the contributing page in the documentation: https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","warnings_status":"Met","warnings_justification":"The project build system has an option to enable the set of compiler warnings the project guards against. A second option allows to turn warnings into errors. Finally both options are enabled in our continuous integration process to prevent these warnings from being introduced in the source code. \r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/cmake/kokkoskernels_warnings.cmake\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/osx.yml","warnings_fixed_status":"Met","warnings_fixed_justification":"Warnings selected as important are added to our set of warnings and will generate build failures in our continuous integration system.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/osx.yml","warnings_strict_status":"Met","warnings_strict_justification":"The project enables both the recommended set of warnings from gcc/clang: \"-Wall\" and the additional set of warnings in \"-Wextra\"","know_secure_design_status":"Met","know_secure_design_justification":"The library maintainer (github handle lucbv) has audited the \"secure software development fundamentals\"","know_common_errors_status":"Met","know_common_errors_justification":"The library maintainer (github handle lucbv) has audited the \"secure software development fundamentals\"","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"The releases are hosted on github which uses https protocol for archive downloads. \r\nhttps://github.com/kokkos/kokkos-kernels/releases\r\nhttps://kokkos.org/about/releases/","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Each release is cryptographically hashed and signed with pgp keys, the public keys for signature verifications are retrieved over https protocol.\r\nhttps://kokkos.org/about/releases/","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"There are currently no none vulnerabilities and only automatically reported vulnerabilities have been reported. All have been fixed in a timely manner.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning?query=branch%3Adevelop+is%3Aopen","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"Vulnerabilities are patched as soon as possible.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning?query=branch%3Adevelop+is%3Aopen","static_analysis_status":"Met","static_analysis_justification":"CodeQL is used to perform static analysis on our code base prior to every release.","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"Both CodeQL and the OpenSSF scorecard are scanning the code repository for vulnerabilities in each pull request.","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"All vulnerabilities are addressed in a timely manner.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning","static_analysis_often_status":"Met","static_analysis_often_justification":"Our static analysis tool, CodeQL, runs on every pull request and must return without issues detected before a code change can be merged, it is also triggered on a regular basis even if no changes are submitted.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/codeql.yml","dynamic_analysis_status":"Met","dynamic_analysis_justification":"The project uses clang sanitizers and compute sanitizer to perform dynamic analysis on the automated testing suite.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"The project uses clang sanitizers and compute sanitizer to test the software for unsafe memory usage.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/linux.yml\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/h100_lychee.yml","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"As the kokkos kernels project implements mathematical algorithms, numerous assertions are tested in the code to detect bad inputs and/or outputs.\r\nFor instance our GEMM algorithm performs multiple static assertions and runtime checks on input parameters:\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/blas/src/KokkosBlas3_gemm.hpp","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"No vulnerabilities reported by our dynamic analysis tools are allowed, see output of pull request passing for the sanitizer actions.","general_comments":"","created_at":"2024-10-08T16:49:18.266Z","updated_at":"2026-02-09T21:11:00.541Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"The project uses github actions to implement a continuous integration process. This means that every pull request against the project is individually tested and merged into the default branch (develop) once it has been reviewed and has passed all the tests. https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests. We also have meeting agenda and notes available here: https://github.com/kokkos/development/tree/main/meeting_notes/kokkos_kernels_devs ","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"The project takes great care to avoid the public dissemination of passwords and/or private keys.\r\nhttps://github.com/kokkos/kokkos-kernels/security/secret-scanning","english_status":"Met","english_justification":"All issues and pull requests as well as our meetings are in english, meeting agenda and notes are available publicly on github here: https://github.com/kokkos/development/tree/main/meeting_notes/kokkos_kernels_devs","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Met","hardened_site_justification":"Found all required security hardening headers.","installation_common_status":"Met","installation_common_justification":"The project can be installed using the standard cmake command `cmake --install` or `make install`.\r\nhttps://kokkos.org/kokkos-kernels/docs/building.html","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-12-16T23:28:06.184Z","lost_passing_at":null,"last_reminder_at":"2025-08-01T23:01:03.195Z","disabled_reminders":false,"implementation_languages":"C++, Objective-C++, CMake, Shell, Python, Groovy, C","lock_version":19,"badge_percentage_1":64,"dco_status":"Met","dco_justification":"We are enforcing the use of the DCO in our repository: https://kokkos.org/kokkos-kernels/docs/Contributing.html","governance_status":"Met","governance_justification":"https://github.com/kokkos/governance","code_of_conduct_status":"Met","code_of_conduct_justification":"https://github.com/kokkos/governance/blob/main/code-of-conduct.md","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://kokkos.org/kokkos-kernels/docs/quick_start.html","documentation_current_status":"Met","documentation_current_justification":"Our documentation includes an \"deprecations\" page https://kokkos.org/kokkos-kernels/docs/deprecation_page.html and the documentation source is included in the repository with an action that checks for API changes to keep it up to date.","documentation_achievements_status":"Met","documentation_achievements_justification":"The readme displayed on the front page of the repository includes achievements: https://github.com/kokkos/kokkos-kernels/tree/develop","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"N/A","sites_password_security_justification":"The website does not store any password, neither do our download URLs. The repo is hosted on GitHub which satisfies these requirements.","maintenance_or_update_status":"Met","maintenance_or_update_justification":"The project offers an upgrade path and documents the deprecated APIs between versions to help with the update process. https://kokkos.org/kokkos-kernels/docs/deprecation_page.html","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"There has not been any vulnerabilities reported in the past 12 months","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"We have a process to respond to vulnerabilities, it is described here: https://github.com/kokkos/kokkos-kernels/tree/develop?tab=security-ov-file","coding_standards_status":"Met","coding_standards_justification":"We use a coding style for our c++ code and it is enforced using a github action that checks it has been followed appropriately.\r\nhttps://kokkos.org/kokkos-kernels/docs/Contributing.html","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"Our automated clang-format check enforces the coding style.\r\nhttps://github.com/kokkos/kokkos-kernels/actions/workflows/format.yml\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/format.yml","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"Met","build_non_recursive_justification":"The build system produced does not recursively build subdirectories.","build_repeatable_status":"?","installation_standard_variables_status":"Met","installation_standard_variables_justification":"The build system relies on CMake's standard build installation logic.","installation_development_quick_status":"Met","installation_development_quick_justification":"Users can quickly and easily enable testing and checks support by turning on our unit-test harness using a single configuration parameter.","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"Met","interfaces_current_justification":"The project turns on -Werror and -Wdeprecated warnings in its CI builds to ensure that no deprecated/obsolete functions are used.","automated_integration_testing_status":"Met","automated_integration_testing_justification":"The project uses a suite unit-tests using gtest and pass/fail status is reported in each of the CI build for each Pull Request.\r\nhttps://github.com/kokkos/kokkos-kernels/tree/develop/.github/workflows","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"Met","test_policy_mandated_justification":"The project does require every change to be tested and to pass our unit-tests. We also require all new APIs and their various implementation to be tested in a unit-test prior to merging any changes.","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"Met","signed_releases_justification":"The maintainers have each release verified for provenance using the slsa framework which generates an in.toto artifact, additionally all release are verified (sha256sum --check) and signed using maintainers gpg keys. The keys are easily accessible from a link in the release page which points to a different website.\r\nhttps://github.com/kokkos/kokkos-kernels/releases","version_tags_signed_status":"Met","version_tags_signed_justification":"Releases are traceable by tags in our repository, each release tag is generated with a signature (git tag -s MYTAG) and github displays the key ID of the signing key.","badge_percentage_2":26,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":164,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-12-16T23:28:06.184Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"The project is continuously being worked on and issues and pull request can be seen on github. We also have regular releases about every 3 to 4 months for minor release and about every 3 years for major releases.","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Luc Berger and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file +{"id":9534,"user_id":39990,"name":"kokkos-kernels","description":"Kokkos C++ Performance Portability Programming Ecosystem: Math Kernels - Provides BLAS, Sparse BLAS and Graph Kernels","homepage_url":"https://github.com/kokkos/kokkos-kernels","repo_url":"https://github.com/kokkos/kokkos-kernels","license":"Apache-2.0","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"Our main website and the documentation both provide overview of what the library does and provides.\r\nhttps://kokkos.org/about/overview and https://kokkos.org/kokkos-kernels/docs/","interact_status":"Met","interact_justification":"The project has a release page on github (https://github.com/kokkos/kokkos-kernels/releases) and our website (https://kokkos.org/about/releases/). We also provide information on how to contribute to the project here: https://kokkos.org/kokkos-kernels/docs/Contributing.html","contribution_status":"Met","contribution_justification":"The process on how to submit code changes by pull request to Kokkos Kernels is documented here: https://kokkos.org/kokkos-kernels/docs/Contributing.html ","contribution_requirements_status":"Met","contribution_requirements_justification":"The requirement for change submissions is detailed here: https://kokkos.org/kokkos-kernels/docs/Contributing.html, various aspect of the required testing and format are explained.","license_location_status":"Met","license_location_justification":"License location file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/LICENSE\u003e.","floss_license_status":"Met","floss_license_justification":"The library is license under Apache 2.0 with LLVM exception, the license is available here: https://github.com/kokkos/kokkos-kernels/blob/develop/LICENSE The Apache-2.0 license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"While Apache 2.0 is approved by OSI, the specific LLVM exception is not even though it derives from the OSI approved license. The Apache-2.0 license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"The documentation is developed within the code repository and is built and published automatically with our CI.\r\nDocumentation source: https://github.com/kokkos/kokkos-kernels/tree/develop/docs\r\nDocumentation website: https://kokkos.org/kokkos-kernels/docs/index.html","documentation_interface_status":"Met","documentation_interface_justification":"The API documentation can be found in the following sections of the documentation:\r\nhttps://kokkos.org/kokkos-kernels/docs/API/blas-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/batched-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/lapack-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/sparse-index.html\r\nhttps://kokkos.org/kokkos-kernels/docs/API/graph-index.html","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs, https://github.com/kokkos/kokkos-kernels","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Every pull request on github is subject to a review process which is open and public. The release process itself is independent from the individual pull request submitted to the repository.","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"The project uses SemVer 2.0.0, we had a blog post on the topic recently: https://kokkos.org/blog/2025-07-08-aligning-with-semver/ and the version numbers of the current release can be seen on our release page: https://kokkos.org/about/releases/","version_semver_status":"Met","version_tags_status":"Met","version_tags_justification":"We are using tags to identify each release and actually use the GitHub feature that associate tags and releases to maintain the list of releases on github, see https://github.com/kokkos/kokkos-kernels/releases","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"There are no publicly none vulnerabilities so far.","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"The project uses github issues track individual issues: https://github.com/kokkos/kokkos-kernels/issues","report_process_status":"Met","report_process_justification":"The project uses github issues for bug submissions from users: https://github.com/kokkos/kokkos-kernels/issues","report_responses_status":"Met","report_responses_justification":"Project members add the label: \"bug\" on issues that contain a bug report, this makes it easy for anyone to filter the issues to see all bug reports: https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug","enhancement_responses_status":"Met","enhancement_responses_justification":"Enhancement and feature requests are tracked with label in github issues and are responded to in timely manner more than 50% of the time: https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue%20state%3Aopen%20label%3Aenhancement%20label%3A%22feature%20request%22","report_archive_status":"Met","report_archive_justification":"Github provides various filters to show open, closed or all issues allowing users to search in past issues and see the associated discussions. https://github.com/kokkos/kokkos-kernels/issues?q=is%3Aissue","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"Kokkos Kernels has a security.md file in the repository under .github/ which is the standard location for this file and it is automatically picked up by the github API and displayed under the security tab of the repository's main page. https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"We recommend submitting vulnerability report via github's mechanism for privacy or directly to the library leads. https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md ","vulnerability_report_response_status":"Met","vulnerability_report_response_justification":"Any vulnerability report submit to the project gets a response within 5 business days see: https://github.com/kokkos/kokkos-kernels/blob/develop/.github/SECURITY.md ","build_status":"Met","build_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CMakeLists.txt\u003e.","build_common_tools_status":"Met","build_common_tools_justification":"Non-trivial build file in repository: \u003chttps://github.com/kokkos/kokkos-kernels/blob/develop/CMakeLists.txt\u003e.","build_floss_tools_status":"Met","build_floss_tools_justification":"The build system is based on CMake which is distributed under BSD-3: https://github.com/Kitware/CMake","test_status":"Met","test_justification":"The project uses a combination of gtest and ctest for automated testing. The build and test process are described in the documentation: https://kokkos.org/kokkos-kernels/docs/building.html","test_invocation_status":"Met","test_invocation_justification":"Once the library and its tests are built, executable are generated that can be run without any argument to run all the test. Passing the `--help` option on the command line prints an explanation to run only selected subset of tests.","test_most_status":"Met","test_most_justification":"Our tests are as extensive as possible and attempt to cover all code path in the library: https://kokkos.org/kokkos-kernels/docs/Contributing.html#testing-policy","test_policy_status":"Met","test_policy_justification":"All new features and their associated APIs are required to be tested with associated unit-tests, ideally simple usage example are also created. https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","tests_are_added_status":"Met","tests_are_added_justification":"One can observed the status of the CI after each Pull Request was merged, additionally our scorecard how many pull requests are merged without proper reviews: https://github.com/kokkos/kokkos-kernels/security/code-scanning","tests_documented_added_status":"Met","tests_documented_added_justification":"This policy is documented clearly in the pull request section of the contributing page in the documentation: https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","warnings_status":"Met","warnings_justification":"The project build system has an option to enable the set of compiler warnings the project guards against. A second option allows to turn warnings into errors. Finally both options are enabled in our continuous integration process to prevent these warnings from being introduced in the source code. \r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/cmake/kokkoskernels_warnings.cmake\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/osx.yml","warnings_fixed_status":"Met","warnings_fixed_justification":"Warnings selected as important are added to our set of warnings and will generate build failures in our continuous integration system.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/osx.yml","warnings_strict_status":"Met","warnings_strict_justification":"The project enables both the recommended set of warnings from gcc/clang: \"-Wall\" and the additional set of warnings in \"-Wextra\"","know_secure_design_status":"Met","know_secure_design_justification":"The library maintainer (github handle lucbv) has audited the \"secure software development fundamentals\"","know_common_errors_status":"Met","know_common_errors_justification":"The library maintainer (github handle lucbv) has audited the \"secure software development fundamentals\"","crypto_published_status":"N/A","crypto_call_status":"N/A","crypto_floss_status":"N/A","crypto_keylength_status":"N/A","crypto_working_status":"N/A","crypto_pfs_status":"N/A","crypto_password_storage_status":"N/A","crypto_random_status":"N/A","delivery_mitm_status":"Met","delivery_mitm_justification":"The releases are hosted on github which uses https protocol for archive downloads. \r\nhttps://github.com/kokkos/kokkos-kernels/releases\r\nhttps://kokkos.org/about/releases/","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Each release is cryptographically hashed and signed with pgp keys, the public keys for signature verifications are retrieved over https protocol.\r\nhttps://kokkos.org/about/releases/","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"There are currently no none vulnerabilities and only automatically reported vulnerabilities have been reported. All have been fixed in a timely manner.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning?query=branch%3Adevelop+is%3Aopen","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"Vulnerabilities are patched as soon as possible.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning?query=branch%3Adevelop+is%3Aopen","static_analysis_status":"Met","static_analysis_justification":"CodeQL is used to perform static analysis on our code base prior to every release.","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"Both CodeQL and the OpenSSF scorecard are scanning the code repository for vulnerabilities in each pull request.","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"All vulnerabilities are addressed in a timely manner.\r\nhttps://github.com/kokkos/kokkos-kernels/security/code-scanning","static_analysis_often_status":"Met","static_analysis_often_justification":"Our static analysis tool, CodeQL, runs on every pull request and must return without issues detected before a code change can be merged, it is also triggered on a regular basis even if no changes are submitted.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/codeql.yml","dynamic_analysis_status":"Met","dynamic_analysis_justification":"The project uses clang sanitizers and compute sanitizer to perform dynamic analysis on the automated testing suite.","dynamic_analysis_unsafe_status":"Met","dynamic_analysis_unsafe_justification":"The project uses clang sanitizers and compute sanitizer to test the software for unsafe memory usage.\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/linux.yml\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/h100_lychee.yml","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"As the kokkos kernels project implements mathematical algorithms, numerous assertions are tested in the code to detect bad inputs and/or outputs.\r\nFor instance our GEMM algorithm performs multiple static assertions and runtime checks on input parameters:\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/blas/src/KokkosBlas3_gemm.hpp","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"No vulnerabilities reported by our dynamic analysis tools are allowed, see output of pull request passing for the sanitizer actions.","general_comments":"","created_at":"2024-10-08T16:49:18.266Z","updated_at":"2026-02-09T21:11:00.541Z","crypto_weaknesses_status":"N/A","test_continuous_integration_status":"Met","test_continuous_integration_justification":"The project uses github actions to implement a continuous integration process. This means that every pull request against the project is individually tested and merged into the default branch (develop) once it has been reviewed and has passed all the tests. https://kokkos.org/kokkos-kernels/docs/Contributing.html#pull-requests","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests. We also have meeting agenda and notes available here: https://github.com/kokkos/development/tree/main/meeting_notes/kokkos_kernels_devs ","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"The project takes great care to avoid the public dissemination of passwords and/or private keys.\r\nhttps://github.com/kokkos/kokkos-kernels/security/secret-scanning","english_status":"Met","english_justification":"All issues and pull requests as well as our meetings are in english, meeting agenda and notes are available publicly on github here: https://github.com/kokkos/development/tree/main/meeting_notes/kokkos_kernels_devs","hardening_status":"?","crypto_used_network_status":"N/A","crypto_tls12_status":"N/A","crypto_certificate_verification_status":"N/A","crypto_verification_private_status":"N/A","hardened_site_status":"Met","hardened_site_justification":"Found all required security hardening headers.","installation_common_status":"Met","installation_common_justification":"The project can be installed using the standard cmake command `cmake --install` or `make install`.\r\nhttps://kokkos.org/kokkos-kernels/docs/building.html","build_reproducible_status":"?","badge_percentage_0":100,"achieved_passing_at":"2025-12-16T23:28:06.184Z","lost_passing_at":null,"last_reminder_at":"2025-08-01T23:01:03.195Z","disabled_reminders":false,"implementation_languages":"C++, Objective-C++, CMake, Shell, Python, Groovy, C","lock_version":19,"badge_percentage_1":64,"dco_status":"Met","dco_justification":"We are enforcing the use of the DCO in our repository: https://kokkos.org/kokkos-kernels/docs/Contributing.html","governance_status":"Met","governance_justification":"https://github.com/kokkos/governance","code_of_conduct_status":"Met","code_of_conduct_justification":"https://github.com/kokkos/governance/blob/main/code-of-conduct.md","roles_responsibilities_status":"?","access_continuity_status":"?","bus_factor_status":"?","documentation_roadmap_status":"?","documentation_architecture_status":"?","documentation_security_status":"?","documentation_quick_start_status":"Met","documentation_quick_start_justification":"https://kokkos.org/kokkos-kernels/docs/quick_start.html","documentation_current_status":"Met","documentation_current_justification":"Our documentation includes an \"deprecations\" page https://kokkos.org/kokkos-kernels/docs/deprecation_page.html and the documentation source is included in the repository with an action that checks for API changes to keep it up to date.","documentation_achievements_status":"Met","documentation_achievements_justification":"The readme displayed on the front page of the repository includes achievements: https://github.com/kokkos/kokkos-kernels/tree/develop","accessibility_best_practices_status":"?","internationalization_status":"?","sites_password_security_status":"N/A","sites_password_security_justification":"The website does not store any password, neither do our download URLs. The repo is hosted on GitHub which satisfies these requirements.","maintenance_or_update_status":"Met","maintenance_or_update_justification":"The project offers an upgrade path and documents the deprecated APIs between versions to help with the update process. https://kokkos.org/kokkos-kernels/docs/deprecation_page.html","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"There has not been any vulnerabilities reported in the past 12 months","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"We have a process to respond to vulnerabilities, it is described here: https://github.com/kokkos/kokkos-kernels/tree/develop?tab=security-ov-file","coding_standards_status":"Met","coding_standards_justification":"We use a coding style for our c++ code and it is enforced using a github action that checks it has been followed appropriately.\r\nhttps://kokkos.org/kokkos-kernels/docs/Contributing.html","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"Our automated clang-format check enforces the coding style.\r\nhttps://github.com/kokkos/kokkos-kernels/actions/workflows/format.yml\r\nhttps://github.com/kokkos/kokkos-kernels/blob/develop/.github/workflows/format.yml","build_standard_variables_status":"?","build_preserve_debug_status":"?","build_non_recursive_status":"Met","build_non_recursive_justification":"The build system produced does not recursively build subdirectories.","build_repeatable_status":"?","installation_standard_variables_status":"Met","installation_standard_variables_justification":"The build system relies on CMake's standard build installation logic.","installation_development_quick_status":"Met","installation_development_quick_justification":"Users can quickly and easily enable testing and checks support by turning on our unit-test harness using a single configuration parameter.","external_dependencies_status":"?","dependency_monitoring_status":"?","updateable_reused_components_status":"?","interfaces_current_status":"Met","interfaces_current_justification":"The project turns on -Werror and -Wdeprecated warnings in its CI builds to ensure that no deprecated/obsolete functions are used.","automated_integration_testing_status":"Met","automated_integration_testing_justification":"The project uses a suite unit-tests using gtest and pass/fail status is reported in each of the CI build for each Pull Request.\r\nhttps://github.com/kokkos/kokkos-kernels/tree/develop/.github/workflows","regression_tests_added50_status":"?","test_statement_coverage80_status":"?","test_policy_mandated_status":"Met","test_policy_mandated_justification":"The project does require every change to be tested and to pass our unit-tests. We also require all new APIs and their various implementation to be tested in a unit-test prior to merging any changes.","implement_secure_design_status":"?","input_validation_status":"?","crypto_algorithm_agility_status":"N/A","crypto_credential_agility_status":"N/A","signed_releases_status":"Met","signed_releases_justification":"The maintainers have each release verified for provenance using the slsa framework which generates an in.toto artifact, additionally all release are verified (sha256sum --check) and signed using maintainers gpg keys. The keys are easily accessible from a link in the release page which points to a different website.\r\nhttps://github.com/kokkos/kokkos-kernels/releases","version_tags_signed_status":"Met","version_tags_signed_justification":"Releases are traceable by tags in our repository, each release tag is generated with a signature (git tag -s MYTAG) and github displays the key ID of the signing key.","badge_percentage_2":26,"contributors_unassociated_status":"?","copyright_per_file_status":"?","license_per_file_status":"?","small_tasks_status":"?","require_2FA_status":"?","secure_2FA_status":"?","code_review_standards_status":"?","two_person_review_status":"?","test_statement_coverage90_status":"?","test_branch_coverage80_status":"?","security_review_status":"?","assurance_case_status":"?","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":164,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2025-12-16T23:28:06.184Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"The project is continuously being worked on and issues and pull request can be seen on github. We also have regular releases about every 3 to 4 months for minor release and about every 3 years for major releases.","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":"?","OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","passing_saved":true,"silver_saved":true,"gold_saved":true,"baseline_1_saved":false,"baseline_2_saved":false,"baseline_3_saved":false,"OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit Luc Berger and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"} \ No newline at end of file