Skip to content

Gold groundwork: code review, security-review procedure, REUSE compliance - #6

Merged
HackTuah merged 1 commit into
mainfrom
docs/gold-groundwork
Sep 23, 2026
Merged

HackTuah merged 1 commit into
mainfrom
docs/gold-groundwork

Conversation

@HackTuah

Copy link
Copy Markdown
Member

Groundwork for the OpenSSF gold criteria: a code-review section in CONTRIBUTING (centred on the key), docs/security-review.md (procedure, checklist, empty record), and REUSE compliance with reuse lint in CI (24 / 24 files locally). No code change.

…edure and record, REUSE compliance

For the OpenSSF gold criteria code_review_standards, security_review, copyright_per_file and
license_per_file. CONTRIBUTING gains a Code review section centred on the key (one source,
nothing kept, nothing printed, the census shown red against a planted break). docs/security-
review.md: measured against SECURITY.md and the assurance case, a seven-item checklist, an
empty record (the audit that closed the key-in-exception defect is named groundwork, not a
review). REUSE: .gitignore headed; .tool-versions, mix.lock and NOTICE with .license sidecars;
LICENSES/Apache-2.0.txt; reuse lint (6.2.0, beam_mcp's pin) as a CI job. Local: uvx
reuse==6.2.0 lint "compliant with version 3.3", 24 / 24 files with copyright and licence;
mix docs 0 warnings; 14 tests, 0 failures. No code change.

Signed-off-by: Ayla Croft <aylacroft@proton.me>
@HackTuah
HackTuah merged commit f8bb198 into main Sep 23, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant