diff --git a/README.md b/README.md index 7f6969c..7ba1177 100644 --- a/README.md +++ b/README.md @@ -5,6 +5,7 @@ [![Python](https://img.shields.io/pypi/pyversions/forgeguard.svg)](https://pypi.org/project/forgeguard/) [![License: Apache-2.0](https://img.shields.io/pypi/l/forgeguard.svg)](https://github.com/gexiro-global/forgeguard/blob/main/LICENSE) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/gexiro-global/forgeguard/badge)](https://scorecard.dev/viewer/?uri=github.com/gexiro-global/forgeguard) [Security and trust evidence](docs/SECURITY-TRUST.md) documents the project's policies and automated checks. No certification or badge level is claimed. Read-only security posture self-check for one explicitly authorized self-hosted Gitea instance. diff --git a/docs/SECURITY-TRUST.md b/docs/SECURITY-TRUST.md index aff7c41..8e2cfda 100644 --- a/docs/SECURITY-TRUST.md +++ b/docs/SECURITY-TRUST.md @@ -8,4 +8,4 @@ This page is an evidence index, not a certification. The evidence does not prove - GitHub default CodeQL setup is active; dependency review, Dependabot, secret scanning and OpenSSF Scorecard supplement it. - Third-party actions are pinned to immutable commit SHAs with version comments. -The Scorecard badge is intentionally withheld until a successful default-branch run has produced a public API result. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission. +The official public Scorecard result is 6.5, generated 2026-09-04T13:39:26Z for commit `fa48e28109ad45ffb222bf8423d437daa92f5cc1`; see the [official public viewer](https://scorecard.dev/viewer/?uri=github.com/gexiro-global/forgeguard). This numeric result is point-in-time posture evidence, not a certification. `.bestpractices.json` contains evidence-backed automation proposals only; it is not an OpenSSF Best Practices or OSPS Baseline claim. A human must review any badge submission.