OpenSSF project
Best Practices Badge
A voluntary self-certification program that lets open source projects demonstrate they follow recognized development best practices.
How each persona uses Best Practices Badge
Software Developer / Maintainer Developer
Achieves the Best Practices Badge to voluntarily self-certify and demonstrate their adherence to secure development standards.
Open Source Professional (OSPO) OSPO
Mandates the achievement of the badge across internal open source projects to demonstrate a commitment to security and quality.
Security Engineer / Architect Security
Uses the Best Practices Badge as a signaling mechanism to verify that a project adheres to good practices.
CI/CD DevOps & Tooling Integrator DevOps
Integrates badge status checks into the pipeline to block the inclusion of dependencies that fail to meet baseline security practices.
Package & Repository Manager Package Manager
Uses the badge as a metadata indicator to highlight secure and well-maintained packages to end users in the repository.
Executive / End-User Consumer Executive
Uses the badge as a trust signal to make risk-aware procurement and enterprise decisions.
Problems Best Practices Badge helps with
Measuring Security Posture Posture
Turns adherence to recognised practices into a single, comparable trust signal that consumers can read at a glance.
Policy & Compliance Enforcement Compliance
Gives organizations a published bar that internal projects can be required to meet and demonstrate.