π Make OpenSSF badge status consistent across the self-assessment - #6715
Conversation
|
/approve |
|
/approve |
Recording the OpenSSF badge in the "Open SSF best practices" section left three other passages still saying it was not held: the assurance-case bullet, the resolved-questions entry, and the TAG-Security response table at the top of the document β the most reviewer-visible text in the file. The document therefore answered the same question two ways, which is worse than answering it wrongly once: a reviewer cannot tell which answer was checked against anything. All four now state the verified fact from the programme API: project 14261, passing, 100%, awarded 2026-08-27, never lapsed; silver and gold not claimed. The remaining "not yet held" wording is deliberate, and scoped to the paragraph recording this documents own error history. Refs #6684 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: clubanderson <clubanderson@users.noreply.github.com>
general-technical-review.md said the badge supersedes the self-assessments earlier "not yet pursued" note. That note is gone as of this branch, so the cross-reference pointed at text that no longer exists. Refs #6684 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: clubanderson <clubanderson@users.noreply.github.com>
210cf68 to
93041c3
Compare
93041c3 to
433cf07
Compare
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: clubanderson The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Thank you for your contribution! Your PR has been merged. We'd love to hear how your experience was: share feedback |
There was a problem hiding this comment.
Architect review β claims independently re-verified against the badge API.
curl https://www.bestpractices.dev/projects/14261.json returns: passing 100%, silver 15%, gold 22%, achieved_passing_at: 2026-08-27T17:47:12Z, lost_passing_at: null β exactly matching all four corrected passages.
I also grepped the PR head of security-self-assessment.md for residual contradictions: the only remaining "not yet held / being pursued" wording sits inside the error-history paragraph (~lines 736β743), which is deliberate and correctly scoped as stated in the PR body. The reviewer response table, assurance-case bullet, resolved-questions entry, and general-technical-review.md all now agree.
No structural concerns β consistent, API-verified, single source of truth restored.
π Hive Agent: architect | Instance: hosted-available-oke-11-placeholder-r05x | SHA: unknown
β hive: agent=architect backend=copilot model=claude-opus-4-6
Refs #6684
Follow-up to #6697. That PR corrected the "Open SSF best practices" section, but three other passages in the same document still asserted the badge was not held β so the self-assessment answered the same question two ways.
The worst of the three is the TAG-Security response table at the top of the document, the most reviewer-visible text in the file, which read "Agreed; being pursued."
A document that answers the same question two ways is worse than one that answers it wrongly once, because a reviewer cannot tell which answer was actually checked against anything.
All now state the same API-verified fact: project 14261, passing, 100% of passing criteria, awarded 2026-08-27, never lapsed; silver (15%) and gold (22%) explicitly not claimed.
The one remaining "not yet held" string is deliberate β it sits inside the paragraph that records the document's own error history, which is kept rather than quietly overwritten.
Mirror
This file's canonical-source note states that corrections belong here and are mirrored into
cncf/toc, never the reverse. The mirror in cncf/toc#2286 is being regenerated from this file in the same pass, so the two agree.Testing
src/scripts/test-compile-changelog.shβ all cases pass.