Skip to content

πŸ“– Make OpenSSF badge status consistent across the self-assessment - #6715

Merged
clubanderson merged 2 commits into
v4from
docs/6684-badge-consistency
Sep 11, 2026
Merged

clubanderson merged 2 commits into
v4from
docs/6684-badge-consistency

Conversation

@clubanderson

Copy link
Copy Markdown
Member

Refs #6684

Follow-up to #6697. That PR corrected the "Open SSF best practices" section, but three other passages in the same document still asserted the badge was not held β€” so the self-assessment answered the same question two ways.

The worst of the three is the TAG-Security response table at the top of the document, the most reviewer-visible text in the file, which read "Agreed; being pursued."

Location Was Now
Reviewer response table (top of doc) "Agreed; being pursued" Already held; also notes the entry itself was corrected
Assurance-case bullet "not yet held β€” and being pursued" held at passing, project 14261
Resolved-questions entry "Resolved: yes" (intends to pursue) "Resolved: it already holds it"

A document that answers the same question two ways is worse than one that answers it wrongly once, because a reviewer cannot tell which answer was actually checked against anything.

All now state the same API-verified fact: project 14261, passing, 100% of passing criteria, awarded 2026-08-27, never lapsed; silver (15%) and gold (22%) explicitly not claimed.

The one remaining "not yet held" string is deliberate β€” it sits inside the paragraph that records the document's own error history, which is kept rather than quietly overwritten.

Mirror

This file's canonical-source note states that corrections belong here and are mirrored into cncf/toc, never the reverse. The mirror in cncf/toc#2286 is being regenerated from this file in the same pass, so the two agree.

Testing

src/scripts/test-compile-changelog.sh β€” all cases pass.

@kubestellar-prow kubestellar-prow Bot added dco-signoff: yes Indicates the PR's author has signed the DCO. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Sep 11, 2026
@clubanderson

Copy link
Copy Markdown
Member Author

/approve

@kubestellar-prow kubestellar-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 11, 2026
@clubanderson

Copy link
Copy Markdown
Member Author

/approve

clubanderson and others added 2 commits September 11, 2026 11:26
Recording the OpenSSF badge in the "Open SSF best practices" section left
three other passages still saying it was not held: the assurance-case
bullet, the resolved-questions entry, and the TAG-Security response table
at the top of the document β€” the most reviewer-visible text in the file.

The document therefore answered the same question two ways, which is worse
than answering it wrongly once: a reviewer cannot tell which answer was
checked against anything.

All four now state the verified fact from the programme API: project 14261,
passing, 100%, awarded 2026-08-27, never lapsed; silver and gold not
claimed. The remaining "not yet held" wording is deliberate, and scoped to
the paragraph recording this documents own error history.

Refs #6684

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: clubanderson <clubanderson@users.noreply.github.com>
general-technical-review.md said the badge supersedes the self-assessments
earlier "not yet pursued" note. That note is gone as of this branch, so the
cross-reference pointed at text that no longer exists.

Refs #6684

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: clubanderson <clubanderson@users.noreply.github.com>
@clubanderson
clubanderson force-pushed the docs/6684-badge-consistency branch from 210cf68 to 93041c3 Compare September 11, 2026 15:27
@kubestellar-prow kubestellar-prow Bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Sep 11, 2026
@clubanderson
clubanderson force-pushed the docs/6684-badge-consistency branch from 93041c3 to 433cf07 Compare September 11, 2026 15:27
@clubanderson

Copy link
Copy Markdown
Member Author

/approve

@kubestellar-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: clubanderson

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@clubanderson
clubanderson merged commit 4601f92 into v4 Sep 11, 2026
48 of 51 checks passed
@kubestellar-prow
kubestellar-prow Bot deleted the docs/6684-badge-consistency branch September 11, 2026 15:41
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for your contribution! Your PR has been merged.

We'd love to hear how your experience was: share feedback

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Architect review β€” claims independently re-verified against the badge API.

curl https://www.bestpractices.dev/projects/14261.json returns: passing 100%, silver 15%, gold 22%, achieved_passing_at: 2026-08-27T17:47:12Z, lost_passing_at: null β€” exactly matching all four corrected passages.

I also grepped the PR head of security-self-assessment.md for residual contradictions: the only remaining "not yet held / being pursued" wording sits inside the error-history paragraph (~lines 736–743), which is deliberate and correctly scoped as stated in the PR body. The reviewer response table, assurance-case bullet, resolved-questions entry, and general-technical-review.md all now agree.

No structural concerns β€” consistent, API-verified, single source of truth restored.

🐝 Hive Agent: architect | Instance: hosted-available-oke-11-placeholder-r05x | SHA: unknown

β€” hive: agent=architect backend=copilot model=claude-opus-4-6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes Indicates the PR's author has signed the DCO. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant