OpenSSF Best Practices evidence

August 21, 2026 ยท View on GitHub

This register tracks the Gold assessment for this repository.

The official entry is bestpractices.dev project 13733.

Assessment date: 2026-07-23.

Eligibility

This active, released C# SDK meets the OpenSSF eligibility rules.

Verified technical controls

AreaEvidence
LicenseApache-2.0 and REUSE 3.3 metadata
Contribution processDCO sign-off and independent review rules
GovernancePublic roles, decisions, releases, and continuity policy
Security reportingPrivate reporting, response targets, boundaries, and threat model
Runtime compatibility.NET 8 and .NET Framework 4.7.2 tests
Functional tests7,103 tests with no skips
Line coverage./scripts/coverage enforces 90%
Branch coverage./scripts/coverage enforces 80%
Static analysisCompiler analyzers, formatting checks, and CodeQL
Dependency reviewDependabot, locked restores, vulnerability audit, and license policy
Licensing gatePinned REUSE action checks every repository file
Reproducibility2 normalized NuGet builds must have identical bytes
CIPull requests and pushes run pinned, least-privilege workflows
Two-factor authenticationThe Xquik-dev organization requires 2FA

The current suite covers 49,965 of 52,555 executable lines.

That result is 95.07% line coverage.

It covers 11,262 of 12,475 branches, or 90.27%.

Coverage includes generated models, services, and the runtime core.

Loopback service tests cannot contact remote hosts.

The default transport blocks redirects that could forward credentials.

Multipart request bodies are not retried after consumption.

Verified release provenance

Release v0.6.1 points to commit 96c7c4bced1bc217cf8e89a4786338725866028a. Its GitHub-hosted publish workflow attested XTwitterScraper.0.6.1.nupkg. The asset, SLSA subject, and local SHA-256 match 207c6c76eb240e9c64def34cd51d5973998327e76892aa391fbf44b32b4f39d0. The documented verification command succeeds for the exact tag and workflow.

Outstanding Gold blockers

Human and organizational evidence remains incomplete.

Do not claim Gold while any mandatory criterion remains unmet.

Gold requirementCurrent evidenceRequired action
Access continuityPublic evidence does not prove 2 release-capable maintainersGrant and verify another maintainer's access
Bus factorGit history shows one significant contributorAdd another significant contributor
Unassociated contributorsFewer than 2 qualifying contributors are independentAccept qualifying external contributions
Independent reviewHistory does not prove 50% qualifying review coverageRequire and record independent reviews
Human security reviewNo completed review exists within 5 yearsCommission and publish a scoped review

Gold eligibility still requires review by a different human.

Maintenance

Run these evidence commands before releases:

./scripts/lint
./scripts/test
./scripts/coverage
./scripts/audit
uvx --from reuse==5.1.1 reuse lint
./scripts/check-reproducible
gh attestation verify PACKAGE \
  --repo Xquik-dev/x-twitter-scraper-csharp \
  --signer-workflow Xquik-dev/x-twitter-scraper-csharp/.github/workflows/publish-nuget.yml \
  --source-ref refs/tags/vVERSION \
  --deny-self-hosted-runners

Reassess the register before every major release.

Update bestpractices.dev only with public evidence.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.