OpenSSF Best Practices Evidence

August 20, 2026 ยท View on GitHub

This register tracks the Gold assessment for this repository.

The official entry is bestpractices.dev project 13737.

Assessment date: 2026-07-23.

Eligibility

This active, public PHP SDK qualifies for the OpenSSF Best Practices badge.

Verified Technical Controls

AreaEvidence
LicenseApache-2.0 and REUSE 3.3 metadata
Contribution processDCO sign-off and independent review rules
GovernancePublic roles, decisions, releases, and continuity policy
Security reportingPrivate reporting, response targets, boundaries, and threat model
Runtime compatibilityPHP 8.1 and 8.2 syntax and production dependency checks
Functional testsPHP 8.3, 8.4, and 8.5
Executable line coverage./scripts/coverage enforces 90%
Branch coverage./scripts/coverage enforces 80%
Static analysisPHPStan level max and PHP CS Fixer
Dependency reviewDependabot, Composer audit, and a license allowlist
Licensing gatePinned REUSE action checks every repository file
Reproducibility2 normalized Composer archives must have identical bytes
CIPull requests and pushes run pinned, least-privilege workflows
Two-factor authenticationThe Xquik-dev organization requires 2FA

The suite runs 247 tests with 689 assertions and 7 intentional skips.

It covers 3,887 of 4,052 executable lines, or 95.93%.

It covers 1,059 of 1,282 branches, or 82.61%.

Dynamic coverage includes the client, runtime core, and service facades.

Generated DTO boilerplate does not inflate the dynamic coverage score.

PHPStan checks every generated DTO at its strictest level.

The loopback service suite also parses generated response models.

REUSE validates license metadata for all 962 repository files.

Verified Release Provenance

Release v0.13.2 provides an attested Composer archive and Sigstore bundle. Its tag targets commit 66eb960e5324007f28792e5b4e5c99456005ece3. GitHub verifies the archive against the release workflow and hosted-runner policy.

Outstanding Gold Blockers

Human and organizational evidence remains incomplete.

Do not claim Gold while any mandatory criterion remains unmet.

Gold RequirementCurrent EvidenceRequired Action
Access continuityPublic evidence does not prove 2 release-capable maintainersGrant and verify another maintainer's access
Bus factorGit history shows one significant contributorAdd another significant contributor
Unassociated contributorsFewer than 2 qualifying contributors are independentAccept qualifying external contributions
Independent reviewHistory does not prove 50% qualifying review coverageRequire and record independent reviews
Human security reviewNo completed review exists within 5 yearsCommission and publish a scoped review

Gold eligibility still requires review by a different human.

Maintenance

Run these evidence commands before releases:

./scripts/lint
./scripts/test
./scripts/coverage
./scripts/audit
reuse lint
./scripts/check-reproducible
gh attestation verify ARCHIVE \
  --repo Xquik-dev/x-twitter-scraper-php \
  --signer-workflow Xquik-dev/x-twitter-scraper-php/.github/workflows/release-provenance.yml

Reassess the register before every major release.

Update bestpractices.dev only with public evidence.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.