What the Scorecard badge says, including the parts that are low

September 5, 2026 · View on GitHub

The badge is live, so it moves. This file is the measurement behind it, not a summary of it.

Measured 2026-09-05T06:29:04Z against api.scorecard.dev, the JSON endpoint for github.com/b7n0de/proofbundle, on commit 049b3195 (the frozen head of 6.0.0). Overall score 7.3 / 10.

Where a value differs from an earlier reading, the new value stands with its date and the old one is not carried forward.

CheckScore
Binary-Artifacts10
CI-Tests10
Dangerous-Workflow10
Dependency-Update-Tool10
Fuzzing10
License10
Packaging10
SAST10
Security-Policy10
Token-Permissions10
Vulnerabilities10
Signed-Releases10
Branch-Protection3
Pinned-Dependencies3
CII-Best-Practices0
Code-Review0
Contributors0
Maintained0

The four zeros, one sentence each

  • Maintained (0/10) — The check wants sustained activity on the default branch across a 90 day window. This repository is younger than that window. It resolves itself with time and is not worth chasing.
  • Code-Review (0/10) — Most commits are not reviewed by a second person. That is structural for a single maintainer, and the zero is an accurate description of it rather than a defect to hide. It moved from 1 to 0 since the 2026-08-10 reading.
  • CII-Best-Practices (0/10) — The OpenSSF Best Practices badge has not been applied for. The criteria were walked through honestly first, in docs/openssf_best_practices_self_assessment.md.
  • Contributors (0/10) — The check counts contributors from two or more organisations. This is a one person project, and the zero says exactly that.

The two in between

  • Signed-Releases (10/10) — the check reads GitHub release assets looking for a signature file. It read 0 on 2026-08-10, 6 at 11:12:23Z on 2026-09-02, 8 at 19:56:38Z the same day and 10 at 06:29:04Z on 2026-09-05, after the provenance file of v5.1.0.post1 joined the release assets. The badge is live and moves between two readings hours apart, which is the reason this file carries a timestamp rather than a claim.
  • Branch-Protection (3/10) — the check cannot see every setting through the API it uses, and the ruleset in force is stricter than the value suggests. This is the value as measured, not as argued.
  • Pinned-Dependencies (3/10) — workflow actions are pinned by commit SHA; the deduction comes from unpinned dependencies elsewhere in the toolchain.

Honest limit

A Scorecard number measures what the checks can see from outside. It is evidence about the repository's posture, not about whether the code is correct. Nothing in this file should be read as a claim about the latter.