OpenSSF Best Practices Badge Criteria
Passing level: Reporting – OpenSSF Best Practices Badge Criteria

OpenSSF Best Practices Badge Criteria passing.vulnerability_report_response: vulnerability_report_response (Passing, MUST)

Passing criterion vulnerability_report_response (MUST; group Reporting, Vulnerability report process). Criterion text: The project's initial response time for any vulnerability report received in the last 6 months MUST be less than or equal to 14 days.

Maintained by Gerard Blokdyk

Other controls in Passing level: Reporting – OpenSSF Best Practices Badge Criteria

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.