OpenSSF Best Practices Badge Criteria
Silver level: Security – OpenSSF Best Practices Badge Criteria

OpenSSF Best Practices Badge Criteria silver.crypto_credential_agility: crypto_credential_agility (Silver, MUST)

Silver criterion crypto_credential_agility (MUST; group Security, Use basic good cryptographic practices). Criterion text: The project MUST support storing authentication credentials (such as passwords and dynamic tokens) and private cryptographic keys in files that are separate from other information (such as configuration files, databases, and logs), and permit users to update and replace them without code recompilation. If the project never processes authentication credentials and private cryptographic keys, select "not applicable" (N/A).

Maintained by Gerard Blokdyk

Other controls in Silver level: Security – OpenSSF Best Practices Badge Criteria

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.