OpenSSF Best Practices Badge Criteria
Silver level: Security – OpenSSF Best Practices Badge Criteria

OpenSSF Best Practices Badge Criteria silver.version_tags_signed: version_tags_signed (Silver, SUGGESTED)

Silver criterion version_tags_signed (SUGGESTED; group Security, Secure release). Criterion text: It is SUGGESTED that in the version control system, each important version tag (a tag that is part of a major release, minor release, or fixes publicly noted vulnerabilities) be cryptographically signed and verifiable as described in signed_releases.

Maintained by Gerard Blokdyk

Other controls in Silver level: Security – OpenSSF Best Practices Badge Criteria

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.