OpenSSF Scorecard
High-risk checks – OpenSSF Scorecard

OpenSSF Scorecard Binary-Artifacts: Binary-Artifacts check

Scorecard checks whether generated executable artifacts (compiled machine code, Java class files, Python bytecode, minified JavaScript and similar) are committed to the source repository. Such binaries cannot practically be reviewed against the source, may drift from it or be maliciously substituted, and let the build process atrophy. Files that are simultaneously source and executable (shell scripts), source generated by tools such as bison or yacc, and generated documentation are allowed. Remediation is to remove the binaries and build from source.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in High-risk checks – OpenSSF Scorecard

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.