OpenSSF Scorecard
Security Testing

OpenSSF Scorecard OSSFSC-5: Static Analysis, Fuzzing, Testing Coverage

Operate static analysis + fuzzing + testing per OpenSSF Scorecard checks SAST + Fuzzing + CI-Tests. Static Analysis SAST must (a) run SAST on every PR + (b) detect common security vulnerabilities (injection + authentication + authorisation + crypto + secrets + supply chain) + (c) integrate with code review gating + (d) align with broader SDLC security testing. Fuzzing must (a) operate fuzzing on appropriate components (parsers + network protocols + cryptographic routines + complex input handlers) + (b) integrate with OSS-Fuzz or equivalent + (c) maintain corpus + regression tracking + (d) coordinate fuzzing-found vulnerabilities with VDP + remediation. Test coverage must (a) measure test coverage + (b) maintain coverage thresholds for security-critical code + (c) treat coverage gaps in security boundaries as remediation priorities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.