OpenSSF Scorecard
Release Integrity and Provenance

OpenSSF Scorecard OSSFSC-6: Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

Maintain release integrity + provenance per OpenSSF Scorecard checks Signed-Releases + Binary-Artifacts + Packaging. Signed Releases must (a) sign release artifacts with cryptographic signature (Sigstore + GPG + Cosign + similar) + (b) publish public key or verify via transparency log + (c) integrate signature verification into consumer workflow. Binary Artifacts Absent from Repository must (a) avoid committing binary artifacts to source repository + (b) use artifact repositories for binary distribution + (c) document exceptions where binaries are necessary. Packaging via Trusted Publishers extends OSSFSC-3 ensuring (a) packages published via OIDC-based trusted publishing + (b) avoid long-lived publishing credentials, (c) verify package provenance at consumption. License Declared must (a) declare project license in standard location (LICENSE file + package metadata) + (b) align with SPDX identifier + (c) verify compatibility for dependencies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.