Purpose
Assess ENTITY against the current OpenSSF Open Source Project Security (OSPS) Baseline v2026.08.28 and identify what is already evidenced publicly, what is ambiguous, and what remains incomplete.
This is a readiness/evidence review. BTG is not claiming an OpenSSF Best Practices or OSPS Baseline badge in this issue. A badge or compliance level should only be stated after the applicable OpenSSF process is actually completed.
Current baseline reference:
https://baseline.openssf.org/
OpenSSF Best Practices Badge program:
https://www.bestpractices.dev/
Why external review is useful
ENTITY already publishes several security-development signals, including CI, dependency review, OpenSSF Scorecard, security documentation, protected release evidence and public conformance work. The useful question is not whether those look good in isolation; it is whether they provide the evidence required by the current OSPS Baseline and where the project has real gaps.
An unrelated reviewer is especially useful because maintainers can easily overestimate how clear their own evidence is.
Bounded task
Pick one OSPS Baseline v2026.08.28 control or one control family and report:
OSPS control / section:
Status: evidenced / partially evidenced / not evidenced / unclear
Public evidence URL(s):
Why the evidence is sufficient or insufficient:
Missing evidence or control:
Recommended remediation (optional):
Reviewer environment/context (optional):
Useful evidence surfaces
Start with:
Do not assume a badge in the README proves a specific baseline control; inspect the underlying evidence.
Scope boundary
This task does not replace an independent security audit, penetration test, legal assessment or OpenSSF's own badge/self-certification process. It is a public gap-analysis and evidence-mapping exercise.
Negative findings are welcome. If a control is not met or cannot be evidenced, say so directly and provide a reproducible basis where possible.
Purpose
Assess ENTITY against the current OpenSSF Open Source Project Security (OSPS) Baseline v2026.08.28 and identify what is already evidenced publicly, what is ambiguous, and what remains incomplete.
This is a readiness/evidence review. BTG is not claiming an OpenSSF Best Practices or OSPS Baseline badge in this issue. A badge or compliance level should only be stated after the applicable OpenSSF process is actually completed.
Current baseline reference:
https://baseline.openssf.org/
OpenSSF Best Practices Badge program:
https://www.bestpractices.dev/
Why external review is useful
ENTITY already publishes several security-development signals, including CI, dependency review, OpenSSF Scorecard, security documentation, protected release evidence and public conformance work. The useful question is not whether those look good in isolation; it is whether they provide the evidence required by the current OSPS Baseline and where the project has real gaps.
An unrelated reviewer is especially useful because maintainers can easily overestimate how clear their own evidence is.
Bounded task
Pick one OSPS Baseline v2026.08.28 control or one control family and report:
Useful evidence surfaces
Start with:
Do not assume a badge in the README proves a specific baseline control; inspect the underlying evidence.
Scope boundary
This task does not replace an independent security audit, penetration test, legal assessment or OpenSSF's own badge/self-certification process. It is a public gap-analysis and evidence-mapping exercise.
Negative findings are welcome. If a control is not met or cannot be evidenced, say so directly and provide a reproducible basis where possible.