# ossf/best-practices-badge

🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)

Repository: https://github.com/ossf/best-practices-badge
Canonical: https://ross.abutalabs.com/products/best-practices-badge
Homepage: https://www.bestpractices.dev
Language: Ruby
License: MIT
License Family: permissive
Topics: badge, best-practices, rails, open-source, security, floss, openssf, ossf, foss, supply-chain
Last push: 2026-08-26T14:57:40+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 87, longevity 100
- inputs: {"age_days": 4060, "days_push": 7, "days_rel": 8, "gap_med": 0, "n_releases_24m": 92}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1357, forks 234 (observed 2026-08-28T04:04:29.504431+00:00)

## What it is
The OpenSSF Best Practices Badge is a web application (BadgeApp) that lets Free/Libre and Open Source Software projects self-certify that they follow open source best practices and display a badge. It defines the badge criteria and hosts the badging service at bestpractices.dev, formerly known as the CII Best Practices Badge.

## Use cases
- get an open source best practices badge for my project
- self-certify my floss project against security best practices
- check whether an open source project follows best practices
- show a supply-chain security badge in my github readme
- evaluate open source projects for secure development practices

## When to choose
- you maintain an open source project and want to demonstrate best practices
- you want to assess the maturity and security hygiene of dependencies
- you need a recognized OpenSSF badge for supply-chain compliance

## When to avoid
- you need automated security scanning rather than self-certification
- you want a static analysis or vulnerability detection tool
- your project is not open source

## Facets
- artifact type: application
- maturity: active
- function: security, web-framework, developer-tools, documentation
- domain: security, developer-tools, self-hosted, web-development
- platform: ruby
- tags: openssf, badge, best-practices, floss, supply-chain-security, self-certification, rails, cii, open-source, web-server, linux, docker

## Member repositories
- ossf/best-practices-badge (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:29.504431+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:41:51.105302+00:00, confidence not recorded.
  - readme: https://github.com/ossf/best-practices-badge (fetched 2026-08-28T04:04:29.504431+00:00, sha 0a721aa12399)
  - homepage: https://www.bestpractices.dev (fetched 2026-08-29T12:00:01.727415+00:00, sha 70db4a2a7790)
  - site_page: https://www.bestpractices.dev/en/cookies (fetched 2026-08-29T12:00:01.736557+00:00, sha 06a95efeb2b4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
