Skip to content
CAI
Software that uses CAICheck a score

ossf/best-practices-badge

56.0

Adequate · 19 September 2026

24.9k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a web application for managing and displaying OpenSSF Baseline project badges, tracking project compliance against tiered security criteria. It provides user-facing features for project submission, status monitoring, and statistics, alongside administrative tools for managing user accounts, login sessions, and notification preferences. The platform supports internationalization, integrates with GitHub for authentication, and handles automated badge generation and CDN cache purging.

How it got here

2015 — Rails 8.1 upgrade and security hardening

30 changes.

The project underwent a major infrastructure upgrade to Rails 8.1 and Ruby 3.4, establishing a robust foundation with comprehensive security hardening, session management, and input validation. This period also introduced the OpenSSF Baseline criteria integration, internationalization support, and a complete overhaul of the test suite to ensure reliability and compliance.

2016–2017 — Mailer architecture and baseline criteria support

15 changes.

This period focused on implementing a structured mailer system with privacy enhancements and internationalization for user and project notifications. It also introduced core libraries and logic for managing OpenSSF Baseline criteria, alongside operational scripts for deployment and maintenance.

2018–2026 — Infrastructure hardening and internationalization

15 changes.

This period focused on stabilizing the platform through a major CI/CD overhaul, comprehensive test coverage expansion, and the introduction of fuzz testing for security. Concurrently, the application expanded its feature set by adding machine translation support for multiple languages, new user-facing views for account management, and robust asynchronous job handling for CDN cache purging.

Features

Add internationalized email templates for user account events

The user mailer views now support internationalization (i18n) for account activation, password reset, GitHub welcome, direct messages, and user update notifications. All email templates use translation keys (e.g., \user\_mailer.account\_activation.before\_html\) to display localized content, ensuring users receive messages in their preferred language. This change introduces new view files for these email types, replacing any previous hardcoded text with dynamic, locale-aware content.

_app/views/user\mailer · high confidence

Add password reset user interface

Users can now initiate and complete password resets through new views. The 'new' view provides a form to request a reset link by entering an email address, while the 'edit' view allows users to set a new password and confirmation after clicking the reset link. Both views are internationalized using translation keys.

_app/views/password\resets · high confidence

Add security contact file and standard error pages

The application now includes a .well-known/security.txt file to provide a standardized contact point for reporting security vulnerabilities, along with custom HTML error pages for 404 (Not Found), 422 (Unprocessable Entity), and 500 (Internal Server Error) responses to improve user experience during errors. Additionally, a Google site verification file has been added to support search engine ownership verification.

public · high confidence

Add unsubscribe notification management page

Users can now manage their notification preferences via a new unsubscribe page. The interface displays the user's email, issue date, and a masked token for verification, allowing them to confirm their subscription status before submitting the change.

app/views/unsubscribe · high confidence

Added development and maintenance binstubs

The repository now includes a set of executable binstubs in the \bin/\ directory to streamline local development and maintenance tasks. These scripts provide direct access to tools like \rubocop\, \brakeman\, \license\_finder\, and \rails\, while also introducing new entry points for the application server (\bin/dev\), background job processing via Solid Queue (\bin/jobs\), and environment setup (\bin/setup\) and updates (\bin/update\).

bin · high confidence

Admin login sessions listing view

Added a new view for the login sessions index page that displays a table of all currently active login sessions, sorted by most recently used. The table includes hyperlinked User ID and User Name columns, the user's role, IP address, user agent, creation and last-used timestamps, and a truncated session digest. The view also includes a note on how to revoke suspicious sessions via a rake task and renders pagination for large lists.

_app/views/login\sessions · high confidence

Initial internationalization framework and locale files added

The application now supports multiple languages through a new i18n structure. This change introduces the core English translation file (en.yml) and separate localization files for number, date, and time formatting for German (de), Spanish (es), French (fr), Japanese (ja), Brazilian Portuguese (pt-BR), Russian (ru), Swahili (sw), and Simplified Chinese (zh-CN). It also adds a configuration file for the Translation.io service to manage ongoing translations.

config/locales · high confidence

Initial machine-translated UI strings for German, Spanish, and French

The application now includes machine-translated localization files for German (de), Spanish (es), and French (fr) in the config/machine\_translations directory. These files provide translated text for user-facing elements such as project submission forms, baseline version notices, automation hints, and notification settings, enabling the interface to be displayed in these languages.

_config/machine\translations · high confidence

Initial repository configuration and tooling setup

The repository is initialized with a comprehensive set of configuration files and documentation to establish the development environment and quality standards. This includes a Ruby version file (3.4.10) and tool versions (Node.js 19.5.0), alongside linter configurations for RuboCop (Ruby), ESLint (JavaScript), Markdownlint, and Codespell. Security and testing infrastructure is defined via \.bundler-audit.yml\ (with specific CVE ignores for jquery-ui and Bootstrap), SimpleCov (test coverage), and \.slugignore\ (Heroku deployment). The project also introduces standard governance and contribution documents, including a Code of Conduct, CONTRIBUTING guide, CHANGELOG, and AI assistant instructions (AGENTS.md/CLAUDE.md).

(repo-wide) · high confidence

Introduce additional rights and hardened session management

Users can now grant other users edit permissions on their projects via a new AdditionalRight join model, and the system enforces stricter security for login sessions and stashed form submissions by using HMAC-based identifiers instead of database IDs to prevent forgery if secret keys are leaked.

app/models · high confidence

New account activation confirmation page

A new view for account activation confirmation has been added, providing a user-facing form to confirm their account. The page displays a localized heading and prompt, includes a hidden field for the user's email, and presents a primary button to submit the activation token via a PATCH request.

_app/views/account\activations · high confidence

New baseline badge and status icons

Added SVG assets for the OpenSSF baseline badge (including versioned levels 1–3 and in-progress percentages) and thumbs-up/down icons to visually indicate project status.

app/assets/images · high confidence

New baseline criteria forms and project details toggler

The project editing interface now supports the new Baseline criteria series (baseline-1, baseline-2, and baseline-3) with dedicated form wrappers and a shared baseline form partial that displays a version transition notice when applicable. Additionally, a new \\_details.html.erb\ partial has been introduced to provide a toggleable details section for form fields, allowing users to expand or collapse explanatory text for criteria like project name, description, and license.

app/views/projects · high confidence

New baseline criteria management and asset staleness detection libraries

This change introduces a suite of new libraries to support the OpenSSF Baseline criteria system and improve deployment reliability. It adds \AssetStalenessChecker\ and \AssetStalenessMiddleware\ to detect and warn about stale precompiled assets on the first request, ensuring assets are up-to-date. It also introduces a comprehensive set of tools for the Baseline criteria feature: \BaselineCriteriaSync\ for synchronization, \BaselineCriteriaValidator\ for validating criteria and mapping files, \BaselineHtmlParser\ for parsing the OpenSSF spec, \BaselineI18nExtractor\ for managing translations, and \BaselineMigrationGenerator\ for database schema updates. Additionally, \CriterionStatus\ centralizes status value handling, \DatabaseBootRetry\ and \DatabaseUrlGuard\ improve database connection resilience at boot, \GcCompactThread\ manages garbage collection compaction, \HerokuRubyAvailability\ probes Heroku for supported Ruby versions, and \LocaleUtils\ and \MachineTranslationFallbackBackend\ enhance localization capabilities.

lib · high confidence

New baseline criteria sync and machine translation automation tasks

Added new Rake tasks to manage the OpenSSF Best Practices baseline criteria and automate machine translations. The \baseline\ namespace (\lib/tasks/baseline.rake\) provides tasks to sync, extract i18n strings, generate migrations, and validate baseline criteria from the official source. Additionally, a comprehensive machine translation workflow (\lib/tasks/machine\_translations.rake\ and \lib/tasks/machine\_translation\_helpers.rb\) allows exporting untranslated keys, importing translations, and running automated AI-assisted translations for missing or outdated segments across multiple locales, with support for configurable AI CLI tools and strict YAML formatting instructions.

lib/tasks · high confidence

New email notifications for project lifecycle events and badge changes

Users will now receive automated emails for several new project events: project owners are notified when a new project is created; reminders are sent for projects needing updates and include an unsubscribe link; users are alerted when a project's badge level is gained, lost, or warned about; and administrators receive notifications when a project's status changes or is deleted (including the deletion rationale). Additionally, a monthly announcement report is sent to subscribers, detailing statistics and listing projects that newly achieved badge levels.

_app/views/report\mailer · high confidence

New operational and maintenance scripts for deployment, baseline management, and markdown processing

A suite of new scripts has been added to the \script/\ directory to support deployment workflows, baseline management, and code quality. \script/deploy\ enables branch-based deployments to staging and production with pre-deploy checks against GitHub status and workflow runs, while \script/dependabot\_review\_due\ monitors Dependabot ignore entries for expired review dates. Baseline management is supported by \script/extract\_baseline.rb\ and \script/extract\_justifications.rb\ for parsing and exporting OpenSSF Baseline criteria and project justifications, and \script/generate\_baseline\_badges.rb\ for creating SVG badge images. Markdown processing is enhanced with \script/fix\_markdown.rb\ for automatic linting fixes, \script/compare\_markdown\_output.rb\ for validating output consistency, and \script/fuzz\_markdown\_processor.rb\ for security fuzzing. Additional utility scripts include \script/get-sbom\ for downloading Software Bill of Materials, \script/gather\_postgres\_state\ for Heroku diagnostics, and \script/find\_non\_english\_projects.rb\ for identifying non-English content in projects.

script · high confidence

New project statistics dashboard with charts and CSV export

The project stats view has been replaced with a new interface that displays various metrics (such as total projects, activity over the last 30 days, and badge statistics) using interactive line charts. The page is cached for performance and includes a section for administrators to view additional HTML data. Users can now download the underlying statistics as a CSV file, which is generated efficiently by querying the database directly rather than loading all records into memory.

_app/views/project\stats · high confidence

New user profile, edit, and listing views with GDPR-compliant JSON export

The application now provides dedicated views for user management: the user index lists users with provider details and admin-only search/delete capabilities; the edit page allows users to update their name, email, locale, and notification preferences, with password fields restricted to local accounts; the show page displays owned and editable projects, external GitHub links, and admin privileges. Additionally, JSON endpoints for user listing and individual profiles expose structured data, including email and locale only for the account owner or admins, to support GDPR data portability requirements.

app/views/users · high confidence

Behavioural changes

Added asset manifest configuration

A new manifest.js file has been added to the assets configuration directory to explicitly define how stylesheets, JavaScript, and images are linked within the application's asset pipeline.

app/assets/config · low confidence

Added delayed job for CDN project purges with retry logic

A new \PurgeCdnProjectJob\ has been introduced to handle CDN cache purging asynchronously, addressing race conditions in cache invalidation. The job accepts a \cdn\_badge\_key\ to target specific resources and includes automatic retry logic with polynomial backoff (up to 5 attempts) for transient failures, ensuring robustness against API outages. This change also establishes a base \ApplicationJob\ class that discards jobs on deserialization errors.

app/jobs · high confidence

Adopts CDLA-Permissive-2.0 for new managed data

New content managed by the service is now released under the Community Data License Agreement - Permissive, Version 2.0 (CDLA-Permissive-2.0), replacing the previous CC-BY-3.0 or CC-BY-3.0+ licenses. This change is implemented by adding the full text of the CDLA-Permissive-2.0 license to the repository and updating the LICENSES directory documentation to reflect the new licensing terms for recent submissions.

LICENSES · high confidence

CSS architecture reorganized into modular SCSS files

The application's stylesheet has been restructured from a single or monolithic file into a modular SCSS architecture. The main manifest is now \application.scss\, which explicitly imports components in a specific order: Bootstrap framework, extensions, shared mixins, base styles, layout components (header, footer), and controller-specific styles. New partial files have been created for \\_base\, \\_header\, \\_footer\, \\_forms\, \\_projects\, \\_static\_pages\, \\_users\, \\_sessions\, \\_utilities\, \\_variables\, and others, replacing the previous \static\_pages.scss\ and \application.css\ structure. This change improves maintainability by separating concerns and allows for better organization of global, layout, and page-specific styles.

app/assets/stylesheets · high confidence

Database schema evolution and criteria updates

This location contains the database migrations that define the application's data structure and scoring logic. The changes include adding new assessment criteria (such as TLS, hardening, and continuous integration), renaming fields to reflect updated terminology (e.g., 'changelog' to 'release\_notes', 'oss' to 'floss'), and introducing new tables for features like user activation, reminders, and project statistics. It also covers structural improvements like adding indexes for performance, enforcing 'not null' constraints for data integrity, and migrating email storage to case-insensitive 'citext'.

db/migrate · high confidence

Database schema updated to version 8.1 with new tables and expanded project metrics

The database schema has been regenerated for Rails 8.1, introducing several new tables including \login\_sessions\ for tracking active user logins with HMAC-digested session IDs, \pending\_resubmissions\ to securely stash form data across re-login flows, and \additional\_rights\ to manage user permissions per project. The \projects\ table now includes fields for tiered baseline percentages (\baseline\_tiered\_percentage\), specific achievement timestamps for gold and silver badges, and a Common Platform Enumeration (CPE) identifier for vulnerability tracking. Additionally, the \project\_stats\ table has been expanded to record detailed daily metrics for higher-level badge tiers (baseline-1 through baseline-3) and user activity, while the \bad\_passwords\ table supports password strength validation.

db · high confidence

Documentation of logo sources and processing steps

A new NOTES file has been added to the project logos directory, documenting the original sources and processing steps for several project logos including Gnu, GnuTLS, Kubernetes, TUF, and AppArmor. This file records where the original images were downloaded from and the commands used to resize and optimize them for use on the front page.

app/assets/images/project-logos-originals · high confidence

Internationalized error messages and enhanced pagination controls

Form validation errors are now displayed using internationalized text via the new shared partial \\_error\_messages.html.erb\, ensuring consistent and localized messaging for users. Additionally, the pagination UI has been updated with a new \\_pagination.html.erb\ partial that integrates Pagy with Bootstrap styling and adds explicit 'First' and 'Last' navigation links to improve accessibility and ease of use when browsing through multiple pages.

app/views/shared · high confidence

Introduce dedicated controllers for account activation, password resets, and login sessions

The application now uses dedicated controllers to handle previously implicit or scattered authentication flows. AccountActivationsController manages the local user activation process with a configurable cool-off period before login is permitted. PasswordResetsController implements a privacy-preserving password reset flow that sends emails only to the original account address and revokes all active sessions upon a successful reset. LoginSessionsController provides an admin-only interface to view and manage active login sessions. These changes centralize security-critical logic, improve session fixation protection, and enhance user privacy during account recovery.

app/controllers · high confidence

Introduce frozen cache fragments and hardened session management

The application now uses a custom \cache\_frozen\ helper that stores view fragments as frozen \SafeBuffer\ objects, significantly reducing memory allocation and copying during high-traffic rendering. Session handling has been hardened against fixation by resetting the session on login while preserving specific keys, and login attempts are now rate-limited per user to prevent brute-force attacks. Additionally, unsubscribe tokens are generated and verified using HMAC with constant-time comparison and time-based expiration, and user avatars now include a \no-referrer\ policy to improve privacy.

app/helpers · high confidence

Introduce structured mailer architecture with privacy and localization enhancements

The application now uses a dedicated \ApplicationMailer\ base class that standardizes email headers to disable SendGrid tracking (click, open, and analytics) for improved user privacy, and sets a configurable default sender address. \ReportMailer\ and \UserMailer\ are implemented to handle project badge status notifications and user account events respectively, with both mailers respecting the recipient's preferred locale for internationalized subject lines and content. Additionally, user activation emails are intentionally delayed via SendGrid scheduling to mitigate spam, and report reminders now include unsubscribe links while removing previous blind carbon copy (BCC) practices to enhance email privacy.

app/mailers · high confidence

Major CI/CD overhaul: pinned images, Heroku stack alignment, and removed orbs

The CI configuration has been completely rewritten to improve security, reliability, and environment parity. Docker images are now pinned using SHA-256 digests to prevent supply-chain risks and silent version drift, and uncertified public orbs (Codecov, Brakeman) have been removed in favor of native CLI execution and GitHub Actions checks. The test environment now uses the official Heroku \heroku/heroku:26-build\ image, aligning CI with the production Heroku-24 stack and eliminating the need to maintain a separate, stale test image. Additionally, system tests now run against a dedicated Selenium/Chrome container with the desktop UI disabled to save memory, and the Heroku CLI is installed via a new setup script.

.circleci · high confidence

New criteria listing and detail views with autofill support

The application now provides dedicated views for listing all criteria and displaying individual criterion details, replacing the previous rendering logic. These new pages render criteria hierarchically and include support for displaying 'autofill' entries when available. The implementation also introduces view-level caching to freeze content ahead-of-time and fixes a previous issue where criterion markers were displayed unconditionally.

app/views/criteria · high confidence

New input validators for email, password, text, and URLs

The application now uses dedicated validators to enforce stricter input rules. Email addresses are validated against a standard format. Passwords are checked against a database of known bad passwords to prevent weak credentials. Text fields reject invalid control characters (except standard whitespace) to ensure data integrity and prevent database errors. URLs are validated to allow only safe schemes (http/https), valid domain names, and specific path characters, while rejecting dubious URLs like IP addresses or loopbacks and ensuring proper UTF-8 encoding.

app/validators · high confidence

New level conversion logic and symbol refinements for criteria handling

This change introduces two new modules in the models concerns directory to support updated criteria logic. The LevelConversion module provides a method to map criteria level names (including new 'baseline' levels like baseline-1, baseline-2, and baseline-3) to numeric values for consistent ordering and comparison across Project and Criteria models. Additionally, the SymbolRefinements module adds refinements to the Symbol class, enabling dynamic generation of status and justification field symbols based on criterion names, which simplifies attribute access in the models.

app/models/concerns · high confidence

New static pages for cookies, criteria, 404/409 errors, and robots.txt

The application now includes dedicated static views for cookies, criteria discussion, and criteria statistics, alongside optimized 404 and 409 error pages that are intentionally lightweight to mitigate abuse. A new robots.txt view dynamically restricts crawler access to user data and specific paths in production while blocking all crawling in development. The home page view has been updated to display project logos and social sharing links for Twitter, Reddit, Facebook, LinkedIn, Hacker News, and email.

_app/views/static\pages · high confidence

Rails 8.1 configuration and baseline criteria synchronization setup

The application configuration has been updated to load Rails 8.1 defaults, which introduces security improvements such as Regexp.timeout for ReDoS defense and strict ETag freshness, alongside performance features like YJIT. The system now supports synchronization with the OpenSSF Baseline criteria (version 2026-08-28) via new configuration files (\baseline\_config.yml\, \baseline\_field\_mapping.json\) that define source URLs, cache locations, and field mappings for baseline-1 through baseline-3 levels. Additionally, the boot process now explicitly enables Bootsnap only in the development environment to accelerate startup, and the Puma server is configured to use Solid Queue for background job processing and to purge CDN caches after deployment.

config · high confidence

Rails 8.1 environment configuration overhaul

The application environment files (development, test, production, and the new fake\_production) have been rewritten to align with Rails 8.1 defaults and modern best practices. Key changes include replacing the deprecated \config.cache\_classes\ with \config.enable\_reloading\, configuring explicit memory cache stores with a custom \NoDupCoder\ to prevent duplication issues, and standardizing asset pipeline settings (e.g., \config.assets.compile = false\ in production). Production logging is now explicitly configured to use \TaggedLogging\ to stdout with an \:info\ default level, and email delivery is set up via SMTP with TLS wrapper support. The test environment now raises errors on missing i18n translations and enables Rack compression to better mirror production behavior.

config/environments · high confidence

Redesigned login page with GitHub OAuth, local auth, and security hardening

The login interface has been replaced with a new view that prominently features a 'Log in with GitHub' button alongside a traditional email/password form. The GitHub login flow now correctly handles CSRF protection by emitting the necessary meta tag and uses same-origin referrer policies to prevent leaking return tokens to external providers. The local login form includes a 'remember me' checkbox, a link to password resets, and explicitly disables browser autocomplete for passwords to address security risks. Additionally, the page supports a configuration mode that can disable login entirely, and all text is internationalized.

app/views/sessions · high confidence

Redesigned site layout with internationalization and performance optimizations

The application's visual structure has been completely overhauled: the header now uses a standard Bootstrap navigation with a locale selector dropdown, and the footer displays OpenSSF and Linux Foundation logos alongside the Fastly CDN attribution. To support global users, the layout is fully internationalized (i18n), with locale-specific URLs and metadata for search engines. Performance is improved through deferred JavaScript loading, preloading of critical assets (stylesheets, fonts, images), and frozen caching of static layout elements. Additionally, a new 'system announcement' capability allows administrators to display site-wide alerts via environment variables, and CSRF meta tags are now conditionally rendered to preserve CDN caching for anonymous visitors.

app/views/layouts · high confidence

Restructured JavaScript asset pipeline and added automation highlighting

The JavaScript assets have been reorganized to improve load performance and maintainability. A new manifest file (application.js) explicitly requires jQuery 3, Bootstrap, and imagesloaded, while deferring Chart.bundle and chartkick to the project-stats page. A new automation-highlighting.js script automatically expands panels containing automated or overridden fields and scrolls to the first overridden field when a URL anchor is present. Additionally, criteria.js.erb now serves as a server-to-client bridge, injecting criteria definitions and translations into global variables for use by the project form.

app/assets/javascripts · high confidence

Rewrite of application initializers for security, performance, and reliability

The application's initialization logic has been comprehensively rewritten to improve security, performance, and operational reliability. Key changes include: replacing the legacy \will\_paginate\ gem with \pagy\ (v43.x) and reducing the default page limit to 20 to lower memory usage; introducing a new criteria data pipeline (\00\_criteria\_hash.rb\) that loads YAML criteria files at boot and provides a single source of truth for routing and badge logic; hardening security by setting all cookies to \SameSite=Lax\, rotating cookie encryption from AES-256-CBC/SHA1 to AES-256-GCM/SHA256, and adding a \CacheControlFixMiddleware\ to prevent CDN caching of CSRF-protected responses; improving CDN integration with Fastly by validating credentials at boot, dynamically loading trusted proxy IPs, and optimizing CORS headers to reduce \Vary\ header complexity for public assets; and enhancing stability with automatic database connection retries at boot and periodic garbage collection compaction in a background thread.

config/initializers · high confidence

Updated OpenSSF Baseline criteria to version v2026.08.28

The OpenSSF Baseline criteria version has been updated to v2026.08.28. This change updates the central configuration in \app/lib/baseline\_config.rb\ to reflect the new version, which will appear in badge text and drive the criteria checks performed by the analysis framework.

app/lib · high confidence

Test coverage

Added OSS-Fuzz integration configuration for fuzz testing; Added Rails system tests for core application flows; Added mailer previews for user and report emails; Added model tests for core application components; Added test coverage for core library utilities; Added test coverage for report and user mailers; Added tests for LevelConversion concern and SymbolRefinements; Added tests for PurgeCdnProjectJob; Added tests for config/initializers to ensure correct autoload ordering and coverage; Added tests for helper methods; Added tests for login session revocation and machine translation helper tasks; Added unit tests for core analysis and security components; Expanded controller test coverage for core application features; Expanded integration test coverage for core application features; Test infrastructure overhaul: system test setup, coverage validation, and VCR redaction; Updated test fixtures for OpenSSF badges and tiered feed data.

Dependencies

Upgrade to Rails 8.1 and Ruby 3.4 with hardened dependencies

The application has been upgraded to Rails 8.1.1 (specifically resolving to 8.1.3.1 in the lock file) and Ruby 3.4, replacing the previous Rails 6/7 stack. This update includes a significant security hardening by upgrading \secure\_headers\ to version 7 and \omniauth-rails\_csrf\_protection\ to version 2.0 to mitigate [CVE redacted]. The dependency list has been refined to load only specific Rails components (e.g., \actionpack\, \activerecord\) to reduce memory usage and attack surface, while also introducing \solid\_queue\ for ActiveJob backends and pinning the Node.js version to 24.19.0 via \package.json\ to ensure consistent JavaScript minification during deployment.

(dependencies) · high confidence

Housekeeping

Added placeholder files for asset and log directories

Empty .keep files were added to the lib/assets, log, vendor/assets/javascripts, and vendor/assets/stylesheets directories to ensure these folders are tracked by version control.

lib/assets, log, vendor · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 56.

Lenses

  • Code Health 95
  • Architecture 84
  • Maturity 79
  • Readiness 67
  • Security 70
  • Domain Modelling 48
  • Accessibility 53

Changes since last survey

  • 300 commits — 271 feature/other, 29 fixes

By area

  • (root) — 39 commits
  • .circleci/config.yml — 39 commits
  • (repo) — 36 commits
  • .github/workflows — 32 commits
  • docs/build-environment-staleness.md — 25 commits
  • app/controllers — 24 commits
  • app/models — 21 commits
  • lib/tasks — 11 commits
  • app/views — 8 commits
  • test/controllers — 6 commits
  • docs/warning_failures.md — 5 commits
  • config/initializers — 4 commits
  • docs/INSTALL.md — 4 commits
  • config/machine_translations — 3 commits
  • docs/login-session-18.md — 3 commits
  • docs/login-session-simplify.md — 3 commits
  • test/integration — 3 commits
  • .github/renovate.json5 — 2 commits
  • docs/admin.md — 2 commits
  • docs/automation-proposals.md — 2 commits

Notable commits

  • fix: Add 'require' to fix NameError in deploy (#3032)
  • fix: Bound memory in project recalc loops (fix OOM) (#2864)
  • fix: Bump rubocop-rails to 2.37.0; fix/disable new cops (#3008)
  • fix: Document step 22 (GET-triggered stash fix) and its docs pointers
  • fix: Document the four ways to run a system test, and fix stale testing docs
  • fix: Fix a crash when a stashed permissions-form edit is resumed
  • fix: Fix arm64 Linux system test setup and 2 test bugs (#2970)
  • fix: Fix codespell complaints: GET's -> GET request's
  • fix: Fix criteria renderer logic displaying markers uncoditionally (#3018)
  • fix: Fix cross-user pending-resubmission leak on a shared browser (Step 21)
  • fix: Fix flaky system test: wait for navigation after Submit-and-exit
  • fix: Fix logout crash if session is old
  • fix: Fix notification flags never clearing (set 1)
  • fix: Fix pull_production's Rails marker and audit (#2977)
  • fix: Fix recalc migration oom (#2881)
  • fix: Fix release json parsing (#2905)
  • fix: Fix signing: use cosign --bundle (#2880)
  • fix: Fix stale-translation detection for keys with a blank human placeholder (#2991)
  • fix: Fix style offenses found by RuboCop 1.88.2
  • fix: Fix the dependency cache, which my executor change had broken twice
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ossf/best-practices-badge was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e4937b250f6109daff14c1ea8245e73391deb95a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.