Objective
Track the four remaining OpenSSF Scorecard findings without representing temporal, historical, or external-governance signals as undiscovered source vulnerabilities.
Pinned evidence snapshot: e9090ef18aac3f48549187acb2095e7c14d138c9
Snapshot date: 2026-08-30
Review date: 2026-10-26
Latest Scorecard run: https://github.com/BlueDot-IT/DarkPrompt/actions/runs/33341356387
Current controls
main uses classic branch protection with strict required checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, and force-push/deletion prevention. Required checks are Python 3.10, Python 3.11, Python 3.13, package, analyze (python), and CodeQL.
Findings and acceptance criteria
Maintained — alert #3
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/3
The repository was created at 2026-07-26T23:21:31Z and crosses Scorecard's 90-day threshold at 2026-10-24T23:21:31Z.
Code-Review — alert #4
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/4
The current instance reports 2/28 approved changesets. Historical changesets cannot be retroactively approved, while current main protection requires one approval.
CII-Best-Practices — alert #5
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/5
No OpenSSF Best Practices badge enrollment or badge reference is currently detected.
Fuzzing — alert #6
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/6
No recognized fuzz integration or local fuzz harness exists. This alert remains open until the control exists.
Closure
Re-query open code-scanning alerts at the then-current immutable main SHA. Close this issue only when every item is fixed, superseded with evidence, or explicitly risk-accepted by the repository owner.
Objective
Track the four remaining OpenSSF Scorecard findings without representing temporal, historical, or external-governance signals as undiscovered source vulnerabilities.
Pinned evidence snapshot:
e9090ef18aac3f48549187acb2095e7c14d138c9Snapshot date: 2026-08-30
Review date: 2026-10-26
Latest Scorecard run: https://github.com/BlueDot-IT/DarkPrompt/actions/runs/33341356387
Current controls
mainuses classic branch protection with strict required checks, admin enforcement, one required approval, stale-review dismissal, conversation resolution, and force-push/deletion prevention. Required checks are Python 3.10, Python 3.11, Python 3.13, package, analyze (python), and CodeQL.Findings and acceptance criteria
Maintained — alert #3
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/3
The repository was created at
2026-07-26T23:21:31Zand crosses Scorecard's 90-day threshold at2026-10-24T23:21:31Z.Code-Review — alert #4
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/4
The current instance reports
2/28approved changesets. Historical changesets cannot be retroactively approved, while currentmainprotection requires one approval.CII-Best-Practices — alert #5
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/5
No OpenSSF Best Practices badge enrollment or badge reference is currently detected.
Fuzzing — alert #6
https://github.com/BlueDot-IT/DarkPrompt/security/code-scanning/6
No recognized fuzz integration or local fuzz harness exists. This alert remains open until the control exists.
sample_pack/andsecurity_pack_v1/.Closure
Re-query open code-scanning alerts at the then-current immutable
mainSHA. Close this issue only when every item is fixed, superseded with evidence, or explicitly risk-accepted by the repository owner.