|
233 | 233 | "sites_password_security_status": "N/A", |
234 | 234 | "sites_password_security_justification": "N/A — no user accounts or passwords. Maintainer auth handled by GitHub.", |
235 | 235 |
|
236 | | - "code_of_conduct_status": "?", |
237 | | - "code_of_conduct_justification": "TODO — add CODE_OF_CONDUCT.md (Contributor Covenant 2.1) at repo root.", |
| 236 | + "code_of_conduct_status": "Met", |
| 237 | + "code_of_conduct_justification": "Contributor Covenant 2.1 adopted. https://github.com/RandomCodeSpace/docsiq/blob/main/CODE_OF_CONDUCT.md", |
238 | 238 |
|
239 | | - "governance_status": "?", |
240 | | - "governance_justification": "TODO — add GOVERNANCE.md describing BDFL model with sole maintainer, PR-review decision process, and security-contact continuity plan.", |
| 239 | + "governance_status": "Met", |
| 240 | + "governance_justification": "Lead-maintainer model documented with decision-making process, roles, and continuity plan. https://github.com/RandomCodeSpace/docsiq/blob/main/GOVERNANCE.md", |
241 | 241 |
|
242 | | - "roles_responsibilities_status": "?", |
243 | | - "roles_responsibilities_justification": "TODO — document maintainer / reviewer / security-contact roles in GOVERNANCE.md.", |
| 242 | + "roles_responsibilities_status": "Met", |
| 243 | + "roles_responsibilities_justification": "Lead maintainer, security contact, and reviewer roles documented. https://github.com/RandomCodeSpace/docsiq/blob/main/GOVERNANCE.md#roles", |
244 | 244 |
|
245 | | - "access_continuity_status": "?", |
246 | | - "access_continuity_justification": "TODO — add .github/CODEOWNERS plus GOVERNANCE.md section on admin-access backup and account-recovery plan.", |
| 245 | + "access_continuity_status": "Met", |
| 246 | + "access_continuity_justification": ".github/CODEOWNERS routes PR review to @aksOps; GOVERNANCE.md documents admin-access continuity via reproducible builds and cosign keyless signing. https://github.com/RandomCodeSpace/docsiq/blob/main/.github/CODEOWNERS", |
247 | 247 |
|
248 | | - "bus_factor_status": "?", |
249 | | - "bus_factor_justification": "TODO — note in GOVERNANCE.md that project is single-maintainer but all build/signing/registry artifacts are reproducible from source, mitigating bus-factor risk.", |
| 248 | + "bus_factor_status": "Met", |
| 249 | + "bus_factor_justification": "Single-maintainer risk mitigated by reproducible builds and keyless cosign signing anchored to GitHub OIDC + Rekor — not a private key. Any fork can reproduce identical release artifacts. https://github.com/RandomCodeSpace/docsiq/blob/main/GOVERNANCE.md#continuity-and-resilience", |
250 | 250 |
|
251 | | - "report_archive_status": "?", |
252 | | - "report_archive_justification": "TODO — confirm GitHub Issues serves as the report archive and note it in SECURITY.md.", |
| 251 | + "report_archive_status": "Met", |
| 252 | + "report_archive_justification": "GitHub Issues serves as the public report archive; Security Advisories archive coordinated-disclosure reports. https://github.com/RandomCodeSpace/docsiq/blob/main/SECURITY.md#report-archive", |
253 | 253 |
|
254 | | - "release_notes_vulns_status": "?", |
255 | | - "release_notes_vulns_justification": "TODO — add .github/release.yml template with a 'Security fixes' section auto-populated from PRs labelled `security`.", |
| 254 | + "release_notes_vulns_status": "Met", |
| 255 | + "release_notes_vulns_justification": ".github/release.yml defines a 'Security fixes' section auto-populated from PRs labelled `security` in GitHub-generated release notes. https://github.com/RandomCodeSpace/docsiq/blob/main/.github/release.yml", |
256 | 256 |
|
257 | | - "accessibility_best_practices_status": "?", |
258 | | - "accessibility_best_practices_justification": "TODO — add docs/ACCESSIBILITY.md covering WCAG AA stance for the embedded React SPA (keyboard nav, contrast tokens, prefers-reduced-motion)." |
| 257 | + "accessibility_best_practices_status": "Met", |
| 258 | + "accessibility_best_practices_justification": "WCAG 2.1 Level AA stance documented for the embedded React SPA: contrast ≥ 4.5:1, keyboard nav, prefers-reduced-motion, semantic HTML, axe-core checks. https://github.com/RandomCodeSpace/docsiq/blob/main/docs/ACCESSIBILITY.md" |
259 | 259 | } |
0 commit comments