Security
Security & Trust
We publish our OpenSSF security posture from a build-time snapshot and direct links to the source, so teams evaluating Atmos can verify it themselves instead of trusting a static badge.
What is OpenSSF?
The Open Source Security Foundation (OpenSSF) is a Linux Foundation project that runs two independent, automated assessments of open source projects: Scorecard, which checks a repository against ~18 supply-chain security practices, and the Best Practices badge, which verifies a project against a broader set of security and quality criteria. Both re-scan and re-verify Atmos on an ongoing basis — these aren't one-time certifications, they're a continuously updated assessment. Verify it yourself at the Scorecard viewer or the Best Practices project page.
OpenSSF Scorecard Report
passingBest Practices badge — achieved September 1, 2026. Verify at bestpractices.dev/projects/14393.
no dangerous workflow patterns detected
30 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10
all changesets reviewed
no binaries found in the repo
badge detected: Passing
30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Data fetched at build time: September 8, 2026 at 2:49 AM UTC.
Actively hardening
Security posture is an ongoing effort, not a one-time score. We track open gaps against these checks and work through them as part of our normal development process, the same way we track any other open issue.
Found a vulnerability? See our security policy for how to report it. Disclosed issues are published as security advisories.