Skip to main content

Security

Security & Trust

We publish our OpenSSF security posture from a build-time snapshot and direct links to the source, so teams evaluating Atmos can verify it themselves instead of trusting a static badge.

What is OpenSSF?

The Open Source Security Foundation (OpenSSF) is a Linux Foundation project that runs two independent, automated assessments of open source projects: Scorecard, which checks a repository against ~18 supply-chain security practices, and the Best Practices badge, which verifies a project against a broader set of security and quality criteria. Both re-scan and re-verify Atmos on an ongoing basis — these aren't one-time certifications, they're a continuously updated assessment. Verify it yourself at the Scorecard viewer or the Best Practices project page.

OpenSSF Scorecard Report

passingBest Practices badge — achieved September 1, 2026. Verify at bestpractices.dev/projects/14393.

9.0
Repository
github.com/cloudposse/atmos
Commit
82f5413
Scorecard version
v5.5.0
Scan generated
September 8, 2026 at 2:17 AM UTC
10

no dangerous workflow patterns detected

5*
VulnerabilitiesHighScore inaccurate

5 existing vulnerabilities detected

5*
Branch-ProtectionHighScore inaccurate

branch protection is not maximal on development and all release branches

8

4 out of the last 4 releases have a total of 4 signed artifacts.

10

update tool detected

10

30 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10

10

all changesets reviewed

10

GitHub workflow tokens follow principle of least privilege

10

no binaries found in the repo

9

dependency not pinned by hash detected -- score normalized to 9

10
PackagingMedium

packaging workflow detected

10
FuzzingMedium

project is fuzzed

10
SASTMedium

SAST tool detected

10

security policy file detected

5

badge detected: Passing

10

license file detected

10

30 out of 30 merged PRs checked by a CI test -- score normalized to 10

10

project has 28 contributing companies or organizations

Data fetched at build time: September 8, 2026 at 2:49 AM UTC.

Actively hardening

Security posture is an ongoing effort, not a one-time score. We track open gaps against these checks and work through them as part of our normal development process, the same way we track any other open issue.

Found a vulnerability? See our security policy for how to report it. Disclosed issues are published as security advisories.