Skip to main content

Security

Security & Trust

We publish our OpenSSF security posture from a build-time snapshot and direct links to the source, so teams evaluating Atmos can verify it themselves instead of trusting a static badge.

What is OpenSSF?

The Open Source Security Foundation (OpenSSF) is a Linux Foundation project that runs two independent, automated assessments of open source projects: Scorecard, which checks a repository against ~18 supply-chain security practices, and the Best Practices badge, which verifies a project against a broader set of security and quality criteria. Both re-scan and re-verify Atmos on an ongoing basis — these aren't one-time certifications, they're a continuously updated assessment. Verify it yourself at the Scorecard viewer or the Best Practices project page.

OpenSSF Scorecard Report

passingBest Practices badge — achieved September 1, 2026. Verify at bestpractices.dev/projects/14393.

9.0
Repository
github.com/cloudposse/atmos
Commit
6217df7
Scorecard version
v5.5.0
Scan generated
September 16, 2026 at 2:26 AM UTC
10

no dangerous workflow patterns detected

5*
VulnerabilitiesHighScore inaccurate

5 existing vulnerabilities detected

5*
Branch-ProtectionHighScore inaccurate

branch protection is not maximal on development and all release branches

8

5 out of the last 5 releases have a total of 5 signed artifacts.

10

all changesets reviewed

10

update tool detected

10

30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10

10

GitHub workflow tokens follow principle of least privilege

10

no binaries found in the repo

10

all dependencies are pinned

10
SASTMedium

SAST tool detected

10
PackagingMedium

packaging workflow detected

10

security policy file detected

10
FuzzingMedium

project is fuzzed

5

badge detected: Passing

10

license file detected

10

30 out of 30 merged PRs checked by a CI test -- score normalized to 10

10

project has 28 contributing companies or organizations

Data fetched at build time: September 16, 2026 at 3:27 AM UTC.

Actively hardening

Security posture is an ongoing effort, not a one-time score. We track open gaps against these checks and work through them as part of our normal development process, the same way we track any other open issue.

Found a vulnerability? See our security policy for how to report it. Disclosed issues are published as security advisories.