Docs / OpenSSF Best Practices

On this page · 6 sections
Contents

PLANNED

Docker imageAPI referenceMigrating from Supabase

Docs / PROJECT / OpenSSF Best Practices

OpenSSF Best Practices

Met, Unmet, or N/A for every passing criterion of project 15348, with a repo URL.

docs/BESTPRACTICES.md · Built from commit 951df46 · 2026-10-10 · Edit on GitHub ↗

Passing-level answers for project 15348. The criterion list is the English passing set (67 criteria, before achieve_passing). Silver and gold are not in this file.

Assessed 2026-10-09 from this repository. Copy the Status cell into the form. A one-line justification is the text to paste when the form asks for one. N/A is allowed only where the criterion says so, and it counts as met.

The passing badge needs every MUST met (or N/A where allowed), every SHOULD met or unmet with a justification, and every SUGGESTED at least considered. Every MUST criterion below is Met or N/A. Every SHOULD is Met or N/A. Three SUGGESTED criteria stay Unmet: test_most, dynamic_analysis, and dynamic_analysis_enable_assertions.

Counts: MUST 38 Met, 0 Unmet, 5 N/A. SHOULD 9 Met, 0 Unmet, 1 N/A. SUGGESTED 10 Met, 3 Unmet, 1 N/A.

Basics

Basic project website content

CriterionLevelStatusJustificationEvidence
description_goodMUSTMetThe site and README say, in plain language, that this is a Supabase-compatible API in one Rust binary.README
interactMUSTMetInstall docs say how to obtain it, the FAQ says how a person can help, and GitHub Issues take bug reports.Install, FAQ source
contributionMUSTMetContributions are pull requests from agents, with the workflow in AGENTS.md; humans use issues.CONTRIBUTING.md
contribution_requirementsSHOULDMetAcceptable changes need Rust, tests for new behavior, Conventional Commits, and the hard rules in AGENTS.md.AGENTS.md

FLOSS license

CriterionLevelStatusJustificationEvidence
floss_licenseMUSTMetResults are Apache-2.0, an OSI-approved license.LICENSE
floss_license_osiSUGGESTEDMetApache-2.0 is OSI-approved.LICENSE
license_locationMUSTMetThe license text is the repository root file LICENSE.LICENSE

Documentation

CriterionLevelStatusJustificationEvidence
documentation_basicsMUSTMetInstall, quickstart, and configuration cover build, start, use, and what not to do with JWT_SECRET and database TLS.docs/install.md, docs/configuration.md
documentation_interfaceMUSTMetThe HTTP interface that exists today is documented: env vars, /_megabase/health, gateway prefixes, and the 501 JSON body.docs/quickstart.md, ADR 0002

Other

CriterionLevelStatusJustificationEvidence
sites_httpsMUSTMethttps://megabase.sh, the GitHub repository, and GitHub Release downloads all use HTTPS.README
discussionMUSTMetGitHub Issues, pull requests, and Discussions are searchable, URL-addressable, and open to new people.Discussions
englishSHOULDMetRepository docs and issue text are in English.AGENTS.md
maintainedMUSTMetThe project is actively developed (release v0.1.0 on 2026-10-09) and is pursuing this badge.Releases

Change control

Public version-controlled source repository

CriterionLevelStatusJustificationEvidence
repo_publicMUSTMetThe git repository is public at a stable GitHub URL.Zouhairmaj/megabase
repo_trackMUSTMetGit history records the change, the author, and the time.commits
repo_interimMUSTMetWork lands through pull requests, so the history is not release snapshots only.pull requests
repo_distributedSUGGESTEDMetThe repository is git.Zouhairmaj/megabase

Unique version numbering

CriterionLevelStatusJustificationEvidence
version_uniqueMUSTMetEach release-please release has one version; the published release is v0.1.0.v0.1.0
version_semverSUGGESTEDMetVersions follow semantic versioning, with level gates called out in the roadmap.docs/ROADMAP.md
version_tagsSUGGESTEDMetReleases are git tags; v0.1.0 exists.v0.1.0

Release notes

CriterionLevelStatusJustificationEvidence
release_notesMUSTMetCHANGELOG.md and the GitHub Release are a human summary from release-please, not git log.CHANGELOG.md
release_notes_vulnsMUSTN/ANo CVE or similar public vulnerability has been assigned to Megabase, which is the criterion's N/A case.security advisories

Reporting

Bug-reporting process

CriterionLevelStatusJustificationEvidence
report_processMUSTMetBugs are filed as GitHub Issues.issues
report_trackerSHOULDMetGitHub Issues tracks one report per issue.issues
report_responsesMUSTMetThe repository was created on 2026-10-09, so the 2–12 month window contains no bug reports.Zouhairmaj/megabase
enhancement_responsesSHOULDMetThe same 2–12 month window contains no enhancement requests.issues
report_archiveMUSTMetIssues and their comments stay public on GitHub.issues

Vulnerability report process

CriterionLevelStatusJustificationEvidence
vulnerability_report_processMUSTMetSECURITY.md tells reporters not to open a public issue and where to report instead.SECURITY.md
vulnerability_report_privateMUSTMetPrivate channels are email to agent@megabase.sh and GitHub private vulnerability reporting.SECURITY.md
vulnerability_report_responseMUSTN/ANo vulnerability report was received in the last 6 months (zero published advisories on 2026-10-09).security advisories

Quality

Working build system

CriterionLevelStatusJustificationEvidence
buildMUSTMetcargo build --release --locked -p megabase rebuilds the binary from source.docs/install.md
build_common_toolsSUGGESTEDMetThe build uses Cargo and rustc, the standard Rust tools.Cargo.toml
build_floss_toolsSHOULDMetThe Rust toolchain and Cargo are FLOSS; CI builds on that toolchain..github/workflows/ci.yml

Automated test suite

CriterionLevelStatusJustificationEvidence
testMUSTMetcargo test --workspace --locked is the public FLOSS suite, and CI runs it..github/workflows/ci.yml
test_invocationSHOULDMetcargo test is the standard Rust invocation.README
test_mostSUGGESTEDUnmetCodecov on main (2026-10-09) reports 51.32% line coverage and no branch coverage, which is not most branches.Codecov
test_continuous_integrationSUGGESTEDMetGitHub Actions runs the test suite on pull requests and on pushes to main..github/workflows/ci.yml

New functionality testing

CriterionLevelStatusJustificationEvidence
test_policyMUSTMetThe definition of done requires tests in the crate for new behavior and a failing test for a bug fix.AGENTS.md
tests_are_addedMUSTMetRecent major changes (JWT verification, Auth SQL install, the 501 gateway) ship with crate tests.crates/megabase-core/src/jwt.rs
tests_documented_addedSUGGESTEDMetThe same test policy is in the contributor instructions.AGENTS.md

Warning flags

CriterionLevelStatusJustificationEvidence
warningsMUSTMetCI runs cargo clippy --workspace --all-targets --locked -- -D warnings on the Rust sources..github/workflows/ci.yml
warnings_fixedMUSTMet-D warnings fails the build, so a green CI run has no remaining default warnings..github/workflows/ci.yml
warnings_strictSUGGESTEDMetThat flag turns every default rustc and Clippy warning into an error; clippy::pedantic is not enabled..github/workflows/ci.yml

Security

Secure development knowledge

CriterionLevelStatusJustificationEvidence
know_secure_designMUSTMetdocs/SECURE_DESIGN.md records the Saltzer and Schroeder principles as applied to this gateway, including the ones not fully implemented yet.docs/SECURE_DESIGN.md
know_common_errorsMUSTMetThe same document lists the OWASP Top 10 and the CWE classes that apply to this Rust HTTP server, with the mitigation in the tree for each.docs/SECURE_DESIGN.md

Use basic good cryptographic practices

CriterionLevelStatusJustificationEvidence
crypto_publishedMUSTMetThe only default algorithm is HS256 (HMAC-SHA-256), which is published and widely reviewed.crates/megabase-core/src/jwt.rs
crypto_callSHOULDMetHMAC and SHA-256 come from the hmac and sha2 crates; the project does not reimplement those primitives.Cargo.toml
crypto_flossMUSTMetThose crates are FLOSS (RustCrypto, MIT or Apache-2.0).Cargo.toml
crypto_keylengthMUSTMetStartup rejects a JWT_SECRET shorter than 32 bytes (256 bits), above the NIST SP 800-131A 112-bit minimum through 2030. Hs256::new rejects the same short keys.crates/megabase-core/src/config.rs, docs/configuration.md
crypto_workingMUSTMetVerification rejects every alg other than HS256, including none; MD4, MD5, DES, and RC4 are not used.crates/megabase-core/src/jwt.rs
crypto_weaknessesSHOULDMetThe default mechanism is HMAC-SHA-256, not SHA-1 and not SSH CBC.docs/configuration.md
crypto_pfsSHOULDN/AThe binary does not implement a key-agreement protocol: HTTP is plaintext and PostgreSQL uses NoTls.docs/configuration.md
crypto_password_storageMUSTMetSignup stores passwords as bcrypt at cost 10, the GoTrue DefaultCost. POST /auth/v1/token verifies that hash. Passwords and hashes are not logged.docs/SECURE_DESIGN.md
crypto_randomMUSTN/AProduct code does not generate cryptographic keys or nonces; JWT_SECRET is supplied by the operator.docs/configuration.md

Secured delivery against man-in-the-middle (MITM) attacks

CriterionLevelStatusJustificationEvidence
delivery_mitmMUSTMetSource, the site, and GitHub Releases are HTTPS; later releases also keyless-sign assets, but v0.1.0 shipped without them.docs/install.md
delivery_unsignedMUSTMetSHA256SUMS is downloaded over HTTPS and cosign verify-blob runs before sha256sum -c.docs/install.md

Publicly known vulnerabilities fixed

CriterionLevelStatusJustificationEvidence
vulnerabilities_fixed_60_daysMUSTMetThere is no public medium-or-higher vulnerability in Megabase (zero GitHub advisories on 2026-10-09).security advisories
vulnerabilities_critical_fixedSHOULDMetNo critical vulnerability has been reported to fix.SECURITY.md

Other security issues

CriterionLevelStatusJustificationEvidence
no_leaked_credentialsMUSTMetThe only embedded token material is the public Supabase demo secret from .env.example, which the criterion allows as a sample.crates/megabase-core/src/jwt.rs

Analysis

Static code analysis

CriterionLevelStatusJustificationEvidence
static_analysisMUSTMetBefore release, CI runs Clippy (beyond rustc warnings), forbids unsafe_code, and runs cargo-deny and cargo audit on both owned lockfiles..github/workflows/ci.yml
static_analysis_common_vulnerabilitiesSUGGESTEDMetGitHub code scanning default setup runs CodeQL on Rust for pull requests; that query set looks for common vulnerabilities.README
static_analysis_fixedMUSTMetClippy -D warnings, unsafe_code = "forbid", cargo-deny, and cargo-audit fail CI, so a release from green main has no open finding from those tools..github/workflows/ci.yml
static_analysis_oftenSUGGESTEDMetThose jobs run on every pull request and on every push to main..github/workflows/ci.yml

scorecard.yml uploads Scorecard SARIF through codeql-action/upload-sarif. That upload is not the CodeQL analysis. The analysis is GitHub code scanning default setup (CODE_SCANNING_IS_STEADY_STATE_DEFAULT_SETUP), which extracted Rust and uploaded results on this change. There is no codeql.yml in the repository.

Dynamic code analysis

CriterionLevelStatusJustificationEvidence
dynamic_analysisSUGGESTEDUnmetThere is no fuzzer or web scanner, and branch coverage is not the 80% alternative the criterion allows.issue 153
dynamic_analysis_unsafeSUGGESTEDN/AThe software produced is Rust. Workspace crates forbid unsafe_code, so there is no unsafe block for a fuzzer to exercise.Cargo.toml
dynamic_analysis_enable_assertionsSUGGESTEDUnmetcrates/ has no debug_assert! or other production assertions for a test or fuzz build to turn on.crates/
dynamic_analysis_fixedMUSTN/ANo dynamic-analysis tool is run, so there is no confirmed finding from one.issue 153

Wrong or unfinished? Open an issue or edit docs/BESTPRACTICES.md on GitHub.