Rubric: L-SUPPLY-RELEASE
Lens: L-SUPPLY-RELEASE Β· Density: D-HIGH Β· Axes: SEC, OPS, RCV
Criteria (exhaustive checklist)
- LICENSE / NOTICE / copyright present and consistent.
- Dependency lockfiles committed where ecosystem expects them.
- Release artifacts: reproducible notes, checksums, provenance if claimed.
- CI presence for build/test on primary branches.
- Secret scanning / .gitignore for local state.
- SBOM or dependency review process β present or tooling gap.
- Install path works without private credentials if public distribution is claimed.
Citations
| Work |
Point |
| NIST SSDF |
Secure releases; provenance |
| SLSA framework (conceptual) |
Supply-chain levels β cite only if claiming provenance |
| OpenSSF Scorecard concepts |
Heuristic checks for OSS health |
| SPDX / license best practices |
License clarity |
Pros / cons
| Pros |
Cons |
| Discrete yes/no checks β low hallucination |
Scorecard cosplay without running tools β prefer actual commands |
| High launch relevance generally |
Private monorepos may fail βpublic installβ checks β mark N/A with reason |