What do the OpenSSF badge's silver and gold levels add over passing?
answer
- three levels, and they nest
- passing is one-maintainer hygiene
- silver looks at people and paperwork
- gold turns on independent review
- unassociated means different employers
basics
~20 sPassing is baseline hygiene: license, public version control, tests, a vulnerability reporting path. Silver adds governance documentation and at least two unassociated significant contributors. Gold requires every change to be reviewed by someone other than its author.
solid answer
~50 sThe three levels are cumulative — silver contains all of passing, gold all of silver. **Passing** is hygiene a single motivated maintainer can achieve alone: an OSI-approved license, a public repository with versioning and release notes, a documented bug and vulnerability reporting path, a working build and test suite, static analysis, and no publicly known unpatched medium-or-higher vulnerabilities older than 60 days. **Silver** starts measuring the project as an organisation: a documented governance model and key roles, a code of conduct, documented security requirements and design, documented cryptography use, and at least two *unassociated* significant contributors — significant contributors not employed by the same organisation — plus a statement-coverage floor around 80%. **Gold** demands that every proposed change is reviewed by someone other than its author and raises coverage further (roughly 90% statement, 80% branch). The escalation is deliberate: passing measures practice, silver and gold measure resilience of the people behind it.
go deeper
Recall the three level names in order and that they are cumulative, and that passing is the baseline hygiene level most badged projects sit at.
Explain what each level adds and why: passing is practice a lone maintainer can do, silver adds governance and independent contributors, gold adds mandatory review by someone other than the author.
Point out that a level is a statement about the project's people and process, not a defect count, and that the ceiling for small libraries is structural rather than a sign of neglect.
Be ready to argue whether chasing a level is worth the organisational commitments it implies — a second unassociated maintainer and mandatory review are real staffing decisions, not documentation tasks.
## The shape of the ladder The OpenSSF Best Practices Badge has three levels — **passing**, **silver**, **gold** — and they nest. A gold project satisfies every silver criterion, and a silver project every passing criterion. What changes as you climb is not merely *more* of the same criteria; it is **what kind of thing is being measured**. ### Passing — can this project be used safely at all? Passing is the set of practices one committed maintainer can put in place over a weekend. Representative criteria: - An OSI-approved FLOSS license, with the license file in the repository. - A public, version-controlled source repository, with unique version numbering and release notes. - A documented way to report bugs, and a documented **private** way to report vulnerabilities, with evidence that reports get responses. - A working build system and an automated test suite, plus a stated policy that new functionality ships with tests. - Warning flags enabled and warnings addressed. - At least one primary developer who knows how to design secure software and the common classes of error; sound cryptographic practice with no hardcoded credentials; delivery protected against tampering in transit. - No publicly known unpatched vulnerability of medium or higher severity older than 60 days. - Static analysis applied, with exploitable findings fixed. Notice what is absent: nothing about how many people there are, nothing about governance, nothing about who reviews whom. ### Silver — is this project an organisation or a person? Silver introduces criteria that a solo project structurally cannot satisfy, and criteria about *written-down* practice rather than practice: - A **documented governance model** and publicly documented key roles, so a stranger can tell who decides what. - A **code of conduct**. - **Documented security requirements** and a description of the project's security-relevant design, plus documentation of how it uses cryptography. - **At least two unassociated significant contributors** — the word *unassociated* is doing real work: contributors who are not employed by the same organisation. A project entirely staffed by one employer fails this even with ten contributors. - A statement-coverage floor for the automated test suite (80%). Silver is the level at which the badge stops describing the code and starts describing the **bus factor and the paper trail**. ### Gold — is every change seen by a second pair of eyes? Gold's defining criterion is that **all proposed modifications are reviewed by someone other than the author** before being accepted, and it raises the coverage floors (around 90% statement and 80% branch). That single review criterion is why gold is out of reach for an excellent one-person library: there is no second person to review. It is not a statement that the code is worse — it is a statement that the *process* has no independent check in it, which is exactly what a consumer worried about a compromised or coerced maintainer wants to know. ## Reading the ladder correctly A few conclusions follow directly, and interviewers probe all of them: - **Level is not a security score.** Gold does not mean fewer vulnerabilities than silver. It means more people and more written process. - **The ceiling is often structural, not a lack of effort.** A conscientiously maintained module with one author is permanently capped below silver on contributor criteria. If you use badge level as a filter, you will systematically exclude small, stable, well-behaved libraries and favour large, corporate-adjacent ones. - **Higher levels still prove nothing about the artifact.** Even at gold, the criteria describe development practice. They do not tell you that the package on the registry was built from the reviewed source, nor who pressed publish. - **The upgrade path is meaningful for your own projects.** If you maintain something and want to move up, the honest question is not "which boxes can I tick" but "do I actually want a second unassociated maintainer and mandatory review" — because those are real organisational commitments, not paperwork. The most useful thing to say in an interview is the shape: **passing measures hygiene, silver measures governance and independence, gold measures mandatory independent review** — and none of the three measure the thing you actually install.
- Why can a well-run one-person project never reach gold?Because gold requires every proposed change to be reviewed by someone other than its author, and silver already requires at least two significant contributors who are not employed by the same organisation. Those are properties of the team, not of the code. A solo maintainer can write flawless, well-tested software and remain capped — the badge is measuring independence, which they do not have.
- What does 'unassociated' mean in the two-contributor criterion?Significant contributors who are not employed by, or otherwise tied to, the same organisation. The intent is resilience: if one company withdraws its staff, the project does not stop. A project with a dozen contributors who all work for one vendor fails the criterion despite the headcount.
- Does moving from silver to gold reduce the project's vulnerability count?Not directly. Gold adds mandatory independent review and higher coverage floors, which tend to catch mistakes earlier, but no level asserts anything about the number of defects present. Reading level as a security score is the standard misuse of the ladder.
saying these in an interview costs you the question
- Thinks gold means the code has no vulnerabilities
- Assumes the levels are independent tracks, not cumulative
- Describes silver and gold as just more testing
- Says a solo project reaches gold by trying harder
- Reads 'unassociated' as simply meaning two people