Verification standard · observed-controls/3

What we observed.
What we can claim.

An assessment concerns a named set of provider controls. It does not prove that software is safe or that every release authority has been identified. A paid plan cannot change a check's outcome.

Pass

The observed setting meets this control's criterion.

Fail

The observed setting does not meet that criterion.

Unknown

Evidence is missing, inaccessible, incomplete or from an older incompatible evaluation.

Not applicable

The control does not apply to this assessment's stated scope.

Scope and freshness

All required controls for every represented provider must be present and pass before the assessment says “Observed controls passed.” No score averages away a failure. Evidence expires eight days after a completed assessment. Provider reports may describe an earlier reporting date; enrollment counts do not establish which factor is required at authentication. An incomplete assessment cannot establish end-to-end publisher protection.

Current control inventory

ProviderControl
googleActive super-administrator 2SV enforcement
googleActive-user 2SV enforcement
googleReported password policy compliance
googleSuper-administrator count
googleReported legacy app access
githubOrganization 2FA requirement
githubDefault workflow token permissions
githubSecret scanning coverage
githubPush protection coverage
githubDefault-branch required reviews
githubActions SHA-pinning policy
githubActions allowlist policy
githubWorkflow review-approval policy
githubFork workflow approval policy
githubOrganization runner public-repository access
githubRelease immutability coverage
registryRegistry-reported publishing evidence
registryArtifact origin matches connected GitHub account
registryDeclared npm install hooks

Important boundaries

Public and private evidence

Publishers explicitly choose publication. Public assessments expose scope, aggregate outcomes and dates. Private findings, dependency inventories and review notes remain in the signed-in workspace. JSON assessments identify their schema and policy version; unsigned assessments explicitly report a null signature.