遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/5602)
<a href="https://www.bestpractices.dev/projects/5602"><img src="https://www.bestpractices.dev/projects/5602/badge"></a>
Drupal is content management software. It's used to make many of the websites and applications you use every day. Drupal has great standard features, like easy content authoring, reliable performance, and excellent security. But what sets it apart is its flexibility; modularity is one of its core principles. Its tools help you build the versatile, structured content that dynamic web experiences need.
https://www.drupal.org/community/contributor-guide/contribution-areas
We require all folks who want to use our git services https://www.drupal.org/docs/develop/git/setting-up-git-for-drupal/drupal-git-usage-policies/drupal-git-contributor
https://www.drupal.org/governance
https://www.drupal.org/dcoc
https://www.drupal.org/community/contributor-guide/find-your-role
The Drupal association owns all the infrastructure for the project and has root on all systems. https://www.drupal.org/association
Drupal has a world wide community of developers. https://www.drupal.org/contribute/core/maintainers
https://www.drupal.org/about/core/strategic-initiatives
https://www.drupal.org/docs/7/understanding-drupal/overview
https://www.drupal.org/security/secure-configuration
https://www.drupal.org/docs/installing-drupal/drupal-quick-start-command
https://www.drupal.org/docs
We don't link to anything external to Drupal from the primary repository page.
https://www.drupal.org/about/features/accessibility
https://www.drupal.org/node/1268692
警告:需要更长的理由。
https://www.drupal.org/docs/updating-drupal
https://www.drupal.org/project/issues/drupal?categories=All
https://drupal.org/security
https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquette/reporting-a-security-issue
https://www.drupal.org/docs/develop/standards
We run code linters on every patch/merge request.
We don't create binaries
https://www.drupal.org/node/2461619
https://git.drupalcode.org/project/drupal/-/blob/9.5.x/composer.json
The security team gets alerts when we have external dependancies with known vulnerabilities
https://dispatcher.drupalci.org/
https://www.drupal.org/about/core/policies/core-change-policies/drupal-core-gates
https://www.drupal.org/docs/security-in-drupal/writing-secure-code-for-drupal
There are no keys used inside Drupal core. Modern, strong cryptographic algorithms with appropriate modes are used by default.
We don't use C or C++
后退