{
  "id": 13584997,
  "title": "Four supply-chain badges for a one-person open-source project, in a day",
  "url": "https://urgent.news/2026/10/10/four-supply-chain-badges-for-a-one-person-open-source-project-in-a-day",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T23:43:25.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/ashish_sinha_5241c7673d93/four-supply-chain-badges-for-a-one-person-open-source-project-in-a-day-mn4"
  },
  "original_language": "en",
  "account": "Maintaining schemagate, an open-source library and MCP server that safeguards AI agents from unauthorized database access, requires adherence to several security certifications and compliance standards. To verify the project's integrity, four distinct badges were obtained in a single day.\n\nFirstly, the OpenSSF Best Practices certification was achieved. This self-assessment covers essential aspects such as handling vulnerabilities, testing, and static analysis. By carefully examining the repository, proper links to existing files were provided as evidence, and CodeQL, a static analysis tool, yielded zero alerts. The only unmet criterion was the absence of dynamic analysis, which is suggested but not mandatory at this level. Hence, the project secured a passing grade of 100%.\n\nNext, the OpenSSF Baseline Level 1 certification was secured. This checklist assesses critical security controls, with most requirements already fulfilled. The sole requirement that needed adjustment was the implementation of branch protection, ensuring that commits to the main branch necessitate a successful CI check. By enforcing pull requests and disabling the admin bypass, this criterion was met, resulting in an additional 100% score.\n\nThe REUSE compliance (FSFE) certification confirmed that each file within the repository contains machine-readable copyright and license information. This is crucial for legal teams scrutinizing dependencies. By utilizing the reuse lint tool, missing copyright and license details were identified, such as a bundled BLAKE2b implementation and a test fixture derived from the MCP registry's schema. Registration at api.reuse.software followed, after which the checker confirmed compliance for all 238 files.\n\nLastly, the SLSA Build Level 3 certification addressed the question of whether the PyPI-hosted file was genuinely derived from the repository. The official slsa-github-generator was employed to generate a provenance statement, verifying that the installed files match the original source. After validating the PyPI package's integrity through the slsa-verifier, both the built wheel and source distribution (sdist) successfully passed verification. It was crucial to align the verification command with the workflow's default branch, as the tag verification process failed. A total of 238 files were confirmed compliant, satisfying the SLSA requirements.\n\nIn summary, by diligently following these four steps—OpenSSF Best Practices, Baseline Level 1, REUSE compliance, and SLSA Build Level 3—one can establish a robust security posture for an open-source project like schemagate. Each badge not only emphasizes the importance of security but also streamlines the process for subsequent certifications. The complete documentation is available on the project's README at https://github.com/ashishsinha1602/schemagate.",
  "summary": "I maintain schemagate , an open-source library and MCP server that stops an AI agent from seeing database tables the user isn't allowed to read. It's a security tool, so \"trust me\" isn't good enough. A security team looking at it reasonably asks: is the project run properly, is the licensing clean, and is the package on PyPI really built from this repository? There are free, public answers to all…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "adagents.json vs ads.txt and schain: Four Files, Two Supply-Chain Questions",
        "url": "https://urgent.news/2026/10/10/adagents-json-vs-ads-txt-and-schain-four-files-two-supply-chain",
        "published": "2026-10-10T00:30:25.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}