The maintainer's side of Safeguard Gold Open Source, the free public directory at gold.safeguard.sh. Keep your own project's supply chain clean using the free badge, continuous integration gate and read API, with a triage method built for the hour a week a volunteer actually has. Learn the precise, load bearing difference between a signal, an automated point in time observation, and a certification, an audited and attested claim, so you can describe your own posture honestly. Handle a report about your own project from first contact through a reasoned severity decision, including the case where you disagree with a finding and how to document that disagreement credibly. Publish provenance and a Software Bill of Materials for a release using the free path, built on Supply-chain Levels for Software Artifacts (SLSA) and Sigstore tooling rather than a paid product. Close with the honest limits of any automated signal about a volunteer maintained project, including the maintainer availability blind spot no scanner can see. Complements course 301, Safeguard for Open Source Maintainers, and does not repeat its ground.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.