Public project roadmap

This roadmap covers public Xquik-dev projects through July 2027.

Security, compatibility, and maintainability take priority throughout every phase.

July through September 2026#

  • Register each standalone public project with OpenSSF Best Practices.
  • Document each repository's architecture and security boundary.
  • Publish shared governance, review, contribution, and vulnerability policies.
  • Identify small tasks for new contributors.
  • Verify private vulnerability reporting across every public repository.
  • Measure current statement and branch coverage.
  • Align repository descriptions, topics, and READMEs with supported user tasks.
  • Verify public documentation remains accessible to approved search crawlers.

October through December 2026#

  • Enforce at least 90% statement coverage.
  • Enforce at least 80% branch coverage.
  • Document deterministic build environments and commands.
  • Verify reproducible release artifacts.
  • Publish release signature and provenance verification instructions.
  • Complete dependency and static analysis evidence.
  • Measure search visibility and cited pages with webmaster tools.

January through March 2027#

  • Complete human security reviews for every standalone project.
  • Record threat models, trust boundaries, and assurance cases.
  • Recruit additional maintainers with release and incident access.
  • Grow independent, significant contributors through scoped issues.
  • Measure review coverage across released modifications.

April through July 2027#

  • Close remaining Silver and Gold evidence gaps.
  • Submit truthful evidence for each applicable OpenSSF criterion.
  • Add achieved badges to project front pages.
  • Automate quarterly badge and evidence verification.
  • Review governance, continuity, and contributor independence.

Out of scope#

  • Claims without public or reproducible evidence.
  • Weakened tests, reviews, security controls, or release checks.
  • Private infrastructure details in public compliance records.

Track repository-specific work in that repository's issue tracker.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.

Was this page helpful?