NextPDF-authored compliance documents
At a glance
Section titled “At a glance”NextPDF authors and maintains the first-party compliance documents below, each listed with its type and scope.
Security and supply chain
Section titled “Security and supply chain”| Document | Type | Scope |
|---|---|---|
| Supply-chain trust pipeline | NextPDF-authored specification | The PR- and tag-time gates the release pipeline runs: SBOM generation, build provenance, reproducibility checks, lockfile fingerprint-drift checks, and in-toto build-input statements |
| Verifying a release | NextPDF-authored procedure | Step-by-step verification of a release artifact against its cosign signature and SLSA build provenance |
| Fuzzing posture | NextPDF-authored methodology | The nightly php-fuzzer matrix and the AST fuzzing harness |
| Static-analysis methodology | NextPDF-authored methodology | The build-blocking PHPStan Level 10 gate on src/ and the scoped tests/ baseline |
| OpenSSF S2C2F self-assessment | NextPDF-authored self-assessment | Consumption-side supply-chain controls, recorded per S2C2F requirement |
| OpenSSF Best Practices answer worksheet | NextPDF-authored worksheet | The answer set for the bestpractices.dev passing, silver, and gold criteria |
| OSPS Baseline self-assessment | NextPDF-authored self-assessment | The active requirements of the OpenSSF OSPS Baseline, answered per requirement |
Regulatory and legal
Section titled “Regulatory and legal”| Document | Type | Scope |
|---|---|---|
| EU CRA self-assessment | NextPDF-authored self-assessment | A self-assessment against the manufacturer obligations of Regulation (EU) 2024/2847 |
| EU CRA Article 14 reporting SOP | NextPDF-authored procedure | Regulatory notification of actively exploited vulnerabilities and severe incidents, with reporting clocks and escalation path |
NIST SSDF (SP 800-218) mapping | NextPDF-authored mapping | SSDF practices mapped, practice by practice, to the controls NextPDF operates |
Open-source licence compliance
Section titled “Open-source licence compliance”| Document | Type | Scope |
|---|---|---|
| OpenChain ISO/IEC 5230 program | NextPDF-authored program documentation | Licence-compliance policy, scope statement, checklist answers, obligation-review procedure, contribution policy, archival procedure, and training log |
| OpenChain ISO/IEC 18974 program | NextPDF-authored program documentation | Open-source security policy, checklist answers, and training log |
Accessibility and conformance
Section titled “Accessibility and conformance”| Document | Type | Scope |
|---|---|---|
Accessibility Conformance Report (VPAT 2.5) | NextPDF-authored self-assessment | Generated-PDF output; criteria that depend on author-supplied content are recorded per criterion as author-dependent |
| ACR manual-criteria checklist | NextPDF-authored worksheet | The manual check procedure and current result per criterion; criteria that require an assistive-technology reading session are flagged as such |
| Conformance evidence index | NextPDF-authored index | Machine-verifiable conformance evidence; each entry records the profile, the pinned validator version, the corpus, and the reproduction command |