Skip to content
getnextpdf.com

NextPDF-authored compliance documents

NextPDF authors and maintains the first-party compliance documents below, each listed with its type and scope.

DocumentTypeScope
Supply-chain trust pipelineNextPDF-authored specificationThe PR- and tag-time gates the release pipeline runs: SBOM generation, build provenance, reproducibility checks, lockfile fingerprint-drift checks, and in-toto build-input statements
Verifying a releaseNextPDF-authored procedureStep-by-step verification of a release artifact against its cosign signature and SLSA build provenance
Fuzzing postureNextPDF-authored methodologyThe nightly php-fuzzer matrix and the AST fuzzing harness
Static-analysis methodologyNextPDF-authored methodologyThe build-blocking PHPStan Level 10 gate on src/ and the scoped tests/ baseline
OpenSSF S2C2F self-assessmentNextPDF-authored self-assessmentConsumption-side supply-chain controls, recorded per S2C2F requirement
OpenSSF Best Practices answer worksheetNextPDF-authored worksheetThe answer set for the bestpractices.dev passing, silver, and gold criteria
OSPS Baseline self-assessmentNextPDF-authored self-assessmentThe active requirements of the OpenSSF OSPS Baseline, answered per requirement
DocumentTypeScope
EU CRA self-assessmentNextPDF-authored self-assessmentA self-assessment against the manufacturer obligations of Regulation (EU) 2024/2847
EU CRA Article 14 reporting SOPNextPDF-authored procedureRegulatory notification of actively exploited vulnerabilities and severe incidents, with reporting clocks and escalation path
NIST SSDF (SP 800-218) mappingNextPDF-authored mappingSSDF practices mapped, practice by practice, to the controls NextPDF operates
DocumentTypeScope
OpenChain ISO/IEC 5230 programNextPDF-authored program documentationLicence-compliance policy, scope statement, checklist answers, obligation-review procedure, contribution policy, archival procedure, and training log
OpenChain ISO/IEC 18974 programNextPDF-authored program documentationOpen-source security policy, checklist answers, and training log
DocumentTypeScope
Accessibility Conformance Report (VPAT 2.5)NextPDF-authored self-assessmentGenerated-PDF output; criteria that depend on author-supplied content are recorded per criterion as author-dependent
ACR manual-criteria checklistNextPDF-authored worksheetThe manual check procedure and current result per criterion; criteria that require an assistive-technology reading session are flagged as such
Conformance evidence indexNextPDF-authored indexMachine-verifiable conformance evidence; each entry records the profile, the pinned validator version, the corpus, and the reproduction command