Conformance
A live, computed conformance report — not a badge. The build folds its own evidence (the gates that ran, the artifacts it signs) through lone's web-build conformance model. The strong claim is withheld unless every required criterion is met; anything not yet assessed says so, plainly.
Conformance
Partial conformance: automated DOM checks clean; WCAG 2.2 AA (manual audit) not supplied; OWASP ASVS Level 2 not supplied; Core Web Vitals (p75) not supplied; runtime reliability not supplied.
22/37 criteria met · 1 unmet · 14 not assessed · Bounded Systems Web-Build Conformance Standard v1.0.0
html 2/2 met
html: 2/2 met
- met HTML author requirements HTML Living Standard · author conformance lone static checks clean (no findings) api/v1/conformance.json
- met Nu HTML Checker errors Nu Html Checker · zero errors 0 validator errors workflow: conformance.yml
accessibility 4/6 met
accessibility: 4/6 met (2 not assessed)
- met WAI-ARIA author requirements WAI-ARIA 1.2 · author conformance lone static checks clean (no findings) api/v1/conformance.json
- met WCAG 2.2 AA (automated subset) WCAG 2.2 · AA (automated subset) lone static checks clean (no findings) api/v1/conformance.json
- met axe serious/critical violations axe-core · serious/critical 0 serious/critical violations workflow: axe.yml
- not assessed WCAG 2.2 AA (manual audit) WCAG 2.2 · AA (manual) no manual WCAG 2.2 AA audit supplied provenance
- not assessed WCAG 2.2 AAA (selected) WCAG 2.2 · AAA (selected) no AAA attestation supplied (optional) provenance
- met Agent heuristic accessibility review ARIA/WCAG (machine heuristic) · agent heuristic (recommended) agent heuristic pass clean — 7 page(s), 0 warning(s). AGENT/STATIC HEURISTIC — NOT AT-user testing; a11y.wcag22-aa-manual stays not-assessed. workflow: a11y-heuristic.yml
design 3/5 met
design: 3/5 met (2 not assessed)
- met Palette contrast (design tokens) WCAG 2.2 + APCA · AA (token-level) color tokens CVD-safe, APCA baseline, non-text contrast ok bdelanghe/brand: tokens/token-a11y.json
- met Typography tokens WCAG 2.2 · AA (token-level) type tokens meet line-height, spacing, size, and weight bars bdelanghe/brand: tokens/token-a11y.json
- not assessed Target size (interactive tokens) WCAG 2.2 · AA (token-level) no target-size report supplied bdelanghe/brand: tokens/token-a11y.json
- not assessed Effective contrast under opacity WCAG 2.2 · AA (token-level) no opacity-contrast report supplied bdelanghe/brand: tokens/token-a11y.json
- met Token likeness hygiene Design-system hygiene · recommended categorical tokens distinct; no redundant tokens bdelanghe/brand: tokens/token-a11y.json
security 1/3 met
security: 1/3 met (2 not assessed)
- not assessed OWASP ASVS Level 2 OWASP ASVS 5.0.0 · L2 no OWASP ASVS attestation supplied provenance
- met known critical/high vulns OWASP ASVS 5.0.0 · zero critical/high 0 known critical/high vulns workflow: brand-checks.yml
- not assessed HSTS preload RFC 6797 / hstspreload.org · preloaded no HSTS preload status supplied provenance
performance 0/1 met
performance: 0/1 met (1 not assessed)
- not assessed Core Web Vitals (p75) Core Web Vitals · p75 mobile + desktop no Core Web Vitals field data supplied provenance
compatibility 1/1 met
compatibility: 1/1 met
- met Baseline Widely Available Baseline · Widely Available Baseline Widely Available workflow: conformance.yml
reliability 0/1 met
reliability: 0/1 met (1 not assessed)
- not assessed runtime reliability Bounded Systems reliability bar · — no runtime reliability report supplied provenance
semantic 3/5 met
semantic: 3/5 met (2 not assessed)
- met JSON-LD 1.1 + SHACL conformance JSON-LD 1.1 / SHACL · conforms JSON-LD 1.1 conforms to SHACL shapes (0 violating blocks) workflow: shacl.yml
- not assessed CommonMark conformance CommonMark · conforms no CommonMark report supplied workflow: seo.yml
- met AI-readability llms.txt convention · recommended llms.txt present, links resolve, Markdown siblings exposed llms.txt
- not assessed OpenAPI 3.2 + JSON Schema 2020-12 OpenAPI 3.2 / JSON Schema 2020-12 · conditional no OpenAPI report supplied (only applies if an API is published) provenance
- met Atom feed (RFC 4287) RFC 4287 · recommended Atom feed valid (RFC 4287) feed.xml
seo 1/1 met
seo: 1/1 met
- met Technical SEO Search-engine technical guidelines / RFC 9309 · clean canonical/titles/robots/sitemap clean, 0 broken internal links sitemap.xml
integrity 6/9 met
integrity: 6/9 met (3 not assessed)
- met SLSA provenance + in-toto SLSA / in-toto · present + signed + verified SLSA/in-toto provenance present, signed, and verified attestation.intoto.json
- met Reproducible build Reproducible Builds · reproducible build is byte-reproducible bdelanghe/site: flake.lock
- met SPDX SBOM SPDX · present + valid + complete + signed SPDX SBOM present, valid, complete, and signed sbom.spdx.json
- met Content digests (RFC 9530) RFC 9530 · recommended Repr-Digest headers present (RFC 9530) provenance
- met Signed release manifest Bounded Systems release bar · present + signed release manifest present and signed site.sha256
- met IPFS CID recorded IPFS / CIDv1 · recommended IPFS CID recorded provenance.json
- not assessed HTTP correctness (RFC 9110) RFC 9110 · recommended no RFC 9110 HTTP report supplied (optional) provenance
- not assessed OpenSSF Scorecard OpenSSF Scorecard · score ≥ 7.0 no OpenSSF Scorecard result supplied provenance
- not assessed SLSA build level SLSA · ≥ target (default L3) no SLSA build level supplied provenance
cognitive 1/3 met
cognitive: 1/3 met (1 unmet, 1 not assessed)
- met Interface-complexity budget (W3C COGA-derived) W3C COGA (derived) · budget (recommended) lone static checks clean (no findings) api/v1/conformance.json
- unmet COGA Obj-5: Focus budget (attention proxy) W3C COGA Making Content Usable — Objective 5 · Obj-5 proxy (recommended) not-yet-met: readingGrade threshold exceeded, avgSentenceLength threshold exceeded, jargonDensity threshold exceeded. AGENT/STATIC PROXY for COGA Obj-5 — NOT COGA usability testing with cognitive disabilities. Do NOT mass-rewrite content — editorial is the maintainer's call; gate reports honestly. workflow: a11y-heuristic.yml
- not assessed COGA usability testing W3C COGA · manual (recommended) no COGA usability testing supplied (optional) provenance