Verified

Privacy only works if the security around it does.

Thaw asks for permissions that reach across your Mac. These are the outside checks on how it is built and released: what each one is, and who vouches for it. A score a machine gives is not the same as a checklist a project fills in, so each says which it is.

SLSA build levelLevel 3

A standard for how software gets built. At Level 3 a release is built by a hosted service, not on someone’s laptop, and comes with a signed record of which source it was built from. You can check that record against your download.

Who says so. You can verify it yourself for any release.

slsa.dev

OpenSSF Best PracticesGold

A checklist from the Open Source Security Foundation for how a project is run, such as how changes get reviewed and how security reports are handled. It has three badges, Passing, Silver and Gold.

Who says so. The project answers each item and publishes its evidence.

bestpractices.dev

OpenSSF BaselineLevel 3

A shorter list of security controls every open source project should have, in three levels. Level 3 is the one meant for projects many people depend on.

Who says so. The project answers these too, on the same public page.

baseline.openssf.org

OpenSSF Scorecard9.1 / 10

A tool that inspects the repository itself and scores it out of 10 on things such as whether changes are reviewed, dependencies are pinned and releases are signed.

Who says so. Run by OpenSSF every week. The project cannot edit the score.

scorecard.dev

Test coverage92.3%

The share of Thaw’s code that its automated tests run.

Who says so. SonarQube Cloud measures it on every change.

sonarcloud.io

Values read on 10 October 2026. How to verify a release yourself.