OpenSSF Scorecard report
-
API URL: -
COMMIT: -
GENERATED AT: -
SCORECARD VERSION: -
SORT:
-
Dangerous-Workflow
critical
Determines if the project's GitHub Action workflows avoid dangerous patterns.
-
Binary-Artifacts
high
Determines if the project has generated executable (binary) artifacts in the source repository.
-
Branch-Protection
high
Determines if the default and release branches are protected with GitHub's branch protection settings.
-
Code-Review
high
Determines if the project requires code review before pull requests (aka merge requests) are merged.
-
Dependency-Update-Tool
high
Determines if the project uses a dependency update tool.
-
Maintained
high
Determines if the project is "actively maintained".
-
Signed-Releases
high
Determines if the project cryptographically signs release artifacts.
-
Token-Permissions
high
Determines if the project's workflows follow the principle of least privilege.
-
Vulnerabilities
high
Determines if the project has open, known unfixed vulnerabilities.
-
Fuzzing
medium
Determines if the project uses fuzzing.
-
Packaging
medium
Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.
-
Pinned-Dependencies
medium
Determines if the project has declared and pinned the dependencies of its build process.
-
SAST
medium
Determines if the project uses static code analysis.
-
Security-Policy
medium
Determines if the project has published a security policy.
-
CI-Tests
low
Determines if the project runs tests before pull requests are merged.
-
CII-Best-Practices
low
Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.
-
Contributors
low
Determines if the project has a set of contributors from multiple organizations (e.g., companies).
-
License
low
Determines if the project has defined a license.