{"date":"2026-09-19T17:08:50Z","repo":{"name":"github.com/OpenCoworkAI/open-codesign","commit":"c25a5765c6ce7eec6c7e184643613bfcd3bfa403"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":5.5,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1","Info: detected update tool: RenovateBot: renovate.json:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool","short":"Determines if the project uses a dependency update tool."}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"Dangerous-Workflow","score":0,"reason":"dangerous workflow patterns detected","details":["Warn: untrusted code checkout '${{ github.event.pull_request.base.sha }}': .github/workflows/codex-pr-review.yml:73"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:25","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:24","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codex-pr-review.yml:25","Info: jobLevel 'contents' permission set to 'read': .github/workflows/deploy-website.yml:50","Info: jobLevel 'contents' permission set to 'read': .github/workflows/issue-auto-response.yml:27","Info: jobLevel 'actions' permission set to 'read': .github/workflows/release.yml:368","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:369","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:490","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:91","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/release.yml:92","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:435","Info: jobLevel 'actions' permission set to 'read': .github/workflows/release.yml:434","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:16","Info: topLevel 'contents' permission set to 'read': .github/workflows/codex-pr-review.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:11","Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy-website.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/issue-auto-response.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/labeler.yml:11","Info: topLevel 'contents' permission set to 'read': .github/workflows/packaging-smoke.yml:38","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-macos-x64-native-check.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yml:23","Info: topLevel 'contents' permission set to 'read': .github/workflows/repository-activity-snapshot.yml:9","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:12"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Warn: downloadThenRun not pinned by hash: packaging/update-shas.sh:38","Info:  50 out of  50 GitHub-owned GitHubAction dependencies pinned","Info:  15 out of  15 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.2.2 not signed: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/391932704","Warn: release artifact v0.2.1 not signed: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/328365348","Warn: release artifact v0.2.0 not signed: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/319891290","Warn: release artifact v0.1.4 not signed: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/312661417","Warn: release artifact v0.1.3 not signed: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/311621097","Warn: release artifact v0.2.2 does not have provenance: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/391932704","Warn: release artifact v0.2.1 does not have provenance: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/328365348","Warn: release artifact v0.2.0 does not have provenance: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/319891290","Warn: release artifact v0.1.4 does not have provenance: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/312661417","Warn: release artifact v0.1.3 does not have provenance: https://api.github.com/repos/OpenCoworkAI/open-codesign/releases/311621097"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (5) are checked with a SAST tool"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Vulnerabilities","score":0,"reason":"72 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-4x5r-pxfx-6jf8","Warn: Project is vulnerable to: GHSA-7v5m-pr3q-6453","Warn: Project is vulnerable to: GHSA-jfgx-wxx8-mp94","Warn: Project is vulnerable to: GHSA-r95r-rj6r-c39x","Warn: Project is vulnerable to: GHSA-82fw-gwwq-j7x9","Warn: Project is vulnerable to: GHSA-27p8-2357-5qqv","Warn: Project is vulnerable to: GHSA-4w3w-2rp5-g8jm","Warn: Project is vulnerable to: GHSA-6gmq-8vp8-gcm6","Warn: Project is vulnerable to: GHSA-6h8r-xr42-gp59","Warn: Project is vulnerable to: GHSA-8344-3jmq-59r6","Warn: Project is vulnerable to: GHSA-93r5-fhx6-vmg9","Warn: Project is vulnerable to: GHSA-965w-775f-mr7g","Warn: Project is vulnerable to: GHSA-c7q8-3ch8-vqpv","Warn: Project is vulnerable to: GHSA-w2rr-34g9-rvrj","Warn: Project is vulnerable to: GHSA-x4fp-j954-r2f4","Warn: Project is vulnerable to: GHSA-7g7r-gx96-252g","Warn: Project is vulnerable to: GHSA-w5vr-8v7q-w6rv","Warn: Project is vulnerable to: GHSA-3jxr-9vmj-r5cp","Warn: Project is vulnerable to: GHSA-mh99-v99m-4gvg","Warn: Project is vulnerable to: GHSA-rgw5-rvv9-x895","Warn: Project is vulnerable to: GHSA-jxxr-4gwj-5jf2","Warn: Project is vulnerable to: GHSA-73wf-gq98-2v4g","Warn: Project is vulnerable to: GHSA-c83g-rgw3-j3cx","Warn: Project is vulnerable to: GHSA-p2f4-r6v6-j797","Warn: Project is vulnerable to: GHSA-g7r4-m6w7-qqqr","Warn: Project is vulnerable to: GHSA-7pqw-9j4j-h8q3","Warn: Project is vulnerable to: GHSA-jmr9-qjv8-65gv","Warn: Project is vulnerable to: GHSA-45c6-75p6-83cc","Warn: Project is vulnerable to: GHSA-5wm8-gmm8-39j9","Warn: Project is vulnerable to: GHSA-hmw2-7cc7-3qxx","Warn: Project is vulnerable to: GHSA-5p2g-fcmc-qvqq","Warn: Project is vulnerable to: GHSA-w3rx-r6r6-pgpr","Warn: Project is vulnerable to: GHSA-22jq-vg5j-6vgg","Warn: Project is vulnerable to: GHSA-4xrf-jv44-h6hh","Warn: Project is vulnerable to: GHSA-mwp4-54f8-5fhr","Warn: Project is vulnerable to: GHSA-2883-xcg3-v3hh","Warn: Project is vulnerable to: GHSA-52cp-r559-cp3m","Warn: Project is vulnerable to: GHSA-5p4m-2wfm-xmqj","Warn: Project is vulnerable to: GHSA-h67p-54hq-rp68","Warn: Project is vulnerable to: GHSA-28wg-ghj8-5hjv","Warn: Project is vulnerable to: GHSA-2v37-7h3g-55p8","Warn: Project is vulnerable to: GHSA-6g55-p6wh-862q","Warn: Project is vulnerable to: GHSA-fxqj-rqcc-2cmp","Warn: Project is vulnerable to: GHSA-r28c-9q8g-f849","Warn: Project is vulnerable to: GHSA-f38q-mgvj-vph7","Warn: Project is vulnerable to: GHSA-j3f2-48v5-ccww","Warn: Project is vulnerable to: GHSA-jggg-4jg4-v7c6","Warn: Project is vulnerable to: GHSA-wcpc-wj8m-hjx6","Warn: Project is vulnerable to: GHSA-7w5x-hrqm-74c2","Warn: Project is vulnerable to: GHSA-23hp-3jrh-7fpw","Warn: Project is vulnerable to: GHSA-8x88-c5mf-7j5w","Warn: Project is vulnerable to: GHSA-gvwx-54wh-qm9j","Warn: Project is vulnerable to: GHSA-r292-9mhp-454m","Warn: Project is vulnerable to: GHSA-vmf3-w455-68vh","Warn: Project is vulnerable to: GHSA-w8wr-v893-vjvp","Warn: Project is vulnerable to: GHSA-ph9p-34f9-6g65","Warn: Project is vulnerable to: GHSA-35p6-xmwp-9g52","Warn: Project is vulnerable to: GHSA-4cwx-7wf7-3272","Warn: Project is vulnerable to: GHSA-8xcm-r25x-g524","Warn: Project is vulnerable to: GHSA-g8m3-5g58-fq7m","Warn: Project is vulnerable to: GHSA-hm92-r4w5-c3mj","Warn: Project is vulnerable to: GHSA-jr45-8vmc-qm54","Warn: Project is vulnerable to: GHSA-m8rv-5g2x-5cg5","Warn: Project is vulnerable to: GHSA-p88m-4jfj-68fv","Warn: Project is vulnerable to: GHSA-pr7r-676h-xcf6","Warn: Project is vulnerable to: GHSA-v3r7-h72x-cjcm","Warn: Project is vulnerable to: GHSA-vmh5-mc38-953g","Warn: Project is vulnerable to: GHSA-vxpw-j846-p89q","Warn: Project is vulnerable to: GHSA-fx2h-pf6j-xcff","Warn: Project is vulnerable to: GHSA-v6wh-96g9-6wx3","Warn: Project is vulnerable to: GHSA-58qx-3vcg-4xpx","Warn: Project is vulnerable to: GHSA-96hv-2xvq-fx4p"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities","short":"Determines if the project has open, known unfixed vulnerabilities."}},{"name":"CI-Tests","score":10,"reason":"5 out of 5 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests","short":"Determines if the project runs tests before pull requests are merged."}},{"name":"Contributors","score":6,"reason":"project has 2 contributing companies or organizations -- score normalized to 6","details":["Info: found contributions from: bupt, bupt / msra"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors","short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies)."}}]}
