{"date":"2026-09-14","repo":{"name":"github.com/QwenLM/qwen-code","commit":"87437db784f6ffbdb725b46b4a5fdd5fbac9cd74"},"scorecard":{"version":"v5.5.1-0.20260908181711-f92023a3f778","commit":"f92023a3f77879f96e0c9c1305f289d755be4bb6"},"score":4.3,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Dangerous-Workflow","score":0,"reason":"dangerous workflow patterns detected","details":["Warn: untrusted code checkout '${{ github.event.pull_request.base.sha || github.sha }}': .github/workflows/assign-pr-owner.yml:42"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Binary-Artifacts","score":3,"reason":"binaries present in source code","details":["Warn: binary detected: packages/core/vendor/ripgrep/arm64-darwin/rg:1","Warn: binary detected: packages/core/vendor/ripgrep/arm64-linux/rg:1","Warn: binary detected: packages/core/vendor/ripgrep/x64-darwin/rg:1","Warn: binary detected: packages/core/vendor/ripgrep/x64-linux/rg:1","Warn: binary detected: packages/core/vendor/ripgrep/x64-win32/rg.exe:1","Warn: binary detected: packages/core/vendor/tree-sitter/tree-sitter-bash.wasm:1","Warn: binary detected: packages/core/vendor/tree-sitter/tree-sitter.wasm:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/assign-issue-owner.yml:48","Info: jobLevel 'contents' permission set to 'read': .github/workflows/assign-pr-owner.yml:38","Info: jobLevel 'issues' permission set to 'read': .github/workflows/assign-pr-owner.yml:39","Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-and-publish-image.yml:26","Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-and-publish-image.yml:188","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cd-cua-driver.yml:628","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cd-cua-driver.yml:869","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cd-cua-driver.yml:694","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cd-cua-driver.yml:990","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cd-mobile-mcp.yml:24","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:2257","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/ci.yml:2258","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/ci.yml:125","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:124","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1313","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1666","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1852","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:388","Warn: jobLevel 'checks' permission set to 'write': .github/workflows/ci.yml:389","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:863","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1569","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:2066","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/desktop-release.yml:602","Info: jobLevel 'actions' permission set to 'read': .github/workflows/desktop-release.yml:747","Info: jobLevel 'contents' permission set to 'read': .github/workflows/desktop-release.yml:748","Info: jobLevel 'contents' permission set to 'read': .github/workflows/finalize-release.yml:26","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/live-host-release.yml:280","Info: jobLevel 'actions' permission set to 'read': .github/workflows/main-ci-failure-issue.yml:40","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main-ci-failure-issue.yml:41","Info: jobLevel 'issues' permission set to 'read': .github/workflows/main-ci-failure-issue.yml:43","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:1726","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:1975","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:2029","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:3553","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:3724","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:256","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:674","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:29","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:30","Info: jobLevel 'actions' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:28","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:144","Info: jobLevel 'actions' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:142","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:143","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:500","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:3875","Info: found token with 'none' permissions: .github/workflows/qwen-code-pr-review.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:264","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:265","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:3348","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:108","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:109","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-code-pr-review.yml:357","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-pr-safety-precheck.yml:21","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-pr-safety-precheck.yml:22","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:1213","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:2236","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:5025","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:37","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-triage.yml:38","Info: jobLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:85","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-sdk-java.yml:25","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-sdk-python.yml:49","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-sdk.yml:72","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-vscode-companion.yml:293","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-vscode-companion.yml:392","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-vscode-companion.yml:57","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-vscode-companion.yml:207","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:605","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/release.yml:607","Warn: jobLevel 'actions' permission set to 'write': .github/workflows/release.yml:779","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:780","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:293","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:347","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:386","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:56","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:233","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:421","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:485","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:516","Info: jobLevel 'contents' permission set to 'read': .github/workflows/repo-hygiene.yml:46","Info: jobLevel 'contents' permission set to 'read': .github/workflows/repo-hygiene.yml:83","Info: jobLevel 'contents' permission set to 'read': .github/workflows/repo-hygiene.yml:217","Info: jobLevel 'contents' permission set to 'read': .github/workflows/security-checks.yml:120","Info: jobLevel 'actions' permission set to 'read': .github/workflows/sync-desktop-to-oss.yml:44","Info: jobLevel 'contents' permission set to 'read': .github/workflows/sync-desktop-to-oss.yml:45","Info: jobLevel 'actions' permission set to 'read': .github/workflows/sync-live-host-to-oss.yml:44","Info: jobLevel 'contents' permission set to 'read': .github/workflows/sync-live-host-to-oss.yml:45","Info: jobLevel 'contents' permission set to 'read': .github/workflows/sync-release-to-oss.yml:26","Info: jobLevel 'contents' permission set to 'read': .github/workflows/update-ecs-runner-qwen.yml:155","Info: jobLevel 'actions' permission set to 'read': .github/workflows/update-ecs-runner-qwen.yml:157","Info: topLevel 'contents' permission set to 'read': .github/workflows/assign-issue-owner.yml:36","Info: topLevel 'contents' permission set to 'read': .github/workflows/assign-pr-owner.yml:26","Info: topLevel 'contents' permission set to 'read': .github/workflows/audio-capture-prebuilds.yml:23","Info: topLevel 'contents' permission set to 'read': .github/workflows/auto-minimize-spam.yml:39","Warn: no topLevel permission defined: .github/workflows/build-and-publish-image.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/cd-cua-driver.yml:56","Warn: no topLevel permission defined: .github/workflows/cd-mobile-mcp.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci.yml:67","Warn: topLevel 'statuses' permission set to 'write': .github/workflows/ci.yml:68","Warn: topLevel 'checks' permission set to 'write': .github/workflows/ci.yml:66","Info: topLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:16","Warn: topLevel 'security-events' permission set to 'write': .github/workflows/codeql.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/comment-attachment-guard.yml:18","Info: topLevel 'actions' permission set to 'read': .github/workflows/desktop-packaging-check.yml:32","Warn: topLevel 'contents' permission set to 'write': .github/workflows/desktop-packaging-check.yml:33","Info: topLevel 'contents' permission set to 'read': .github/workflows/desktop-release.yml:70","Info: topLevel 'contents' permission set to 'read': .github/workflows/docs-page-action.yml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/dsw-swe-verified-release.yml:53","Info: topLevel 'contents' permission set to 'read': .github/workflows/e2e.yml:4","Warn: no topLevel permission defined: .github/workflows/finalize-release.yml:1","Info: topLevel 'actions' permission set to 'read': .github/workflows/live-host-release.yml:38","Info: topLevel 'contents' permission set to 'read': .github/workflows/live-host-release.yml:39","Info: topLevel 'contents' permission set to 'read': .github/workflows/live-host.yml:20","Warn: no topLevel permission defined: .github/workflows/main-ci-failure-issue.yml:1","Warn: topLevel 'actions' permission set to 'write': .github/workflows/npm-cache.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/npm-cache.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/pnpm-lock-freshness.yml:51","Info: topLevel 'contents' permission set to 'read': .github/workflows/pnpm-worktree-smoke.yml:60","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-force-push-reminder.yml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-self-report-label.yml:15","Warn: topLevel 'actions' permission set to 'write': .github/workflows/qwen-autofix-fork-bridge.yml:47","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix-fork-bridge.yml:51","Info: topLevel 'pull-requests' permission set to 'read': .github/workflows/qwen-autofix-fork-bridge.yml:52","Info: found token with 'none' permissions: .github/workflows/qwen-autofix-fork-signal.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-autofix.yml:71","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-ci-flaky-rerun.yml:9","Warn: no topLevel permission defined: .github/workflows/qwen-code-pr-review.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-fleet-shepherd.yml:66","Warn: topLevel 'actions' permission set to 'write': .github/workflows/qwen-fleet-shepherd.yml:67","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-issue-followup-bot.yml:40","Warn: no topLevel permission defined: .github/workflows/qwen-pr-safety-precheck.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-triage-finalize.yml:44","Info: topLevel 'contents' permission set to 'read': .github/workflows/qwen-triage.yml:27","Warn: no topLevel permission defined: .github/workflows/release-sdk-java.yml:1","Warn: no topLevel permission defined: .github/workflows/release-sdk-python.yml:1","Warn: no topLevel permission defined: .github/workflows/release-sdk.yml:1","Warn: no topLevel permission defined: .github/workflows/release-vscode-companion.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/repo-hygiene.yml:25","Info: topLevel 'contents' permission set to 'read': .github/workflows/scorecard-monthly.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/sdk-java.yml:44","Info: topLevel 'contents' permission set to 'read': .github/workflows/sdk-python.yml:4","Info: topLevel 'contents' permission set to 'read': .github/workflows/security-checks.yml:12","Info: topLevel 'actions' permission set to 'read': .github/workflows/serve-ab-publish.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/serve-ab.yml:56","Warn: no topLevel permission defined: .github/workflows/stale.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-desktop-to-oss.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-live-host-to-oss.yml:1","Warn: no topLevel permission defined: .github/workflows/sync-release-to-oss.yml:1","Warn: no topLevel permission defined: .github/workflows/tui-parity.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-ecs-runner-qwen.yml:18","Info: topLevel 'contents' permission set to 'read': .github/workflows/web-shell-visuals-cleanup.yml:14","Info: topLevel 'actions' permission set to 'read': .github/workflows/web-shell-visuals-publish.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/web-shell-visuals.yml:44","Info: topLevel 'contents' permission set to 'read': .github/workflows/windows-runner-smoke.yml:7"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact cua-driver-rs-v0.20.7 not signed: https://api.github.com/repos/QwenLM/qwen-code/releases/388367866","Warn: release artifact v0.23.3-nightly.20260913.faa395885e not signed: https://api.github.com/repos/QwenLM/qwen-code/releases/388048681","Warn: release artifact cua-driver-rs-v0.20.6 not signed: https://api.github.com/repos/QwenLM/qwen-code/releases/387875283","Warn: release artifact v0.23.3-nightly.20260912.54aa66834b not signed: https://api.github.com/repos/QwenLM/qwen-code/releases/387717074","Warn: release artifact v0.23.3-nightly.20260911.aaa6a32aae not signed: https://api.github.com/repos/QwenLM/qwen-code/releases/387360798","Warn: release artifact cua-driver-rs-v0.20.7 does not have provenance: https://api.github.com/repos/QwenLM/qwen-code/releases/388367866","Warn: release artifact v0.23.3-nightly.20260913.faa395885e does not have provenance: https://api.github.com/repos/QwenLM/qwen-code/releases/388048681","Warn: release artifact cua-driver-rs-v0.20.6 does not have provenance: https://api.github.com/repos/QwenLM/qwen-code/releases/387875283","Warn: release artifact v0.23.3-nightly.20260912.54aa66834b does not have provenance: https://api.github.com/repos/QwenLM/qwen-code/releases/387717074","Warn: release artifact v0.23.3-nightly.20260911.aaa6a32aae does not have provenance: https://api.github.com/repos/QwenLM/qwen-code/releases/387360798"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build-and-publish-image.yml:23"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-image.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/build-and-publish-image.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:222: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:241: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:281: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:396: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:397: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:412: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:415: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:580: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:591: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:630: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:631: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:640: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:682: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:696: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:697: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:721: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:749: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:750: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:829: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:872: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:879: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:303: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:304: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:319: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:322: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:378: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:993: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:1000: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd-cua-driver.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-cua-driver.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-mobile-mcp.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-mobile-mcp.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd-mobile-mcp.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/QwenLM/qwen-code/cd-mobile-mcp.yml/main?enable=pin","Warn: containerImage not pinned by hash: integration-tests/terminal-bench/ci-tasks/hello-world/Dockerfile:2: pin your Docker image by updating ghcr.io/laude-institute/t-bench/python-3-13:20250620 to ghcr.io/laude-institute/t-bench/python-3-13:20250620@sha256:236734f0cafcce942ca09316d57236c2273a2b5411e116454a22cf6d718d95f5","Warn: containerImage not pinned by hash: integration-tests/terminal-bench/ci-tasks/swe-bench-astropy-1/Dockerfile:14: pin your Docker image by updating python:3.9-slim-bookworm to python:3.9-slim-bookworm@sha256:a02e9c5406c416c504d6c9a1a306ff4080c3173f1008d192f953bd20382a2d5c","Warn: npmCommand not pinned by hash: Dockerfile:77-79","Warn: downloadThenRun not pinned by hash: integration-tests/terminal-bench/ci-tasks/hello-world/tests/setup-uv-pytest.sh:8","Warn: pipCommand not pinned by hash: integration-tests/terminal-bench/ci-tasks/swe-bench-astropy-1/run-tests.sh:49","Warn: pipCommand not pinned by hash: integration-tests/terminal-bench/ci-tasks/swe-bench-astropy-1/run-tests.sh:50","Warn: downloadThenRun not pinned by hash: integration-tests/terminal-bench/qwen-code-setup.sh.j2:7","Warn: npmCommand not pinned by hash: integration-tests/terminal-bench/qwen-code-setup.sh.j2:13","Warn: npmCommand not pinned by hash: packages/cua-driver/tests/fixtures/apps/cross-platform/electron/build.sh:74","Warn: npmCommand not pinned by hash: .github/workflows/audio-capture-prebuilds.yml:61","Warn: npmCommand not pinned by hash: .github/workflows/cd-cua-driver.yml:640","Warn: npmCommand not pinned by hash: .github/workflows/cd-cua-driver.yml:879","Warn: npmCommand not pinned by hash: .github/workflows/cd-cua-driver.yml:909","Warn: npmCommand not pinned by hash: .github/workflows/cd-cua-driver.yml:706","Warn: npmCommand not pinned by hash: .github/workflows/cd-cua-driver.yml:1000","Warn: npmCommand not pinned by hash: .github/workflows/cd-mobile-mcp.yml:39","Warn: npmCommand not pinned by hash: .github/workflows/live-host-release.yml:361","Warn: npmCommand not pinned by hash: .github/workflows/qwen-code-pr-review.yml:825","Warn: npmCommand not pinned by hash: .github/workflows/qwen-code-pr-review.yml:3577","Warn: npmCommand not pinned by hash: .github/workflows/qwen-issue-followup-bot.yml:309","Warn: npmCommand not pinned by hash: .github/workflows/qwen-triage.yml:1307","Warn: npmCommand not pinned by hash: .github/workflows/qwen-triage.yml:2610","Warn: npmCommand not pinned by hash: .github/workflows/qwen-triage.yml:712","Warn: pipCommand not pinned by hash: .github/workflows/release-sdk-python.yml:214","Warn: pipCommand not pinned by hash: .github/workflows/release-sdk-python.yml:215","Warn: npmCommand not pinned by hash: .github/workflows/release-sdk.yml:122","Warn: npmCommand not pinned by hash: .github/workflows/release-vscode-companion.yml:231","Warn: npmCommand not pinned by hash: .github/workflows/release-vscode-companion.yml:316","Warn: npmCommand not pinned by hash: .github/workflows/release-vscode-companion.yml:317","Warn: npmCommand not pinned by hash: .github/workflows/release.yml:634","Warn: pipCommand not pinned by hash: .github/workflows/sdk-python.yml:89","Warn: pipCommand not pinned by hash: .github/workflows/sdk-python.yml:90","Info: 222 out of 251 GitHub-owned GitHubAction dependencies pinned","Info:  16 out of  27 third-party GitHubAction dependencies pinned","Info:   0 out of   6 pipCommand dependencies pinned","Info:   2 out of   4 containerImage dependencies pinned","Info:  57 out of  79 npmCommand dependencies pinned","Info:   0 out of   2 downloadThenRun dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'release/v0.23.3-nightly.20260913.faa395885e'","Warn: branch protection not enabled for branch 'release/v0.23.3-nightly.20260912.54aa66834b'","Warn: branch protection not enabled for branch 'release/v0.23.3-nightly.20260911.aaa6a32aae'","Warn: branch protection not enabled for branch 'release/v0.23.3'","Warn: branch protection not enabled for branch 'release/v0.23.3-nightly.20260910.c46cb85cf2'","Warn: branch protection not enabled for branch 'release/sdk-typescript/v0.1.12'","Warn: branch protection not enabled for branch 'release/v0.23.2'","Warn: branch protection not enabled for branch 'release/v0.23.2-nightly.20260909.2e212144d3'","Warn: branch protection not enabled for branch 'release/sdk-typescript/v0.1.11'","Warn: branch protection not enabled for branch 'release/v0.23.2-preview.0'","Warn: branch protection not enabled for branch 'release/v0.23.1'","Warn: branch protection not enabled for branch 'release/sdk-typescript/v0.1.9'","Warn: branch protection not enabled for branch 'release/sdk-typescript/v0.1.10'","Warn: branch protection not enabled for branch 'release/v0.23.1-preview.2'","Warn: branch protection not enabled for branch 'release/v0.23.0-nightly.20260907.f1ed3bc31a'","Warn: branch protection not enabled for branch 'release/v0.23.1-preview.1'","Warn: branch protection not enabled for branch 'release/v0.23.0-nightly.20260906.92a8a8d179'","Warn: branch protection not enabled for branch 'release/v0.23.0-nightly.20260905.0c945a6136'","Warn: branch protection not enabled for branch 'release/v0.23.1-preview.0'","Warn: branch protection not enabled for branch 'release/v0.23.0-nightly.20260905.e3d26283e6'","Warn: branch protection not enabled for branch 'release/v0.23.0'","Warn: branch protection not enabled for branch 'release/v0.22.3-nightly.20260831.3a0c4c6108'","Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Info: 'branch protection settings apply to administrators' is required to merge on branch 'main'","Warn: 'stale review dismissal' is disabled on branch 'main'","Info: required approving review count is 2 on branch 'main'","Info: codeowner review is required on branch 'main'","Warn: 'last push approval' is disabled on branch 'main'","Warn: no status checks found to merge onto branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}}]}
