{"date":"2026-08-21T15:45:55Z","repo":{"name":"github.com/aaif-goose/goose","commit":"45b322c1df30295caaceb23a8a043fc9fa032527"},"scorecard":{"version":"v5.5.0","commit":"c395761df6afe1a69e476bc60a013a94bcbc153f"},"score":5.4,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"}},{"name":"Dangerous-Workflow","score":0,"reason":"dangerous workflow patterns detected","details":["Warn: untrusted code checkout '${{ github.event.pull_request.base.sha }}': .github/workflows/recipe-security-scanner.yml:129","Warn: untrusted code checkout '${{ github.event.pull_request.head.sha }}': .github/workflows/recipe-security-scanner.yml:136"],"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-cli.yml:65","Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-cli.yml:35","Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-cli.yml:53","Info: found token with 'none' permissions: .github/workflows/bundle-macos.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/bundle-macos.yml:202","Info: jobLevel 'contents' permission set to 'read': .github/workflows/bundle-macos.yml:73","Info: jobLevel 'contents' permission set to 'read': .github/workflows/canary.yml:71","Info: jobLevel 'contents' permission set to 'read': .github/workflows/canary.yml:86","Info: jobLevel 'contents' permission set to 'read': .github/workflows/canary.yml:122","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/canary.yml:139","Info: jobLevel 'contents' permission set to 'read': .github/workflows/canary.yml:110","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cargo-deny.yml:23","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cargo-machete.yml:21","Info: found token with 'none' permissions: .github/workflows/code-review.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/code-review.yml:31","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/code-review.yml:32","Info: jobLevel 'contents' permission set to 'read': .github/workflows/deploy-docs-and-extensions.yml:18","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/goose-release-notes.yml:171","Info: jobLevel 'contents' permission set to 'read': .github/workflows/pr-website-preview.yml:21","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/recipe-security-scanner.yml:28","Warn: jobLevel 'statuses' permission set to 'write': .github/workflows/recipe-security-scanner.yml:538","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-branches.yml:11","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:51","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:66","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:88","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release.yml:100","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:118","Info: topLevel 'contents' permission set to 'read': .github/workflows/build-cli-linux.yml:17","Warn: no topLevel permission defined: .github/workflows/build-cli.yml:1","Warn: no topLevel permission defined: .github/workflows/build-notify.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/bundle-desktop-linux.yml:23","Warn: no topLevel permission defined: .github/workflows/bundle-macos.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/bundle-windows.yml:67","Info: topLevel 'contents' permission set to 'read': .github/workflows/canary.yml:19","Warn: no topLevel permission defined: .github/workflows/cargo-deny.yml:1","Warn: no topLevel permission defined: .github/workflows/cargo-machete.yml:1","Warn: no topLevel permission defined: .github/workflows/check-release-pr.yaml:1","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/close-release-pr-on-tag.yaml:10","Warn: topLevel 'actions' permission set to 'write': .github/workflows/close-release-pr-on-tag.yaml:9","Warn: no topLevel permission defined: .github/workflows/code-review.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/create-release-branch.yaml:11","Warn: topLevel 'contents' permission set to 'write': .github/workflows/create-version-bump-pr.yaml:20","Warn: topLevel 'contents' permission set to 'write': .github/workflows/dependabot-auto-merge.yml:7","Warn: no topLevel permission defined: .github/workflows/deploy-docs-and-extensions.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/docs-update-cli-ref.yml:33","Warn: topLevel 'contents' permission set to 'write': .github/workflows/goose-issue-solver.yml:114","Info: topLevel 'contents' permission set to 'read': .github/workflows/goose-pr-reviewer.yml:208","Warn: topLevel 'contents' permission set to 'write': .github/workflows/goose-release-notes.yml:71","Info: topLevel 'contents' permission set to 'read': .github/workflows/maven-sdk.yml:13","Warn: no topLevel permission defined: .github/workflows/mcp-conformance.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/minor-release.yaml:4","Info: topLevel 'contents' permission set to 'read': .github/workflows/model-toolcall-conformance.yml:26","Warn: topLevel 'contents' permission set to 'write': .github/workflows/patch-release.yaml:4","Warn: no topLevel permission defined: .github/workflows/pr-smoke-test.yml:1","Warn: no topLevel permission defined: .github/workflows/pr-website-preview.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/publish-ask-ai-bot.yml:14","Warn: topLevel 'packages' permission set to 'write': .github/workflows/publish-ask-ai-bot.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/publish-docker.yml:16","Warn: topLevel 'packages' permission set to 'write': .github/workflows/publish-docker.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/publish-npm.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/python-sdk-wheels.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/recipe-security-scanner.yml:14","Warn: topLevel 'statuses' permission set to 'write': .github/workflows/recipe-security-scanner.yml:17","Warn: no topLevel permission defined: .github/workflows/release-branches.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yml:14","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:18","Info: topLevel 'contents' permission set to 'read': .github/workflows/stale.yml:17","Warn: no topLevel permission defined: .github/workflows/take.yml:1","Info: topLevel 'issues' permission set to 'read': .github/workflows/update-health-dashboard.yml:17","Info: topLevel 'pull-requests' permission set to 'read': .github/workflows/update-health-dashboard.yml:18","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-health-dashboard.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-release-pr.yaml:12"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v1.46.0 not signed: https://api.github.com/repos/aaif-goose/goose/releases/369368159","Warn: release artifact v1.45.0 not signed: https://api.github.com/repos/aaif-goose/goose/releases/362024365","Warn: release artifact v1.44.0 not signed: https://api.github.com/repos/aaif-goose/goose/releases/358902599","Warn: release artifact v1.43.0 not signed: https://api.github.com/repos/aaif-goose/goose/releases/353697558","Warn: release artifact v1.42.0 not signed: https://api.github.com/repos/aaif-goose/goose/releases/353383155","Warn: release artifact v1.46.0 does not have provenance: https://api.github.com/repos/aaif-goose/goose/releases/369368159","Warn: release artifact v1.45.0 does not have provenance: https://api.github.com/repos/aaif-goose/goose/releases/362024365","Warn: release artifact v1.44.0 does not have provenance: https://api.github.com/repos/aaif-goose/goose/releases/358902599","Warn: release artifact v1.43.0 does not have provenance: https://api.github.com/repos/aaif-goose/goose/releases/353697558","Warn: release artifact v1.42.0 does not have provenance: https://api.github.com/repos/aaif-goose/goose/releases/353383155"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 1 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"71 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2025-0141","Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2026-0221","Warn: Project is vulnerable to: https://osv.dev/GHSA-w9wp-h8wv-79jx","Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2024-0436","Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2024-0370","Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2023-0071","Warn: Project is vulnerable to: https://osv.dev/RUSTSEC-2026-0249","Warn: Project is vulnerable to: https://osv.dev/GHSA-866g-f22w-33x8","Warn: Project is vulnerable to: https://osv.dev/GHSA-4x5r-pxfx-6jf8","Warn: Project is vulnerable to: https://osv.dev/GHSA-64mm-vxmg-q3vj","Warn: Project is vulnerable to: https://osv.dev/GHSA-5p2g-fcmc-qvqq","Warn: Project is vulnerable to: https://osv.dev/GHSA-w3rx-r6r6-pgpr","Warn: Project is vulnerable to: https://osv.dev/GHSA-q7cg-457f-vx79","Warn: Project is vulnerable to: https://osv.dev/GHSA-52cp-r559-cp3m","Warn: Project is vulnerable to: https://osv.dev/GHSA-5p4m-2wfm-xmqj","Warn: Project is vulnerable to: https://osv.dev/GHSA-h67p-54hq-rp68","Warn: Project is vulnerable to: https://osv.dev/GHSA-23c5-xmqv-rm74","Warn: Project is vulnerable to: https://osv.dev/GHSA-3ppc-4f35-3m26","Warn: Project is vulnerable to: https://osv.dev/GHSA-7r86-cg39-jmmj","Warn: Project is vulnerable to: https://osv.dev/GHSA-2v37-7h3g-55p8","Warn: Project is vulnerable to: https://osv.dev/GHSA-5c6j-r48x-rmvq","Warn: Project is vulnerable to: https://osv.dev/GHSA-qj8w-gfj5-8c6v","Warn: Project is vulnerable to: https://osv.dev/GHSA-w5hq-g745-h8pq","Warn: Project is vulnerable to: https://osv.dev/GHSA-38r7-794h-5758","Warn: Project is vulnerable to: https://osv.dev/GHSA-8fgc-7cc6-rx7x","Warn: Project is vulnerable to: https://osv.dev/GHSA-48c2-rrv3-qjmp","Warn: Project is vulnerable to: https://osv.dev/GHSA-7h2j-956f-4vf2","Warn: Project is vulnerable to: https://osv.dev/GHSA-f23m-r3pf-42rh","Warn: Project is vulnerable to: https://osv.dev/GHSA-r5fr-rjxr-66jc","Warn: Project is vulnerable to: https://osv.dev/GHSA-2mjp-6q6p-2qxm","Warn: Project is vulnerable to: https://osv.dev/GHSA-35p6-xmwp-9g52","Warn: Project is vulnerable to: https://osv.dev/GHSA-4992-7rv2-5pvq","Warn: Project is vulnerable to: https://osv.dev/GHSA-8xcm-r25x-g524","Warn: Project is vulnerable to: https://osv.dev/GHSA-f269-vfmq-vjvj","Warn: Project is vulnerable to: https://osv.dev/GHSA-g8m3-5g58-fq7m","Warn: Project is vulnerable to: https://osv.dev/GHSA-g9mf-h72j-4rw9","Warn: Project is vulnerable to: https://osv.dev/GHSA-m8rv-5g2x-5cg5","Warn: Project is vulnerable to: https://osv.dev/GHSA-p88m-4jfj-68fv","Warn: Project is vulnerable to: https://osv.dev/GHSA-v3r7-h72x-cjcm","Warn: Project is vulnerable to: https://osv.dev/GHSA-v9p9-hfj2-hcw8","Warn: Project is vulnerable to: https://osv.dev/GHSA-vrm6-8vpv-qv8q","Warn: Project is vulnerable to: https://osv.dev/GHSA-vxpw-j846-p89q","Warn: Project is vulnerable to: https://osv.dev/GHSA-58qx-3vcg-4xpx","Warn: Project is vulnerable to: https://osv.dev/GHSA-96hv-2xvq-fx4p","Warn: Project is vulnerable to: https://osv.dev/GHSA-v422-hmwv-36x6","Warn: Project is vulnerable to: https://osv.dev/GHSA-jmr9-qjv8-65gv","Warn: Project is vulnerable to: https://osv.dev/GHSA-27v5-c462-wpq7","Warn: Project is vulnerable to: https://osv.dev/GHSA-j3q9-mxjg-w52f","Warn: Project is vulnerable to: https://osv.dev/GHSA-3v7f-55p6-f55p","Warn: Project is vulnerable to: https://osv.dev/GHSA-c2c7-rcm5-vvqj","Warn: Project is vulnerable to: https://osv.dev/GHSA-q8mj-m7cp-5q26","Warn: Project is vulnerable to: https://osv.dev/GHSA-v3rj-xjv7-4jmq","Warn: Project is vulnerable to: https://osv.dev/GHSA-23hp-3jrh-7fpw","Warn: Project is vulnerable to: https://osv.dev/GHSA-34x7-hfp2-rc4v","Warn: Project is vulnerable to: https://osv.dev/GHSA-83g3-92jg-28cx","Warn: Project is vulnerable to: https://osv.dev/GHSA-8qq5-rm4j-mr97","Warn: Project is vulnerable to: https://osv.dev/GHSA-8x88-c5mf-7j5w","Warn: Project is vulnerable to: https://osv.dev/GHSA-9ppj-qmqm-q256","Warn: Project is vulnerable to: https://osv.dev/GHSA-gvwx-54wh-qm9j","Warn: Project is vulnerable to: https://osv.dev/GHSA-qffp-2rhf-9h96","Warn: Project is vulnerable to: https://osv.dev/GHSA-r292-9mhp-454m","Warn: Project is vulnerable to: https://osv.dev/GHSA-r6q2-hw4h-h46w","Warn: Project is vulnerable to: https://osv.dev/GHSA-vmf3-w455-68vh","Warn: Project is vulnerable to: https://osv.dev/GHSA-w8wr-v893-vjvp","Warn: Project is vulnerable to: https://osv.dev/GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: https://osv.dev/GHSA-ph9p-34f9-6g65","Warn: Project is vulnerable to: https://osv.dev/GHSA-4cwx-7wf7-3272","Warn: Project is vulnerable to: https://osv.dev/GHSA-hm92-r4w5-c3mj","Warn: Project is vulnerable to: https://osv.dev/GHSA-jr45-8vmc-qm54","Warn: Project is vulnerable to: https://osv.dev/GHSA-pr7r-676h-xcf6","Warn: Project is vulnerable to: https://osv.dev/GHSA-vmh5-mc38-953g"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/maven-sdk.yml:68"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":8,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Info: codeowner review is required on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Info: Possibly incomplete results: error parsing shell code: parameter expansion requires a literal: bin/activate-hermit:0","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cargo-deny.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/aaif-goose/goose/cargo-deny.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-smoke-test.yml:227: update your workflow using https://app.stepsecurity.io/secureworkflow/aaif-goose/goose/pr-smoke-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-smoke-test.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/aaif-goose/goose/pr-smoke-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-smoke-test.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/aaif-goose/goose/pr-smoke-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecard.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/aaif-goose/goose/scorecard.yml/main?enable=pin","Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:2: pin your Docker image by updating mcr.microsoft.com/devcontainers/rust:1 to mcr.microsoft.com/devcontainers/rust:1@sha256:0ef7110175191659b975c1b89217217a093667851bde031b48f8ceab9cd1be1f","Warn: containerImage not pinned by hash: Dockerfile:6: pin your Docker image by updating rust:1.82-bookworm to rust:1.82-bookworm@sha256:d9c3c6f1264a547d84560e06ffd79ed7a799ce0bff0980b26cf10d29af888377","Warn: containerImage not pinned by hash: documentation/docs/docker/Dockerfile:2: pin your Docker image by updating rust:bullseye to rust:bullseye@sha256:97cc99038824c3cee60ae9d0f75e0171ae0ae8b80786d26d0e7d21956f8d0164","Warn: containerImage not pinned by hash: documentation/docs/docker/Dockerfile:25: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:2edbbc5dc405e9612ba3584ce95480277e3eb374407b5505fe26f17df77c7dbc","Warn: containerImage not pinned by hash: recipe-scanner/Dockerfile:1: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241","Warn: containerImage not pinned by hash: services/ask-ai-bot/Dockerfile:1: pin your Docker image by updating oven/bun:1 to oven/bun:1@sha256:5ff609364c049b54eb0ff560ec96319729a972078ef2c755d758f0c6ef89c2d6","Warn: containerImage not pinned by hash: services/ask-ai-bot/Dockerfile:5","Warn: containerImage not pinned by hash: services/ask-ai-bot/Dockerfile:10","Warn: containerImage not pinned by hash: services/ask-ai-bot/Dockerfile:16","Warn: downloadThenRun not pinned by hash: documentation/docs/docker/Dockerfile:7-11","Warn: downloadThenRun not pinned by hash: documentation/docs/docker/Dockerfile:48-50","Warn: downloadThenRun not pinned by hash: documentation/docs/docker/Dockerfile:87","Warn: downloadThenRun not pinned by hash: documentation/docs/docker/Dockerfile:90","Warn: downloadThenRun not pinned by hash: recipe-scanner/Dockerfile:36-39","Warn: downloadThenRun not pinned by hash: recipe-scanner/Dockerfile:42-46","Warn: downloadThenRun not pinned by hash: recipe-scanner/Dockerfile:49-51","Warn: downloadThenRun not pinned by hash: documentation/automation/cli-command-tracking/scripts/extract-cli-structure.sh:35","Warn: downloadThenRun not pinned by hash: recipe-scanner/scan-recipe.sh:206","Warn: downloadThenRun not pinned by hash: ui/desktop/src/bin/jbang:153","Warn: downloadThenRun not pinned by hash: .github/workflows/build-cli-linux.yml:147","Warn: npmCommand not pinned by hash: .github/workflows/bundle-windows.yml:209","Warn: npmCommand not pinned by hash: .github/workflows/deploy-docs-and-extensions.yml:49","Warn: downloadThenRun not pinned by hash: .github/workflows/docs-update-cli-ref.yml:83","Warn: npmCommand not pinned by hash: .github/workflows/pr-smoke-test.yml:102","Warn: pipCommand not pinned by hash: .github/workflows/python-sdk-wheels.yml:56","Warn: pipCommand not pinned by hash: .github/workflows/python-sdk-wheels.yml:57","Warn: downloadThenRun not pinned by hash: .github/workflows/python-sdk-wheels.yml:59","Warn: pipCommand not pinned by hash: .github/workflows/python-sdk-wheels.yml:73","Info: 133 out of 138 GitHub-owned GitHubAction dependencies pinned","Info:  70 out of  70 third-party GitHubAction dependencies pinned","Info:   1 out of  10 containerImage dependencies pinned","Info:   0 out of  13 downloadThenRun dependencies pinned","Info:   1 out of   4 npmCommand dependencies pinned","Info:   0 out of   3 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 22 contributing companies or organizations","details":["Info: found contributions from: GCodeHouse, GitHub-Stars, TestAutomationU, aaif, aaif-goose, amongus-02, block, block - tbd, castorini, devcenter-square, dsg-uwaterloo, hydeparksda, iandouglas736.com, jenkinsci, netflix, not applicable, openai, openzipkin, red hat, runlayer, square, squareup"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"}}]}
