{"date":"2022-11-28","repo":{"name":"github.com/bridgecrewio/checkov","commit":"ab685b36445bb1f7a14366194659fb7869f0edc4"},"scorecard":{"version":"v4.8.0-79-gd8fefc9","commit":"d8fefc9b246db3600c777e9d60d441d7c386ce1d"},"score":7,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) out of 30 and 7 issue activity out of 30 found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Code-Review","score":3,"reason":"11 out of last 30 changesets reviewed before merge -- score normalized to 3","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#code-review","short":"Determines if the project requires code review before pull requests (aka merge requests) are merged."}},{"name":"Vulnerabilities","score":10,"reason":"no vulnerabilities detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#vulnerabilities","short":"Determines if the project has open, known unfixed vulnerabilities."}},{"name":"CII-Best-Practices","score":2,"reason":"badge detected: in_progress","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":["Warn: no GitHub releases found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Branch-Protection","score":6,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'force pushes' disabled on branch 'main'","Info: 'allow deletion' disabled on branch 'main'","Warn: no status checks found to merge onto branch 'main'","Info: number of required reviewers is 2 on branch 'main'","Warn: codeowner review is not required on branch 'main'"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Token-Permissions","score":0,"reason":"non read-only tokens detected in GitHub workflows","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/build.yml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/codeql-analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/codeql-analysis.yml/main?enable=permissions","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/codeql-analysis.yml/main?enable=permissions","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/codeql-analysis.yml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/coverage.yaml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/coverage.yaml/main?enable=permissions","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/coverage.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/coverage.yaml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/nightly.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/nightly.yml/main?enable=permissions","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/nightly.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/nightly.yml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/pipenv-update.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/pipenv-update.yml/main?enable=permissions","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pipenv-update.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/pipenv-update.yml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/pr-test.yml:5: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/pr-test.yml/main?enable=permissions","Warn: no topLevel permission defined: .github/workflows/pr-title.yaml:1: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/pr-title.yaml/main?enable=permissions","Info: topLevel permissions set to 'read-all': .github/workflows/security.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/security.yaml/main?enable=permissions"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: Found linked content in security policy: SECURITY.md","Info: Found text in security policy: SECURITY.md","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md","Info: security policy detected in current repo: SECURITY.md"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: : LICENSE:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: Dependabot detected: .github/dependabot.yml:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#dependency-update-tool","short":"Determines if the project uses a dependency update tool."}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (11) are checked with a SAST tool","Info: SAST tool detected: CodeQL"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"Packaging","score":10,"reason":"publishing workflow detected","details":["Info: GitHub publishing workflow used in run https://api.github.com/repos/bridgecrewio/checkov/actions/runs/3572272552: .github/workflows/build.yml:246"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:298: update your workflow using https://app.stepsecurity.io/secureworkflow/bridgecrewio/checkov/build.yml/main?enable=pin","Warn: containerImage not pinned by hash: .gitpod.Dockerfile:1: pin your Docker image by updating gitpod/workspace-python to gitpod/workspace-python@sha256:25e14c240990d5f09ddb1176822bff0ec2d13982e84e684679e7354e9c417122","Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating python to python@sha256:10fc14aa6ae69f69e4c953cffd9b0964843d8c163950491d2138af891377bc1d","Warn: containerImage not pinned by hash: Dockerfile.pyston:1: pin your Docker image by updating pyston/slim to pyston/slim@sha256:078eccc767f568d1a75c98aa2fd010ab17c032d611021015203497ea51f7f1e5","Warn: containerImage not pinned by hash: admissioncontroller/Dockerfile:2: pin your Docker image by updating python to python@sha256:10fc14aa6ae69f69e4c953cffd9b0964843d8c163950491d2138af891377bc1d","Warn: containerImage not pinned by hash: docs/7.Scan Examples/Dockerfile.md:18: pin your Docker image by updating node to node@sha256:bff0e689cb433913ab411af7a58253d54c7fd8c3134ffeb25287cdf24d9a5972","Warn: containerImage not pinned by hash: kubernetes/Dockerfile:1: pin your Docker image by updating python to python@sha256:10fc14aa6ae69f69e4c953cffd9b0964843d8c163950491d2138af891377bc1d","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AddExists/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AliasIsUnique/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AliasIsUnique/failure/Dockerfile:4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AliasIsUnique/failure/Dockerfile:7","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AliasIsUnique/success/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_AliasIsUnique/success/Dockerfile:4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ExposePort22/failure/Dockerfile:1: pin your Docker image by updating busybox to busybox@sha256:fcd85228d7a25feb59f101ac3a955d27c80df4ad824d65f5757a954831450185","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ExposePort22/failure_tcp/Dockerfile:1: pin your Docker image by updating busybox to busybox@sha256:fcd85228d7a25feb59f101ac3a955d27c80df4ad824d65f5757a954831450185","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ExposePort22/success/Dockerfile:1: pin your Docker image by updating busybox to busybox@sha256:fcd85228d7a25feb59f101ac3a955d27c80df4ad824d65f5757a954831450185","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_HealthcheckExists/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_HealthcheckExists/success/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_MaintainerExists/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/failure_default_version_tag/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/failure_latest_version_tag/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage/Dockerfile:1: pin your Docker image by updating alpine:3 to alpine:3@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage/Dockerfile:4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage_capital/Dockerfile:1: pin your Docker image by updating alpine:3 to alpine:3@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage_capital/Dockerfile:4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage_capital/Dockerfile:7","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_ReferenceLatestTag/success_multi_stage_scratch/Dockerfile:4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_RootUser/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_RootUser/success/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_RunUsingAPT/failure/Dockerfile:1: pin your Docker image by updating busybox to busybox@sha256:fcd85228d7a25feb59f101ac3a955d27c80df4ad824d65f5757a954831450185","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_RunUsingAPT/success/Dockerfile:1: pin your Docker image by updating busybox to busybox@sha256:fcd85228d7a25feb59f101ac3a955d27c80df4ad824d65f5757a954831450185","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_UpdateNotAlone/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_UpdateNotAlone/failure/Dockerfile.simple:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_UpdateNotAlone/success/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_UserExists/failure/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_UserExists/success/Dockerfile:1","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/failure/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/failure/Dockerfile.simple:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/success/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/image_referencer/resources/Dockerfile.multi_platform:1: pin your Docker image by updating golang:alpine to golang:alpine@sha256:d171aa333fb386089206252503bc6ab545072670e0286e3d1bbc644362825c6e","Warn: containerImage not pinned by hash: tests/dockerfile/image_referencer/resources/Dockerfile.multi_platform:8: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/image_referencer/resources/Dockerfile.multi_stage:2: pin your Docker image by updating maven:3.8-openjdk-17-slim to maven:3.8-openjdk-17-slim@sha256:502e781d39f0b40fbd02eb23f5b7663618b76ba52034da218c64e92f6c5647be","Warn: containerImage not pinned by hash: tests/dockerfile/image_referencer/resources/Dockerfile.multi_stage:10: pin your Docker image by updating amazonlinux:2 to amazonlinux:2@sha256:a8e94ea6c17f7749b1beb0ac2c3245e0b99804190f31e05f68a0fabb5bea1787","Warn: containerImage not pinned by hash: tests/dockerfile/image_referencer/resources/Dockerfile.simple:1: pin your Docker image by updating php to php@sha256:77671163eeb253bea487bb745dc9185386d2e531e8c668acb3c255da6fde78fb","Warn: containerImage not pinned by hash: tests/dockerfile/resources/expose_port/fail/Dockerfile:1: pin your Docker image by updating node to node@sha256:bff0e689cb433913ab411af7a58253d54c7fd8c3134ffeb25287cdf24d9a5972","Warn: containerImage not pinned by hash: tests/dockerfile/resources/expose_port/pass/Dockerfile:1: pin your Docker image by updating gliderlabs/alpine to gliderlabs/alpine@sha256:23b993692b943f0799b3f36042d8a1331557103eb4ac2c0b8ab36cab9f399f8b","Warn: containerImage not pinned by hash: tests/dockerfile/resources/expose_port/skip/Dockerfile:1: pin your Docker image by updating gliderlabs/alpine to gliderlabs/alpine@sha256:23b993692b943f0799b3f36042d8a1331557103eb4ac2c0b8ab36cab9f399f8b","Warn: containerImage not pinned by hash: tests/dockerfile/resources/name_variations/.Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/resources/name_variations/Dockerfile.prod:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/resources/name_variations/prod.dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:8914eb54f968791faf6a8638949e480fef81e697984fba772b3976835194c6d4","Warn: containerImage not pinned by hash: tests/dockerfile/resources/wildcard_skip/Dockerfile:1: pin your Docker image by updating python to python@sha256:10fc14aa6ae69f69e4c953cffd9b0964843d8c163950491d2138af891377bc1d","Warn: containerImage not pinned by hash: tests/sca_image/examples/dockerfile/Dockerfile:1: pin your Docker image by updating ubuntu to ubuntu@sha256:4b1d0c4a2d2aaf63b37111f34eb9fa89fa1bf53dd6e4ca954d47caebca4005c2","Warn: containerImage not pinned by hash: tests/secrets/custom_regex_detector/Dockerfile:1","Warn: containerImage not pinned by hash: tests/secrets/resources/file_type/Dockerfile:1","Warn: containerImage not pinned by hash: tests/secrets/resources/file_type/Dockerfile.simple:1","Warn: downloadThenRun not pinned by hash: .gitpod.Dockerfile:4-8","Warn: pipCommand not pinned by hash: Dockerfile:29","Warn: pipCommand not pinned by hash: Dockerfile.pyston:26-34","Warn: pipCommand not pinned by hash: admissioncontroller/Dockerfile:11","Warn: pipCommand not pinned by hash: admissioncontroller/Dockerfile:12","Warn: npmCommand not pinned by hash: docs/7.Scan Examples/Dockerfile.md:21","Warn: pipCommand not pinned by hash: kubernetes/Dockerfile:8","Warn: pipCommand not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/failure/Dockerfile:3","Warn: pipCommand not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/failure/Dockerfile:8","Warn: pipCommand not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/success/Dockerfile:3","Warn: pipCommand not pinned by hash: tests/dockerfile/checks/example_WorkdirIsAbsolute/success/Dockerfile:14","Warn: npmCommand not pinned by hash: tests/dockerfile/resources/expose_port/fail/Dockerfile:4","Warn: pipCommand not pinned by hash: .github/workflows/build.yml:121","Warn: pipCommand not pinned by hash: .github/workflows/build.yml:55","Warn: pipCommand not pinned by hash: .github/workflows/build.yml:93","Warn: pipCommand not pinned by hash: .github/workflows/build.yml:154","Warn: pipCommand not pinned by hash: .github/workflows/codeql-analysis.yml:43","Warn: pipCommand not pinned by hash: .github/workflows/codeql-analysis.yml:54","Warn: pipCommand not pinned by hash: .github/workflows/coverage.yaml:33","Warn: pipCommand not pinned by hash: .github/workflows/pipenv-update.yml:31","Warn: pipCommand not pinned by hash: .github/workflows/pr-test.yml:27","Warn: pipCommand not pinned by hash: .github/workflows/pr-test.yml:41","Warn: pipCommand not pinned by hash: .github/workflows/pr-test.yml:66","Warn: pipCommand not pinned by hash: .github/workflows/pr-test.yml:98","Warn: pipCommand not pinned by hash: .github/workflows/pr-test.yml:146","Info: GitHub-owned GitHubActions are pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/d8fefc9b246db3600c777e9d60d441d7c386ce1d/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}}]}
