{"date":"2026-02-24T02:46:43Z","repo":{"name":"github.com/bytedance/UI-TARS-desktop","commit":"a3cfa5f112a7a970428486bacf298a7951519156"},"scorecard":{"version":"v5.1.1","commit":"cd152cb6742c5b8f2f3d2b5193b41d9c50905198"},"score":5.9,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#code-review"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#security-policy"}},{"name":"Maintained","score":10,"reason":"16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/secretlint.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/agent_tars_test.yml:12","Info: topLevel 'attestations' permission set to 'read': .github/workflows/agent_tars_test.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/benchmark.yml:12","Info: topLevel 'attestations' permission set to 'read': .github/workflows/benchmark.yml:13","Info: topLevel 'attestations' permission set to 'read': .github/workflows/e2e-ui-tars.yml:26","Info: topLevel 'contents' permission set to 'read': .github/workflows/e2e-ui-tars.yml:25","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-ui-tars.yml:15","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:18","Info: topLevel 'contents' permission set to 'read': .github/workflows/secret-scan.yml:9","Warn: no topLevel permission defined: .github/workflows/secretlint.yml:1","Info: topLevel 'attestations' permission set to 'read': .github/workflows/test.yml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:16","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":4,"reason":"dependency not pinned by hash detected -- score normalized to 4","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/bytedance/UI-TARS-desktop/test.yml/main?enable=pin","Warn: containerImage not pinned by hash: packages/agent-infra/mcp-servers/filesystem/Dockerfile:1","Warn: containerImage not pinned by hash: packages/agent-infra/mcp-servers/filesystem/Dockerfile:13","Warn: npmCommand not pinned by hash: packages/agent-infra/mcp-servers/browser/Dockerfile:33","Warn: npmCommand not pinned by hash: packages/agent-infra/mcp-servers/browser/Dockerfile:42","Warn: npmCommand not pinned by hash: packages/agent-infra/mcp-servers/browser/Dockerfile.http:33","Warn: npmCommand not pinned by hash: packages/agent-infra/mcp-servers/browser/Dockerfile.http:42","Warn: npmCommand not pinned by hash: packages/agent-infra/mcp-servers/filesystem/Dockerfile:8","Warn: npmCommand not pinned by hash: .github/workflows/agent_tars_test.yml:33","Warn: npmCommand not pinned by hash: .github/workflows/benchmark.yml:42","Warn: pipCommand not pinned by hash: .github/workflows/benchmark.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/benchmark.yml:51","Warn: npmCommand not pinned by hash: .github/workflows/e2e-ui-tars.yml:49","Warn: npmCommand not pinned by hash: .github/workflows/e2e-ui-tars.yml:59","Warn: npmCommand not pinned by hash: .github/workflows/release-ui-tars.yml:29","Warn: npmCommand not pinned by hash: .github/workflows/release-ui-tars.yml:37","Warn: npmCommand not pinned by hash: .github/workflows/release-ui-tars.yml:95","Warn: npmCommand not pinned by hash: .github/workflows/release-ui-tars.yml:103","Warn: npmCommand not pinned by hash: .github/workflows/release-ui-tars.yml:164","Warn: npmCommand not pinned by hash: .github/workflows/test.yml:46","Info:  27 out of  27 GitHub-owned GitHubAction dependencies pinned","Info:   5 out of   6 third-party GitHubAction dependencies pinned","Info:   2 out of   4 containerImage dependencies pinned","Info:   2 out of  17 npmCommand dependencies pinned","Info:   0 out of   2 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#pinned-dependencies"}},{"name":"Dependency-Update-Tool","score":0,"reason":"no update tool detected","details":["Warn: no dependency update tool configurations found"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dependency-update-tool"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#signed-releases"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#fuzzing"}},{"name":"SAST","score":7,"reason":"SAST tool is not run on all commits -- score normalized to 7","details":["Warn: 23 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#sast"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#license"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":8,"reason":"25 out of 30 merged PRs checked by a CI test -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 14 contributing companies or organizations","details":["Info: found contributions from: ServiceComb, alc-beijing, apache, apachecn, bytedance, bytedance seed, bytedance.inc, fusesource, ops4j, r3kapig, react-component, volcengine, vuejs, web-infra-dev"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#contributors"}},{"name":"Vulnerabilities","score":0,"reason":"110 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-rwvc-j5jr-mgvh","Warn: Project is vulnerable to: GHSA-2g4f-4pwh-qvx6","Warn: Project is vulnerable to: GHSA-33vc-wfww-vjfv","Warn: Project is vulnerable to: GHSA-3ppc-4f35-3m26","Warn: Project is vulnerable to: GHSA-3h52-269p-cp9r","Warn: Project is vulnerable to: GHSA-4342-x723-ch2f","Warn: Project is vulnerable to: GHSA-5f7q-jpqc-wp7h","Warn: Project is vulnerable to: GHSA-9g9p-9gw9-jx7f","Warn: Project is vulnerable to: GHSA-f82v-jwr5-mffw","Warn: Project is vulnerable to: GHSA-g5qg-72qw-gw5v","Warn: Project is vulnerable to: GHSA-h25m-26qc-wcjf","Warn: Project is vulnerable to: GHSA-mwv6-3258-q52c","Warn: Project is vulnerable to: GHSA-w37m-7fhw-fmv9","Warn: Project is vulnerable to: GHSA-xv57-4mr9-wg8v","Warn: Project is vulnerable to: GHSA-36hm-qxxp-pg3m","Warn: Project is vulnerable to: GHSA-345p-7cg4-v4c7","Warn: Project is vulnerable to: GHSA-8r9q-7v3j-jr4g","Warn: Project is vulnerable to: GHSA-mh29-5h37-fv8m","Warn: Project is vulnerable to: GHSA-xxjr-mmjv-4gpg","Warn: Project is vulnerable to: GHSA-6rw7-vpxm-498p","Warn: Project is vulnerable to: GHSA-w7fw-mjwx-w883","Warn: Project is vulnerable to: GHSA-7h2j-956f-4vf2","Warn: Project is vulnerable to: GHSA-w48q-cv73-mx4w","Warn: Project is vulnerable to: GHSA-2w69-qvjg-hvjx","Warn: Project is vulnerable to: GHSA-6475-r3vj-m8vf","Warn: Project is vulnerable to: GHSA-43fc-jf86-j433","Warn: Project is vulnerable to: GHSA-4hjh-wcwx-xvwj","Warn: Project is vulnerable to: GHSA-wqch-xfxh-vrr4","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-73rr-hh4g-fpgx","Warn: Project is vulnerable to: GHSA-vhxf-7vqr-mrjg","Warn: Project is vulnerable to: GHSA-67mh-4wv8-2f99","Warn: Project is vulnerable to: GHSA-jmr7-xgp7-cmfj","Warn: Project is vulnerable to: GHSA-m7jm-9gc2-mpf2","Warn: Project is vulnerable to: GHSA-37qj-frw5-hhjh","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-5j98-mcp5-4vw2","Warn: Project is vulnerable to: GHSA-pfrx-2q88-qq97","Warn: Project is vulnerable to: GHSA-3vhc-576x-3qv4","Warn: Project is vulnerable to: GHSA-6wqw-2p9w-4vw4","Warn: Project is vulnerable to: GHSA-92vj-g62v-jqhh","Warn: Project is vulnerable to: GHSA-9r54-q6cx-xmh5","Warn: Project is vulnerable to: GHSA-f67f-6cw9-8mq4","Warn: Project is vulnerable to: GHSA-gq3j-xvxp-8hrf","Warn: Project is vulnerable to: GHSA-m732-5p4w-x69g","Warn: Project is vulnerable to: GHSA-q7jf-gf43-6x6p","Warn: Project is vulnerable to: GHSA-r354-f388-2fhh","Warn: Project is vulnerable to: GHSA-w332-q679-j88p","Warn: Project is vulnerable to: GHSA-rc47-6667-2j5j","Warn: Project is vulnerable to: GHSA-869p-cjfg-cm3x","Warn: Project is vulnerable to: GHSA-4fh9-h7wg-q85m","Warn: Project is vulnerable to: GHSA-7rqq-prvp-x9jh","Warn: Project is vulnerable to: GHSA-rx8g-88g5-qh64","Warn: Project is vulnerable to: GHSA-9jcx-v3wj-wh4m","Warn: Project is vulnerable to: GHSA-44c6-4v22-4mhx","Warn: Project is vulnerable to: GHSA-4x5v-gmq8-25ch","Warn: Project is vulnerable to: GHSA-vj76-c3g6-qr5v","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-93m4-6634-74q7","Warn: Project is vulnerable to: GHSA-g4jq-h2w9-997c","Warn: Project is vulnerable to: GHSA-jqfw-vq24-v9c3","Warn: Project is vulnerable to: GHSA-38r7-794h-5758","Warn: Project is vulnerable to: GHSA-8fgc-7cc6-rx7x","Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-84jw-g43v-8gjm","Warn: Project is vulnerable to: GHSA-jr5f-v2jv-69x6","Warn: Project is vulnerable to: GHSA-378v-28hj-76wf","Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-848j-6mx2-7j84","Warn: Project is vulnerable to: GHSA-4www-5p9h-95mh","Warn: Project is vulnerable to: GHSA-9gqv-wp59-fq42","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w","Warn: Project is vulnerable to: GHSA-h7cp-r72f-jxh6","Warn: Project is vulnerable to: GHSA-v62p-rq8g-8h59","Warn: Project is vulnerable to: GHSA-7mvr-c777-76hp","Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j","Warn: Project is vulnerable to: GHSA-x7hr-w5r2-h6wg","Warn: Project is vulnerable to: GHSA-95m3-7q98-8xr5","Warn: Project is vulnerable to: GHSA-g3ch-rx76-35fx","Warn: Project is vulnerable to: GHSA-r399-636x-v7f6","Warn: Project is vulnerable to: GHSA-3p6v-hrg8-8qj7","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-vmqv-hx8q-j7mg","Warn: Project is vulnerable to: GHSA-37j7-fg3j-429f","Warn: Project is vulnerable to: GHSA-38c4-r59v-3vqw","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-554w-wpv2-vw27","Warn: Project is vulnerable to: GHSA-5gfm-wpxj-wjgq","Warn: Project is vulnerable to: GHSA-65ch-62r8-g69g","Warn: Project is vulnerable to: GHSA-3cgp-3xvw-98x8","Warn: Project is vulnerable to: GHSA-8v8x-cx79-35w7","Warn: Project is vulnerable to: GHSA-cpj6-fhp6-mr6j","Warn: Project is vulnerable to: GHSA-h5cw-625j-3rxh","Warn: Project is vulnerable to: GHSA-34x7-hfp2-rc4v","Warn: Project is vulnerable to: GHSA-83g3-92jg-28cx","Warn: Project is vulnerable to: GHSA-8qq5-rm4j-mr97","Warn: Project is vulnerable to: GHSA-r6q2-hw4h-h46w","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-cxrh-j4jr-qwg3","Warn: Project is vulnerable to: GHSA-g9mf-h72j-4rw9","Warn: Project is vulnerable to: GHSA-356w-63v5-8wf4","Warn: Project is vulnerable to: GHSA-4r4m-qw57-chr8","Warn: Project is vulnerable to: GHSA-859w-5945-r5v3","Warn: Project is vulnerable to: GHSA-x574-m823-4x7w","Warn: Project is vulnerable to: GHSA-xcj6-pq6g-qj4x"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#vulnerabilities"}}]}
