{"date":"2026-08-18T07:30:22Z","repo":{"name":"github.com/kaito-project/aikit","commit":"73d60c2d2ffd3919b44a9f855cc8291d73c180c9"},"scorecard":{"version":"v5.5.0","commit":"c395761df6afe1a69e476bc60a013a94bcbc153f"},"score":6.2,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/12 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yaml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:32","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:31","Info: jobLevel 'models' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:502","Info: jobLevel 'packages' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:503","Info: jobLevel 'pages' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:504","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:505","Info: jobLevel 'actions' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:494","Info: jobLevel 'discussions' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:499","Info: jobLevel 'repository-projects' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:506","Info: jobLevel 'checks' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:496","Info: jobLevel 'deployments' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:498","Info: jobLevel 'issues' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:501","Info: jobLevel 'security-events' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:507","Info: jobLevel 'attestations' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:495","Info: jobLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:497","Info: jobLevel 'statuses' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:508","Info: jobLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:3857","Info: jobLevel permissions set to 'read-all': .github/workflows/daily-test-improver.lock.yml:4568","Info: jobLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:4800","Info: jobLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:4980","Info: jobLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:102","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/daily-test-improver.lock.yml:4106","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/dependabot.yaml:10","Info: jobLevel 'contents' permission set to 'read': .github/workflows/issue-triage.lock.yml:812","Info: jobLevel permissions set to 'read-all': .github/workflows/issue-triage.lock.yml:1048","Info: jobLevel permissions set to 'read-all': .github/workflows/issue-triage.lock.yml:4222","Info: jobLevel 'contents' permission set to 'read': .github/workflows/issue-triage.lock.yml:4452","Info: jobLevel 'contents' permission set to 'read': .github/workflows/issue-triage.lock.yml:4705","Info: jobLevel 'contents' permission set to 'read': .github/workflows/issue-triage.lock.yml:421","Info: jobLevel 'contents' permission set to 'read': .github/workflows/patch-models.yaml:14","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pre-release.yaml:15","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-base.yaml:14","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-hf-cli.yaml:14","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-pr.yaml:18","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-runners.yaml:15","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yaml:14","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards.yml:30","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards.yml:29","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/update-models.yaml:28","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:24","Info: topLevel 'security-events' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:63","Info: topLevel 'statuses' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:64","Info: topLevel 'deployments' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:54","Info: topLevel 'actions' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:50","Info: topLevel 'checks' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:52","Info: topLevel 'issues' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:57","Info: topLevel 'models' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:58","Info: topLevel 'packages' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:59","Info: topLevel 'pages' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:60","Info: topLevel 'attestations' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:51","Info: topLevel 'contents' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:53","Info: topLevel 'discussions' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:55","Info: topLevel 'pull-requests' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:61","Info: topLevel 'repository-projects' permission set to 'read': .github/workflows/daily-test-improver.lock.yml:62","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependabot.yaml:5","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy-docs.yaml:17","Info: topLevel permissions set to 'read-all': .github/workflows/issue-triage.lock.yml:44","Info: topLevel permissions set to 'read-all': .github/workflows/lint.yaml:13","Warn: topLevel 'packages' permission set to 'write': .github/workflows/mirror-localai.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/mirror-localai.yml:12","Info: topLevel 'actions' permission set to 'read': .github/workflows/mirror-localai.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/patch-models.yaml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/pre-release.yaml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-base.yaml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-hf-cli.yaml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-pr.yaml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-runners.yaml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yaml:9","Info: topLevel permissions set to 'read-all': .github/workflows/scorecards.yml:18","Info: topLevel permissions set to 'read-all': .github/workflows/test-docker-args.yaml:20","Info: topLevel permissions set to 'read-all': .github/workflows/test-docker-gpu.yaml:19","Info: topLevel permissions set to 'read-all': .github/workflows/test-docker-runner-gpu.yaml:17","Info: topLevel permissions set to 'read-all': .github/workflows/test-docker-runner.yaml:14","Info: topLevel permissions set to 'read-all': .github/workflows/test-docker.yaml:21","Info: topLevel permissions set to 'read-all': .github/workflows/test-finetune.yaml:24","Info: topLevel permissions set to 'read-all': .github/workflows/test-helm.yaml:24","Info: topLevel permissions set to 'read-all': .github/workflows/test-kubernetes.yaml:20","Info: topLevel permissions set to 'read-all': .github/workflows/test-local-context.yaml:18","Info: topLevel permissions set to 'read-all': .github/workflows/test-oci-platforms.yaml:18","Info: topLevel permissions set to 'read-all': .github/workflows/test-packager-inference.yaml:14","Info: topLevel permissions set to 'read-all': .github/workflows/test-packager.yaml:14","Info: topLevel permissions set to 'read-all': .github/workflows/test-podman-applesilicon.yaml:6","Info: topLevel permissions set to 'read-all': .github/workflows/unit-test.yaml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/update-models.yaml:23"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Warn: containerImage not pinned by hash: Dockerfile.hf-cli:1: pin your Docker image by updating python:3.14-slim to python:3.14-slim@sha256:ce40764625a4ff50df3548277632e7f96c4e77fe75fa848aae9885476e7df5a4","Warn: pipCommand not pinned by hash: Dockerfile.hf-cli:2","Warn: npmCommand not pinned by hash: .github/workflows/daily-test-improver.lock.yml:598","Warn: npmCommand not pinned by hash: .github/workflows/daily-test-improver.lock.yml:4724","Warn: npmCommand not pinned by hash: .github/workflows/issue-triage.lock.yml:1122","Warn: npmCommand not pinned by hash: .github/workflows/issue-triage.lock.yml:4376","Info: 126 out of 126 GitHub-owned GitHubAction dependencies pinned","Info:  83 out of  83 third-party GitHubAction dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned","Info:   0 out of   4 npmCommand dependencies pinned","Info:   3 out of   4 containerImage dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":8,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 20 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"}},{"name":"Vulnerabilities","score":0,"reason":"62 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: https://osv.dev/GO-2026-5932","Warn: Project is vulnerable to: https://osv.dev/GHSA-4x5r-pxfx-6jf8","Warn: Project is vulnerable to: https://osv.dev/GHSA-fv7c-fp4j-7gwp","Warn: Project is vulnerable to: https://osv.dev/GHSA-2g4f-4pwh-qvx6","Warn: Project is vulnerable to: https://osv.dev/GHSA-v422-hmwv-36x6","Warn: Project is vulnerable to: https://osv.dev/GHSA-3jxr-9vmj-r5cp","Warn: Project is vulnerable to: https://osv.dev/GHSA-f886-m6hf-6m8v","Warn: Project is vulnerable to: https://osv.dev/GHSA-mh99-v99m-4gvg","Warn: Project is vulnerable to: https://osv.dev/GHSA-rgw5-rvv9-x895","Warn: Project is vulnerable to: https://osv.dev/GHSA-r4q5-vmmm-2653","Warn: Project is vulnerable to: https://osv.dev/GHSA-64mm-vxmg-q3vj","Warn: Project is vulnerable to: https://osv.dev/GHSA-5p2g-fcmc-qvqq","Warn: Project is vulnerable to: https://osv.dev/GHSA-w3rx-r6r6-pgpr","Warn: Project is vulnerable to: https://osv.dev/GHSA-q7cg-457f-vx79","Warn: Project is vulnerable to: https://osv.dev/GHSA-52cp-r559-cp3m","Warn: Project is vulnerable to: https://osv.dev/GHSA-5p4m-2wfm-xmqj","Warn: Project is vulnerable to: https://osv.dev/GHSA-h67p-54hq-rp68","Warn: Project is vulnerable to: https://osv.dev/GHSA-mh29-5h37-fv8m","Warn: Project is vulnerable to: https://osv.dev/GHSA-c27g-q93r-2cwf","Warn: Project is vulnerable to: https://osv.dev/GHSA-v6wh-96g9-6wx3","Warn: Project is vulnerable to: https://osv.dev/GHSA-f23m-r3pf-42rh","Warn: Project is vulnerable to: https://osv.dev/GHSA-r5fr-rjxr-66jc","Warn: Project is vulnerable to: https://osv.dev/GHSA-4fh9-h7wg-q85m","Warn: Project is vulnerable to: https://osv.dev/GHSA-23c5-xmqv-rm74","Warn: Project is vulnerable to: https://osv.dev/GHSA-3ppc-4f35-3m26","Warn: Project is vulnerable to: https://osv.dev/GHSA-7r86-cg39-jmmj","Warn: Project is vulnerable to: https://osv.dev/GHSA-28wg-ghj8-5hjv","Warn: Project is vulnerable to: https://osv.dev/GHSA-2v37-7h3g-55p8","Warn: Project is vulnerable to: https://osv.dev/GHSA-2328-f5f3-gj25","Warn: Project is vulnerable to: https://osv.dev/GHSA-554w-wpv2-vw27","Warn: Project is vulnerable to: https://osv.dev/GHSA-5gfm-wpxj-wjgq","Warn: Project is vulnerable to: https://osv.dev/GHSA-5m6q-g25r-mvwx","Warn: Project is vulnerable to: https://osv.dev/GHSA-65ch-62r8-g69g","Warn: Project is vulnerable to: https://osv.dev/GHSA-ppp5-5v6c-4jwp","Warn: Project is vulnerable to: https://osv.dev/GHSA-q67f-28xg-22rw","Warn: Project is vulnerable to: https://osv.dev/GHSA-3v7f-55p6-f55p","Warn: Project is vulnerable to: https://osv.dev/GHSA-c2c7-rcm5-vvqj","Warn: Project is vulnerable to: https://osv.dev/GHSA-6g55-p6wh-862q","Warn: Project is vulnerable to: https://osv.dev/GHSA-fxqj-rqcc-2cmp","Warn: Project is vulnerable to: https://osv.dev/GHSA-qx2v-qp2m-jg93","Warn: Project is vulnerable to: https://osv.dev/GHSA-r28c-9q8g-f849","Warn: Project is vulnerable to: https://osv.dev/GHSA-6rw7-vpxm-498p","Warn: Project is vulnerable to: https://osv.dev/GHSA-q8mj-m7cp-5q26","Warn: Project is vulnerable to: https://osv.dev/GHSA-w7fw-mjwx-w883","Warn: Project is vulnerable to: https://osv.dev/GHSA-5c6j-r48x-rmvq","Warn: Project is vulnerable to: https://osv.dev/GHSA-qj8w-gfj5-8c6v","Warn: Project is vulnerable to: https://osv.dev/GHSA-395f-4hp3-45gv","Warn: Project is vulnerable to: https://osv.dev/GHSA-w7jw-789q-3m8p","Warn: Project is vulnerable to: https://osv.dev/GHSA-2p49-hgcm-8545","Warn: Project is vulnerable to: https://osv.dev/GHSA-xpqw-6gx7-v673","Warn: Project is vulnerable to: https://osv.dev/GHSA-w5hq-g745-h8pq","Warn: Project is vulnerable to: https://osv.dev/GHSA-38r7-794h-5758","Warn: Project is vulnerable to: https://osv.dev/GHSA-8fgc-7cc6-rx7x","Warn: Project is vulnerable to: https://osv.dev/GHSA-79cf-xcqc-c78w","Warn: Project is vulnerable to: https://osv.dev/GHSA-f5vj-f2hx-8m93","Warn: Project is vulnerable to: https://osv.dev/GHSA-m28w-2pqf-7qgj","Warn: Project is vulnerable to: https://osv.dev/GHSA-mx8g-39q3-5c79","Warn: Project is vulnerable to: https://osv.dev/GHSA-mp7j-qc5w-4988","Warn: Project is vulnerable to: https://osv.dev/GHSA-xv26-6w52-cph6","Warn: Project is vulnerable to: https://osv.dev/GHSA-96hv-2xvq-fx4p","Warn: Project is vulnerable to: https://osv.dev/GHSA-58qx-3vcg-4xpx","Warn: Project is vulnerable to: https://osv.dev/GHSA-48c2-rrv3-qjmp"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/pre-release.yaml:13"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":3,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Info: 'branch protection settings apply to administrators' is required to merge on branch 'main'","Warn: 'stale review dismissal' is disabled on branch 'main'","Warn: branch 'main' does not require approvers","Warn: codeowners review is not required on branch 'main'","Warn: 'last push approval' is disabled on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"}},{"name":"Contributors","score":10,"reason":"project has 14 contributing companies or organizations","details":["Info: found contributions from: Azure, CatalystCode, MicrosoftCopilot, MicrosoftDocs, azure, deis, deislabs, eraser-dev, github, kaito-project, microsoft, open-policy-agent, project-copacetic, project-dalec"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"}},{"name":"CI-Tests","score":10,"reason":"14 out of 14 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"}}]}
