{"date":"2026-08-17","repo":{"name":"github.com/kaldi-asr/kaldi","commit":"e02e35f0254bb033fab73d1df99fc34123e31d56"},"scorecard":{"version":"v5.5.1-0.20260815060127-d1fab88f5463","commit":"d1fab88f54636ff366076edfc5c239f97b3c8e66"},"score":3.9,"checks":[{"name":"Code-Review","score":4,"reason":"Found 8/17 approved changesets -- score normalized to 4","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/c-cpp.yml:1","Warn: no topLevel permission defined: .github/workflows/docker-images.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: COPYING:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: windows/NewGuidCmd.exe:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/docker-images.yml:48"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/ami/s5/RESULTS_ihm:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/ami/s5/RESULTS_mdm:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/ami/s5/RESULTS_sdm:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/babel/s5b/run-4-anydecode.sh:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/babel/s5c/run-4-anydecode.sh:0","Info: Possibly incomplete results: error parsing shell code: \"fi\" can only be used to end an if: egs/babel/s5d/local/make_L_align.sh:0","Info: Possibly incomplete results: error parsing shell code: $ cannot be followed by a word: egs/babel/s5d/local/nist_eval/filter_data.sh:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/babel/s5d/run-4-anydecode.sh:0","Info: Possibly incomplete results: error parsing shell code: for statement must end with \"done\": egs/gale_mandarin/s5/local/nnet/run_dnn.sh:0","Info: Possibly incomplete results: error parsing shell code: reached EOF without matching { with }: egs/gp/s1/run.sh:0","Info: Possibly incomplete results: error parsing shell code: \"do\" can only be used in a loop: egs/gp/s5/RESULTS:0","Info: Possibly incomplete results: error parsing shell code: \"done\" can only be used to end a loop: egs/libri_css/s5_mono/local/score_reco_diarized.sh:0","Info: Possibly incomplete results: error parsing shell code: if statement must end with \"fi\": egs/librispeech/s5/fairseq_ltlm/recipes/run.sh:0","Info: Possibly incomplete results: error parsing shell code: if statement must end with \"fi\": egs/librispeech/s5/fairseq_ltlm/recipes/tuning/train_small_ltlm.lr1e-4.ddp2.sh:0","Info: Possibly incomplete results: error parsing shell code: ) can only be used to close a subshell: egs/librispeech/s5/local/online/run_nnet2_ms_disc.sh:0","Info: Possibly incomplete results: error parsing shell code: \"fi\" can only be used to end an if: egs/multi_en/s5/local/chain/run_blstm_6h.sh:0","Info: Possibly incomplete results: error parsing shell code: \"do\" can only be used in a loop: egs/swbd/s5c/local/chain/tuning/run_tdnn_2e.sh:0","Info: Possibly incomplete results: error parsing shell code: \"foo(\" must be followed by ): egs/swbd/s5c/local/chain/tuning/run_tdnn_2r.sh:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/timit/s5/RESULTS:0","Info: Possibly incomplete results: error parsing shell code: statements must be separated by &, ; or a newline: egs/wsj/s5/RESULTS:0","Info: Possibly incomplete results: error parsing shell code: reached ` without closing quote \": egs/wsj/s5/steps/tandem/mk_aslf_lda_mllt.sh:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: egs/zeroth_korean/s5/RESULTS:0","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/c-cpp.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/c-cpp.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/c-cpp.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/c-cpp.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/c-cpp.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/c-cpp.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/kaldi-asr/kaldi/docker-images.yml/master?enable=pin","Warn: containerImage not pinned by hash: .gitpod.Dockerfile:1: pin your Docker image by updating gitpod/workspace-full to gitpod/workspace-full@sha256:ee2f624ca47c33e50c6de33023c37f945ad1304efa869e9410adcf3b2319eb1b","Warn: containerImage not pinned by hash: .gitpod.Dockerfile:12: pin your Docker image by updating gitpod/workspace-full to gitpod/workspace-full@sha256:ee2f624ca47c33e50c6de33023c37f945ad1304efa869e9410adcf3b2319eb1b","Warn: containerImage not pinned by hash: docker/debian12-cpu-mkl/Dockerfile:1: pin your Docker image by updating debian:12 to debian:12@sha256:813017f3d62be4b5891a7acca6a01bdcd4b8513daa81b1ab99d3a50385b26931","Warn: containerImage not pinned by hash: docker/debian12-cpu/Dockerfile:1: pin your Docker image by updating debian:12 to debian:12@sha256:813017f3d62be4b5891a7acca6a01bdcd4b8513daa81b1ab99d3a50385b26931","Warn: containerImage not pinned by hash: docker/devcontainer/.devcontainer/Dockerfile:5","Warn: containerImage not pinned by hash: docker/ubuntu20.04-cuda11/Dockerfile:1: pin your Docker image by updating nvidia/cuda:11.8.0-cudnn8-devel-ubuntu20.04 to nvidia/cuda:11.8.0-cudnn8-devel-ubuntu20.04@sha256:28cb396884380adc15a4bda23e9654610cbc4e20a3292d7e7679a717db5f90d2","Warn: containerImage not pinned by hash: docker/ubuntu22.04-cuda12/Dockerfile:1: pin your Docker image by updating nvidia/cuda:12.6.1-cudnn-devel-ubuntu22.04 to nvidia/cuda:12.6.1-cudnn-devel-ubuntu22.04@sha256:bd579cc2f93e39d49a95853de794734e2682c536eeb498d3f7d6fcba741d83c9","Warn: pipCommand not pinned by hash: egs/callhome_diarization/v1/diarization/vb_hmm_xvector.sh:67","Warn: pipCommand not pinned by hash: egs/callhome_diarization/v1/diarization/vb_hmm_xvector.sh:68","Warn: pipCommand not pinned by hash: egs/chime6/s5_track2/local/diarize.sh:109","Warn: pipCommand not pinned by hash: egs/chime6/s5_track2/local/install_dscore.sh:5","Warn: pipCommand not pinned by hash: egs/chime6/s5_track2/local/install_dscore.sh:6","Warn: pipCommand not pinned by hash: egs/chime6/s5_track2/local/install_dscore.sh:7","Warn: pipCommand not pinned by hash: egs/chime6/s5_track2/local/install_dscore.sh:8","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/diarize.sh:109","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/diarize_vb.sh:134","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/install_dscore.sh:5","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/install_dscore.sh:6","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/install_dscore.sh:7","Warn: pipCommand not pinned by hash: egs/chime6/s5b_track2/local/install_dscore.sh:8","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/diarize.sh:109","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/diarize_sc.sh:108","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/install_dscore.sh:5","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/install_dscore.sh:6","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/install_dscore.sh:7","Warn: pipCommand not pinned by hash: egs/chime6/s5c_track2/local/install_dscore.sh:8","Warn: pipCommand not pinned by hash: egs/hub4_english/s5/run.sh:70","Warn: pipCommand not pinned by hash: egs/libri_css/s5_mono/local/dscore.sh:32","Warn: pipCommand not pinned by hash: egs/librispeech/s5/fairseq_ltlm/setup.sh:20","Warn: pipCommand not pinned by hash: egs/librispeech/s5/fairseq_ltlm/setup.sh:32","Warn: pipCommand not pinned by hash: egs/nsc/s5/local/nsc_data_prep.sh:12","Warn: pipCommand not pinned by hash: egs/nsc/s5/local/nsc_data_prep.sh:13","Warn: pipCommand not pinned by hash: egs/wsj/s5/steps/overlap/detect_overlaps_pyannote.sh:38","Warn: pipCommand not pinned by hash: tools/extras/install_kaldi_io.sh:6","Warn: pipCommand not pinned by hash: tools/extras/install_tensorflow_py.sh:13","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  11 third-party GitHubAction dependencies pinned","Info:   0 out of   7 containerImage dependencies pinned","Info:   0 out of  28 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}}]}
