{"date":"2026-09-21","repo":{"name":"github.com/kubesphere/kubekey","commit":"a896b8f591727f8f06b47155052e10cdfd672111"},"scorecard":{"version":"v5.5.1-0.20260908181711-f92023a3f778","commit":"f92023a3f77879f96e0c9c1305f289d755be4bb6"},"score":5.2,"checks":[{"name":"Code-Review","score":9,"reason":"Found 27/30 approved changesets -- score normalized to 9","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build-multiarch.yaml:1","Warn: no topLevel permission defined: .github/workflows/gen-repository-iso.yaml:1","Info: found token with 'none' permissions: .github/workflows/golangci-lint.yaml:1","Warn: no topLevel permission defined: .github/workflows/releaser.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v4.0.7 not signed: https://api.github.com/repos/kubesphere/kubekey/releases/383647023","Warn: release artifact v4.0.7-alpha.1 not signed: https://api.github.com/repos/kubesphere/kubekey/releases/374420650","Warn: release artifact v4.0.7-alpha.0 not signed: https://api.github.com/repos/kubesphere/kubekey/releases/373459810","Warn: release artifact v4.0.6 not signed: https://api.github.com/repos/kubesphere/kubekey/releases/370444005","Warn: release artifact iso-latest not signed: https://api.github.com/repos/kubesphere/kubekey/releases/276612433","Warn: release artifact v4.0.7 does not have provenance: https://api.github.com/repos/kubesphere/kubekey/releases/383647023","Warn: release artifact v4.0.7-alpha.1 does not have provenance: https://api.github.com/repos/kubesphere/kubekey/releases/374420650","Warn: release artifact v4.0.7-alpha.0 does not have provenance: https://api.github.com/repos/kubesphere/kubekey/releases/373459810","Warn: release artifact v4.0.6 does not have provenance: https://api.github.com/repos/kubesphere/kubekey/releases/370444005","Warn: release artifact iso-latest does not have provenance: https://api.github.com/repos/kubesphere/kubekey/releases/276612433"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'","Warn: branch protection not enabled for branch 'release-v3.1.0-rc.0'","Warn: branch protection not enabled for branch 'release-3.1'"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build-multiarch.yaml:9"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Info: Possibly incomplete results: error parsing shell code: \"for foo [in words]\" must be followed by \"do\": builtin/capkk/roles/init/init-os/templates/init-os.sh:0","Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: builtin/core/roles/etcd/install/templates/backup.sh:0","Info: Possibly incomplete results: error parsing shell code: \"for foo [in words]\" must be followed by \"do\": builtin/core/roles/native/init/templates/init-os.sh:0","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-multiarch.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/build-multiarch.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-multiarch.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/build-multiarch.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-multiarch.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/build-multiarch.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-multiarch.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/build-multiarch.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gen-repository-iso.yaml:212: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/gen-repository-iso.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/golangci-lint.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/releaser.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/releaser.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/releaser.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/releaser.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/releaser.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/releaser.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/releaser.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/releaser.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/releaser.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/kubesphere/kubekey/releaser.yaml/main?enable=pin","Warn: containerImage not pinned by hash: build/controller-manager/Dockerfile:3","Warn: containerImage not pinned by hash: build/controller-manager/Dockerfile:30: pin your Docker image by updating alpine:3.19.0 to alpine:3.19.0@sha256:51b67269f354137895d43f3b3d810bfacd3945438e94dc5ac55fdac340352f48","Warn: containerImage not pinned by hash: build/kk/Dockerfile:3","Warn: containerImage not pinned by hash: build/kk/Dockerfile:30: pin your Docker image by updating alpine:3.19.0 to alpine:3.19.0@sha256:51b67269f354137895d43f3b3d810bfacd3945438e94dc5ac55fdac340352f48","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.almalinux90:1: pin your Docker image by updating almalinux:9.0 to almalinux:9.0@sha256:a95a7766fd056b35f72f7b7f7301bcd46e40a6eecd9017e9c41cb4bf22ecb28b","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.centos7:1: pin your Docker image by updating centos:7 to centos:7@sha256:be65f488b7764ad3638f236b7b515b3678369a5124c47b8d32916d6487418ea4","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.centos8:1: pin your Docker image by updating centos:8 to centos:8@sha256:a27fd8080b517143cbbbab9dfb7c8571c40d67d534bbdee55bd6c473f432b177","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.debian10:1: pin your Docker image by updating debian:10 to debian:10@sha256:58ce6f1271ae1c8a2006ff7d3e54e9874d839f573d8009c20154ad0f2fb0a225","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.debian11:1: pin your Docker image by updating debian:11.6 to debian:11.6@sha256:0a78ed641b76252739e28ebbbe8cdbd80dc367fba4502565ca839e5803cfd86e","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.kylinv10sp1:1: pin your Docker image by updating hxsoong/kylin:v10-sp1 to hxsoong/kylin:v10-sp1@sha256:93ba61a4785720106a5d02306042c06f4465bfcd5f577246b0a4b8d5a699d697","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.kylinv10sp2:1: pin your Docker image by updating hxsoong/kylin:v10-sp2 to hxsoong/kylin:v10-sp2@sha256:a22d6cb8b9e407e8cbcaf1c20517b9807d79ec5015ecb59ca492fb84fe298ed5","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.kylinv10sp3:1: pin your Docker image by updating hxsoong/kylin:v10-sp3 to hxsoong/kylin:v10-sp3@sha256:b49a72ecf3213e00c5316935a51594c11d43fbccb13ad0cecf939f0f1c1101a3","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.kylinv10sp3-2403:1: pin your Docker image by updating hxsoong/kylin:v10-sp3 to hxsoong/kylin:v10-sp3@sha256:b49a72ecf3213e00c5316935a51594c11d43fbccb13ad0cecf939f0f1c1101a3","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.ubuntu1604:1: pin your Docker image by updating ubuntu:16.04 to ubuntu:16.04@sha256:1f1a2d56de1d604801a9671f301190704c25d604a416f59e03c04f5c6ffee0d6","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.ubuntu1804:1: pin your Docker image by updating ubuntu:18.04 to ubuntu:18.04@sha256:152dc042452c496007f07ca9127571cb9c29697f42acbfad72324b2bb2e43c98","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.ubuntu2004:1: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8feb4d8ca5354def3d8fce243717141ce31e2c428701f6682bd2fafe15388214","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.ubuntu2204:1: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:b8b6ee6aa931ecd9d0d952abc34dc0e5f7c6a30c6bb71b079fe399fde0329c02","Warn: containerImage not pinned by hash: hack/gen-repository-iso/dockerfile.ubuntu2404:1: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:008173c23f95b170204355c12626cb5a965d779a7e1283b09e9cffbb1bf33ca3","Info:   0 out of  18 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  10 third-party GitHubAction dependencies pinned","Info:   0 out of  18 containerImage dependencies pinned","Info:   2 out of   2 goCommand dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (27) are checked with a SAST tool"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/f92023a3f77879f96e0c9c1305f289d755be4bb6/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}}]}
