{"date":"2026-07-30T03:04:16Z","repo":{"name":"github.com/open-edge-platform/geti_v2","commit":"49f1528e37a312c767b00644c466803460c84ae1"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":7.8,"checks":[{"name":"Maintained","score":10,"reason":"27 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: RenovateBot: .github/renovate.json5:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/bdd-stylecheck.yml:19","Info: jobLevel 'contents' permission set to 'read': .github/workflows/builder-images.yml:35","Info: jobLevel 'contents' permission set to 'read': .github/workflows/builder-images.yml:59","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/builder-images.yml:60","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cleanup-old-packages.yml:68","Info: jobLevel 'contents' permission set to 'read': .github/workflows/collect-source.yml:59","Info: jobLevel 'contents' permission set to 'read': .github/workflows/component.yml:73","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/component.yml:74","Info: jobLevel 'contents' permission set to 'read': .github/workflows/label.yml:16","Info: jobLevel 'contents' permission set to 'read': .github/workflows/libs_test.yml:48","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main.yml:63","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main.yml:194","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/main.yml:209","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main.yml:208","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main.yml:228","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/main.yml:229","Info: jobLevel 'contents' permission set to 'read': .github/workflows/main.yml:244","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/main.yml:245","Info: jobLevel 'contents' permission set to 'read': .github/workflows/package-distribution.yaml:62","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/package-distribution.yaml:63","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/pr-security-scan.yaml:24","Info: jobLevel 'contents' permission set to 'read': .github/workflows/pr-security-scan.yaml:23","Info: jobLevel 'contents' permission set to 'read': .github/workflows/pr-security-scan.yaml:45","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/pr-security-scan.yaml:46","Info: jobLevel 'contents' permission set to 'read': .github/workflows/renovate.yml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/security-scan.yml:19","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/security-scan.yml:20","Info: jobLevel 'contents' permission set to 'read': .github/workflows/security-scan.yml:41","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/security-scan.yml:42","Info: jobLevel 'contents' permission set to 'read': .github/workflows/security-scan.yml:64","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/security-scan.yml:65","Info: jobLevel 'contents' permission set to 'read': .github/workflows/security-scan.yml:88","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:93","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:135","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:169","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:226","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:271","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/web-ui.yml:272","Info: jobLevel 'contents' permission set to 'read': .github/workflows/web-ui.yml:54","Info: found token with 'none' permissions: .github/workflows/bdd-stylecheck.yml:1","Info: found token with 'none' permissions: .github/workflows/builder-images.yml:1","Info: found token with 'none' permissions: .github/workflows/cleanup-old-packages.yml:1","Info: found token with 'none' permissions: .github/workflows/codeql.yml:1","Info: found token with 'none' permissions: .github/workflows/collect-source.yml:1","Info: found token with 'none' permissions: .github/workflows/component.yml:1","Info: found token with 'none' permissions: .github/workflows/label.yml:1","Info: found token with 'none' permissions: .github/workflows/libs_test.yml:1","Info: found token with 'none' permissions: .github/workflows/main.yml:1","Info: found token with 'none' permissions: .github/workflows/notify-teams.yml:1","Info: found token with 'none' permissions: .github/workflows/package-distribution.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-security-scan.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/renovate-config-validator.yml:9","Info: found token with 'none' permissions: .github/workflows/renovate.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecards.yml:1","Info: found token with 'none' permissions: .github/workflows/security-scan.yml:1","Info: found token with 'none' permissions: .github/workflows/sign-artifacts.yml:1","Info: found token with 'none' permissions: .github/workflows/web-ui.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Warn: npmCommand not pinned by hash: .github/workflows/bdd-stylecheck.yml:51","Warn: npmCommand not pinned by hash: .github/workflows/bdd-stylecheck.yml:52","Info:  49 out of  49 GitHub-owned GitHubAction dependencies pinned","Info:  40 out of  40 third-party GitHubAction dependencies pinned","Info:   6 out of   8 npmCommand dependencies pinned","Info:  88 out of  88 containerImage dependencies pinned","Info:   7 out of   7 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":5,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Info: codeowner review is required on branch 'main'","Info: 'last push approval' is required to merge on branch 'main'","Warn: 'up-to-date branches' is disabled on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Vulnerabilities","score":0,"reason":"124 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2026-4883 / GHSA-pxq6-2prw-chj9","Warn: Project is vulnerable to: GO-2026-5617 / GHSA-rg2x-37c3-w2rh","Warn: Project is vulnerable to: GO-2026-5668 / GHSA-vp62-88p7-qqf5","Warn: Project is vulnerable to: GO-2026-4887 / GHSA-x744-4wpc-v9h2","Warn: Project is vulnerable to: GO-2026-5746 / GHSA-x86f-5xw2-fm2r","Warn: Project is vulnerable to: GO-2026-5841","Warn: Project is vulnerable to: GO-2026-5158","Warn: Project is vulnerable to: GO-2026-4985 / GHSA-w8rr-5gcm-pp58","Warn: Project is vulnerable to: GO-2026-5014 / GHSA-45gg-vh54-h5m9","Warn: Project is vulnerable to: GO-2026-5021 / GHSA-5cgq-3rg8-m6cv","Warn: Project is vulnerable to: GO-2026-5015 / GHSA-78mq-xcr3-xm33","Warn: Project is vulnerable to: GO-2026-5019 / GHSA-89gr-r52h-f8rx","Warn: Project is vulnerable to: GO-2026-5033 / GHSA-9m57-25v3-79x9","Warn: Project is vulnerable to: GO-2026-5006 / GHSA-f5wc-c3c7-36mc","Warn: Project is vulnerable to: GO-2026-5005 / GHSA-jppx-rxg9-jmrx","Warn: Project is vulnerable to: GO-2026-5013 / GHSA-q4h4-gmj2-qvw2","Warn: Project is vulnerable to: GO-2026-5016 / GHSA-qpw4-5x99-6vjp","Warn: Project is vulnerable to: GO-2026-5020 / GHSA-rm3j-f69w-wqmq","Warn: Project is vulnerable to: GO-2026-5017 / GHSA-vgwf-h737-ff37","Warn: Project is vulnerable to: GO-2026-5018 / GHSA-w879-237q-wc7r","Warn: Project is vulnerable to: GO-2026-5023 / GHSA-x527-x647-q7gg","Warn: Project is vulnerable to: GO-2026-5932","Warn: Project is vulnerable to: GO-2026-5028 / GHSA-5cv4-jp36-h3mw","Warn: Project is vulnerable to: GO-2026-4918","Warn: Project is vulnerable to: GO-2026-5025","Warn: Project is vulnerable to: GO-2026-5026","Warn: Project is vulnerable to: GO-2026-5027","Warn: Project is vulnerable to: GO-2026-5029","Warn: Project is vulnerable to: GO-2026-5030","Warn: Project is vulnerable to: GO-2026-5942","Warn: Project is vulnerable to: GO-2026-5024","Warn: Project is vulnerable to: GO-2026-5970","Warn: Project is vulnerable to: GO-2026-6061 / GHSA-hrxh-6v49-42gf","Warn: Project is vulnerable to: GO-2026-4961","Warn: Project is vulnerable to: GO-2026-5061","Warn: Project is vulnerable to: GO-2026-5062","Warn: Project is vulnerable to: GO-2026-5066","Warn: Project is vulnerable to: PYSEC-2026-164 / GHSA-37w4-hwhx-4rc4","Warn: Project is vulnerable to: GHSA-gx64-gj6p-pc4c","Warn: Project is vulnerable to: GHSA-h5v5-8746-g7mm","Warn: Project is vulnerable to: PYSEC-2026-2537 / GHSA-mqcg-5x36-vfcg","Warn: Project is vulnerable to: GHSA-pppj-hq3g-57pj","Warn: Project is vulnerable to: PYSEC-2026-2538 / GHSA-rch3-82jr-f9w9","Warn: Project is vulnerable to: GHSA-vmhf-c436-hxj4","Warn: Project is vulnerable to: GHSA-whvh-wf3x-g77j","Warn: Project is vulnerable to: PYSEC-2026-2255 / GHSA-45hq-cxwh-f6vc","Warn: Project is vulnerable to: PYSEC-2026-2257 / GHSA-4x4j-2g7c-83w6","Warn: Project is vulnerable to: PYSEC-2026-2254 / GHSA-5x94-69rx-g8h2","Warn: Project is vulnerable to: PYSEC-2026-3493 / GHSA-62p4-gmf7-7g93","Warn: Project is vulnerable to: PYSEC-2026-3451 / GHSA-6r8x-57c9-28j4","Warn: Project is vulnerable to: PYSEC-2026-2253 / GHSA-8v84-f9pq-wr9x","Warn: Project is vulnerable to: PYSEC-2026-3453 / GHSA-9hw9-ch79-4vh6","Warn: Project is vulnerable to: PYSEC-2026-2249 / GHSA-cfh3-3jmp-rvhc","Warn: Project is vulnerable to: PYSEC-2026-3494 / GHSA-fj7v-r99m-22gq","Warn: Project is vulnerable to: PYSEC-2026-3495 / GHSA-jjj6-mw9f-p565","Warn: Project is vulnerable to: PYSEC-2026-2256 / GHSA-phj9-mv4w-65pm","Warn: Project is vulnerable to: PYSEC-2026-2252 / GHSA-pwv6-vv43-88gr","Warn: Project is vulnerable to: PYSEC-2026-2874 / GHSA-r73j-pqj5-w3x7","Warn: Project is vulnerable to: PYSEC-2026-3496 / GHSA-vjc4-5qp5-m44j","Warn: Project is vulnerable to: PYSEC-2026-2250 / GHSA-whj4-6x5x-4v2j","Warn: Project is vulnerable to: PYSEC-2026-165 / GHSA-wjx4-4jcj-g98j","Warn: Project is vulnerable to: PYSEC-2026-3454 / GHSA-xj96-63gp-2gmr","Warn: Project is vulnerable to: PYSEC-2026-2132","Warn: Project is vulnerable to: PYSEC-2026-1845 / GHSA-6w46-j5rx-g56g","Warn: Project is vulnerable to: GHSA-4x5r-pxfx-6jf8","Warn: Project is vulnerable to: GHSA-8988-4f7v-96qf","Warn: Project is vulnerable to: GHSA-xcpc-8h2w-3j85","Warn: Project is vulnerable to: GHSA-35jp-ww65-95wh","Warn: Project is vulnerable to: GHSA-42h9-826w-cgv3","Warn: Project is vulnerable to: GHSA-654m-c8p4-x5fp","Warn: Project is vulnerable to: GHSA-777c-7fjr-54vf","Warn: Project is vulnerable to: GHSA-7q8q-rj6j-mhjq","Warn: Project is vulnerable to: GHSA-898c-q2cr-xwhg","Warn: Project is vulnerable to: GHSA-f4gw-2p7v-4548","Warn: Project is vulnerable to: GHSA-gcfj-64vw-6mp9","Warn: Project is vulnerable to: GHSA-hcpx-6fm6-wx23","Warn: Project is vulnerable to: GHSA-hfxv-24rg-xrqf","Warn: Project is vulnerable to: GHSA-j5f8-grm9-p9fc","Warn: Project is vulnerable to: GHSA-jqh4-m9w3-8hp9","Warn: Project is vulnerable to: GHSA-mmx7-hfxf-jppx","Warn: Project is vulnerable to: GHSA-mwf2-3pr3-8698","Warn: Project is vulnerable to: GHSA-p92q-9vqr-4j8v","Warn: Project is vulnerable to: GHSA-pjwm-pj3p-43mv","Warn: Project is vulnerable to: GHSA-pmv8-rq9r-6j72","Warn: Project is vulnerable to: GHSA-xj6q-8x83-jv6g","Warn: Project is vulnerable to: GHSA-v422-hmwv-36x6","Warn: Project is vulnerable to: GHSA-3jxr-9vmj-r5cp","Warn: Project is vulnerable to: GHSA-mh99-v99m-4gvg","Warn: Project is vulnerable to: GHSA-76mc-f452-cxcm","Warn: Project is vulnerable to: GHSA-c2j3-45gr-mqc4","Warn: Project is vulnerable to: GHSA-cmwh-pvxp-8882","Warn: Project is vulnerable to: GHSA-gvmj-g25r-r7wr","Warn: Project is vulnerable to: GHSA-hpcv-96wg-7vj8","Warn: Project is vulnerable to: GHSA-r47g-fvhr-h676","Warn: Project is vulnerable to: GHSA-rp9w-3fw7-7cwq","Warn: Project is vulnerable to: GHSA-vxr8-fq34-vvx9","Warn: Project is vulnerable to: GHSA-x4vx-rjvf-j5p4","Warn: Project is vulnerable to: GHSA-r635-g3xr-vw7x","Warn: Project is vulnerable to: GHSA-4c8g-83qw-93j6","Warn: Project is vulnerable to: GHSA-v2hh-gcrm-f6hx","Warn: Project is vulnerable to: GHSA-hmw2-7cc7-3qxx","Warn: Project is vulnerable to: GHSA-64mm-vxmg-q3vj","Warn: Project is vulnerable to: GHSA-gcq2-9pq2-cxqm","Warn: Project is vulnerable to: GHSA-v56q-mh7h-f735","Warn: Project is vulnerable to: GHSA-xvcm-6775-5m9r","Warn: Project is vulnerable to: GHSA-52cp-r559-cp3m","Warn: Project is vulnerable to: GHSA-h67p-54hq-rp68","Warn: Project is vulnerable to: GHSA-r28c-9q8g-f849","Warn: Project is vulnerable to: GHSA-f38q-mgvj-vph7","Warn: Project is vulnerable to: GHSA-j3f2-48v5-ccww","Warn: Project is vulnerable to: GHSA-jggg-4jg4-v7c6","Warn: Project is vulnerable to: GHSA-wcpc-wj8m-hjx6","Warn: Project is vulnerable to: GHSA-q8mj-m7cp-5q26","Warn: Project is vulnerable to: GHSA-2j2x-hqr9-3h42","Warn: Project is vulnerable to: GHSA-337j-9hxr-rhxg","Warn: Project is vulnerable to: GHSA-wrjc-x8rr-h8h6","Warn: Project is vulnerable to: GHSA-jjmj-jmhj-qwj2","Warn: Project is vulnerable to: GHSA-395f-4hp3-45gv","Warn: Project is vulnerable to: GHSA-w7jw-789q-3m8p","Warn: Project is vulnerable to: GHSA-2p49-hgcm-8545","Warn: Project is vulnerable to: GHSA-96hv-2xvq-fx4p","Warn: Project is vulnerable to: GHSA-58qx-3vcg-4xpx"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 28 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 7 contributing companies or organizations","details":["Info: found contributions from: ProfessorFrancken, dzielne-misie, intel, intel corp, intel corporation, open-edge-platform, scriptcie"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}}]}
