{"date":"2026-09-21T10:37:47Z","repo":{"name":"github.com/tmatens/compose-lint","commit":"17ac87866346d3b1782704ffd0bdfe54c1b7e736"},"scorecard":{"version":"v5.5.0","commit":"c395761df6afe1a69e476bc60a013a94bcbc153f"},"score":8.3,"checks":[{"name":"Code-Review","score":0,"reason":"Found 1/28 approved changesets -- score normalized to 0","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: .github/SECURITY.md:1","Info: Found linked content: .github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: .github/SECURITY.md:1","Info: Found text in security policy: .github/SECURITY.md:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: RenovateBot: .github/renovate.json:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool","short":"Determines if the project uses a dependency update tool."}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 29 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/cflite-batch.yml:18","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cflite-batch.yml:13","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cflite-pr.yml:20","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:569","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:692","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:785","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:136","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:303","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:381","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:540","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:952","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1054","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1232","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1457","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:162","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:187","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:428","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:728","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:876","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1392","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:1421","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:43","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:243","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:621","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:821","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:908","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:40","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:36","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:69","Info: jobLevel 'contents' permission set to 'read': .github/workflows/dockerhub-description.yml:40","Info: jobLevel 'contents' permission set to 'read': .github/workflows/eol-watch.yml:36","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/forgejo-smoke-bump.yml:46","Info: jobLevel 'contents' permission set to 'read': .github/workflows/forgejo-smoke-bump.yml:132","Info: jobLevel 'contents' permission set to 'read': .github/workflows/forgejo-smoke.yml:45","Info: jobLevel 'contents' permission set to 'read': .github/workflows/forgejo-smoke.yml:65","Info: jobLevel 'contents' permission set to 'read': .github/workflows/marketplace-smoke.yml:222","Info: jobLevel 'contents' permission set to 'read': .github/workflows/marketplace-smoke.yml:307","Info: found token with 'none' permissions: .github/workflows/marketplace-smoke.yml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/marketplace-smoke.yml:106","Info: jobLevel 'contents' permission set to 'read': .github/workflows/marketplace-smoke.yml:144","Info: jobLevel 'contents' permission set to 'read': .github/workflows/os-smoke.yml:105","Info: jobLevel 'contents' permission set to 'read': .github/workflows/os-smoke.yml:178","Info: jobLevel 'contents' permission set to 'read': .github/workflows/os-smoke.yml:55","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/publish-channel.yml:47","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-channel.yml:126","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-channel.yml:149","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-channel.yml:195","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-channel.yml:31","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:63","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:538","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/publish.yml:731","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:804","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:53","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:411","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:434","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:579","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/publish.yml:884","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish.yml:251","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/publish.yml:1058","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-docker-smoke.yml:52","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-prep.yml:34","Info: jobLevel 'contents' permission set to 'read': .github/workflows/sarif-ingestion.yml:188","Info: jobLevel 'contents' permission set to 'read': .github/workflows/sarif-ingestion.yml:55","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:29","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:56","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scout-scan.yml:16","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scout-scan.yml:18","Info: jobLevel 'contents' permission set to 'read': .github/workflows/verify-tag.yml:39","Info: jobLevel 'contents' permission set to 'read': .github/workflows/vuln-report.yml:35","Info: found token with 'none' permissions: .github/workflows/cflite-batch.yml:1","Info: found token with 'none' permissions: .github/workflows/cflite-pr.yml:1","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: found token with 'none' permissions: .github/workflows/codeql.yml:1","Info: found token with 'none' permissions: .github/workflows/dockerhub-description.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/docs.yml:29","Info: found token with 'none' permissions: .github/workflows/eol-watch.yml:1","Info: found token with 'none' permissions: .github/workflows/forgejo-smoke-bump.yml:1","Info: found token with 'none' permissions: .github/workflows/forgejo-smoke.yml:1","Info: found token with 'none' permissions: .github/workflows/marketplace-smoke.yml:1","Info: found token with 'none' permissions: .github/workflows/os-smoke.yml:1","Info: found token with 'none' permissions: .github/workflows/publish-channel.yml:1","Info: found token with 'none' permissions: .github/workflows/publish.yml:1","Info: found token with 'none' permissions: .github/workflows/release-docker-smoke.yml:1","Info: found token with 'none' permissions: .github/workflows/release-prep.yml:1","Info: found token with 'none' permissions: .github/workflows/sarif-ingestion.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecard.yml:1","Info: found token with 'none' permissions: .github/workflows/scout-scan.yml:1","Info: found token with 'none' permissions: .github/workflows/verify-tag.yml:1","Info: found token with 'none' permissions: .github/workflows/vuln-report.yml:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/cflite-batch.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/cflite-batch.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1459: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1074: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1083: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1120: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1130: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1142: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1160: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1174: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1204: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/codeql.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/codeql.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerhub-description.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/dockerhub-description.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/eol-watch.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/eol-watch.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/forgejo-smoke-bump.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/forgejo-smoke-bump.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/forgejo-smoke.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/forgejo-smoke.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/marketplace-smoke.yml:310: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/marketplace-smoke.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/os-smoke.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/os-smoke.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-channel.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/publish-channel.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-channel.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/publish-channel.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:412: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/publish.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/publish.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:713: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/publish.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/sarif-ingestion.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/sarif-ingestion.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/sarif-ingestion.yml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/sarif-ingestion.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/scorecard.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/scorecard.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/scout-scan.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/scout-scan.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/vuln-report.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/tmatens/compose-lint/vuln-report.yml/main?enable=pin","Warn: pipCommand not pinned by hash: Dockerfile:36-46","Warn: pipCommand not pinned by hash: .clusterfuzzlite/build.sh:9","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:324","Warn: pipCommand not pinned by hash: .github/workflows/publish.yml:350","Info:  99 out of  99 GitHub-owned GitHubAction dependencies pinned","Info:  45 out of  72 third-party GitHubAction dependencies pinned","Info:   4 out of   4 containerImage dependencies pinned","Info:  35 out of  39 pipCommand dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities","short":"Determines if the project has open, known unfixed vulnerabilities."}},{"name":"CII-Best-Practices","score":7,"reason":"badge detected: Silver","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Signed-Releases","score":10,"reason":"5 out of the last 5 releases have a total of 10 signed artifacts.","details":["Info: signed release artifact: compose_lint-0.29.0-py3-none-any.whl.sigstore.json: https://github.com/tmatens/compose-lint/releases/tag/v0.29.0","Info: signed release artifact: compose_lint-0.28.0-py3-none-any.whl.sigstore.json: https://github.com/tmatens/compose-lint/releases/tag/v0.28.0","Info: signed release artifact: compose_lint-0.27.0-py3-none-any.whl.sigstore.json: https://github.com/tmatens/compose-lint/releases/tag/v0.27.0","Info: signed release artifact: compose_lint-0.26.0-py3-none-any.whl.sigstore.json: https://github.com/tmatens/compose-lint/releases/tag/v0.26.0","Info: signed release artifact: compose_lint-0.25.0-py3-none-any.whl.sigstore.json: https://github.com/tmatens/compose-lint/releases/tag/v0.25.0","Info: provenance for release artifact: compose_lint-0.29.0-py3-none-any.whl.intoto.jsonl: https://github.com/tmatens/compose-lint/releases/tag/v0.29.0","Info: provenance for release artifact: compose_lint-0.28.0-py3-none-any.whl.intoto.jsonl: https://github.com/tmatens/compose-lint/releases/tag/v0.28.0","Info: provenance for release artifact: compose_lint-0.27.0-py3-none-any.whl.intoto.jsonl: https://github.com/tmatens/compose-lint/releases/tag/v0.27.0","Info: provenance for release artifact: compose_lint-0.26.0-py3-none-any.whl.intoto.jsonl: https://github.com/tmatens/compose-lint/releases/tag/v0.26.0","Info: provenance for release artifact: compose_lint-0.25.0-py3-none-any.whl.intoto.jsonl: https://github.com/tmatens/compose-lint/releases/tag/v0.25.0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (30) are checked with a SAST tool"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: ClusterFuzzLite integration found","Info: PythonAtherisFuzzer integration found: fuzz/fuzz_compose.py:14"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yml:920"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Branch-Protection","score":3,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Info: 'branch protection settings apply to administrators' is required to merge on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: branch 'main' does not require approvers","Warn: codeowners review is not required on branch 'main'","Warn: 'last push approval' is disabled on branch 'main'","Warn: 'up-to-date branches' is disabled on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors","short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies)."}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests","short":"Determines if the project runs tests before pull requests are merged."}}]}
