{"date":"2026-09-18T22:43:50Z","repo":{"name":"github.com/traceroot-ai/traceroot","commit":"3405b16fe5774443df5fbb52af9581652cec16cf"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":7.8,"checks":[{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool","short":"Determines if the project uses a dependency update tool."}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-tools.yml:41","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecard.yml:20","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/announce-release-discord.yml:30","Info: topLevel 'contents' permission set to 'read': .github/workflows/build-test.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-images.yml:26","Info: topLevel 'contents' permission set to 'read': .github/workflows/lint.yml:4","Info: topLevel 'contents' permission set to 'read': .github/workflows/publish-tools.yml:17","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:15","Info: no jobLevel write permissions found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build-test.yml:70"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Vulnerabilities","score":0,"reason":"18 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2026-2976 / GHSA-2jrp-274c-jhv3","Warn: Project is vulnerable to: PYSEC-2026-2270 / GHSA-mf9w-mj56-hr94","Warn: Project is vulnerable to: PYSEC-2026-2333 / GHSA-82m5-3pcp-hccq","Warn: Project is vulnerable to: PYSEC-2026-2555 / GHSA-3644-q5cj-c5c7","Warn: Project is vulnerable to: PYSEC-2026-2192 / PYSEC-2026-2556 / GHSA-gr75-jv2w-4656","Warn: Project is vulnerable to: PYSEC-2026-1318 / GHSA-vvw2-h478-xwr3","Warn: Project is vulnerable to: PYSEC-2026-83 / GHSA-g48c-2wqr-h844","Warn: Project is vulnerable to: PYSEC-2026-2194","Warn: Project is vulnerable to: PYSEC-2026-1559 / GHSA-3wxx-q3gv-pvvv","Warn: Project is vulnerable to: PYSEC-2026-1560 / GHSA-488g-hw5f-x29p","Warn: Project is vulnerable to: PYSEC-2026-1561 / GHSA-7753-xrfw-ch36","Warn: Project is vulnerable to: PYSEC-2026-1562 / GHSA-cr7q-2w66-hjcm","Warn: Project is vulnerable to: PYSEC-2026-395 / GHSA-fxc2-8m62-m85x","Warn: Project is vulnerable to: PYSEC-2026-1563 / GHSA-j3wr-m6xh-64hg","Warn: Project is vulnerable to: PYSEC-2026-396 / GHSA-r6gp-rff2-p3hf","Warn: Project is vulnerable to: PYSEC-2026-397 / GHSA-wvpx-g427-q9wc","Warn: Project is vulnerable to: GHSA-8988-4f7v-96qf","Warn: Project is vulnerable to: GHSA-45rx-2jwx-cxfr"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities","short":"Determines if the project has open, known unfixed vulnerabilities."}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (30) are checked with a SAST tool"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/build-test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-images.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-images.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/docker-images.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-tools.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/publish-tools.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-tools.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/publish-tools.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-tools.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/publish-tools.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-tools.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/publish-tools.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecard.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/scorecard.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/scorecard.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/scorecard.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecard.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/scorecard.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecard.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/scorecard.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:321: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:329: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:361: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:371: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:421: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:212: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:239: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:264: update your workflow using https://app.stepsecurity.io/secureworkflow/traceroot-ai/traceroot/test.yml/main?enable=pin","Warn: containerImage not pinned by hash: docker/Dockerfile.agent:2: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.agent:6","Warn: containerImage not pinned by hash: docker/Dockerfile.agent:17","Warn: containerImage not pinned by hash: docker/Dockerfile.agent:47: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.billing:2: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.billing:6","Warn: containerImage not pinned by hash: docker/Dockerfile.billing:17","Warn: containerImage not pinned by hash: docker/Dockerfile.billing:48: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.detector:2: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.detector:6","Warn: containerImage not pinned by hash: docker/Dockerfile.detector:17","Warn: containerImage not pinned by hash: docker/Dockerfile.detector:48: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.migrate-clickhouse:3: pin your Docker image by updating golang:1.27-alpine to golang:1.27-alpine@sha256:4cb7ac979db5fcc41cae44b2227ba5ab8a51e8807f40d9ba4dee20a0ad960b5b","Warn: containerImage not pinned by hash: docker/Dockerfile.migrate-clickhouse:6: pin your Docker image by updating alpine:3.24 to alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6","Warn: containerImage not pinned by hash: docker/Dockerfile.migrate-postgres:4: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.migrate-postgres:8","Warn: containerImage not pinned by hash: docker/Dockerfile.migrate-postgres:16: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.rest:2: pin your Docker image by updating python:3.12-slim to python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea","Warn: containerImage not pinned by hash: docker/Dockerfile.rest:17: pin your Docker image by updating python:3.12-slim to python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea","Warn: containerImage not pinned by hash: docker/Dockerfile.web:2: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.web:7","Warn: containerImage not pinned by hash: docker/Dockerfile.web:24","Warn: containerImage not pinned by hash: docker/Dockerfile.web:76","Warn: containerImage not pinned by hash: docker/Dockerfile.web:84: pin your Docker image by updating node:24-alpine to node:24-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1","Warn: containerImage not pinned by hash: docker/Dockerfile.worker:2: pin your Docker image by updating python:3.12-slim to python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea","Warn: containerImage not pinned by hash: docker/Dockerfile.worker:12: pin your Docker image by updating python:3.12-slim to python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea","Warn: pipCommand not pinned by hash: docker/Dockerfile.rest:5","Warn: pipCommand not pinned by hash: docker/Dockerfile.worker:5","Warn: npmCommand not pinned by hash: .github/workflows/publish-tools.yml:64","Warn: pipCommand not pinned by hash: .github/workflows/test.yml:377","Info:   3 out of  29 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  20 third-party GitHubAction dependencies pinned","Info:   0 out of  26 containerImage dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned","Info:   0 out of   3 pipCommand dependencies pinned","Info:   0 out of   1 npmCommand dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"CI-Tests","score":10,"reason":"4 out of 4 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests","short":"Determines if the project runs tests before pull requests are merged."}},{"name":"Contributors","score":10,"reason":"project has 19 contributing companies or organizations","details":["Info: found contributions from: 3388N-Nova-Robotics, DeedDesk, aalto university, camel-ai, cyclops-community, indian institute of technology kharagpur, isoform, layer5io, layer5io @meshery, layer5labs, macexo, mcmaster university, meshery, meshery-extensions, pyg-team, service-mesh-performance, shark-auth, traceroot-ai, university of california santa cruz"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors","short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies)."}}]}
