:crossed_swords: A CodeQL automation tool to execute code scanning.
OpenSSF Scorecard report
4.7
Overall Score
Security Checks
no binaries found in the repo
Determines if the project has generated executable (binary) artifacts in the source repository.
3 different organizations found -- score normalized to 10
Determines if the project has a set of contributors from multiple organizations (e.g., companies).
Show details
no dangerous workflow patterns detected
Determines if the project's GitHub Action workflows avoid dangerous patterns.
license file detected
Determines if the project has defined a license.
Show details
14 commit(s) out of 30 and 3 issue activity out of 3 found in the last 90 days -- score normalized to 10
Determines if the project is "actively maintained".
no vulnerabilities detected
Determines if the project has open, known unfixed vulnerabilities.
dependency not pinned by hash detected -- score normalized to 9
Determines if the project has declared and pinned the dependencies of its build process.
Show details
3 out of 5 merged PRs checked by a CI test -- score normalized to 6
Determines if the project runs tests before pull requests are merged.
branch protection not enabled on development/release branches
Determines if the default and release branches are protected with GitHub's branch protection settings.
Show details
no badge detected
Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.
0 out of last 18 changesets reviewed before merge -- score normalized to 0
Determines if the project requires code review before pull requests (aka merge requests) are merged.
no update tool detected
Determines if the project uses a dependency update tool.
Show details
SAST tool is not run on all commits -- score normalized to 0
Determines if the project uses static code analysis.
Show details
security policy file not detected
Determines if the project has published a security policy.
non read-only tokens detected in GitHub workflows
Determines if the project's workflows follow the principle of least privilege.
Show details
no published package detected
Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.
Show details
- Source: https://github.com/codeql-agent-project/codeql-agent-cli
- JSON API: repos.ecosyste.ms
-
PURL:
pkg:github/codeql-agent-project/codeql-agent-cli
- Stars 12
- Forks 2
- Open issues 4
- License mit
- Language JavaScript
- Size 14.3 MB
- Created at over 3 years ago
- Updated at 3 months ago
- Pushed at over 2 years ago
- Last synced at 18 days ago
- Dependencies parsed at Pending