Ecosyste.ms: Repos
An open API service providing repository metadata for many open source software ecosystems.
GitHub / ossf / scorecard-action
Official GitHub Action for OpenSSF Scorecard.
JSON API: https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ossf%2Fscorecard-action
Stars: 227
Forks: 62
Open Issues: 25
License: apache-2.0
Language: Go
Repo Size: 6.44 MB
Dependencies:
3,081
Created: over 2 years ago
Updated: 1 day ago
Last pushed: 1 day ago
Last synced: about 14 hours ago
Commit Stats
Commits: 326
Authors: 18
Mean commits per author: 18.11
Development Distribution Score: 0.494
More commit stats: https://commits.ecosyste.ms/hosts/GitHub/repositories/ossf/scorecard-action
Topics: github, github-actions, security, supply-chain
Files
Dependencies
- actions/checkout 629c2de402a417ea7690ca6ce3f33229e27606a5 composite
- github/codeql-action/analyze 3e7e3b32d0fb8283594bb0a76cc60a00918b0969 composite
- github/codeql-action/autobuild 3e7e3b32d0fb8283594bb0a76cc60a00918b0969 composite
- github/codeql-action/init 3e7e3b32d0fb8283594bb0a76cc60a00918b0969 composite
- actions/checkout d0651293c4a5a52e711f25b41b05b2212f385d28 composite
- actions/dependency-review-action 310e0dd64f63b1d00101ecd3225d605a74261fb7 composite
- step-security/harden-runner 74b568e8591fbb3115c70f3436a0c6b0909a8504 composite
- actions/checkout ec3a7ce113134d7a93b817d10a8272cb61118579 composite
- actions/setup-go 84cbf8094393cdc5fe1fe1671ff2647332956b1a composite
- golangci/golangci-lint-action 537aa1903e5d359d0b27dbc19ddd22c5087f3fbc composite
- actions/cache c3f1317a9e7b1ef106c153ac8c0f00fed3ddbc0d composite
- actions/checkout ec3a7ce113134d7a93b817d10a8272cb61118579 composite
- actions/setup-go 84cbf8094393cdc5fe1fe1671ff2647332956b1a composite
- codecov/codecov-action 81cd2dc8148241f03f5839d295e000b8f761e378 composite
- docker://gcr.io/openssf/scorecard-action v2.0.0-beta.1 docker
- base latest build
- debian 11.4-slim@sha256 build
- golang@sha256 ea3d912d500b1ae0a691b2e53eb8a6345b579d42d7e6a64acca83d274b949740 build
- bitbucket.org/creachadair/shell v0.0.7
- cloud.google.com/go v0.100.2
- cloud.google.com/go/compute v1.6.1
- cloud.google.com/go/iam v0.3.0
- cloud.google.com/go/storage v1.22.1
- github.com/Azure/azure-sdk-for-go v65.0.0+incompatible
- github.com/Azure/go-autorest v14.2.0+incompatible
- github.com/Azure/go-autorest/autorest v0.11.27
- github.com/Azure/go-autorest/autorest/adal v0.9.18
- github.com/Azure/go-autorest/autorest/azure/auth v0.5.11
- github.com/Azure/go-autorest/autorest/azure/cli v0.4.5
- github.com/Azure/go-autorest/autorest/date v0.3.0
- github.com/Azure/go-autorest/logger v0.2.1
- github.com/Azure/go-autorest/tracing v0.6.0
- github.com/Microsoft/go-winio v0.5.2
- github.com/PaesslerAG/gval v1.0.0
- github.com/PaesslerAG/jsonpath v0.1.1
- github.com/ProtonMail/go-crypto v0.0.0-20210428141323-04723f9f07d7
- github.com/ThalesIgnite/crypto11 v1.2.5
- github.com/acomagu/bufpipe v1.0.3
- github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d
- github.com/aws/aws-sdk-go-v2 v1.16.5
- github.com/aws/aws-sdk-go-v2/config v1.15.10
- github.com/aws/aws-sdk-go-v2/credentials v1.12.5
- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.6
- github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.12
- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.6
- github.com/aws/aws-sdk-go-v2/internal/ini v1.3.13
- github.com/aws/aws-sdk-go-v2/service/ecr v1.15.0
- github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.12.0
- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.6
- github.com/aws/aws-sdk-go-v2/service/sso v1.11.8
- github.com/aws/aws-sdk-go-v2/service/sts v1.16.7
- github.com/aws/smithy-go v1.11.3
- github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20220228164355-396b2034c795
- github.com/benbjohnson/clock v1.1.0
- github.com/beorn7/perks v1.0.1
- github.com/bgentry/speakeasy v0.1.0
- github.com/blang/semver v3.5.1+incompatible
- github.com/blang/semver/v4 v4.0.0
- github.com/bombsimon/logrusr/v2 v2.0.1
- github.com/bradleyfalzon/ghinstallation/v2 v2.0.4
- github.com/caarlos0/env/v6 v6.9.3
- github.com/cenkalti/backoff/v4 v4.1.2
- github.com/census-instrumentation/opencensus-proto v0.3.0
- github.com/cespare/xxhash/v2 v2.1.2
- github.com/chrismellard/docker-credential-acr-env v0.0.0-20220119192733-fe33c00cee21
- github.com/cncf/udpa/go v0.0.0-20210930031921-04548b0d99d4
- github.com/cncf/xds/go v0.0.0-20211130200136-a8f946100490
- github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be
- github.com/containerd/stargz-snapshotter/estargz v0.11.4
- github.com/containerd/typeurl v1.0.2
- github.com/coreos/go-oidc/v3 v3.2.0
- github.com/coreos/go-semver v0.3.0
- github.com/coreos/go-systemd/v22 v22.3.2
- github.com/cpuguy83/go-md2man/v2 v2.0.2
- github.com/cyberphone/json-canonicalization v0.0.0-20210823021906-dc406ceaf94b
- github.com/davecgh/go-spew v1.1.1
- github.com/dimchansky/utfbom v1.1.1
- github.com/docker/cli v20.10.16+incompatible
- github.com/docker/distribution v2.8.1+incompatible
- github.com/docker/docker v20.10.16+incompatible
- github.com/docker/docker-credential-helpers v0.6.4
- github.com/dustin/go-humanize v1.0.0
- github.com/emicklei/go-restful v2.9.5+incompatible
- github.com/emirpasic/gods v1.12.0
- github.com/envoyproxy/go-control-plane v0.10.2-0.20220325020618-49ff273808a1
- github.com/envoyproxy/protoc-gen-validate v0.6.2
- github.com/fatih/color v1.13.0
- github.com/fsnotify/fsnotify v1.5.4
- github.com/fullstorydev/grpcurl v1.8.6
- github.com/ghodss/yaml v1.0.0
- github.com/go-chi/chi v4.1.2+incompatible
- github.com/go-git/gcfg v1.5.0
- github.com/go-git/go-billy/v5 v5.3.1
- github.com/go-git/go-git/v5 v5.4.2
- github.com/go-logr/logr v1.2.3
- github.com/go-logr/stdr v1.2.2
- github.com/go-openapi/analysis v0.21.2
- github.com/go-openapi/errors v0.20.2
- github.com/go-openapi/jsonpointer v0.19.5
- github.com/go-openapi/jsonreference v0.20.0
- github.com/go-openapi/loads v0.21.1
- github.com/go-openapi/runtime v0.24.1
- github.com/go-openapi/spec v0.20.6
- github.com/go-openapi/strfmt v0.21.2
- github.com/go-openapi/swag v0.21.1
- github.com/go-openapi/validate v0.22.0
- github.com/go-piv/piv-go v1.9.0
- github.com/go-playground/locales v0.14.0
- github.com/go-playground/universal-translator v0.18.0
- github.com/go-playground/validator/v10 v10.11.0
- github.com/go-stack/stack v1.8.1
- github.com/gogo/protobuf v1.3.2
- github.com/golang-jwt/jwt v3.2.2+incompatible
- github.com/golang-jwt/jwt/v4 v4.4.1
- github.com/golang/glog v1.0.0
- github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da
- github.com/golang/mock v1.6.0
- github.com/golang/protobuf v1.5.2
- github.com/golang/snappy v0.0.4
- github.com/google/btree v1.0.1
- github.com/google/certificate-transparency-go v1.1.2
- github.com/google/gnostic v0.5.7-v3refs
- github.com/google/go-cmp v0.5.8
- github.com/google/go-containerregistry v0.10.0
- github.com/google/go-github/v38 v38.1.0
- github.com/google/go-github/v41 v41.0.0
- github.com/google/go-github/v42 v42.0.0
- github.com/google/go-github/v45 v45.2.0
- github.com/google/go-querystring v1.1.0
- github.com/google/gofuzz v1.2.0
- github.com/google/trillian v1.4.1
- github.com/google/uuid v1.3.0
- github.com/google/wire v0.5.0
- github.com/googleapis/gax-go/v2 v2.4.0
- github.com/googleapis/go-type-adapters v1.0.0
- github.com/gorilla/websocket v1.4.2
- github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79
- github.com/grpc-ecosystem/go-grpc-middleware v1.3.0
- github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0
- github.com/grpc-ecosystem/grpc-gateway v1.16.0
- github.com/h2non/filetype v1.1.3
- github.com/hashicorp/go-cleanhttp v0.5.2
- github.com/hashicorp/go-retryablehttp v0.7.1
- github.com/hashicorp/golang-lru v0.5.4
- github.com/hashicorp/hcl v1.0.0
- github.com/imdario/mergo v0.3.12
- github.com/in-toto/in-toto-golang v0.3.4-0.20211211042327-af1f9fb822bf
- github.com/inconshreveable/mousetrap v1.0.0
- github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99
- github.com/jedisct1/go-minisign v0.0.0-20211028175153-1c139d1cc84b
- github.com/jhump/protoreflect v1.10.3
- github.com/jmespath/go-jmespath v0.4.0
- github.com/jonboulle/clockwork v0.3.0
- github.com/josharian/intern v1.0.0
- github.com/json-iterator/go v1.1.12
- github.com/kevinburke/ssh_config v0.0.0-20201106050909-4977a11b4351
- github.com/klauspost/compress v1.15.4
- github.com/leodido/go-urn v1.2.1
- github.com/letsencrypt/boulder v0.0.0-20220331220046-b23ab962616e
- github.com/magiconair/properties v1.8.6
- github.com/mailru/easyjson v0.7.7
- github.com/mattn/go-colorable v0.1.12
- github.com/mattn/go-isatty v0.0.14
- github.com/mattn/go-runewidth v0.0.13
- github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369
- github.com/miekg/pkcs11 v1.1.1
- github.com/mitchellh/go-homedir v1.1.0
- github.com/mitchellh/mapstructure v1.5.0
- github.com/moby/buildkit v0.10.3
- github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd
- github.com/modern-go/reflect2 v1.0.2
- github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822
- github.com/oklog/ulid v1.3.1
- github.com/olekukonko/tablewriter v0.0.5
- github.com/opencontainers/go-digest v1.0.0
- github.com/opencontainers/image-spec v1.0.3-0.20220114050600-8b9d41f48198
- github.com/opentracing/opentracing-go v1.2.0
- github.com/ossf/scorecard/v4 v4.4.0
- github.com/pelletier/go-toml v1.9.5
- github.com/pelletier/go-toml/v2 v2.0.1
- github.com/peterbourgon/diskv v2.0.1+incompatible
- github.com/pkg/errors v0.9.1
- github.com/pmezard/go-difflib v1.0.0
- github.com/prometheus/client_golang v1.12.2
- github.com/prometheus/client_model v0.2.0
- github.com/prometheus/common v0.34.0
- github.com/prometheus/procfs v0.7.3
- github.com/rhysd/actionlint v1.6.13
- github.com/rivo/uniseg v0.2.0
- github.com/robfig/cron v1.2.0
- github.com/russross/blackfriday/v2 v2.1.0
- github.com/sassoftware/relic v0.0.0-20210427151427-dfb082b79b74
- github.com/secure-systems-lab/go-securesystemslib v0.4.0
- github.com/segmentio/ksuid v1.0.4
- github.com/sergi/go-diff v1.2.0
- github.com/shibumi/go-pathspec v1.3.0
- github.com/shurcooL/githubv4 v0.0.0-20201206200315-234843c633fa
- github.com/shurcooL/graphql v0.0.0-20200928012149-18c5c3165e3a
- github.com/sigstore/cosign v1.9.1-0.20220614200746-190e679f4cf8
- github.com/sigstore/fulcio v0.1.2-0.20220114150912-86a2036f9bc7
- github.com/sigstore/rekor v0.9.1
- github.com/sigstore/sigstore v1.2.1-0.20220614141825-9c0e2e247545
- github.com/sirupsen/logrus v1.8.1
- github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966
- github.com/soheilhy/cmux v0.1.5
- github.com/spf13/afero v1.8.2
- github.com/spf13/cast v1.5.0
- github.com/spf13/cobra v1.5.0
- github.com/spf13/jwalterweatherman v1.1.0
- github.com/spf13/pflag v1.0.5
- github.com/spf13/viper v1.12.0
- github.com/spiffe/go-spiffe/v2 v2.1.0
- github.com/stretchr/testify v1.8.0
- github.com/subosito/gotenv v1.3.0
- github.com/syndtr/goleveldb v1.0.1-0.20210819022825-2ae1ddf74ef7
- github.com/tent/canonical-json-go v0.0.0-20130607151641-96e4ba3a7613
- github.com/thales-e-security/pool v0.0.2
- github.com/theupdateframework/go-tuf v0.3.1
- github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399
- github.com/tmc/grpc-websocket-proxy v0.0.0-20201229170055-e5319fda7802
- github.com/transparency-dev/merkle v0.0.1
- github.com/urfave/cli v1.22.7
- github.com/vbatts/tar-split v0.11.2
- github.com/xanzy/go-gitlab v0.68.0
- github.com/xanzy/ssh-agent v0.3.0
- github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2
- github.com/zeebo/errs v1.2.2
- go.etcd.io/bbolt v1.3.6
- go.etcd.io/etcd/api/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/client/pkg/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/client/v2 v2.306.0-alpha.0
- go.etcd.io/etcd/client/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/etcdctl/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/etcdutl/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/pkg/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/raft/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/server/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/tests/v3 v3.6.0-alpha.0
- go.etcd.io/etcd/v3 v3.6.0-alpha.0
- go.mongodb.org/mongo-driver v1.8.3
- go.opencensus.io v0.23.0
- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.29.0
- go.opentelemetry.io/otel v1.4.1
- go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.4.1
- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.4.1
- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.4.1
- go.opentelemetry.io/otel/sdk v1.4.1
- go.opentelemetry.io/otel/trace v1.4.1
- go.opentelemetry.io/proto/otlp v0.12.0
- go.uber.org/atomic v1.9.0
- go.uber.org/multierr v1.8.0
- go.uber.org/zap v1.21.0
- gocloud.dev v0.25.0
- golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4
- golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
- golang.org/x/net v0.0.0-20220607020251-c690dde0001d
- golang.org/x/oauth2 v0.0.0-20220524215830-622c5d57e401
- golang.org/x/sync v0.0.0-20220601150217-0de741cfad7f
- golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a
- golang.org/x/term v0.0.0-20210927222741-03fcf44c2211
- golang.org/x/text v0.3.7
- golang.org/x/time v0.0.0-20220411224347-583f2d630306
- golang.org/x/tools v0.1.10
- golang.org/x/xerrors v0.0.0-20220517211312-f3a8303e98df
- google.golang.org/api v0.83.0
- google.golang.org/appengine v1.6.7
- google.golang.org/genproto v0.0.0-20220602131408-e326c6e8e9c8
- google.golang.org/grpc v1.47.0
- google.golang.org/protobuf v1.28.0
- gopkg.in/cheggaaa/pb.v1 v1.0.28
- gopkg.in/inf.v0 v0.9.1
- gopkg.in/ini.v1 v1.66.6
- gopkg.in/natefinch/lumberjack.v2 v2.0.0
- gopkg.in/square/go-jose.v2 v2.6.0
- gopkg.in/warnings.v0 v0.1.2
- gopkg.in/yaml.v2 v2.4.0
- gopkg.in/yaml.v3 v3.0.1
- k8s.io/api v0.24.0
- k8s.io/apimachinery v0.24.3
- k8s.io/client-go v0.24.0
- k8s.io/klog/v2 v2.60.1
- k8s.io/kube-openapi v0.0.0-20220328201542-3ee0da9b0b42
- k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9
- knative.dev/pkg v0.0.0-20220325200448-1f7514acd0c2
- mvdan.cc/sh/v3 v3.5.1
- sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2
- sigs.k8s.io/release-sdk v0.9.2
- sigs.k8s.io/release-utils v0.7.2
- sigs.k8s.io/structured-merge-diff/v4 v4.2.1
- sigs.k8s.io/yaml v1.3.0