OpenSSF Scorecard supply-chain health scores (a lower score is weaker). Ranked by the worst severity rung present in the table (most findings at that rung first), then weakest score first. reference โ
| Repository | Critical | High | Medium | Low | Total |
|---|---|---|---|---|---|
| dependamerge | 0 | 0 | 21 | 0 | 21 |
| gerrit-action | 0 | 0 | 19 | 0 | 19 |
| lftools-uv | 0 | 0 | 6 | 0 | 6 |
| github-security-report-action | 0 | 0 | 3 | 0 | 3 |
| Total | 0 | 0 | 49 | 0 | 49 |
aislop AI-slop / code-quality findings, ranked worst-first by severity. reference โ
Open Dependabot alerts for vulnerable dependencies, counted by severity per repository. reference โ
Repositories with Dependabot security alerts disabled. Enable them so vulnerable dependencies surface as alerts. reference โ
Repositories with Dependabot security updates disabled. Enable them so fixes for vulnerable dependencies arrive as pull requests automatically. reference โ
Repositories whose Dependabot configuration omits an update cooldown. A cooldown is mandatory; any cooldown value passes. Repositories with no Dependabot configuration do not appear here. reference โ
| Repository | Critical | High | Medium | Low | Total |
|---|---|---|---|---|---|
| github-security-report-action | 0 | 1 | 0 | 0 | 1 |
| Total | 0 | 1 | 0 | 0 | 1 |
CodeQL code-scanning findings, ranked worst-first by severity. Each row shows a repository's open-alert counts. reference โ
Zizmor static analysis of GitHub Actions workflows, ranked worst-first by severity. reference โ
Open secret-scanning alerts. Each row shows a repository's count of detected, unresolved secrets. reference โ
Repositories created within 21 day(s) are excluded. A repository whose newest release or tag is older than 60 day(s) (or has neither) is shown. Repositories ranked by combined release and tag staleness (oldest first). A repository with neither a release nor a tag ranks highest. reference โ
Repositories whose latest or last-published release is mutable. Republish them as immutable releases so a published artifact cannot change after the fact. reference โ
Repositories with private vulnerability reporting disabled. Enable it so security researchers can privately report vulnerabilities instead of disclosing them publicly. reference โ
| Repository | Bug | Feature | Docs | Other | Untriaged | Total | Oldest |
|---|---|---|---|---|---|---|---|
| docker-workflows | 1 | 3 | 0 | 10 | 1 | 15 | 3 days |
| dependamerge | 7 | 2 | 0 | 2 | 1 | 12 | 59 days |
| .github | 1 | 4 | 0 | 3 | 3 | 11 | 23 days |
| security-workflows | 0 | 6 | 1 | 0 | 0 | 7 | 8 days |
| sigul-sign-docker | 2 | 0 | 0 | 0 | 3 | 5 | 3 days |
| github-security-report-action | 0 | 1 | 0 | 0 | 3 | 4 | 4 days |
| gerrit-clone-action | 4 | 0 | 0 | 0 | 0 | 4 | 3 days |
| node-workflows | 0 | 0 | 0 | 0 | 3 | 3 | 1 day |
| 1password-secrets-action | 1 | 0 | 1 | 0 | 0 | 2 | 52 days |
| tag-validate-action | 2 | 0 | 0 | 0 | 0 | 2 | 2 days |
| go-workflows | 0 | 0 | 0 | 0 | 1 | 1 | 1 day |
| node-publish-action | 0 | 0 | 0 | 0 | 1 | 1 | 1 day |
| python-build-action | 0 | 0 | 0 | 0 | 1 | 1 | 1 day |
| build-metadata-action | 0 | 1 | 0 | 0 | 0 | 1 | 22 days |
| generic-workflows | 0 | 1 | 0 | 0 | 0 | 1 | 19 days |
| gerrit-action | 1 | 0 | 0 | 0 | 0 | 1 | 4 days |
| gha-workflow-linter | 1 | 0 | 0 | 0 | 0 | 1 | 3 days |
| lftools-uv | 1 | 0 | 0 | 0 | 0 | 1 | 1 day |
| python-audit-action | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| python-dynamic-version-action | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| python-project-version-action | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| python-sbom-action | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| python-test-action | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| test-go-project | 1 | 0 | 0 | 0 | 0 | 1 | 8 days |
| test-python-project | 0 | 0 | 0 | 1 | 0 | 1 | 32 days |
| version-extract-action | 1 | 0 | 0 | 0 | 0 | 1 | 8 days |
| Total | 23 | 18 | 2 | 21 | 17 | 81 |
Open issues per repository, split by label into the configured classes. Issues carrying none of the configured labels count as Other; issues with no labels at all count as Untriaged, which is the column to watch -- an unlabelled issue has not been triaged. Ranked by total open issues, then by Untriaged. reference โ