Security report: lfreleng-actions

117 repositories analysed ยท generated 2026-08-23 09:07 UTC

OpenSSF Scorecard

RepositoryScoreCriticalHighMediumLow
grype-scan-action 6.70321
rtd-build-action 7.00321
rtd-config-audit-action 7.00331
security-workflows 7.10221
github-issues-triage 7.20231
go-test-action 7.20221
junit-test-report-action 7.20221
test-maven-project 7.20221
docs-workflows 7.30221
github-security-report-action 7.50221
go-audit-action 7.60221
go-build-action 7.60221
maven-xml-settings-action 7.60221
node-publish-action 7.60221
python-nss-ng 7.60221
sbom-action 7.60221
docker-workflows 7.70221
generic-workflows 7.70221
go-workflows 7.70221
java-workflows 7.70221
node-workflows 7.70221
python-workflows 7.70221
aislop-scan-action 7.80221
change-isolation-action 7.80221
node-audit-action 7.80221
node-create-npmrc-action 7.80221
zizmor-scan-action 7.80221
central-publish-action 7.90221
pull-request-fixer 8.00211
tag-validate-action 8.102101
build-metadata-action 8.40221
node-build-action 8.40221
lftools-uv 8.50241
http-api-tool-docker 8.60221
dependamerge 8.20121
project-reporting-tool 8.20121
gha-workflow-linter 8.30121
harden-runner-block-action 8.30141
gerrit-clone-action 8.40171
python-dynamic-version-action 8.40141
python-project-version-action 8.40151
.github 8.50121
chartmuseum-action 8.50131
gerrit-action 8.50131
markdown-table-fixer 8.50131
python-audit-action 8.50131
tailscale-openstack-bastion-action 8.501101
test-node-project 8.50131
version-extract-action 8.50121
checkout-gerrit-change-action 8.60121
credential-load-action 8.60121
docker-save-images-action 8.60121
draft-release-promote-action 8.60121
file-grep-regex-action 8.60121
file-sed-regex-action 8.60121
gerrit-change-info 8.60121
git-commit-message-action 8.60121
git-configure-action 8.60121
github-list-releases-action 8.60121
github-network-audit 8.60121
github2gerrit-action 8.60121
go-httpbin-action 8.60121
gradle-build-action 8.60121
helm-chart-publish-action 8.60121
inject-issue-id-action 8.60121
json-key-value-lookup-action 8.60121
make-action 8.60121
maven-build-action 8.60121
maven-make-build-action 8.60121
nexus-docker-login-action 8.60121
nexus-publish-action 8.60121
nexus-staging-action 8.60121
openssf-scorecard-summary-action 8.60121
openstack-cron-action 8.60121
packer-build-action 8.60151
path-check-action 8.60121
pinned-versions-action 8.60121
pypi-publish-action 8.60121
pypi-version-check-action 8.60121
python-build-action 8.60121
python-dependencies-update-action 8.60121
python-project-metadata-action 8.60121
python-project-name-action 8.60121
python-project-tag-push-verify-action 8.60121
python-project-version-patch-action 8.60121
python-sbom-action 8.60121
python-supported-versions-action 8.60121
python-twine-check-action 8.60121
release-assets-action 8.60121
repository-content-action 8.60121
repository-metadata-action 8.60121
semantic-tag-increment 8.60121
sonarqube-cloud-scan-action 8.60121
standalone-linting-action 8.60121
tag-push-verify-action 8.60121
tag-validate-calver-action 8.60121
tag-validate-semantic-action 8.60121
test-docker-project 8.60131
tox-run-action 8.60121
url-download-action 8.60121
url-validity-action 8.60121
verify-release-schema-action 8.60121
gerrit-review-action 8.70121
hw-bom-javascript 8.70121
maven-stage-prep-action 8.70121
sonatype-lifecycle-scan-action 8.70121
test-http-api-tool 8.70121
test-makefile-helm-chart 8.70121
test-python-project 8.80111
1password-secrets-action 8.90111
repository-tags-action โ€”0121
sigul-sign-docker 8.10030
Total0148263111

OpenSSF Scorecard supply-chain health scores (a lower score is weaker). Ranked by the worst severity rung present in the table (most findings at that rung first), then weakest score first. reference โ†—

AI Slop Analysis

RepositoryCriticalHighMediumLowTotal
dependamerge 0021021
gerrit-action 0019019
lftools-uv 00606
github-security-report-action 00303
Total0049049

aislop AI-slop / code-quality findings, ranked worst-first by severity. reference โ†—

Dependabot: Security Alerts

Open Dependabot alerts for vulnerable dependencies, counted by severity per repository. reference โ†—

Dependabot: Alerts Enabled

Repositories with Dependabot security alerts disabled. Enable them so vulnerable dependencies surface as alerts. reference โ†—

Dependabot: Security Updates

Repositories with Dependabot security updates disabled. Enable them so fixes for vulnerable dependencies arrive as pull requests automatically. reference โ†—

Dependabot: Cooldown Settings

Repositories whose Dependabot configuration omits an update cooldown. A cooldown is mandatory; any cooldown value passes. Repositories with no Dependabot configuration do not appear here. reference โ†—

CodeQL

RepositoryCriticalHighMediumLowTotal
github-security-report-action 01001
Total01001

CodeQL code-scanning findings, ranked worst-first by severity. Each row shows a repository's open-alert counts. reference โ†—

Zizmor Static Analysis

Zizmor static analysis of GitHub Actions workflows, ranked worst-first by severity. reference โ†—

Secret Scanning

Open secret-scanning alerts. Each row shows a repository's count of detected, unresolved secrets. reference โ†—

Releases / Tagging

Repositories created within 21 day(s) are excluded. A repository whose newest release or tag is older than 60 day(s) (or has neither) is shown. Repositories ranked by combined release and tag staleness (oldest first). A repository with neither a release nor a tag ranks highest. reference โ†—

Mutable Releases

Repositories whose latest or last-published release is mutable. Republish them as immutable releases so a published artifact cannot change after the fact. reference โ†—

Private Vulnerability Reporting

Repositories with private vulnerability reporting disabled. Enable it so security researchers can privately report vulnerabilities instead of disclosing them publicly. reference โ†—

GitHub Issues

RepositoryBugFeatureDocsOtherUntriagedTotalOldest
docker-workflows 130101153 days
dependamerge 720211259 days
.github 140331123 days
security-workflows 0610078 days
sigul-sign-docker 2000353 days
github-security-report-action 0100344 days
gerrit-clone-action 4000043 days
node-workflows 0000331 day
1password-secrets-action 10100252 days
tag-validate-action 2000022 days
go-workflows 0000111 day
node-publish-action 0000111 day
python-build-action 0000111 day
build-metadata-action 01000122 days
generic-workflows 01000119 days
gerrit-action 1000014 days
gha-workflow-linter 1000013 days
lftools-uv 1000011 day
python-audit-action 00010132 days
python-dynamic-version-action 00010132 days
python-project-version-action 00010132 days
python-sbom-action 00010132 days
python-test-action 00010132 days
test-go-project 1000018 days
test-python-project 00010132 days
version-extract-action 1000018 days
Total23182211781

Open issues per repository, split by label into the configured classes. Issues carrying none of the configured labels count as Other; issues with no labels at all count as Untriaged, which is the column to watch -- an unlabelled issue has not been triaged. Ranked by total open issues, then by Untriaged. reference โ†—