Skip to content

Commit 1a74a0a

Browse files
author
GitHub Actions
committed
update CMSgov data: Fri Jan 10 23:25:24 UTC 2025
1 parent a0aa7a0 commit 1a74a0a

File tree

184 files changed

+47529
-46764
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

184 files changed

+47529
-46764
lines changed

app/site/_data/CMSgov/AB2D-Libs/AB2D-Libs_data.json

+400-399
Large diffs are not rendered by default.

app/site/_data/CMSgov/AB2D-Libs/AB2D-Libs_data.json.old

+27-22
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,12 @@
2929
"2024/7": 4,
3030
"2024/6": 15
3131
},
32-
"new_commit_contributors_by_day_over_last_month": [],
32+
"new_commit_contributors_by_day_over_last_month": [
33+
[
34+
"2024-12-12T00:00:00.000Z",
35+
1
36+
]
37+
],
3338
"new_commit_contributors_by_day_over_last_six_months": [
3439
[
3540
"2024-07-22T00:00:00.000Z",
@@ -51,14 +56,14 @@
5156
"nadia_badge_name": "midsize",
5257
"created_at": "2021-08-11T18:29:28Z",
5358
"ossf_scorecard": {
54-
"date": "2024-12-22T09:30:27Z",
59+
"date": "2025-01-05T09:31:46Z",
5560
"repo": {
5661
"name": "github.com/CMSgov/AB2D-Libs",
5762
"commit": "a44b6ee6314fb54db767a0f6c88c4ede2c87dae5"
5863
},
5964
"scorecard": {
60-
"version": "v5.0.0-120-g5e90f2dd",
61-
"commit": "5e90f2dd5f343abfbf4583135d729b8d4167c162"
65+
"version": "v5.0.0-125-g975ee230",
66+
"commit": "975ee2304ef7097c94a377fe95976604b4adcf22"
6267
},
6368
"score": 5.9,
6469
"checks": [
@@ -68,7 +73,7 @@
6873
"reason": "no binaries found in the repo",
6974
"name": "Binary-Artifacts",
7075
"documentation": {
71-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#binary-artifacts",
76+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#binary-artifacts",
7277
"short": "Determines if the project has generated executable (binary) artifacts in the source repository."
7378
}
7479
},
@@ -78,7 +83,7 @@
7883
"reason": "branch protection is not maximal on development and all release branches",
7984
"name": "Branch-Protection",
8085
"documentation": {
81-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#branch-protection",
86+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#branch-protection",
8287
"short": "Determines if the default and release branches are protected with GitHub's branch protection settings."
8388
}
8489
},
@@ -88,7 +93,7 @@
8893
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
8994
"name": "CI-Tests",
9095
"documentation": {
91-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#ci-tests",
96+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#ci-tests",
9297
"short": "Determines if the project runs tests before pull requests are merged."
9398
}
9499
},
@@ -98,7 +103,7 @@
98103
"reason": "no effort to earn an OpenSSF best practices badge detected",
99104
"name": "CII-Best-Practices",
100105
"documentation": {
101-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#cii-best-practices",
106+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#cii-best-practices",
102107
"short": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."
103108
}
104109
},
@@ -108,7 +113,7 @@
108113
"reason": "all changesets reviewed",
109114
"name": "Code-Review",
110115
"documentation": {
111-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#code-review",
116+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#code-review",
112117
"short": "Determines if the project requires human code review before pull requests (aka merge requests) are merged."
113118
}
114119
},
@@ -118,7 +123,7 @@
118123
"reason": "project has 5 contributing companies or organizations",
119124
"name": "Contributors",
120125
"documentation": {
121-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#contributors",
126+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#contributors",
122127
"short": "Determines if the project has a set of contributors from multiple organizations (e.g., companies)."
123128
}
124129
},
@@ -128,7 +133,7 @@
128133
"reason": "no dangerous workflow patterns detected",
129134
"name": "Dangerous-Workflow",
130135
"documentation": {
131-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#dangerous-workflow",
136+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#dangerous-workflow",
132137
"short": "Determines if the project's GitHub Action workflows avoid dangerous patterns."
133138
}
134139
},
@@ -138,7 +143,7 @@
138143
"reason": "update tool detected",
139144
"name": "Dependency-Update-Tool",
140145
"documentation": {
141-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#dependency-update-tool",
146+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#dependency-update-tool",
142147
"short": "Determines if the project uses a dependency update tool."
143148
}
144149
},
@@ -148,7 +153,7 @@
148153
"reason": "project is not fuzzed",
149154
"name": "Fuzzing",
150155
"documentation": {
151-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#fuzzing",
156+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#fuzzing",
152157
"short": "Determines if the project uses fuzzing."
153158
}
154159
},
@@ -158,7 +163,7 @@
158163
"reason": "license file detected",
159164
"name": "License",
160165
"documentation": {
161-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#license",
166+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#license",
162167
"short": "Determines if the project has defined a license."
163168
}
164169
},
@@ -168,7 +173,7 @@
168173
"reason": "4 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3",
169174
"name": "Maintained",
170175
"documentation": {
171-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#maintained",
176+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#maintained",
172177
"short": "Determines if the project is \"actively maintained\"."
173178
}
174179
},
@@ -178,7 +183,7 @@
178183
"reason": "packaging workflow not detected",
179184
"name": "Packaging",
180185
"documentation": {
181-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#packaging",
186+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#packaging",
182187
"short": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."
183188
}
184189
},
@@ -188,7 +193,7 @@
188193
"reason": "dependency not pinned by hash detected -- score normalized to 0",
189194
"name": "Pinned-Dependencies",
190195
"documentation": {
191-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#pinned-dependencies",
196+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#pinned-dependencies",
192197
"short": "Determines if the project has declared and pinned the dependencies of its build process."
193198
}
194199
},
@@ -198,7 +203,7 @@
198203
"reason": "SAST tool is not run on all commits -- score normalized to 0",
199204
"name": "SAST",
200205
"documentation": {
201-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#sast",
206+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#sast",
202207
"short": "Determines if the project uses static code analysis."
203208
}
204209
},
@@ -208,7 +213,7 @@
208213
"reason": "security policy file not detected",
209214
"name": "Security-Policy",
210215
"documentation": {
211-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#security-policy",
216+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#security-policy",
212217
"short": "Determines if the project has published a security policy."
213218
}
214219
},
@@ -218,7 +223,7 @@
218223
"reason": "no releases found",
219224
"name": "Signed-Releases",
220225
"documentation": {
221-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#signed-releases",
226+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#signed-releases",
222227
"short": "Determines if the project cryptographically signs release artifacts."
223228
}
224229
},
@@ -228,7 +233,7 @@
228233
"reason": "detected GitHub workflow tokens with excessive permissions",
229234
"name": "Token-Permissions",
230235
"documentation": {
231-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#token-permissions",
236+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#token-permissions",
232237
"short": "Determines if the project's workflows follow the principle of least privilege."
233238
}
234239
},
@@ -238,7 +243,7 @@
238243
"reason": "0 existing vulnerabilities detected",
239244
"name": "Vulnerabilities",
240245
"documentation": {
241-
"url": "https://github.com/ossf/scorecard/blob/5e90f2dd5f343abfbf4583135d729b8d4167c162/docs/checks.md#vulnerabilities",
246+
"url": "https://github.com/ossf/scorecard/blob/975ee2304ef7097c94a377fe95976604b4adcf22/docs/checks.md#vulnerabilities",
242247
"short": "Determines if the project has open, known unfixed vulnerabilities."
243248
}
244249
}

0 commit comments

Comments
 (0)