{"repository": "GhostManager/Ghostwriter", "owner": "GhostManager", "name": "Ghostwriter", "source_url": "https://github.com/GhostManager/Ghostwriter", "description": "The SpecterOps project management and reporting engine", "homepage": "https://ghostwriter.wiki", "license_id": "BSD-3-Clause", "license_label": "BSD-3-Clause déclarée", "license_status": "ouverte_permissive", "commercial_use": "possible, conditions à vérifier", "stars": 1932, "forks": 257, "open_issues": 34, "language": "Python", "topics": ["informationsecurity", "penetration-testing", "red-team", "reporting"], "archived": false, "disabled": false, "updated_at": "2026-10-08T12:44:42Z", "pushed_at": "2026-10-06T01:56:04Z", "default_branch": "master", "release_tag": "v7.3.1", "release_date": "2026-10-06T01:14:14Z", "release_assets_bytes": 7664, "packages": [], "scorecard_score": null, "scorecard_checks": [{"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 4, "reason": "security policy file detected", "details": ["Info: security policy file detected: SECURITY.md:1", "Warn: no linked content found", "Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1", "Info: Found text in security policy: SECURITY.md:1"]}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 0, "reason": "Found 0/4 approved changesets -- score normalized to 0", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28", "Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29", "Info: topLevel 'contents' permission set to 'read': .github/workflows/cli-install.yml:31", "Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1", "Warn: no topLevel permission defined: .github/workflows/docker.yml:1", "Info: topLevel 'contents' permission set to 'read': .github/workflows/graphql-codegen.yml:35", "Warn: topLevel 'contents' permission set to 'write': .github/workflows/gw-cli-compose-file.yml:8", "Warn: no topLevel permission defined: .github/workflows/inactive-issues.yml:1", "Warn: topLevel 'contents' permission set to 'write': .github/workflows/update-version.yml:9", "Info: topLevel 'contents' permission set to 'read': .github/workflows/workflow.yml:25", "Info: no jobLevel write permissions found"]}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 5, "reason": "badge detected: Passing", "details": []}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 7, "reason": "binaries present in source code", "details": ["Warn: binary detected: ghostwriter-cli-linux:1", "Warn: binary detected: ghostwriter-cli-macos:1", "Warn: binary detected: ghostwriter-cli.exe:1"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": 3, "reason": "branch protection is not maximal on development and all release branches", "details": ["Info: 'allow deletion' disabled on branch 'master'", "Info: 'force pushes' disabled on branch 'master'", "Info: 'branch protection settings apply to administrators' is required to merge on branch 'master'", "Warn: branch 'master' does not require approvers", "Warn: codeowners review is not required on branch 'master'", "Info: status check found to merge onto on branch 'master'", "Warn: PRs are not required to make changes on branch 'master'; or we don't have data to detect it.If you think it might be the latter, make sure to run Scorecard with a PAT or use Repo Rules (that are always public) instead of Branch Protection settings"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact v7.2.6 not signed: https://api.github.com/repos/GhostManager/Ghostwriter/releases/368256322", "Warn: release artifact v7.2.5 not signed: https://api.github.com/repos/GhostManager/Ghostwriter/releases/363584678", "Warn: release artifact v7.2.4 not signed: https://api.github.com/repos/GhostManager/Ghostwriter/releases/357710522", "Warn: release artifact v7.2.3 not signed: https://api.github.com/repos/GhostManager/Ghostwriter/releases/356240099", "Warn: release artifact v7.2.2 not signed: https://api.github.com/repos/GhostManager/Ghostwriter/releases/355900977", "Warn: release artifact v7.2.6 does not have provenance: https://api.github.com/repos/GhostManager/Ghostwriter/releases/368256322", "Warn: release artifact v7.2.5 does not have provenance: https://api.github.com/repos/GhostManager/Ghostwriter/releases/363584678", "Warn: release artifact v7.2.4 does not have provenance: https://api.github.com/repos/GhostManager/Ghostwriter/releases/357710522", "Warn: release artifact v7.2.3 does not have provenance: https://api.github.com/repos/GhostManager/Ghostwriter/releases/356240099", "Warn: release artifact v7.2.2 does not have provenance: https://api.github.com/repos/GhostManager/Ghostwriter/releases/355900977"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 10, "reason": "SAST tool is run on all commits", "details": ["Info: SAST configuration detected: CodeQL", "Info: all commits (30) are checked with a SAST tool"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/cli-install.yml:38"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-install.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-install.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-install.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-install.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-install.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-install.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/cli-install.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/codeql-analysis.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/codeql-analysis.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/codeql-analysis.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/docker.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/graphql-codegen.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/graphql-codegen.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/graphql-codegen.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/graphql-codegen.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gw-cli-compose-file.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/gw-cli-compose-file.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/inactive-issues.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/inactive-issues.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-version.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/update-version.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-version.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/update-version.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/workflow.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/workflow.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/workflow.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/GhostManager/Ghostwriter/workflow.yml/master?enable=pin", "Warn: containerImage not pinned by hash: compose/local/django/Dockerfile:1: pin your Docker image by updating python:3.10.20-alpine3.23 to python:3.10.20-alpine3.23@sha256:81c5715bb79d8edd45a82de842a29c7d6ef2aff4b7fa88e712f93a93806337df", "Warn: containerImage not pinned by hash: compose/local/hasura/Dockerfile:1: pin your Docker image by updating hasura/graphql-engine:v2.45.6.cli-migrations-v3 to hasura/graphql-engine:v2.45.6.cli-migrations-v3@sha256:a6d8e83bba5bbf3772544a007809c066315061288bfb816fdf334be0a48570f2", "Warn: containerImage not pinned by hash: compose/local/node/Dockerfile:1: pin your Docker image by updating node:25.9.0-alpine3.23 to node:25.9.0-alpine3.23@sha256:bdf2cca6fe3dabd014ea60163eca3f0f7015fbd5c7ee1b0e9ccb4ced6eb02ef4", "Warn: containerImage not pinned by hash: compose/production/collab-server/Dockerfile:1: pin your Docker image by updating node:25.9.0-alpine3.23 to node:25.9.0-alpine3.23@sha256:bdf2cca6fe3dabd014ea60163eca3f0f7015fbd5c7ee1b0e9ccb4ced6eb02ef4", "Warn: containerImage not pinned by hash: compose/production/django/Dockerfile:1: pin your Docker image by updating node:25.9.0-alpine3.23 to node:25.9.0-alpine3.23@sha256:bdf2cca6fe3dabd014ea60163eca3f0f7015fbd5c7ee1b0e9ccb4ced6eb02ef4", "Warn: containerImage not pinned by hash: compose/production/django/Dockerfile:6: pin your Docker image by updating python:3.10.20-alpine3.23 to python:3.10.20-alpine3.23@sha256:81c5715bb79d8edd45a82de842a29c7d6ef2aff4b7fa88e712f93a93806337df", "Warn: containerImage not pinned by hash: compose/production/django/Dockerfile:31: pin your Docker image by updating python:3.10.20-alpine3.23 to python:3.10.20-alpine3.23@sha256:81c5715bb79d8edd45a82de842a29c7d6ef2aff4b7fa88e712f93a93806337df", "Warn: containerImage not pinned by hash: compose/production/hasura/Dockerfile:1: pin your Docker image by updating hasura/graphql-engine:v2.45.6.cli-migrations-v3 to hasura/graphql-engine:v2.45.6.cli-migrations-v3@sha256:a6d8e83bba5bbf3772544a007809c066315061288bfb816fdf334be0a48570f2", "Warn: containerImage not pinned by hash: compose/production/nginx/Dockerfile:1: pin your Docker image by updating nginx:1.23.3-alpine to nginx:1.23.3-alpine@sha256:6318314189b40e73145a48060bff4783a116c34cc7241532d0d94198fb2c9629", "Warn: containerImage not pinned by hash: compose/production/postgres/Dockerfile:1: pin your Docker image by updating postgres:16.4 to postgres:16.4@sha256:e62fbf9d3e2b49816a32c400ed2dba83e3b361e6833e624024309c35d334b412", "Warn: containerImage not pinned by hash: compose/production/redis/Dockerfile:1: pin your Docker image by updating redis:6-alpine to redis:6-alpine@sha256:d0c875bdacfb5c4d2c2d9124de3f53cee1dc9ceff8936bd459fabc135cb33015", "Warn: pipCommand not pinned by hash: compose/local/django/Dockerfile:7-26", "Warn: pipCommand not pinned by hash: compose/local/django/Dockerfile:30", "Warn: pipCommand not pinned by hash: compose/production/django/Dockerfile:26-29", "Warn: pipCommand not pinned by hash: compose/production/django/Dockerfile:37-40", "Warn: pipCommand not pinned by hash: compose/local/django/start_debug:23", "Warn: pipCommand not pinned by hash: compose/local/django/start_debug:26", "Info:   0 out of  20 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of  15 third-party GitHubAction dependencies pinned", "Info:   3 out of   3 npmCommand dependencies pinned", "Info:   0 out of  11 containerImage dependencies pinned", "Info:   0 out of   6 pipCommand dependencies pinned"]}], "known_vulnerability_count": null, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/GhostManager/Ghostwriter", "retrieved_at": "2026-10-09T20:18:14.610718+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-09T20:18:14.610718+00:00"}], "retrieved_at": "2026-10-09T20:18:14.610718+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 0.0 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}