{"repository": "GibbonEdu/core", "owner": "GibbonEdu", "name": "core", "source_url": "https://github.com/GibbonEdu/core", "description": "Gibbon is a flexible, open source school management platform designed to make life better for teachers, students, parents and leaders.", "homepage": "https://gibbonedu.org", "license_id": "GPL-3.0", "license_label": "GPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 634, "forks": 419, "open_issues": 39, "language": "PHP", "topics": [], "archived": false, "disabled": false, "updated_at": "2026-10-09T03:29:32Z", "pushed_at": "2026-10-09T03:29:27Z", "default_branch": "v31.0.00", "release_tag": "v30.0.01", "release_date": "2026-02-06T06:53:56Z", "release_assets_bytes": 89921386, "packages": [{"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20210618040741-eeb570a51566", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211029062203-00a3d00d8246", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211101002009-3a281b383d03", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211101020300-fbf900233586", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211101022542-54a639b91ee3", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211101043755-c548b820c038", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211101123152-ce077b62891f", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/GibbonEdu/core", "version": "v0.0.0-20211102003216-1821a8ef2a20", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": -1, "reason": "packaging workflow not detected", "details": ["Warn: no GitHub/GitLab publishing workflow detected."]}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 5, "reason": "Found 10/18 approved changesets -- score normalized to 5", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "15 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 10, "reason": "security policy file detected", "details": ["Info: security policy file detected: .github/SECURITY.md:1", "Info: Found linked content: .github/SECURITY.md:1", "Info: Found disclosure, vulnerability, and/or timelines in security policy: .github/SECURITY.md:1", "Info: Found text in security policy: .github/SECURITY.md:1"]}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Warn: no topLevel permission defined: .github/workflows/ci.yml:1", "Warn: no topLevel permission defined: .github/workflows/release.yml:1", "Info: no jobLevel write permissions found"]}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: GNU General Public License v3.0: LICENSE:0"]}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact v30.0.01 not signed: https://api.github.com/repos/GibbonEdu/core/releases/283635487", "Warn: release artifact v30.0.00 not signed: https://api.github.com/repos/GibbonEdu/core/releases/263939315", "Warn: release artifact v29.0.00 not signed: https://api.github.com/repos/GibbonEdu/core/releases/219760080", "Warn: release artifact v28.0.01 not signed: https://api.github.com/repos/GibbonEdu/core/releases/189657998", "Warn: release artifact v28.0.00 not signed: https://api.github.com/repos/GibbonEdu/core/releases/186316288", "Warn: release artifact v30.0.01 does not have provenance: https://api.github.com/repos/GibbonEdu/core/releases/283635487", "Warn: release artifact v30.0.00 does not have provenance: https://api.github.com/repos/GibbonEdu/core/releases/263939315", "Warn: release artifact v29.0.00 does not have provenance: https://api.github.com/repos/GibbonEdu/core/releases/219760080", "Warn: release artifact v28.0.01 does not have provenance: https://api.github.com/repos/GibbonEdu/core/releases/189657998", "Warn: release artifact v28.0.00 does not have provenance: https://api.github.com/repos/GibbonEdu/core/releases/186316288"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/ci.yml/v31.0.00?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/ci.yml/v31.0.00?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/ci.yml/v31.0.00?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/ci.yml/v31.0.00?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/GibbonEdu/core/release.yml/v31.0.00?enable=pin", "Warn: containerImage not pinned by hash: ops/Dockerfile:3: pin your Docker image by updating php:8.3-apache to php:8.3-apache@sha256:bcf7ac6941725b08123df2732065b8ede097ed0977ba2891b411654efb35cc23", "Info:   0 out of   5 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of   5 third-party GitHubAction dependencies pinned", "Info:   0 out of   1 containerImage dependencies pinned"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "details": ["Warn: 0 commits out of 22 are checked with a SAST tool"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": 0, "reason": "branch protection not enabled on development/release branches", "details": ["Warn: branch protection not enabled for branch 'v30.0.01'", "Warn: branch protection not enabled for branch 'v30.0.00'", "Warn: branch protection not enabled for branch 'v28.0.01'", "Warn: branch protection not enabled for branch 'v28.0.00'", "Warn: branch protection not enabled for branch 'v27.0.01'", "Warn: branch protection not enabled for branch 'v27.0.00'", "Warn: branch protection not enabled for branch 'v25.0.01'", "Warn: branch protection not enabled for branch 'v23.0.01'", "Warn: branch protection not enabled for branch 'v22.0.01'", "Warn: branch protection not enabled for branch 'v22.0.00'", "Info: 'allow deletion' disabled on branch 'v31.0.00'", "Info: 'allow deletion' disabled on branch 'main'", "Info: 'force pushes' disabled on branch 'v31.0.00'", "Info: 'force pushes' disabled on branch 'main'", "Info: 'branch protection settings apply to administrators' is required to merge on branch 'v31.0.00'", "Info: 'branch protection settings apply to administrators' is required to merge on branch 'main'", "Warn: could not determine whether codeowners review is allowed", "Warn: could not determine whether codeowners review is allowed", "Warn: no status checks found to merge onto branch 'v31.0.00'", "Warn: no status checks found to merge onto branch 'main'", "Warn: PRs are not required to make changes on branch 'v31.0.00'; or we don't have data to detect it.If you think it might be the latter, make sure to run Scorecard with a PAT or use Repo Rules (that are always public) instead of Branch Protection settings", "Warn: PRs are not required to make changes on branch 'main'; or we don't have data to detect it.If you think it might be the latter, make sure to run Scorecard with a PAT or use Repo Rules (that are always public) instead of Branch Protection settings"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/GibbonEdu/core", "retrieved_at": "2026-10-09T09:20:45.140613+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-09T09:20:45.140613+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-09T09:20:45.140613+00:00"}], "retrieved_at": "2026-10-09T09:20:45.140613+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 85.8 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}