{"repository": "ONLYOFFICE/Docker-DocumentServer", "owner": "ONLYOFFICE", "name": "Docker-DocumentServer", "source_url": "https://github.com/ONLYOFFICE/Docker-DocumentServer", "description": "ONLYOFFICE Document Server is an online office suite comprising viewers and editors for texts, spreadsheets and presentations, fully compatible with Office Open XML formats: .docx, .xlsx, .pptx and enabling collaborative editing in real time.", "homepage": "", "license_id": "AGPL-3.0", "license_label": "AGPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 2469, "forks": 709, "open_issues": 27, "language": "Shell", "topics": ["docker-image", "onlyoffice"], "archived": false, "disabled": false, "updated_at": "2026-10-09T07:11:38Z", "pushed_at": "2026-10-09T04:48:42Z", "default_branch": "master", "release_tag": "", "release_date": "", "release_assets_bytes": null, "packages": [{"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v4.3.4+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v4.3.5+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v4.3.6+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v5.3.4+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v5.3.5-0.20250227132428-22f8a1004f2a+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/ONLYOFFICE/Docker-DocumentServer", "version": "v5.3.5-0.20260811112222-a4edd7b34e12+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/onlyoffice/docker-documentserver", "version": "v4.3.4+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/onlyoffice/docker-documentserver", "version": "v4.3.5+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "12 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 0, "reason": "Found 0/30 approved changesets -- score normalized to 0", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/stable-build.yml:196", "Warn: no topLevel permission defined: .github/workflows/4testing-build.yml:1", "Warn: no topLevel permission defined: .github/workflows/dockerhub-description-size.yml:1", "Warn: no topLevel permission defined: .github/workflows/secure-rebuild.yml:1", "Warn: no topLevel permission defined: .github/workflows/stable-build.yml:1", "Warn: no topLevel permission defined: .github/workflows/trivy-ds.yml:1", "Warn: no topLevel permission defined: .github/workflows/zap-ds.yaml:1"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "no SAST tool detected", "details": ["Warn: no pull requests merged into dev branch"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: GNU Affero General Public License v3.0: LICENSE:0"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": -1, "reason": "no releases found", "details": []}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 0, "reason": "security policy file not detected", "details": ["Warn: no security policy file detected", "Warn: no security file to analyze", "Warn: no security file to analyze", "Warn: no security file to analyze"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/4testing-build.yml:85"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:232: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:248: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/4testing-build.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/4testing-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dockerhub-description-size.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/dockerhub-description-size.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:533: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:536: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:539: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:545: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:183: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:216: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:417: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:422: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secure-rebuild.yml:499: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/secure-rebuild.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stable-build.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stable-build.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stable-build.yml:167: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stable-build.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/stable-build.yml:467: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/stable-build.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-ds.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/trivy-ds.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-ds.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/trivy-ds.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-ds.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/trivy-ds.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/zap-ds.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/zap-ds.yaml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/zap-ds.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/ONLYOFFICE/Docker-DocumentServer/zap-ds.yaml/master?enable=pin", "Warn: containerImage not pinned by hash: Dockerfile:5", "Warn: containerImage not pinned by hash: Dockerfile:139", "Warn: containerImage not pinned by hash: Dockerfile:143", "Warn: containerImage not pinned by hash: production.dockerfile:8: pin your Docker image by updating onlyoffice/documentserver:latest to onlyoffice/documentserver:latest@sha256:3ab6ebc7c605e5a32b7ae3ff19daed4925090245acc8100ce2230bd766c88212", "Warn: containerImage not pinned by hash: tests/damengdb/damengdb.Dockerfile:1: pin your Docker image by updating onlyoffice/damengdb:8.1.3 to onlyoffice/damengdb:8.1.3@sha256:e3df8251975153155fefcb24ccde7aa002867d40bfab7efc179d6cb108838cc0", "Warn: containerImage not pinned by hash: tests/mssql/mssql.Dockerfile:1: pin your Docker image by updating mcr.microsoft.com/mssql/server:2022-latest to mcr.microsoft.com/mssql/server:2022-latest@sha256:ba4c8329f48fb8f02e1416be6a930ebfd71268caee78aa985f3af4315e457c89", "Warn: containerImage not pinned by hash: tests/oracle/oracle.Dockerfile:1: pin your Docker image by updating container-registry.oracle.com/database/express:21.3.0-xe to container-registry.oracle.com/database/express:21.3.0-xe@sha256:dcf137aab02d5644aaf9299aae736e4429f9bfdf860676ff398a1458ab8d23f2", "Warn: npmCommand not pinned by hash: .github/workflows/secure-rebuild.yml:263", "Info:   0 out of  16 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of  22 third-party GitHubAction dependencies pinned", "Info:   0 out of   7 containerImage dependencies pinned", "Info:   0 out of   1 npmCommand dependencies pinned"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/ONLYOFFICE/Docker-DocumentServer", "retrieved_at": "2026-10-09T07:25:49.364224+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-09T07:25:49.364224+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-09T07:25:49.364224+00:00"}], "retrieved_at": "2026-10-09T07:25:49.364224+00:00", "rank_score": 0, "rank_reasons": [], "warnings": ["Aucune taille d’archive de version récente n’a pu être confirmée."], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "RAM, espace installé et débit minimal ne sont pas publiés dans les métadonnées interrogées."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}