{"repository": "PhilippC/keepass2android", "owner": "PhilippC", "name": "keepass2android", "source_url": "https://github.com/PhilippC/keepass2android", "description": "Password manager app for Android", "homepage": "https://play.google.com/store/apps/details?id=keepass2android.keepass2android", "license_id": "GPL-3.0", "license_label": "GPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 6278, "forks": 480, "open_issues": 1192, "language": "C#", "topics": ["android", "keepass", "keepass2", "keepass2android", "password-manager"], "archived": false, "disabled": false, "updated_at": "2026-10-08T04:58:14Z", "pushed_at": "2026-10-06T16:39:31Z", "default_branch": "main", "release_tag": "v1.15-r4", "release_date": "2026-09-14T11:35:04Z", "release_assets_bytes": 23938154, "packages": [{"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20250422154856-e5d28f097925", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20250603150717-f162e868b98b", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20251125074302-0ba4cecc05ec", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20251226130648-d4b70bc2d54d", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20260119095349-39ab696a81ec", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20260126072845-c1513bf4d55b", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20260427103333-1db0e0ac6867", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/PhilippC/keepass2android", "version": "v0.0.0-20260529115035-68ca53c1e445", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 0, "reason": "Found 0/3 approved changesets -- score normalized to 0", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": -1, "reason": "packaging workflow not detected", "details": ["Warn: no GitHub/GitLab publishing workflow detected."]}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Warn: no topLevel permission defined: .github/workflows/build.yml:1", "Warn: no topLevel permission defined: .github/workflows/release.yml:1", "Info: no jobLevel write permissions found"]}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 0, "reason": "security policy file not detected", "details": ["Warn: no security policy file detected", "Warn: no security file to analyze", "Warn: no security file to analyze", "Warn: no security file to analyze"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: license.md:0", "Info: FSF or OSI recognized license: GNU General Public License v3.0: license.md:0"]}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 0, "reason": "binaries present in source code", "details": ["Warn: binary detected: src/AdalBindings/Jars/gson-2.3.1.jar:1", "Warn: binary detected: src/DropboxBinding/dropbox-core-sdk-7.0.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/commons-logging-1.1.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-api-client-1.30.5.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-api-client-android-1.30.5.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-api-services-drive-v2-rev102-1.16.0-rc.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-http-client-1.32.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-http-client-android-1.32.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-http-client-gson-1.16.0-rc.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-http-client-jackson-1.16.0-rc.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-http-client-jackson2-1.32.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/google-oauth-client-1.30.4.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/grpc-context-1.22.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/httpclient-4.0.3.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/httpcore-4.0.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/httpmime-4.0.3.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/json_simple-1.1.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/jsr305-3.0.2.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/opencensus-api-0.24.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gdrive/opencensus-contrib-http-util-0.24.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/gson-2.8.6.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/jackson-core-2.13.5.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/jsch-2.27.2.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/okhttp-4.12.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/okhttp-digest-3.1.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/okio-3.6.0.jar:1", "Warn: binary detected: src/JavaFileStorageBindings/okio-jvm-3.6.0.jar:1", "Warn: binary detected: src/PCloudBindings/pcloud-sdk-java-core-1.9.1.jar:1", "Warn: binary detected: src/java/JavaFileStorage/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/JavaFileStorageTest-AS/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/KP2AKdbLibrary/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/KP2ASoftkeyboard_AS/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/Keepass2AndroidPluginSDK2/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/PluginQR/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: src/java/android-filechooser-AS/gradle/wrapper/gradle-wrapper.jar:1"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact v1.15-r3 not signed: https://api.github.com/repos/PhilippC/keepass2android/releases/356653392", "Warn: release artifact v1.15-r2 not signed: https://api.github.com/repos/PhilippC/keepass2android/releases/331602614", "Warn: release artifact v1.16-pre1 not signed: https://api.github.com/repos/PhilippC/keepass2android/releases/320434547", "Warn: release artifact v1.16-pre0 not signed: https://api.github.com/repos/PhilippC/keepass2android/releases/314011173", "Warn: release artifact v1.15-r1 not signed: https://api.github.com/repos/PhilippC/keepass2android/releases/277902122", "Warn: release artifact v1.15-r3 does not have provenance: https://api.github.com/repos/PhilippC/keepass2android/releases/356653392", "Warn: release artifact v1.15-r2 does not have provenance: https://api.github.com/repos/PhilippC/keepass2android/releases/331602614", "Warn: release artifact v1.16-pre1 does not have provenance: https://api.github.com/repos/PhilippC/keepass2android/releases/320434547", "Warn: release artifact v1.16-pre0 does not have provenance: https://api.github.com/repos/PhilippC/keepass2android/releases/314011173", "Warn: release artifact v1.15-r1 does not have provenance: https://api.github.com/repos/PhilippC/keepass2android/releases/277902122"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 1, "reason": "dependency not pinned by hash detected -- score normalized to 1", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:259: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:264: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:283: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:288: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:341: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:367: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/build.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/PhilippC/keepass2android/release.yml/main?enable=pin", "Info:   0 out of   9 GitHub-owned GitHubAction dependencies pinned", "Info:   2 out of   8 third-party GitHubAction dependencies pinned"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "details": ["Warn: 0 commits out of 29 are checked with a SAST tool"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/PhilippC/keepass2android", "retrieved_at": "2026-10-08T05:44:09.913935+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-08T05:44:09.913935+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-08T05:44:09.913935+00:00"}], "retrieved_at": "2026-10-08T05:44:09.913935+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 22.8 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}