{"repository": "frappe/frappe_docker", "owner": "frappe", "name": "frappe_docker", "source_url": "https://github.com/frappe/frappe_docker", "description": "Docker environment for developing, deploying, and running Frappe applications (ERPNext and custom apps) in production and development", "homepage": "https://frappe.github.io/frappe_docker/", "license_id": "MIT", "license_label": "MIT déclarée", "license_status": "ouverte_permissive", "commercial_use": "possible, conditions à vérifier", "stars": 2585, "forks": 2741, "open_issues": 16, "language": "Python", "topics": ["apps", "business-software", "containers", "crm", "docker", "docker-compose", "erp", "erpnext", "frappe", "hrms", "self-hosted"], "archived": false, "disabled": false, "updated_at": "2026-10-07T22:25:52Z", "pushed_at": "2026-10-06T14:25:58Z", "default_branch": "main", "release_tag": "v4.0.0", "release_date": "2026-10-03T19:50:40Z", "release_assets_bytes": null, "packages": [{"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v1.0.0", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v1.0.1", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.0.0+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.0.1+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.1.0+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.1.1+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.2.0+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/frappe/frappe_docker", "version": "v2.2.1+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 0, "reason": "Found 0/11 approved changesets -- score normalized to 0", "details": []}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Info: jobLevel 'contents' permission set to 'read': .github/workflows/build_develop.yml:10", "Warn: jobLevel 'packages' permission set to 'write': .github/workflows/build_develop.yml:11", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/build_stable.yml:10", "Warn: jobLevel 'packages' permission set to 'write': .github/workflows/build_stable.yml:11", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/core-build-stable.yml:93", "Warn: topLevel 'packages' permission set to 'write': .github/workflows/app-build-image.yml:70", "Info: topLevel 'contents' permission set to 'read': .github/workflows/app-build-image.yml:69", "Warn: no topLevel permission defined: .github/workflows/build_develop.yml:1", "Warn: no topLevel permission defined: .github/workflows/build_stable.yml:1", "Warn: no topLevel permission defined: .github/workflows/core-build-bench.yml:1", "Info: topLevel 'contents' permission set to 'read': .github/workflows/core-build-develop.yml:4", "Warn: topLevel 'packages' permission set to 'write': .github/workflows/core-build-develop.yml:5", "Info: topLevel 'contents' permission set to 'read': .github/workflows/core-build-stable.yml:4", "Warn: topLevel 'packages' permission set to 'write': .github/workflows/core-build-stable.yml:5", "Info: topLevel 'contents' permission set to 'read': .github/workflows/core-build-test-images.yml:31", "Info: topLevel 'contents' permission set to 'read': .github/workflows/core-publish-images.yml:33", "Warn: topLevel 'packages' permission set to 'write': .github/workflows/core-publish-images.yml:34", "Info: topLevel 'contents' permission set to 'read': .github/workflows/docs-publish-site.yml:18", "Warn: no topLevel permission defined: .github/workflows/lint.yml:1", "Warn: no topLevel permission defined: .github/workflows/pre-commit-autoupdate.yml:1", "Warn: no topLevel permission defined: .github/workflows/stale.yml:1"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: MIT License: LICENSE:0"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": -1, "reason": "packaging workflow not detected", "details": ["Warn: no GitHub/GitLab publishing workflow detected."]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": -1, "reason": "no releases found", "details": []}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 0, "reason": "security policy file not detected", "details": ["Warn: no security policy file detected", "Warn: no security file to analyze", "Warn: no security file to analyze", "Warn: no security file to analyze"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:167: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/app-build-image.yml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/app-build-image.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-bench.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-bench.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-stable.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-stable.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-stable.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-stable.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-stable.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-stable.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-build-test-images.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-build-test-images.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/core-publish-images.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/core-publish-images.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-publish-site.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/docs-publish-site.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-publish-site.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/docs-publish-site.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-publish-site.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/docs-publish-site.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-publish-site.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/docs-publish-site.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/lint.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/lint.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/lint.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-commit-autoupdate.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/pre-commit-autoupdate.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-commit-autoupdate.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/pre-commit-autoupdate.yml/main?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/pre-commit-autoupdate.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/pre-commit-autoupdate.yml/main?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/frappe/frappe_docker/stale.yml/main?enable=pin", "Warn: containerImage not pinned by hash: images/bench/Dockerfile:1: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171", "Warn: containerImage not pinned by hash: images/bench/Dockerfile:157", "Warn: pipCommand not pinned by hash: images/bench/Dockerfile:114-122", "Warn: pipCommand not pinned by hash: images/bench/Dockerfile:114-122", "Warn: pipCommand not pinned by hash: images/bench/Dockerfile:129-132", "Warn: downloadThenRun not pinned by hash: images/bench/Dockerfile:140-152", "Warn: npmCommand not pinned by hash: images/bench/Dockerfile:140-152", "Warn: npmCommand not pinned by hash: images/bench/Dockerfile:140-152", "Warn: pipCommand not pinned by hash: .github/workflows/core-build-stable.yml:147", "Warn: pipCommand not pinned by hash: .github/workflows/core-build-test-images.yml:105", "Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:31", "Warn: pipCommand not pinned by hash: .github/workflows/pre-commit-autoupdate.yml:22", "Info:   0 out of  18 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of  22 third-party GitHubAction dependencies pinned", "Info:   0 out of   2 containerImage dependencies pinned", "Info:   0 out of   7 pipCommand dependencies pinned", "Info:   0 out of   1 downloadThenRun dependencies pinned", "Info:   0 out of   2 npmCommand dependencies pinned"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 4, "reason": "SAST tool is not run on all commits -- score normalized to 4", "details": ["Warn: 11 commits out of 25 are checked with a SAST tool"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/frappe/frappe_docker", "retrieved_at": "2026-10-07T23:40:49.370982+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-07T23:40:49.370982+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-07T23:40:49.370982+00:00"}], "retrieved_at": "2026-10-07T23:40:49.370982+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "RAM, espace installé et débit minimal ne sont pas publiés dans les métadonnées interrogées."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}