{"repository": "future-architect/vuls", "owner": "future-architect", "name": "vuls", "source_url": "https://github.com/future-architect/vuls", "description": "Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices", "homepage": "https://vuls.io/", "license_id": "GPL-3.0", "license_label": "GPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 12280, "forks": 1249, "open_issues": 91, "language": "Go", "topics": ["administrator", "cybersecurity", "freebsd", "go", "golang", "linux", "security", "security-audit", "security-automation", "security-hardening", "security-scanner", "security-tools", "security-vulnerability", "vulnerabilities", "vulnerability-assessment", "vulnerability-detection", "vulnerability-management", "vulnerability-scanner", "vulnerability-scanners", "vuls"], "archived": false, "disabled": false, "updated_at": "2026-10-07T09:14:43Z", "pushed_at": "2026-10-05T06:31:59Z", "default_branch": "master", "release_tag": "v0.41.0", "release_date": "2026-09-30T03:23:32Z", "release_assets_bytes": 3108, "packages": [{"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.0", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.1", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.2", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.3", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.4", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.5", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.6", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/FUTURE-ARCHITECT/VULS", "version": "v0.1.7", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 9, "reason": "security policy file detected", "details": ["Info: security policy file detected: SECURITY.md:1", "Info: Found linked content: SECURITY.md:1", "Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy", "Info: Found text in security policy: SECURITY.md:1"]}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 10, "reason": "all changesets reviewed", "details": []}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 10, "reason": "GitHub workflow tokens follow principle of least privilege", "details": ["Info: jobLevel 'contents' permission set to 'read': .github/workflows/check-enums.yml:22", "Info: topLevel 'contents' permission set to 'read': .github/workflows/build.yml:7", "Info: found token with 'none' permissions: .github/workflows/check-enums.yml:1", "Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:27", "Info: topLevel 'contents' permission set to 'read': .github/workflows/diet-check.yml:7", "Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-publish.yml:11", "Info: topLevel 'contents' permission set to 'read': .github/workflows/golangci.yml:10", "Info: topLevel 'contents' permission set to 'read': .github/workflows/goreleaser.yml:8", "Info: found token with 'none' permissions: .github/workflows/goreleaser.yml:9", "Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:18", "Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:6", "Info: no jobLevel write permissions found"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 10, "reason": "all dependencies are pinned", "details": ["Info:  22 out of  22 GitHub-owned GitHubAction dependencies pinned", "Info:  11 out of  11 third-party GitHubAction dependencies pinned", "Info:   2 out of   2 containerImage dependencies pinned"]}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 2, "reason": "badge detected: InProgress", "details": []}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: GNU General Public License v3.0: LICENSE:0"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": 5, "reason": "branch protection is not maximal on development and all release branches", "details": ["Info: 'allow deletion' disabled on branch 'master'", "Info: 'force pushes' disabled on branch 'master'", "Info: 'branch protection settings apply to administrators' is required to merge on branch 'master'", "Info: 'stale review dismissal' is required to merge on branch 'master'", "Warn: required approving review count is 1 on branch 'master'", "Warn: codeowners review is not required on branch 'master'", "Warn: 'last push approval' is disabled on branch 'master'", "Info: 'up-to-date branches' is required to merge on branch 'master'", "Info: status check found to merge onto on branch 'master'", "Info: PRs are required in order to make changes on branch 'master'"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 8, "reason": "5 out of the last 5 releases have a total of 5 signed artifacts.", "details": ["Info: signed release artifact: future-vuls_0.40.1_darwin_amd64.tar.gz.sigstore.json: https://github.com/future-architect/vuls/releases/tag/v0.40.1", "Info: signed release artifact: future-vuls_0.40.1-rc.1_darwin_amd64.tar.gz.sigstore.json: https://github.com/future-architect/vuls/releases/tag/v0.40.1-rc.1", "Info: signed release artifact: future-vuls_0.40.0-rc.1_darwin_amd64.tar.gz.sigstore.json: https://github.com/future-architect/vuls/releases/tag/v0.40.0-rc.1", "Info: signed release artifact: future-vuls_0.39.3_darwin_amd64.tar.gz.sigstore.json: https://github.com/future-architect/vuls/releases/tag/v0.39.3", "Info: signed release artifact: future-vuls_0.39.2_darwin_amd64.tar.gz.sigstore.json: https://github.com/future-architect/vuls/releases/tag/v0.39.2", "Warn: release artifact v0.40.1 does not have provenance: https://api.github.com/repos/future-architect/vuls/releases/362148174", "Warn: release artifact v0.40.1-rc.1 does not have provenance: https://api.github.com/repos/future-architect/vuls/releases/362139606", "Warn: release artifact v0.40.0-rc.1 does not have provenance: https://api.github.com/repos/future-architect/vuls/releases/361546064", "Warn: release artifact v0.39.3 does not have provenance: https://api.github.com/repos/future-architect/vuls/releases/336472505", "Warn: release artifact v0.39.2 does not have provenance: https://api.github.com/repos/future-architect/vuls/releases/325558121"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 10, "reason": "SAST tool is run on all commits", "details": ["Info: SAST configuration detected: CodeQL", "Info: all commits (30) are checked with a SAST tool"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/docker-publish.yml:13"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/future-architect/vuls", "retrieved_at": "2026-10-07T13:40:18.025096+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-07T13:40:18.025096+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-07T13:40:18.025096+00:00"}], "retrieved_at": "2026-10-07T13:40:18.025096+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 0.0 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}