{"repository": "jitsi/jitsi-meet", "owner": "jitsi", "name": "jitsi-meet", "source_url": "https://github.com/jitsi/jitsi-meet", "description": "Jitsi Meet - Secure, Simple and Scalable Video Conferences that you use as a standalone app or embed in your web application.", "homepage": "https://jitsi.org/meet", "license_id": "Apache-2.0", "license_label": "Apache-2.0 déclarée", "license_status": "ouverte_permissive", "commercial_use": "possible, conditions à vérifier", "stars": 30053, "forks": 8075, "open_issues": 151, "language": "TypeScript", "topics": ["debian", "deep-video", "jitsi", "jitsi-meet", "scalable-video-conferences", "sfu", "video", "video-communication", "video-conferencing", "webrtc"], "archived": false, "disabled": false, "updated_at": "2026-10-07T21:36:34Z", "pushed_at": "2026-10-07T23:21:25Z", "default_branch": "master", "release_tag": "stable/jitsi-meet_11248", "release_date": "2026-09-14T13:07:11Z", "release_assets_bytes": 8240, "packages": [{"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "12.1.3", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "12.1.4", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "12.1.5", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "13.1.0", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "13.1.1", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "NPM", "name": "@jitsi/react-native-sdk", "version": "13.2.0", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/jitsi/jitsi-meet", "version": "v0.0.0-20200221123758-fb8ef366c673", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/jitsi/jitsi-meet", "version": "v0.0.0-20200225124113-202abf2a9aa2", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 10, "reason": "security policy file detected", "details": ["Info: security policy file detected: SECURITY.md:1", "Info: Found linked content: SECURITY.md:1", "Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1", "Info: Found text in security policy: SECURITY.md:1"]}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 10, "reason": "all changesets reviewed", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-rnsdk.yml:30", "Warn: no topLevel permission defined: .github/workflows/ci-lua.yml:1", "Warn: no topLevel permission defined: .github/workflows/ci.yml:1", "Warn: no topLevel permission defined: .github/workflows/prosody-plugin-tests.yml:1", "Warn: no topLevel permission defined: .github/workflows/release-rnsdk.yml:1", "Warn: no topLevel permission defined: .github/workflows/stale.yml:1", "Info: no jobLevel write permissions found"]}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 6, "reason": "binaries present in source code", "details": ["Warn: binary detected: android/gradle/wrapper/gradle-wrapper.jar:1", "Warn: binary detected: react/features/stream-effects/virtual-background/vendor/tflite/tflite-simd.wasm:1", "Warn: binary detected: react/features/stream-effects/virtual-background/vendor/tflite/tflite.wasm:1", "Warn: binary detected: twa/gradle/wrapper/gradle-wrapper.jar:1"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact stable/jitsi-meet_11146 not signed: https://api.github.com/repos/jitsi/jitsi-meet/releases/364048691", "Warn: release artifact stable/jitsi-meet_11031 not signed: https://api.github.com/repos/jitsi/jitsi-meet/releases/336090214", "Warn: release artifact stable/jitsi-meet_10978 not signed: https://api.github.com/repos/jitsi/jitsi-meet/releases/326250667", "Warn: release artifact stable/jitsi-meet_10888 not signed: https://api.github.com/repos/jitsi/jitsi-meet/releases/303232564", "Warn: release artifact stable/jitsi-meet_10741 not signed: https://api.github.com/repos/jitsi/jitsi-meet/releases/282273532", "Warn: release artifact stable/jitsi-meet_11146 does not have provenance: https://api.github.com/repos/jitsi/jitsi-meet/releases/364048691", "Warn: release artifact stable/jitsi-meet_11031 does not have provenance: https://api.github.com/repos/jitsi/jitsi-meet/releases/336090214", "Warn: release artifact stable/jitsi-meet_10978 does not have provenance: https://api.github.com/repos/jitsi/jitsi-meet/releases/326250667", "Warn: release artifact stable/jitsi-meet_10888 does not have provenance: https://api.github.com/repos/jitsi/jitsi-meet/releases/303232564", "Warn: release artifact stable/jitsi-meet_10741 does not have provenance: https://api.github.com/repos/jitsi/jitsi-meet/releases/282273532"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release-rnsdk.yml:26"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 3, "reason": "dependency not pinned by hash detected -- score normalized to 3", "details": ["Warn: containerImage not pinned by hash: tests/prosody/docker/Dockerfile:5: pin your Docker image by updating prosodyim/prosody:13.0 to prosodyim/prosody:13.0@sha256:e44a7dfedb776c8945b5c6401a3437a009b549923f7bbcb5a480c2de5f86e5d7", "Warn: containerImage not pinned by hash: tests/prosody/docker/Dockerfile:17: pin your Docker image by updating prosodyim/prosody:13.0 to prosodyim/prosody:13.0@sha256:e44a7dfedb776c8945b5c6401a3437a009b549923f7bbcb5a480c2de5f86e5d7", "Warn: downloadThenRun not pinned by hash: resources/install-letsencrypt-cert.sh:34", "Warn: npmCommand not pinned by hash: resources/update-ljm.sh:41", "Warn: npmCommand not pinned by hash: resources/update-mobile-rnsdk-version.sh:17", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:26", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:58", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:75", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:90", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:141", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:169", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:228", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:231", "Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:246", "Warn: npmCommand not pinned by hash: .github/workflows/prosody-plugin-tests.yml:39", "Warn: npmCommand not pinned by hash: .github/workflows/release-rnsdk.yml:41", "Info:  26 out of  26 GitHub-owned GitHubAction dependencies pinned", "Info:   3 out of   3 third-party GitHubAction dependencies pinned", "Info:   0 out of   1 downloadThenRun dependencies pinned", "Info:   1 out of  14 npmCommand dependencies pinned", "Info:   0 out of   2 containerImage dependencies pinned"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "details": ["Warn: 0 commits out of 30 are checked with a SAST tool"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/jitsi/jitsi-meet", "retrieved_at": "2026-10-08T01:46:25.562059+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-08T01:46:25.562059+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-08T01:46:25.562059+00:00"}], "retrieved_at": "2026-10-08T01:46:25.562059+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 0.0 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}