{"repository": "k3s-io/k3s", "owner": "k3s-io", "name": "k3s", "source_url": "https://github.com/k3s-io/k3s", "description": "Lightweight Kubernetes", "homepage": "https://k3s.io", "license_id": "Apache-2.0", "license_label": "Apache-2.0 déclarée", "license_status": "ouverte_permissive", "commercial_use": "possible, conditions à vérifier", "stars": 34149, "forks": 2753, "open_issues": 73, "language": "Go", "topics": ["k8s", "kubernetes"], "archived": false, "disabled": false, "updated_at": "2026-10-08T00:18:17Z", "pushed_at": "2026-10-07T19:41:42Z", "default_branch": "main", "release_tag": "v1.37.1+k3s1", "release_date": "2026-09-30T16:10:38Z", "release_assets_bytes": 359, "packages": [{"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20221017180509-3c0cd6f2dce3", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20230131205748-32086717fc7a", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20230525134105-213d7ad499e1", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20231101193147-c7c339f0b731", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20240207180616-e9cec46a23d6", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20240216143255-1c1746114c94", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20240306220405-da7312d08202", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}, {"system": "GO", "name": "github.com/k3s-io/k3s", "version": "v0.0.0-20251023015349-d50a4a894e48", "purl": "", "published_at": "", "vulnerabilities": [{"id": "GHSA-jxr7-mqhw-9p98", "modified": "2026-09-10T03:50:52.566036Z"}, {"id": "GHSA-m4hf-6vgr-75r2", "modified": "2026-09-10T03:49:58.218075Z"}, {"id": "GO-2025-3646", "modified": "2026-02-04T04:34:11.275799Z"}, {"id": "GO-2026-5973", "modified": "2026-07-28T21:00:01.782495Z"}]}], "scorecard_score": null, "scorecard_checks": [{"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 10, "reason": "security policy file detected", "details": ["Info: security policy file detected: .github/SECURITY.md:1", "Info: Found linked content: .github/SECURITY.md:1", "Info: Found disclosure, vulnerability, and/or timelines in security policy: .github/SECURITY.md:1", "Info: Found text in security policy: .github/SECURITY.md:1"]}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 10, "reason": "all changesets reviewed", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 10, "reason": "GitHub workflow tokens follow principle of least privilege", "details": ["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:182", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/stale.yml:13", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/trivy-scan.yml:17", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/updatecli.yaml:17", "Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/updatecli.yaml:18", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/updatecli.yaml:31", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/updatecli_k8s.yaml:13", "Info: topLevel 'contents' permission set to 'read': .github/workflows/actionlint.yaml:8", "Info: topLevel 'contents' permission set to 'read': .github/workflows/airgap.yaml:11", "Info: topLevel 'contents' permission set to 'read': .github/workflows/build-k3s.yaml:26", "Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:9", "Info: topLevel 'contents' permission set to 'read': .github/workflows/e2e.yaml:31", "Info: topLevel 'contents' permission set to 'read': .github/workflows/epic.yaml:7", "Info: topLevel permissions set to 'read-all': .github/workflows/govulncheck.yml:10", "Info: topLevel 'contents' permission set to 'read': .github/workflows/install.yaml:22", "Info: topLevel 'contents' permission set to 'read': .github/workflows/integration.yaml:27", "Info: topLevel 'contents' permission set to 'read': .github/workflows/issue-filter.yaml:8", "Info: topLevel 'contents' permission set to 'read': .github/workflows/nightly-install.yaml:8", "Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yml:9", "Info: topLevel 'packages' permission set to 'read': .github/workflows/release.yml:10", "Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:18", "Info: topLevel 'contents' permission set to 'read': .github/workflows/stale.yml:7", "Info: topLevel 'contents' permission set to 'read': .github/workflows/trivy-scan.yml:10", "Info: topLevel 'contents' permission set to 'read': .github/workflows/trivy-trigger.yml:14", "Info: topLevel 'contents' permission set to 'read': .github/workflows/unitcoverage.yaml:26", "Info: topLevel 'contents' permission set to 'read': .github/workflows/updatecli.yaml:11", "Info: topLevel 'contents' permission set to 'read': .github/workflows/updatecli_k8s.yaml:7", "Info: topLevel 'contents' permission set to 'read': .github/workflows/validate.yaml:16"]}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 5, "reason": "badge detected: Passing", "details": []}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE:0", "Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 10, "reason": "project is fuzzed", "details": ["Info: GoBuiltInFuzzer integration found: pkg/authenticator/hash/scrypt_test.go:41"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact v1.36.4-rc1+k3s1 not signed: https://api.github.com/repos/k3s-io/k3s/releases/374555139", "Warn: release artifact v1.35.8-rc1+k3s1 not signed: https://api.github.com/repos/k3s-io/k3s/releases/374552288", "Warn: release artifact v1.34.11-rc1+k3s1 not signed: https://api.github.com/repos/k3s-io/k3s/releases/374552471", "Warn: release artifact v1.36.3+k3s1 not signed: https://api.github.com/repos/k3s-io/k3s/releases/365110785", "Warn: release artifact v1.36.3-rc2+k3s1 not signed: https://api.github.com/repos/k3s-io/k3s/releases/361390166", "Warn: release artifact v1.36.4-rc1+k3s1 does not have provenance: https://api.github.com/repos/k3s-io/k3s/releases/374555139", "Warn: release artifact v1.35.8-rc1+k3s1 does not have provenance: https://api.github.com/repos/k3s-io/k3s/releases/374552288", "Warn: release artifact v1.34.11-rc1+k3s1 does not have provenance: https://api.github.com/repos/k3s-io/k3s/releases/374552471", "Warn: release artifact v1.36.3+k3s1 does not have provenance: https://api.github.com/repos/k3s-io/k3s/releases/365110785", "Warn: release artifact v1.36.3-rc2+k3s1 does not have provenance: https://api.github.com/repos/k3s-io/k3s/releases/361390166"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:28"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 7, "reason": "SAST tool detected but not run on all commits", "details": ["Info: SAST configuration detected: CodeQL", "Warn: 0 commits out of 30 are checked with a SAST tool"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 8, "reason": "dependency not pinned by hash detected -- score normalized to 8", "details": ["Warn: containerImage not pinned by hash: Dockerfile:4: pin your Docker image by updating tonistiigi/xx:1.6.1 to tonistiigi/xx:1.6.1@sha256:923441d7c25f1e2eb5789f82d987693c47b8ed987c4ab3b075d6ed2b5d6779a3", "Warn: containerImage not pinned by hash: Dockerfile:6: pin your Docker image by updating golang:1.26.7-alpine3.24 to golang:1.26.7-alpine3.24@sha256:28d89ee9cc0ff9fec75c82ca201e6bf7fdf9a679d4b7b24dfa04f2bb766bb468", "Warn: containerImage not pinned by hash: Dockerfile:41", "Warn: containerImage not pinned by hash: Dockerfile:60", "Warn: containerImage not pinned by hash: Dockerfile:69", "Warn: containerImage not pinned by hash: Dockerfile.manifest:2: pin your Docker image by updating golang:1.26.7-alpine3.24 to golang:1.26.7-alpine3.24@sha256:28d89ee9cc0ff9fec75c82ca201e6bf7fdf9a679d4b7b24dfa04f2bb766bb468", "Warn: containerImage not pinned by hash: Dockerfile.test:3: pin your Docker image by updating golang:1.26.7-alpine3.24 to golang:1.26.7-alpine3.24@sha256:28d89ee9cc0ff9fec75c82ca201e6bf7fdf9a679d4b7b24dfa04f2bb766bb468", "Warn: containerImage not pinned by hash: Dockerfile.test:11", "Warn: containerImage not pinned by hash: package/Dockerfile:1: pin your Docker image by updating alpine:3.24 to alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b", "Warn: containerImage not pinned by hash: tests/e2e/scripts/Dockerfile:1: pin your Docker image by updating ubuntu:26.04 to ubuntu:26.04@sha256:2260313b31c8c011cd2eebe728008efac1b3982be73eb71348ea2648d2c0e09b", "Warn: containerImage not pinned by hash: tests/integration/Dockerfile.test:1: pin your Docker image by updating golang:buster to golang:buster@sha256:eb3f9ac805435c1b2c965d63ce460988e1000058e1f67881324746362baf9572", "Warn: goCommand not pinned by hash: Dockerfile:37-39", "Info:  58 out of  58 GitHub-owned GitHubAction dependencies pinned", "Info:  42 out of  42 third-party GitHubAction dependencies pinned", "Info:   0 out of  11 containerImage dependencies pinned", "Info:   3 out of   4 goCommand dependencies pinned"]}], "known_vulnerability_count": 32, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/k3s-io/k3s", "retrieved_at": "2026-10-08T00:45:26.598868+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-08T00:45:26.598868+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-08T00:45:26.598868+00:00"}], "retrieved_at": "2026-10-08T00:45:26.598868+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 0.0 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}