{"repository": "mltframework/shotcut", "owner": "mltframework", "name": "shotcut", "source_url": "https://github.com/mltframework/shotcut", "description": "cross-platform (Qt), open-source (GPLv3) video editor", "homepage": "https://www.shotcut.org", "license_id": "GPL-3.0", "license_label": "GPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 15379, "forks": 1528, "open_issues": 52, "language": "C++", "topics": ["cross-platform", "gplv3", "mlt", "shotcut", "video-editor"], "archived": false, "disabled": false, "updated_at": "2026-10-09T22:11:54Z", "pushed_at": "2026-10-06T19:36:06Z", "default_branch": "master", "release_tag": "v26.9.27", "release_date": "2026-09-28T00:29:29Z", "release_assets_bytes": 702, "packages": [{"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20150105032916-d3b13861ff7c", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20150810010702-e315b88ca1a3", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20150910054007-f24a9c91b571", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20160102030328-1fbe2d26b607", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20160201033939-8dcb3081c991", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v0.0.0-20170402040512-8de07dafef1d", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v18.11.13+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/mltframework/shotcut", "version": "v18.11.18+incompatible", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 1, "reason": "Found 3/28 approved changesets -- score normalized to 1", "details": []}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": -1, "reason": "packaging workflow not detected", "details": ["Warn: no GitHub/GitLab publishing workflow detected."]}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 0, "reason": "security policy file not detected", "details": ["Warn: no security policy file detected", "Warn: no security file to analyze", "Warn: no security file to analyze", "Warn: no security file to analyze"]}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 0, "reason": "dangerous workflow patterns detected", "details": ["Warn: script injection with untrusted input ' github.head_ref || github.ref_name ': .github/workflows/build-linux.yml:21", "Warn: script injection with untrusted input ' github.head_ref || github.ref_name ': .github/workflows/build-windows.yml:101"]}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Warn: no topLevel permission defined: .github/workflows/build-linux.yml:1", "Warn: no topLevel permission defined: .github/workflows/build-macos.yml:1", "Warn: no topLevel permission defined: .github/workflows/build-sdk-windows.yml:1", "Warn: no topLevel permission defined: .github/workflows/build-windows.yml:1", "Warn: no topLevel permission defined: .github/workflows/build-windows_arm64.yml:1", "Warn: no topLevel permission defined: .github/workflows/check-code-format.yml:1", "Warn: no topLevel permission defined: .github/workflows/check-linux-build.yml:1", "Warn: no topLevel permission defined: .github/workflows/sign-windows-from-s3.yml:1", "Info: no jobLevel write permissions found"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: COPYING:0", "Info: FSF or OSI recognized license: GNU General Public License v3.0: COPYING:0"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": 0, "reason": "branch protection not enabled on development/release branches", "details": ["Warn: branch protection not enabled for branch 'master'"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact v26.8.1 not signed: https://api.github.com/repos/mltframework/shotcut/releases/363435242", "Warn: release artifact v26.7.16 not signed: https://api.github.com/repos/mltframework/shotcut/releases/355337182", "Warn: release artifact v26.6.25 not signed: https://api.github.com/repos/mltframework/shotcut/releases/345563954", "Warn: release artifact v26.6.1 not signed: https://api.github.com/repos/mltframework/shotcut/releases/332843695", "Warn: release artifact v26.4.30 not signed: https://api.github.com/repos/mltframework/shotcut/releases/316042409", "Warn: release artifact v26.8.1 does not have provenance: https://api.github.com/repos/mltframework/shotcut/releases/363435242", "Warn: release artifact v26.7.16 does not have provenance: https://api.github.com/repos/mltframework/shotcut/releases/355337182", "Warn: release artifact v26.6.25 does not have provenance: https://api.github.com/repos/mltframework/shotcut/releases/345563954", "Warn: release artifact v26.6.1 does not have provenance: https://api.github.com/repos/mltframework/shotcut/releases/332843695", "Warn: release artifact v26.4.30 does not have provenance: https://api.github.com/repos/mltframework/shotcut/releases/316042409"]}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 3, "reason": "binaries present in source code", "details": ["Warn: binary detected: drmingw/x64/bin/dbghelp.dll:1", "Warn: binary detected: drmingw/x64/bin/drmingw.exe:1", "Warn: binary detected: drmingw/x64/bin/exchndl.dll:1", "Warn: binary detected: drmingw/x64/bin/mgwhelp.dll:1", "Warn: binary detected: drmingw/x64/bin/symsrv.dll:1", "Warn: binary detected: drmingw/x64/lib/libexchndl.a:1", "Warn: binary detected: drmingw/x64/lib/libmgwhelp.a:1"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "details": ["Warn: 0 commits out of 6 are checked with a SAST tool"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-linux.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-linux.yml:137: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-linux.yml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-linux.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-linux.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-linux.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-macos.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-macos.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-sdk-windows.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-sdk-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-sdk-windows.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-sdk-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-sdk-windows.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-sdk-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-windows.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows_arm64.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows_arm64.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-windows_arm64.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows_arm64.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-windows_arm64.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows_arm64.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows_arm64.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows_arm64.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-windows_arm64.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/build-windows_arm64.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-code-format.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/check-code-format.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-linux-build.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/check-linux-build.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sign-windows-from-s3.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/sign-windows-from-s3.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/sign-windows-from-s3.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/sign-windows-from-s3.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/sign-windows-from-s3.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/sign-windows-from-s3.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sign-windows-from-s3.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/sign-windows-from-s3.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sign-windows-from-s3.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/mltframework/shotcut/sign-windows-from-s3.yml/master?enable=pin", "Info:   0 out of  23 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of  10 third-party GitHubAction dependencies pinned"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/mltframework/shotcut", "retrieved_at": "2026-10-09T22:49:27.999306+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-09T22:49:27.999306+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-09T22:49:27.999306+00:00"}], "retrieved_at": "2026-10-09T22:49:27.999306+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 0.0 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}