{"repository": "nilsteampassnet/TeamPass", "owner": "nilsteampassnet", "name": "TeamPass", "source_url": "https://github.com/nilsteampassnet/TeamPass", "description": "Collaborative Passwords Manager", "homepage": "https://www.teampass.net", "license_id": "GPL-3.0", "license_label": "GPL-3.0 déclarée", "license_status": "ouverte_avec_conditions", "commercial_use": "possible, obligations à vérifier", "stars": 1831, "forks": 572, "open_issues": 11, "language": "PHP", "topics": ["php"], "archived": false, "disabled": false, "updated_at": "2026-10-07T04:51:30Z", "pushed_at": "2026-10-07T05:11:40Z", "default_branch": "master", "release_tag": "3.2.2.8", "release_date": "2026-10-07T04:53:39Z", "release_assets_bytes": 2567895, "packages": [{"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260412163840-58feab336bc0", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260527111450-33076a822d1c", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260615054913-159f1262df38", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260723084858-2f271cdd62f9", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260729191936-e4406623ac60", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260802163949-4ddab1f4da97", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260807061426-6b43fc57145c", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/nilsteampassnet/TeamPass", "version": "v0.0.0-20260811131630-719b481dc733", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 0, "reason": "Found 1/11 approved changesets -- score normalized to 0", "details": []}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 9, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:24", "Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:25", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/docker-publish.yml:30", "Info: jobLevel 'contents' permission set to 'read': .github/workflows/docker-publish.yml:195", "Warn: no topLevel permission defined: .github/workflows/codeql.yml:1", "Warn: no topLevel permission defined: .github/workflows/docker-publish.yml:1", "Info: topLevel 'contents' permission set to 'read': .github/workflows/quality.yml:11"]}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 10, "reason": "security policy file detected", "details": ["Info: security policy file detected: SECURITY.md:1", "Info: Found linked content: SECURITY.md:1", "Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1", "Info: Found text in security policy: SECURITY.md:1"]}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE.md:0", "Info: FSF or OSI recognized license: GNU General Public License v3.0: LICENSE.md:0"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": -1, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "details": []}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact 3.2.2.0 not signed: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/375243995", "Warn: release artifact 3.2.1.7 not signed: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/372249661", "Warn: release artifact 3.2.1.6 not signed: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/368629188", "Warn: release artifact 3.2.1.5 not signed: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/366661671", "Warn: release artifact 3.2.1.4 not signed: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/363845080", "Warn: release artifact 3.2.2.0 does not have provenance: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/375243995", "Warn: release artifact 3.2.1.7 does not have provenance: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/372249661", "Warn: release artifact 3.2.1.6 does not have provenance: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/368629188", "Warn: release artifact 3.2.1.5 does not have provenance: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/366661671", "Warn: release artifact 3.2.1.4 does not have provenance: https://api.github.com/repos/nilsteampassnet/TeamPass/releases/363845080"]}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 9, "reason": "binaries present in source code", "details": ["Warn: binary detected: app/vendor/symfony/console/Resources/bin/hiddeninput.exe:1"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/docker-publish.yml:26"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 10, "reason": "SAST tool is run on all commits", "details": ["Info: SAST configuration detected: CodeQL", "Info: all commits (20) are checked with a SAST tool"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 0, "reason": "dependency not pinned by hash detected -- score normalized to 0", "details": ["Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: app/vendor/symfony/console/Resources/completion.bash:0", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/codeql.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/codeql.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/codeql.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/docker-publish.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quality.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/quality.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quality.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/quality.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/quality.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/quality.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quality.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/quality.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/quality.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/nilsteampassnet/TeamPass/quality.yml/master?enable=pin", "Warn: containerImage not pinned by hash: Dockerfile:10: pin your Docker image by updating composer:2.10 to composer:2.10@sha256:4d71c3c2109c61d5415544264b59ad4087e4c5b7244481723664138fd36d5040", "Warn: containerImage not pinned by hash: Dockerfile:33: pin your Docker image by updating php:8.3-fpm-alpine3.24 to php:8.3-fpm-alpine3.24@sha256:bf90236449d333cef008b1f01c72a3d4f11a6470a74629665e4c6b6158f03fc8", "Info:   0 out of  10 GitHub-owned GitHubAction dependencies pinned", "Info:   0 out of  11 third-party GitHubAction dependencies pinned", "Info:   0 out of   2 containerImage dependencies pinned"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/nilsteampassnet/TeamPass", "retrieved_at": "2026-10-08T13:24:59.602386+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-08T13:24:59.602386+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-08T13:24:59.602386+00:00"}], "retrieved_at": "2026-10-08T13:24:59.602386+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 2.4 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}