{"repository": "pypa/hatch", "owner": "pypa", "name": "hatch", "source_url": "https://github.com/pypa/hatch", "description": "Modern, extensible Python project management", "homepage": "https://hatch.pypa.io/latest/", "license_id": "MIT", "license_label": "MIT déclarée", "license_status": "ouverte_permissive", "commercial_use": "possible, conditions à vérifier", "stars": 7240, "forks": 479, "open_issues": 455, "language": "Python", "topics": ["build", "cli", "packaging", "plugin", "python", "versioning", "virtualenv"], "archived": false, "disabled": false, "updated_at": "2026-10-07T10:53:51Z", "pushed_at": "2026-09-20T23:02:27Z", "default_branch": "master", "release_tag": "hatch-v1.18.1", "release_date": "2026-09-16T18:34:56Z", "release_assets_bytes": 1427400, "packages": [{"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231201032543-df34cd021d5b", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231203164921-f5fd22285c97", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231203174556-b15daaf811bb", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231203205641-751b8cab3107", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231203231006-2137d89ac0c2", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231204033434-fe663ba71f52", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231205171041-5f762984d72e", "purl": "", "published_at": "", "vulnerabilities": []}, {"system": "GO", "name": "github.com/pypa/hatch", "version": "v0.0.0-20231205174406-bbcbc4153b34", "purl": "", "published_at": "", "vulnerabilities": []}], "scorecard_score": null, "scorecard_checks": [{"name": "Code-Review", "documentation": {"shortDescription": "Determines if the project requires human code review before pull requests (aka merge requests) are merged.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#code-review"}, "score": 5, "reason": "Found 17/30 approved changesets -- score normalized to 5", "details": []}, {"name": "Maintained", "documentation": {"shortDescription": "Determines if the project is \"actively maintained\".", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#maintained"}, "score": 10, "reason": "30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10", "details": []}, {"name": "Security-Policy", "documentation": {"shortDescription": "Determines if the project has published a security policy.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#security-policy"}, "score": 9, "reason": "security policy file detected", "details": ["Info: security policy file detected: SECURITY.md:1", "Info: Found linked content: SECURITY.md:1", "Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy", "Info: Found text in security policy: SECURITY.md:1"]}, {"name": "Dangerous-Workflow", "documentation": {"shortDescription": "Determines if the project's GitHub Action workflows avoid dangerous patterns.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#dangerous-workflow"}, "score": 10, "reason": "no dangerous workflow patterns detected", "details": []}, {"name": "CII-Best-Practices", "documentation": {"shortDescription": "Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#cii-best-practices"}, "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "details": []}, {"name": "Binary-Artifacts", "documentation": {"shortDescription": "Determines if the project has generated executable (binary) artifacts in the source repository.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#binary-artifacts"}, "score": 10, "reason": "no binaries found in the repo", "details": []}, {"name": "Token-Permissions", "documentation": {"shortDescription": "Determines if the project's workflows follow the principle of least privilege.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#token-permissions"}, "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "details": ["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/build-hatch.yml:588", "Warn: jobLevel 'contents' permission set to 'write': .github/workflows/build-hatchling.yml:53", "Warn: topLevel 'contents' permission set to 'write': .github/workflows/auto-merge.yml:5", "Warn: no topLevel permission defined: .github/workflows/build-distributions.yml:1", "Info: topLevel 'contents' permission set to 'read': .github/workflows/build-hatch.yml:28", "Info: topLevel 'contents' permission set to 'read': .github/workflows/build-hatchling.yml:12", "Warn: no topLevel permission defined: .github/workflows/cli.yml:1", "Warn: no topLevel permission defined: .github/workflows/docs-dev.yml:1", "Warn: no topLevel permission defined: .github/workflows/docs-release.yml:1", "Warn: no topLevel permission defined: .github/workflows/test.yml:1"]}, {"name": "Fuzzing", "documentation": {"shortDescription": "Determines if the project uses fuzzing.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#fuzzing"}, "score": 0, "reason": "project is not fuzzed", "details": ["Warn: no fuzzer integrations found"]}, {"name": "License", "documentation": {"shortDescription": "Determines if the project has defined a license.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#license"}, "score": 10, "reason": "license file detected", "details": ["Info: project has a license file: LICENSE.txt:0", "Info: FSF or OSI recognized license: MIT License: LICENSE.txt:0"]}, {"name": "Pinned-Dependencies", "documentation": {"shortDescription": "Determines if the project has declared and pinned the dependencies of its build process.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#pinned-dependencies"}, "score": 5, "reason": "dependency not pinned by hash detected -- score normalized to 5", "details": ["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/cli.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/cli.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/cli.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/cli.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-dev.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-dev.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-release.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-release.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/docs-release.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/pypa/hatch/test.yml/master?enable=pin", "Warn: containerImage not pinned by hash: tests/index/server/devpi/Dockerfile:1: pin your Docker image by updating python:3.11-alpine to python:3.11-alpine@sha256:6857d2dae63e052057f2db389a7061188ac9a92a3fa8d402bde68f36df6fada1", "Warn: pipCommand not pinned by hash: tests/index/server/devpi/Dockerfile:3-4", "Warn: pipCommand not pinned by hash: .github/workflows/test.yml:132", "Info:  31 out of  49 GitHub-owned GitHubAction dependencies pinned", "Info:  12 out of  22 third-party GitHubAction dependencies pinned", "Info:   0 out of   1 containerImage dependencies pinned", "Info:   0 out of   2 pipCommand dependencies pinned"]}, {"name": "Signed-Releases", "documentation": {"shortDescription": "Determines if the project cryptographically signs release artifacts.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#signed-releases"}, "score": 0, "reason": "Project has not signed or included provenance with any releases.", "details": ["Warn: release artifact hatchling-v1.32.0 not signed: https://api.github.com/repos/pypa/hatch/releases/368341392", "Warn: release artifact hatch-v1.18.0 not signed: https://api.github.com/repos/pypa/hatch/releases/368342138", "Warn: release artifact hatchling-v1.31.0 not signed: https://api.github.com/repos/pypa/hatch/releases/350654789", "Warn: release artifact hatch-v1.17.1 not signed: https://api.github.com/repos/pypa/hatch/releases/350656021", "Warn: release artifact hatchling-v1.30.1 not signed: https://api.github.com/repos/pypa/hatch/releases/332833151", "Warn: release artifact hatchling-v1.32.0 does not have provenance: https://api.github.com/repos/pypa/hatch/releases/368341392", "Warn: release artifact hatch-v1.18.0 does not have provenance: https://api.github.com/repos/pypa/hatch/releases/368342138", "Warn: release artifact hatchling-v1.31.0 does not have provenance: https://api.github.com/repos/pypa/hatch/releases/350654789", "Warn: release artifact hatch-v1.17.1 does not have provenance: https://api.github.com/repos/pypa/hatch/releases/350656021", "Warn: release artifact hatchling-v1.30.1 does not have provenance: https://api.github.com/repos/pypa/hatch/releases/332833151"]}, {"name": "Branch-Protection", "documentation": {"shortDescription": "Determines if the default and release branches are protected with GitHub's branch protection settings.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#branch-protection"}, "score": 1, "reason": "branch protection is not maximal on development and all release branches", "details": ["Warn: branch protection not enabled for branch 'hatch-v1.13.x'", "Info: 'allow deletion' disabled on branch 'master'", "Info: 'force pushes' disabled on branch 'master'", "Warn: 'branch protection settings apply to administrators' is disabled on branch 'master'", "Info: 'stale review dismissal' is required to merge on branch 'master'", "Warn: required approving review count is 1 on branch 'master'", "Warn: codeowners review is not required on branch 'master'", "Warn: 'last push approval' is disabled on branch 'master'", "Warn: 'up-to-date branches' is disabled on branch 'master'", "Info: status check found to merge onto on branch 'master'", "Info: PRs are required in order to make changes on branch 'master'"]}, {"name": "Packaging", "documentation": {"shortDescription": "Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#packaging"}, "score": 10, "reason": "packaging workflow detected", "details": ["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build-hatch.yml:84"]}, {"name": "SAST", "documentation": {"shortDescription": "Determines if the project uses static code analysis.", "url": "https://github.com/ossf/scorecard/blob/d1fab88f54636ff366076edfc5c239f97b3c8e66/docs/checks.md#sast"}, "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "details": ["Warn: 0 commits out of 30 are checked with a SAST tool"]}], "known_vulnerability_count": 0, "provenance": [{"source": "GitHub REST API", "url": "https://github.com/pypa/hatch", "retrieved_at": "2026-10-07T22:37:42.081122+00:00"}, {"source": "deps.dev API", "url": "https://deps.dev/", "retrieved_at": "2026-10-07T22:37:42.081122+00:00"}, {"source": "OSV API", "url": "https://osv.dev/", "retrieved_at": "2026-10-07T22:37:42.081122+00:00"}], "retrieved_at": "2026-10-07T22:37:42.081122+00:00", "rank_score": 0, "rank_reasons": [], "warnings": [], "adaptation": {"state": "unknown", "label": "Compatibilité à vérifier", "summary": "Les métadonnées publiques ne suffisent pas à certifier la compatibilité avec votre équipement.", "factors": ["Une activité récente est visible dans les métadonnées du dépôt.", "Plus petite archive de la dernière version observée : 1.4 Mo ; ce n’est pas l’espace installé."], "checks": []}, "exclusion_reason": "", "quality_doubt": "", "description_issue": ""}