Security Dashboard

Weighted posture score: permissions, scanners, supply chain, token handling, and runner hardening.

Average 19.6/100

Score Distribution

200 repos · median 14.58 · 0–100 weighted posture score

0173552690–10: 6910–20: 4720–30: 3430–40: 2040–50: 1750–60: 460–70: 670–80: 380–90: 090–100: 0020406080100
RepositoryScoreToolsNext step
argoproj/argo-cd77.26github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
open-telemetry/opentelemetry-collector72.55github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
goreleaser/goreleaser70github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, gitleaks/gitleaks-action, ossf/scorecard-actionPrefer GitHub App installation tokens for automation that needs write access.
caddyserver/caddy68.33github/codeql-action/upload-sarif, ossf/scorecard-actionPrefer GitHub App installation tokens for automation that needs write access.
home-assistant/core68.33github/codeql-action/analyze, github/codeql-action/initConsider `step-security/harden-runner` for sensitive workflows.
Stirling-Tools/Stirling-PDF67.24github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
containerd/containerd61.67github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionPrefer GitHub App installation tokens for automation that needs write access.
falcosecurity/falco61.67github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionPrefer GitHub App installation tokens for automation that needs write access.
nodejs/node60.83github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
ohmyzsh/ohmyzsh58.33github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
immich-app/immich55.91github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
mermaid-js/mermaid54.4github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
nvm-sh/nvm52.5github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
n8n-io/n8n48.69aquasecurity/trivy-action, github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
electron/electron48.33github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
prometheus/prometheus45.83github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
facebook/react45-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
microsoft/TypeScript44.44github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
twbs/bootstrap44.16github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
grafana/grafana43.07aquasecurity/setup-trivy, github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
astral-sh/uv42-Set explicit `permissions:` in every workflow.
moby/moby41.67github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarifAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
mui/material-ui41.67github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
surrealdb/surrealdb41.67github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
junegunn/fzf41.45github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
neovim/neovim40.83github/codeql-action/analyze, github/codeql-action/initAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
axios/axios40-Set explicit `permissions:` in every workflow.
langchain-ai/langchain40-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
puppeteer/puppeteer40github/codeql-action/upload-sarif, ossf/scorecard-actionPrefer GitHub App installation tokens for automation that needs write access.
sveltejs/svelte40-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
anuraghazra/github-readme-stats39.88github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
astral-sh/ruff39.74-Set explicit `permissions:` in every workflow.
crewAIInc/crewAI38.71github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
obsproject/obs-studio38.06github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
pulumi/pulumi37.86-Set explicit `permissions:` in every workflow.
supabase/supabase37.73-Set explicit `permissions:` in every workflow.
openclaw/openclaw37.12github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
gin-gonic/gin35.42aquasecurity/trivy-action, github/codeql-action/analyze, github/codeql-action/init, github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
coder/code-server35.12aquasecurity/trivy-action, github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/init, github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
louislam/uptime-kuma34.72github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
pnpm/pnpm34.38github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
microsoft/promptflow34.37-Set explicit `permissions:` in every workflow.
tensorflow/tensorflow33.33github/codeql-action/upload-sarif, ossf/scorecard-actionAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
yt-dlp/yt-dlp33.33github/codeql-action/analyze, github/codeql-action/initAdd supply-chain controls such as SBOM generation, artifact attestation, dependency review, or cosign signing.
oxc-project/oxc33.06github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
mrdoob/three.js32.5github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
gradle/gradle32.08github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
angular/angular31.41github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
syncthing/syncthing31.11-Set explicit `permissions:` in every workflow.
microsoft/PowerToys30-Set explicit `permissions:` in every workflow.
aquasecurity/trivy28.33./.github/actions/trivy-triage, knqyf263/trivy-issue-actionSet explicit `permissions:` in every workflow.
strapi/strapi26.82-Set explicit `permissions:` in every workflow.
zed-industries/zed25.83-Set explicit `permissions:` in every workflow.
biomejs/biome25.47-Set explicit `permissions:` in every workflow.
BurntSushi/ripgrep25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
Effect-TS/effect25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
NVIDIA/NemoClaw25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
axolotl-ai-cloud/axolotl25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
d2l-ai/d2l-zh25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
django/django25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
gohugoio/hugo25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
infiniflow/ragflow25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
laravel/laravel25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
microsoft/generative-ai-for-beginners25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
pallets/flask25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
spring-projects/spring-boot25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
tailwindlabs/tailwindcss25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
tensorflow/models25-Add at least one CI security scanner such as CodeQL, Trivy, Semgrep, Gitleaks, or Scorecard.
ant-design/ant-design24.24-Set explicit `permissions:` in every workflow.
apache/superset24.04github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
chroma-core/chroma23.57-Set explicit `permissions:` in every workflow.
qdrant/qdrant23.33-Set explicit `permissions:` in every workflow.
microsoft/semantic-kernel23.21github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
google-gemini/gemini-cli23.15github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
python/cpython22.8github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
github/spec-kit22.62github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
pytorch/pytorch22.62github/codeql-action/upload-sarif, ossf/scorecard-actionSet explicit `permissions:` in every workflow.
openai/openai-agents-python22.22-Set explicit `permissions:` in every workflow.
EbookFoundation/free-programming-books21.43-Set explicit `permissions:` in every workflow.
iptv-org/iptv21.25-Set explicit `permissions:` in every workflow.
vitejs/vite21.25-Set explicit `permissions:` in every workflow.
vllm-project/vllm20.83-Set explicit `permissions:` in every workflow.
browser-use/browser-use20-Set explicit `permissions:` in every workflow.
redis/redis20github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
continuedev/continue19.17-Set explicit `permissions:` in every workflow.
typicode/json-server19.17-Set explicit `permissions:` in every workflow.
PrefectHQ/marvin18.75-Set explicit `permissions:` in every workflow.
fatedier/frp18.75-Set explicit `permissions:` in every workflow.
microsoft/autogen18.75github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
openai/codex18.59-Set explicit `permissions:` in every workflow.
affaan-m/everything-claude-code17.86-Set explicit `permissions:` in every workflow.
hashicorp/terraform17.5-Set explicit `permissions:` in every workflow.
clash-verge-rev/clash-verge-rev17.31-Set explicit `permissions:` in every workflow.
vuejs/core16.67-Set explicit `permissions:` in every workflow.
lobehub/lobehub16.41-Set explicit `permissions:` in every workflow.
flutter/flutter16.07-Set explicit `permissions:` in every workflow.
microsoft/vscode15.38-Set explicit `permissions:` in every workflow.
langflow-ai/langflow15.36github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
pingcap/tidb15-Set explicit `permissions:` in every workflow.
realworld-apps/realworld14.58github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
kserve/kserve14.42github/codeql-action/upload-sarif, securego/gosec, snyk/actions/dockerSet explicit `permissions:` in every workflow.
pydantic/pydantic-ai14.29-Set explicit `permissions:` in every workflow.
lancedb/lancedb14.02-Set explicit `permissions:` in every workflow.
PaddlePaddle/PaddleOCR13.89-Set explicit `permissions:` in every workflow.
langgenius/dify13.64-Set explicit `permissions:` in every workflow.
netdata/netdata13.64github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
weaviate/weaviate13.55github/codeql-action/upload-sarifSet explicit `permissions:` in every workflow.
vercel/turborepo13.46-Set explicit `permissions:` in every workflow.
Significant-Gravitas/AutoGPT13.33github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
microsoft/ML-For-Beginners13.33-Set explicit `permissions:` in every workflow.
anthropics/claude-code12.5-Set explicit `permissions:` in every workflow.
bentoml/BentoML12.5github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
elastic/elasticsearch12.5-Set explicit `permissions:` in every workflow.
freeCodeCamp/freeCodeCamp12.5-Set explicit `permissions:` in every workflow.
guidance-ai/guidance12.5-Set explicit `permissions:` in every workflow.
hoppscotch/hoppscotch12.5github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
iluwatar/java-design-patterns12.5-Set explicit `permissions:` in every workflow.
meta-pytorch/torchtune12.5-Set explicit `permissions:` in every workflow.
rust-lang/rust12.5-Set explicit `permissions:` in every workflow.
triton-inference-server/server12.5github/codeql-action/analyze, github/codeql-action/autobuild, github/codeql-action/initSet explicit `permissions:` in every workflow.
storybookjs/storybook11.67-Set explicit `permissions:` in every workflow.
laravel/framework11.36-Set explicit `permissions:` in every workflow.
mudler/LocalAI11.11github/codeql-action/upload-sarif, securego/gosecSet explicit `permissions:` in every workflow.
TabbyML/tabby10.94-Set explicit `permissions:` in every workflow.
ChatGPTNextWeb/NextChat10.71-Set explicit `permissions:` in every workflow.
vercel/next.js10.46-Set explicit `permissions:` in every workflow.
microsoft/playwright10.28-Set explicit `permissions:` in every workflow.
danny-avila/LibreChat10.24-Set explicit `permissions:` in every workflow.
anomalyco/opencode10.16-Set explicit `permissions:` in every workflow.
dottxt-ai/outlines10-Set explicit `permissions:` in every workflow.
honojs/hono10-Set explicit `permissions:` in every workflow.
cockroachdb/cockroach9.77-Set explicit `permissions:` in every workflow.
Mintplex-Labs/anything-llm9.45-Set explicit `permissions:` in every workflow.
vibrantlabsai/ragas9.38-Set explicit `permissions:` in every workflow.
deepspeedai/DeepSpeed9.26-Set explicit `permissions:` in every workflow.
jesseduffield/lazygit8.33-Set explicit `permissions:` in every workflow.
microsoft/terminal8.33-Set explicit `permissions:` in every workflow.
tesseract-ocr/tesseract8.33github/codeql-action/analyze, github/codeql-action/initSet explicit `permissions:` in every workflow.
NVIDIA/Megatron-LM8.06-Set explicit `permissions:` in every workflow.
sgl-project/sglang7.69-Set explicit `permissions:` in every workflow.
shadcn-ui/ui7.14-Set explicit `permissions:` in every workflow.
facebook/react-native6.82-Set explicit `permissions:` in every workflow.
Chalarangelo/30-seconds-of-code6.25-Set explicit `permissions:` in every workflow.
NVIDIA/TensorRT-LLM6.25-Set explicit `permissions:` in every workflow.
SWE-agent/SWE-agent6.25-Set explicit `permissions:` in every workflow.
agno-agi/agno6.25-Set explicit `permissions:` in every workflow.
unionlabs/union6.25-Set explicit `permissions:` in every workflow.
krahets/hello-algo5.77-Set explicit `permissions:` in every workflow.
fastapi/fastapi5.26-Set explicit `permissions:` in every workflow.
InternLM/lmdeploy5-Set explicit `permissions:` in every workflow.
f/prompts.chat5-Set explicit `permissions:` in every workflow.
guardrails-ai/guardrails5-Set explicit `permissions:` in every workflow.
microsoft/Web-Dev-For-Beginners5-Set explicit `permissions:` in every workflow.
2dust/v2rayN4.17-Set explicit `permissions:` in every workflow.
TheAlgorithms/Python4.17-Set explicit `permissions:` in every workflow.
hiyouga/LlamaFactory3.57-Set explicit `permissions:` in every workflow.
invoke-ai/InvokeAI3.57-Set explicit `permissions:` in every workflow.
567-labs/instructor3.12-Set explicit `permissions:` in every workflow.
huggingface/transformers2.83-Set explicit `permissions:` in every workflow.
Aider-AI/aider2.5-Set explicit `permissions:` in every workflow.
denoland/deno2.5-Set explicit `permissions:` in every workflow.
rustdesk/rustdesk2.5-Set explicit `permissions:` in every workflow.
Comfy-Org/ComfyUI2.38-Set explicit `permissions:` in every workflow.
tauri-apps/tauri2.38-Set explicit `permissions:` in every workflow.
deepset-ai/haystack2-Set explicit `permissions:` in every workflow.
ggml-org/llama.cpp1.52-Set explicit `permissions:` in every workflow.
oven-sh/bun1-Set explicit `permissions:` in every workflow.
milvus-io/milvus0.83-Set explicit `permissions:` in every workflow.
expo/expo0.62-Set explicit `permissions:` in every workflow.
3b1b/manim0-Set explicit `permissions:` in every workflow.
AUTOMATIC1111/stable-diffusion-webui0-Set explicit `permissions:` in every workflow.
Alliedium/awesome-github-actions0-Set explicit `permissions:` in every workflow.
EleutherAI/lm-evaluation-harness0-Set explicit `permissions:` in every workflow.
FoundationAgents/MetaGPT0-Set explicit `permissions:` in every workflow.
airbnb/javascript0-Set explicit `permissions:` in every workflow.
d3/d30-Set explicit `permissions:` in every workflow.
dair-ai/Prompt-Engineering-Guide0-Set explicit `permissions:` in every workflow.
doocs/advanced-java0-Set explicit `permissions:` in every workflow.
excalidraw/excalidraw0-Set explicit `permissions:` in every workflow.
facebook/create-react-app0-Set explicit `permissions:` in every workflow.
firecrawl/firecrawl0-Set explicit `permissions:` in every workflow.
godotengine/godot0-Set explicit `permissions:` in every workflow.
janhq/jan0-Set explicit `permissions:` in every workflow.
kamranahmedse/developer-roadmap0-Set explicit `permissions:` in every workflow.
localsend/localsend0-Set explicit `permissions:` in every workflow.
microsoft/markitdown0-Set explicit `permissions:` in every workflow.
modelcontextprotocol/servers0-Set explicit `permissions:` in every workflow.
nomic-ai/gpt4all0-Set explicit `permissions:` in every workflow.
ocornut/imgui0-Set explicit `permissions:` in every workflow.
ollama/ollama0-Set explicit `permissions:` in every workflow.
open-webui/open-webui0-Set explicit `permissions:` in every workflow.
openai/openai-cookbook0-Set explicit `permissions:` in every workflow.
openai/whisper0-Set explicit `permissions:` in every workflow.
opencv/opencv0-Set explicit `permissions:` in every workflow.
rasbt/LLMs-from-scratch0-Set explicit `permissions:` in every workflow.
ray-project/ray0-Set explicit `permissions:` in every workflow.
sherlock-project/sherlock0-Set explicit `permissions:` in every workflow.
stanfordnlp/dspy0-Set explicit `permissions:` in every workflow.
ventoy/Ventoy0-Set explicit `permissions:` in every workflow.
vuejs/vue0-Set explicit `permissions:` in every workflow.