{"date":"2026-09-18T07:19:31Z","repo":{"name":"github.com/coder/coder","commit":"0ea777a34177fa0405f218e6eee1ab69c38fc02c"},"scorecard":{"version":"v5.5.0","commit":"c395761df6afe1a69e476bc60a013a94bcbc153f"},"score":8.6,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained","short":"Determines if the project is \"actively maintained\"."}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yaml:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool","short":"Determines if the project uses a dependency update tool."}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review","short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged."}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy","short":"Determines if the project has published a security policy."}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow","short":"Determines if the project's GitHub Action workflows avoid dangerous patterns."}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU Affero General Public License v3.0: LICENSE:0"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license","short":"Determines if the project has defined a license."}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: found token with 'none' permissions: .github/workflows/aigateway-prices-refresh.yaml:1","Info: jobLevel 'contents' permission set to 'read': .github/workflows/audit-docs-paths.yaml:62","Info: jobLevel 'contents' permission set to 'read': .github/workflows/backport.yaml:43","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/backport.yaml:110","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/cherry-pick.yaml:36","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yaml:1652","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/dependabot.yaml:22","Info: jobLevel 'contents' permission set to 'read': .github/workflows/deploy.yaml:52","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/deploy.yaml:54","Info: jobLevel 'contents' permission set to 'read': .github/workflows/doc-check.yaml:52","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/docker-base.yaml:43","Info: jobLevel 'contents' permission set to 'read': .github/workflows/docs-preview.yaml:66","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/dogfood.yaml:59","Info: jobLevel 'contents' permission set to 'read': .github/workflows/dogfood.yaml:58","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/pr-cleanup.yaml:19","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-mcp-registry.yaml:25","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yaml:68","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/stale.yaml:96","Warn: jobLevel 'actions' permission set to 'write': .github/workflows/stale.yaml:120","Info: jobLevel 'contents' permission set to 'read': .github/workflows/triage-via-chat-api.yaml:31","Info: jobLevel 'contents' permission set to 'read': .github/workflows/weekly-docs.yaml:21","Info: found token with 'none' permissions: .github/workflows/aigateway-prices-refresh.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/audit-docs-paths.yaml:50","Info: found token with 'none' permissions: .github/workflows/backport.yaml:1","Info: found token with 'none' permissions: .github/workflows/cherry-pick.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci.yaml:20","Info: topLevel 'contents' permission set to 'read': .github/workflows/contrib.yaml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependabot.yaml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy-docs.yaml:79","Info: topLevel 'contents' permission set to 'read': .github/workflows/deploy.yaml:13","Info: found token with 'none' permissions: .github/workflows/doc-check.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-base.yaml:31","Info: topLevel 'contents' permission set to 'read': .github/workflows/docs-preview.yaml:57","Info: topLevel 'contents' permission set to 'read': .github/workflows/dogfood.yaml:46","Info: topLevel 'contents' permission set to 'read': .github/workflows/flake-go.yaml:17","Info: topLevel 'contents' permission set to 'read': .github/workflows/linear-release.yaml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/nightly-gauntlet.yaml:11","Info: found token with 'none' permissions: .github/workflows/pr-auto-assign.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-cherry-pick-check.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-cleanup.yaml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-deploy.yaml:33","Info: found token with 'none' permissions: .github/workflows/publish-mcp-registry.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yaml:22","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:9","Info: topLevel 'actions' permission set to 'read': .github/workflows/security.yaml:4","Info: topLevel 'contents' permission set to 'read': .github/workflows/security.yaml:5","Info: topLevel 'contents' permission set to 'read': .github/workflows/stale.yaml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/triage-via-chat-api.yaml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/weekly-docs.yaml:14"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions","short":"Determines if the project's workflows follow the principle of least privilege."}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices","short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge."}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts","short":"Determines if the project has generated executable (binary) artifacts in the source repository."}},{"name":"Vulnerabilities","score":0,"reason":"29 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: https://osv.dev/GO-2026-6237","Warn: Project is vulnerable to: https://osv.dev/GO-2026-5761","Warn: Project is vulnerable to: https://osv.dev/GHSA-8wmf-6v46-5gfg","Warn: Project is vulnerable to: https://osv.dev/GO-2026-5932","Warn: Project is vulnerable to: https://osv.dev/GHSA-2g4f-4pwh-qvx6","Warn: Project is vulnerable to: https://osv.dev/GHSA-3jxr-9vmj-r5cp","Warn: Project is vulnerable to: https://osv.dev/GHSA-mh99-v99m-4gvg","Warn: Project is vulnerable to: https://osv.dev/GHSA-rgw5-rvv9-x895","Warn: Project is vulnerable to: https://osv.dev/GHSA-2883-xcg3-v3hh","Warn: Project is vulnerable to: https://osv.dev/GHSA-52cp-r559-cp3m","Warn: Project is vulnerable to: https://osv.dev/GHSA-5p4m-2wfm-xmqj","Warn: Project is vulnerable to: https://osv.dev/GHSA-h67p-54hq-rp68","Warn: Project is vulnerable to: https://osv.dev/GHSA-6g55-p6wh-862q","Warn: Project is vulnerable to: https://osv.dev/GHSA-fxqj-rqcc-2cmp","Warn: Project is vulnerable to: https://osv.dev/GHSA-r28c-9q8g-f849","Warn: Project is vulnerable to: https://osv.dev/GHSA-f886-m6hf-6m8v","Warn: Project is vulnerable to: https://osv.dev/GHSA-73rr-hh4g-fpgx","Warn: Project is vulnerable to: https://osv.dev/GHSA-22p9-wv53-3rq4","Warn: Project is vulnerable to: https://osv.dev/GHSA-v245-v573-v5vm","Warn: Project is vulnerable to: https://osv.dev/GHSA-38c4-r59v-3vqw","Warn: Project is vulnerable to: https://osv.dev/GHSA-6v5v-wf23-fmfq","Warn: Project is vulnerable to: https://osv.dev/GHSA-23c5-xmqv-rm74","Warn: Project is vulnerable to: https://osv.dev/GHSA-528h-pc64-c93x","Warn: Project is vulnerable to: https://osv.dev/GHSA-48c2-rrv3-qjmp","Warn: Project is vulnerable to: https://osv.dev/GHSA-hmw2-7cc7-3qxx","Warn: Project is vulnerable to: https://osv.dev/GHSA-82fw-gwwq-j7x9","Warn: Project is vulnerable to: https://osv.dev/GHSA-7w5x-hrqm-74c2","Warn: Project is vulnerable to: https://osv.dev/GHSA-v3rj-xjv7-4jmq","Warn: Project is vulnerable to: https://osv.dev/GHSA-5qjj-4xww-7phc"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities","short":"Determines if the project has open, known unfixed vulnerabilities."}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Warn: containerImage not pinned by hash: examples/parameters/build/Dockerfile:1: pin your Docker image by updating ubuntu to ubuntu@sha256:9559ceb7c21e528e233e8dff26a0fb2682f4094cce06176eeb075d87a22b31de","Warn: containerImage not pinned by hash: examples/templates/x/docker-chat-sandbox/Dockerfile.chat:1: pin your Docker image by updating codercom/enterprise-base:ubuntu to codercom/enterprise-base:ubuntu@sha256:cb63bd194081c6bcafb7d4bc9e38796b5ad859808c00cdafcc623ac5c773e418","Warn: containerImage not pinned by hash: scripts/Dockerfile:9","Warn: containerImage not pinned by hash: scripts/ironbank/Dockerfile:5","Warn: downloadThenRun not pinned by hash: dogfood/coder/ubuntu-26.04/Dockerfile.base:133-134","Warn: downloadThenRun not pinned by hash: examples/jfrog/docker/build/Dockerfile:25","Warn: downloadThenRun not pinned by hash: coderd/templatebuilder/bases/quickstart/install-languages.sh.tftpl:71","Warn: downloadThenRun not pinned by hash: examples/templates/quickstart/install-languages.sh.tftpl:61","Warn: goCommand not pinned by hash: scripts/coder-dev.sh:98","Info:  91 out of  91 GitHub-owned GitHubAction dependencies pinned","Info:  95 out of  95 third-party GitHubAction dependencies pinned","Info:   5 out of   9 containerImage dependencies pinned","Info:   0 out of   4 downloadThenRun dependencies pinned","Info:   1 out of   1 npmCommand dependencies pinned","Info:   0 out of   1 goCommand dependencies pinned"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies","short":"Determines if the project has declared and pinned the dependencies of its build process."}},{"name":"CI-Tests","score":-1,"reason":"internal error: internal error: Client.Repositories.ListCheckRunsForRef: error during graphqlHandler.setupCheckRuns: Although you appear to have the correct authorization credentials, the `bridgecrewio` organization has an IP allow list enabled, and your IP address is not permitted to access this resource.","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests","short":"Determines if the project runs tests before pull requests are merged."}},{"name":"SAST","score":-1,"reason":"internal error: internal error: Client.Checks.ListCheckRunsForRef: error during graphqlHandler.setupCheckRuns: Although you appear to have the correct authorization credentials, the `bridgecrewio` organization has an IP allow list enabled, and your IP address is not permitted to access this resource.","details":null,"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast","short":"Determines if the project uses static code analysis."}},{"name":"Signed-Releases","score":8,"reason":"5 out of the last 5 releases have a total of 5 signed artifacts.","details":["Info: signed release artifact: coder_2.34.11_checksums.txt.asc: https://github.com/coder/coder/releases/tag/v2.34.11","Info: signed release artifact: coder_2.36.5_checksums.txt.asc: https://github.com/coder/coder/releases/tag/v2.36.5","Info: signed release artifact: coder_2.37.1_checksums.txt.asc: https://github.com/coder/coder/releases/tag/v2.37.1","Info: signed release artifact: coder_2.34.10_checksums.txt.asc: https://github.com/coder/coder/releases/tag/v2.34.10","Info: signed release artifact: coder_2.37.0_checksums.txt.asc: https://github.com/coder/coder/releases/tag/v2.37.0","Warn: release artifact v2.34.11 does not have provenance: https://api.github.com/repos/coder/coder/releases/390110052","Warn: release artifact v2.36.5 does not have provenance: https://api.github.com/repos/coder/coder/releases/386329835","Warn: release artifact v2.37.1 does not have provenance: https://api.github.com/repos/coder/coder/releases/384512266","Warn: release artifact v2.34.10 does not have provenance: https://api.github.com/repos/coder/coder/releases/382588600","Warn: release artifact v2.37.0 does not have provenance: https://api.github.com/repos/coder/coder/releases/380355303"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases","short":"Determines if the project cryptographically signs release artifacts."}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: GoBuiltInFuzzer integration found: agent/agentrsa/key_test.go:40","Info: GoBuiltInFuzzer integration found: codersdk/usersecretsimport_test.go:257","Info: GoBuiltInFuzzer integration found: provisionersdk/proto/dataupload_test.go:112"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing","short":"Determines if the project uses fuzzing."}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yaml:1276"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging","short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall."}},{"name":"Branch-Protection","score":6,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'allow deletion' disabled on branch 'release/2.34'","Info: 'allow deletion' disabled on branch 'release/2.36'","Info: 'allow deletion' disabled on branch 'release/2.37'","Info: 'allow deletion' disabled on branch 'release/2.35'","Info: 'allow deletion' disabled on branch 'release/2.33'","Info: 'allow deletion' disabled on branch 'release/2.32'","Info: 'allow deletion' disabled on branch 'release/2.29'","Info: 'force pushes' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'release/2.34'","Info: 'force pushes' disabled on branch 'release/2.36'","Info: 'force pushes' disabled on branch 'release/2.37'","Info: 'force pushes' disabled on branch 'release/2.35'","Info: 'force pushes' disabled on branch 'release/2.33'","Info: 'force pushes' disabled on branch 'release/2.32'","Info: 'force pushes' disabled on branch 'release/2.29'","Warn: required approving review count is 1 on branch 'main'","Warn: required approving review count is 1 on branch 'release/2.34'","Warn: required approving review count is 1 on branch 'release/2.36'","Warn: required approving review count is 1 on branch 'release/2.37'","Warn: required approving review count is 1 on branch 'release/2.35'","Warn: required approving review count is 1 on branch 'release/2.33'","Warn: required approving review count is 1 on branch 'release/2.32'","Warn: required approving review count is 1 on branch 'release/2.29'","Warn: codeowners review is not required on branch 'main'","Warn: codeowners review is not required on branch 'release/2.34'","Warn: codeowners review is not required on branch 'release/2.36'","Warn: codeowners review is not required on branch 'release/2.37'","Warn: codeowners review is not required on branch 'release/2.35'","Warn: codeowners review is not required on branch 'release/2.33'","Warn: codeowners review is not required on branch 'release/2.32'","Warn: codeowners review is not required on branch 'release/2.29'","Info: status check found to merge onto on branch 'main'","Warn: no status checks found to merge onto branch 'release/2.34'","Warn: no status checks found to merge onto branch 'release/2.36'","Warn: no status checks found to merge onto branch 'release/2.37'","Warn: no status checks found to merge onto branch 'release/2.35'","Warn: no status checks found to merge onto branch 'release/2.33'","Warn: no status checks found to merge onto branch 'release/2.32'","Warn: no status checks found to merge onto branch 'release/2.29'","Info: PRs are required in order to make changes on branch 'main'","Info: PRs are required in order to make changes on branch 'release/2.34'","Info: PRs are required in order to make changes on branch 'release/2.36'","Info: PRs are required in order to make changes on branch 'release/2.37'","Info: PRs are required in order to make changes on branch 'release/2.35'","Info: PRs are required in order to make changes on branch 'release/2.33'","Info: PRs are required in order to make changes on branch 'release/2.32'","Info: PRs are required in order to make changes on branch 'release/2.29'"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection","short":"Determines if the default and release branches are protected with GitHub's branch protection settings."}},{"name":"Contributors","score":10,"reason":"project has 23 contributing companies or organizations","details":["Info: found contributions from: COMP6991UNSW, CryptidID, EpicGames, FactoidAuthority, Fortify-Labs, MyFactomWallet, NixOS, aerial-framework, amfphp, cdr, coder, coder formerly @smashgg, coder technologies  @coder, coder.com, hocus-dev, hodlzone, hwll, istio, pegnet, pion, soapbox-io, split-learning, spool-player"],"documentation":{"url":"https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors","short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies)."}}]}
