{"id":190660,"name":null,"description":"Confidential Containers Guest Tools and Components","url":"https://github.com/confidential-containers/guest-components","last_synced_at":"2025-09-10T03:56:07.461Z","repository":{"id":37767751,"uuid":"420960738","full_name":"confidential-containers/guest-components","owner":"confidential-containers","description":"Confidential Containers Guest Tools and Components","archived":false,"fork":false,"pushed_at":"2025-09-02T16:03:22.000Z","size":3744,"stargazers_count":103,"open_issues_count":85,"forks_count":119,"subscribers_count":24,"default_branch":"main","last_synced_at":"2025-09-02T18:06:41.098Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/confidential-containers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-10-25T09:33:35.000Z","updated_at":"2025-09-02T16:01:45.000Z","dependencies_parsed_at":"2023-07-12T21:16:13.821Z","dependency_job_id":"7f4f02ad-fb5b-4428-b790-bb6b1047fbe4","html_url":"https://github.com/confidential-containers/guest-components","commit_stats":null,"previous_names":["confidential-containers/guest-components","confidential-containers/image-rs"],"tags_count":14,"template":false,"template_full_name":null,"purl":"pkg:github/confidential-containers/guest-components","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/sbom","scorecard":{"id":614887,"data":{"date":"2025-08-21T01:30:29Z","repo":{"name":"github.com/confidential-containers/guest-components","commit":"7d3c55741caf3b5666775ab506c5bd152e825b9e"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":5.7,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:11","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:98","Warn: no topLevel permission defined: .github/workflows/aa_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_cc_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_crypto.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_occlum_sgx.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_release.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sample_keyprovider.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sev_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/api-server-rest-basic.yml:1","Warn: no topLevel permission defined: .github/workflows/cdh_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/dco.yml:1","Warn: no topLevel permission defined: .github/workflows/image_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/links.yml:1","Warn: no topLevel permission defined: .github/workflows/ocicrypt_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/publish-artifacts.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/rust_stable_check.yml:9","Info: found token with 'none' permissions: .github/workflows/scorecard.yaml:1","Warn: no topLevel permission defined: .github/workflows/trustee-attester.yml:1","Warn: no topLevel permission defined: .github/workflows/vendor_release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_occlum_sgx.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_occlum_sgx.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_release.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/links.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:185: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/vendor_release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/vendor_release.yml/main?enable=pin","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:4","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:19","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:40: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:b1a741487078b369e78119849663d7f1a5341ef2768798f7b7406c4240f86aef","Warn: containerImage not pinned by hash: image-rs/test_data/Dockerfile:1: pin your Docker image by updating amd64/busybox to amd64/busybox@sha256:28b3ca33313d76bf1b71792bdf620b2e8b913147e2c2cd6273920ac4189721a3","Info:   3 out of  24 GitHub-owned GitHubAction dependencies pinned","Info:   3 out of  25 third-party GitHubAction dependencies pinned","Info:   0 out of   4 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.13.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108","Warn: release artifact v0.13.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/aa_release.yml:8"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"Security-Policy","score":4,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/confidential-containers/.github/SECURITY.md:1","Warn: no linked content found","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/confidential-containers/.github/SECURITY.md:1","Info: Found text in security policy: github.com/confidential-containers/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"CI-Tests","score":10,"reason":"19 out of 19 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-2rxc-gjrp-vjhx","Warn: Project is vulnerable to: RUSTSEC-2024-0404","Warn: Project is vulnerable to: RUSTSEC-2023-0088","Warn: Project is vulnerable to: RUSTSEC-2024-0436","Warn: Project is vulnerable to: GHSA-2gh3-rmm4-6rq5","Warn: Project is vulnerable to: RUSTSEC-2024-0437","Warn: Project is vulnerable to: RUSTSEC-2023-0071","Warn: Project is vulnerable to: RUSTSEC-2023-0056 / GHSA-49hh-fprx-m68g","Warn: Project is vulnerable to: RUSTSEC-2024-0002 / GHSA-875g-mfp6-g7f9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"Contributors","score":10,"reason":"project has 38 contributing companies or organizations","details":["Info: found contributions from: Azure, IBM, alibaba cloud (aliyun) alibaba group, alibaba.inc, ant group, cloud-hypervisor, confidential-containers, connectivity, deislabs, dgplug, edgelesssys, emojisum, flatcar, hygon company, ibm, ibm research, ibm t.j. watson research center, ibm united kingdom limited, inclavare-containers, intel, kata-containers, kedgeproject, kinvolk, kubernetes, microsoft, nix-community, nix-community-bochum, northflank, openanolis, opencontainers, openyurtio, red hat, redhatofficial, rivos, rust-vmm, sigstore, transylvaniasprint, zowe"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-21T03:38:26.311Z","repository_id":37767751,"created_at":"2025-08-21T03:38:26.312Z","updated_at":"2025-08-21T03:38:26.312Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":274410129,"owners_count":25279873,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-10T02:00:12.551Z","response_time":83,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"owner":{"login":"confidential-containers","name":"Confidential Containers","uuid":"90701811","kind":"organization","description":"","email":null,"website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/90701811?v=4","repositories_count":16,"last_synced_at":"2023-03-03T21:04:33.193Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/confidential-containers","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:34:06.623Z","updated_at":"2023-03-03T21:04:33.392Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers/repositories"},"packages":[{"id":10010483,"name":"github.com/confidential-containers/guest-components","ecosystem":"go","description":null,"homepage":null,"licenses":"apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/confidential-containers/guest-components","keywords_array":[],"namespace":null,"versions_count":14,"first_release_published_at":"2022-09-06T03:32:50.000Z","latest_release_published_at":"2025-05-06T01:16:24.000Z","latest_release_number":"v0.13.0","last_synced_at":"2025-09-02T18:10:16.465Z","created_at":"2024-05-18T04:09:24.604Z","updated_at":"2025-09-03T01:13:12.960Z","registry_url":"https://pkg.go.dev/github.com/confidential-containers/guest-components","install_command":"go get github.com/confidential-containers/guest-components","documentation_url":"https://pkg.go.dev/github.com/confidential-containers/guest-components#section-documentation","metadata":{},"repo_metadata":{"id":37767751,"uuid":"420960738","full_name":"confidential-containers/guest-components","owner":"confidential-containers","description":"Confidential Containers Guest Tools and Components","archived":false,"fork":false,"pushed_at":"2025-09-02T16:03:22.000Z","size":3744,"stargazers_count":103,"open_issues_count":85,"forks_count":119,"subscribers_count":24,"default_branch":"main","last_synced_at":"2025-09-02T18:06:41.098Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/confidential-containers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-10-25T09:33:35.000Z","updated_at":"2025-09-02T16:01:45.000Z","dependencies_parsed_at":"2023-07-12T21:16:13.821Z","dependency_job_id":"7f4f02ad-fb5b-4428-b790-bb6b1047fbe4","html_url":"https://github.com/confidential-containers/guest-components","commit_stats":null,"previous_names":["confidential-containers/guest-components","confidential-containers/image-rs"],"tags_count":14,"template":false,"template_full_name":null,"purl":"pkg:github/confidential-containers/guest-components","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/sbom","scorecard":{"id":614887,"data":{"date":"2025-08-21T01:30:29Z","repo":{"name":"github.com/confidential-containers/guest-components","commit":"7d3c55741caf3b5666775ab506c5bd152e825b9e"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":5.7,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:11","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:98","Warn: no topLevel permission defined: .github/workflows/aa_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_cc_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_crypto.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_occlum_sgx.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_release.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sample_keyprovider.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sev_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/api-server-rest-basic.yml:1","Warn: no topLevel permission defined: .github/workflows/cdh_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/dco.yml:1","Warn: no topLevel permission defined: .github/workflows/image_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/links.yml:1","Warn: no topLevel permission defined: .github/workflows/ocicrypt_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/publish-artifacts.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/rust_stable_check.yml:9","Info: found token with 'none' permissions: .github/workflows/scorecard.yaml:1","Warn: no topLevel permission defined: .github/workflows/trustee-attester.yml:1","Warn: no topLevel permission defined: .github/workflows/vendor_release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_occlum_sgx.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_occlum_sgx.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_release.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/links.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:185: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/vendor_release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/vendor_release.yml/main?enable=pin","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:4","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:19","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:40: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:b1a741487078b369e78119849663d7f1a5341ef2768798f7b7406c4240f86aef","Warn: containerImage not pinned by hash: image-rs/test_data/Dockerfile:1: pin your Docker image by updating amd64/busybox to amd64/busybox@sha256:28b3ca33313d76bf1b71792bdf620b2e8b913147e2c2cd6273920ac4189721a3","Info:   3 out of  24 GitHub-owned GitHubAction dependencies pinned","Info:   3 out of  25 third-party GitHubAction dependencies pinned","Info:   0 out of   4 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.13.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108","Warn: release artifact v0.13.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/aa_release.yml:8"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"Security-Policy","score":4,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/confidential-containers/.github/SECURITY.md:1","Warn: no linked content found","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/confidential-containers/.github/SECURITY.md:1","Info: Found text in security policy: github.com/confidential-containers/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"CI-Tests","score":10,"reason":"19 out of 19 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-2rxc-gjrp-vjhx","Warn: Project is vulnerable to: RUSTSEC-2024-0404","Warn: Project is vulnerable to: RUSTSEC-2023-0088","Warn: Project is vulnerable to: RUSTSEC-2024-0436","Warn: Project is vulnerable to: GHSA-2gh3-rmm4-6rq5","Warn: Project is vulnerable to: RUSTSEC-2024-0437","Warn: Project is vulnerable to: RUSTSEC-2023-0071","Warn: Project is vulnerable to: RUSTSEC-2023-0056 / GHSA-49hh-fprx-m68g","Warn: Project is vulnerable to: RUSTSEC-2024-0002 / GHSA-875g-mfp6-g7f9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"Contributors","score":10,"reason":"project has 38 contributing companies or organizations","details":["Info: found contributions from: Azure, IBM, alibaba cloud (aliyun) alibaba group, alibaba.inc, ant group, cloud-hypervisor, confidential-containers, connectivity, deislabs, dgplug, edgelesssys, emojisum, flatcar, hygon company, ibm, ibm research, ibm t.j. watson research center, ibm united kingdom limited, inclavare-containers, intel, kata-containers, kedgeproject, kinvolk, kubernetes, microsoft, nix-community, nix-community-bochum, northflank, openanolis, opencontainers, openyurtio, red hat, redhatofficial, rivos, rust-vmm, sigstore, transylvaniasprint, zowe"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-21T03:38:26.311Z","repository_id":37767751,"created_at":"2025-08-21T03:38:26.312Z","updated_at":"2025-08-21T03:38:26.312Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":273373970,"owners_count":25093993,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-02T02:00:09.530Z","response_time":77,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"confidential-containers","name":"Confidential Containers","uuid":"90701811","kind":"organization","description":"","email":null,"website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/90701811?v=4","repositories_count":16,"last_synced_at":"2023-03-03T21:04:33.193Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/confidential-containers","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:34:06.623Z","updated_at":"2023-03-03T21:04:33.392Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers/repositories"},"tags":[{"name":"v0.13.0","sha":"0a06ef241190780840fbb0542e51b198f1f72b0b","kind":"commit","published_at":"2025-05-06T01:16:24.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.13.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.13.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.13.0/manifests"},{"name":"v0.12.0","sha":"1191f8257eb65f42892ab0328cec02e58d40de84","kind":"tag","published_at":"2025-03-28T18:47:17.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.12.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.12.0/manifests"},{"name":"v0.11.0","sha":"3df6c412059f29127715c3fdbac9fa41f56cfce4","kind":"commit","published_at":"2025-01-06T16:25:07.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.11.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.11.0/manifests"},{"name":"v0.10.0","sha":"075b9a9ee77227d9d92b6f3649ef69de5e72d204","kind":"commit","published_at":"2024-09-12T08:11:31.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.10.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.10.0/manifests"},{"name":"v0.9.0","sha":"df60725afe0ba452a25a740cf460c2855442c49a","kind":"commit","published_at":"2024-06-24T12:19:37.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.9.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.9.0/manifests"},{"name":"v0.8.0","sha":"e849dc8921d2a48bec915f1a7c02f8988721022d","kind":"commit","published_at":"2023-11-01T15:08:46.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.8.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.8.0/manifests"},{"name":"v0.7.0","sha":"88dcc147ba8ddf34e8425c98d5931df8a995f04a","kind":"commit","published_at":"2023-07-17T19:59:42.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.7.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.7.0/manifests"},{"name":"v0.6.0","sha":"62288ee4cd275c3c9d02c7f650d2cad8d8920b04","kind":"commit","published_at":"2023-06-05T16:26:01.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.6.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.6.0/manifests"},{"name":"v0.5.1","sha":"767800855738c559d54b3f84810876b669ec3b83","kind":"commit","published_at":"2023-04-14T13:16:08.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.5.1","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"f03174153d1a05ce95d0d4d2e7f01b91fd5b06ad","kind":"commit","published_at":"2023-04-14T09:10:22.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.5.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.0/manifests"},{"name":"v0.4.0","sha":"948db858579be538724266a650e840e75e7e824d","kind":"commit","published_at":"2023-02-21T08:03:48.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.4.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.4.0/manifests"},{"name":"v0.3.0","sha":"cf1f7f96eb60ec4cc4aaa671c04d574a4ea0e441","kind":"commit","published_at":"2022-12-31T06:19:14.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.3.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.3.0/manifests"},{"name":"v0.2.0","sha":"3aca6fd576f50b9e960309caddeb9d91573d4e69","kind":"commit","published_at":"2022-11-07T07:55:32.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.2.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.2.0/manifests"},{"name":"v0.1.0","sha":"a1d7ba31201d9d7a575d05c5fed1f2cb2142a842","kind":"commit","published_at":"2022-09-06T03:32:50.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.1.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.1.0/manifests"}]},"repo_metadata_updated_at":"2025-09-03T01:13:12.960Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":7.830556447901925,"dependent_packages_count":7.3387047761271775,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":7.584630612014552},"purl":"pkg:golang/github.com/confidential-containers/guest-components","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/confidential-containers/guest-components","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/confidential-containers/guest-components","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/confidential-containers/guest-components/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2025-08-31T07:55:43.916Z","issues_count":20,"pull_requests_count":188,"avg_time_to_close_issue":9047350.916666666,"avg_time_to_close_pull_request":1110036.111111111,"issues_closed_count":12,"pull_requests_closed_count":135,"pull_request_authors_count":21,"issue_authors_count":16,"avg_comments_per_issue":2.1,"avg_comments_per_pull_request":0.7127659574468085,"merged_pull_requests_count":112,"bot_issues_count":0,"bot_pull_requests_count":117,"past_year_issues_count":16,"past_year_pull_requests_count":184,"past_year_avg_time_to_close_issue":2789353.5,"past_year_avg_time_to_close_pull_request":382028.8854961832,"past_year_issues_closed_count":8,"past_year_pull_requests_closed_count":131,"past_year_pull_request_authors_count":19,"past_year_issue_authors_count":14,"past_year_avg_comments_per_issue":1.625,"past_year_avg_comments_per_pull_request":0.7119565217391305,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":117,"past_year_merged_pull_requests_count":112,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/issues","maintainers":[{"login":"Xynnn007","count":122,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":20,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"jialez0","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jialez0"},{"login":"bpradipt","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"BbolroC","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"wainersm","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wainersm"},{"login":"portersrc","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"stevenhorsman","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/stevenhorsman"},{"login":"jodh-intel","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"},{"login":"fidencio","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"surajssd","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/surajssd"},{"login":"arronwy","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/arronwy"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"},{"login":"davidhadas","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/davidhadas"},{"login":"zvonkok","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zvonkok"}],"active_maintainers":[{"login":"Xynnn007","count":47,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"portersrc","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"bpradipt","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"jodh-intel","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"},{"login":"fidencio","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"BbolroC","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components/related_packages","maintainers":[],"registry":{"name":"proxy.golang.org","url":"https://proxy.golang.org","ecosystem":"go","default":true,"packages_count":1954776,"maintainers_count":0,"namespaces_count":741920,"keywords_count":109374,"github":"golang","metadata":{"funded_packages_count":49379},"icon_url":"https://github.com/golang.png","created_at":"2022-04-04T15:19:22.939Z","updated_at":"2025-09-09T06:45:13.065Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/namespaces"}},{"id":10655394,"name":"github.com/confidential-containers/guest-components/confidential-data-hub/golang","ecosystem":"go","description":"","homepage":"https://github.com/confidential-containers/guest-components","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/confidential-containers/guest-components","keywords_array":[],"namespace":"github.com/confidential-containers/guest-components/confidential-data-hub","versions_count":0,"first_release_published_at":null,"latest_release_published_at":"2025-08-06T06:42:40.560Z","latest_release_number":null,"last_synced_at":"2025-08-06T06:42:40.559Z","created_at":"2024-07-12T04:54:46.657Z","updated_at":"2025-09-03T01:13:12.961Z","registry_url":"https://pkg.go.dev/github.com/confidential-containers/guest-components/confidential-data-hub/golang","install_command":"go get github.com/confidential-containers/guest-components/confidential-data-hub/golang","documentation_url":"https://pkg.go.dev/github.com/confidential-containers/guest-components/confidential-data-hub/golang#section-documentation","metadata":{},"repo_metadata":{"id":37767751,"uuid":"420960738","full_name":"confidential-containers/guest-components","owner":"confidential-containers","description":"Confidential Containers Guest Tools and Components","archived":false,"fork":false,"pushed_at":"2025-09-02T16:03:22.000Z","size":3744,"stargazers_count":103,"open_issues_count":85,"forks_count":119,"subscribers_count":24,"default_branch":"main","last_synced_at":"2025-09-02T18:06:41.098Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/confidential-containers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-10-25T09:33:35.000Z","updated_at":"2025-09-02T16:01:45.000Z","dependencies_parsed_at":"2023-07-12T21:16:13.821Z","dependency_job_id":"7f4f02ad-fb5b-4428-b790-bb6b1047fbe4","html_url":"https://github.com/confidential-containers/guest-components","commit_stats":null,"previous_names":["confidential-containers/guest-components","confidential-containers/image-rs"],"tags_count":14,"template":false,"template_full_name":null,"purl":"pkg:github/confidential-containers/guest-components","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/sbom","scorecard":{"id":614887,"data":{"date":"2025-08-21T01:30:29Z","repo":{"name":"github.com/confidential-containers/guest-components","commit":"7d3c55741caf3b5666775ab506c5bd152e825b9e"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":5.7,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:11","Info: jobLevel 'contents' permission set to 'read': .github/workflows/publish-artifacts.yml:98","Warn: no topLevel permission defined: .github/workflows/aa_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_cc_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_crypto.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_occlum_sgx.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_release.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sample_keyprovider.yml:1","Warn: no topLevel permission defined: .github/workflows/aa_sev_kbc.yml:1","Warn: no topLevel permission defined: .github/workflows/api-server-rest-basic.yml:1","Warn: no topLevel permission defined: .github/workflows/cdh_basic.yml:1","Warn: no topLevel permission defined: .github/workflows/dco.yml:1","Warn: no topLevel permission defined: .github/workflows/image_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/links.yml:1","Warn: no topLevel permission defined: .github/workflows/ocicrypt_rs_build.yml:1","Warn: no topLevel permission defined: .github/workflows/publish-artifacts.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/rust_stable_check.yml:9","Info: found token with 'none' permissions: .github/workflows/scorecard.yaml:1","Warn: no topLevel permission defined: .github/workflows/trustee-attester.yml:1","Warn: no topLevel permission defined: .github/workflows/vendor_release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_basic.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_cc_kbc.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_cc_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_crypto.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_crypto.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_occlum_sgx.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_occlum_sgx.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_release.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sample_keyprovider.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sample_keyprovider.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/aa_sev_kbc.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/aa_sev_kbc.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/api-server-rest-basic.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/api-server-rest-basic.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cdh_basic.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/cdh_basic.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dco.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/dco.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/image_rs_build.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/image_rs_build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/links.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ocicrypt_rs_build.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/ocicrypt_rs_build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-artifacts.yml:185: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/publish-artifacts.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust_stable_check.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/rust_stable_check.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trustee-attester.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/trustee-attester.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/vendor_release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/confidential-containers/guest-components/vendor_release.yml/main?enable=pin","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:4","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:19","Warn: containerImage not pinned by hash: attestation-agent/docker/Dockerfile.keyprovider:40: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:b1a741487078b369e78119849663d7f1a5341ef2768798f7b7406c4240f86aef","Warn: containerImage not pinned by hash: image-rs/test_data/Dockerfile:1: pin your Docker image by updating amd64/busybox to amd64/busybox@sha256:28b3ca33313d76bf1b71792bdf620b2e8b913147e2c2cd6273920ac4189721a3","Info:   3 out of  24 GitHub-owned GitHubAction dependencies pinned","Info:   3 out of  25 third-party GitHubAction dependencies pinned","Info:   0 out of   4 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.13.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 not signed: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108","Warn: release artifact v0.13.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/221910919","Warn: release artifact v0.12.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/209031372","Warn: release artifact v0.11.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/197839671","Warn: release artifact v0.10.0 does not have provenance: https://api.github.com/repos/confidential-containers/guest-components/releases/174773108"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/aa_release.yml:8"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"Security-Policy","score":4,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/confidential-containers/.github/SECURITY.md:1","Warn: no linked content found","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/confidential-containers/.github/SECURITY.md:1","Info: Found text in security policy: github.com/confidential-containers/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"CI-Tests","score":10,"reason":"19 out of 19 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-2rxc-gjrp-vjhx","Warn: Project is vulnerable to: RUSTSEC-2024-0404","Warn: Project is vulnerable to: RUSTSEC-2023-0088","Warn: Project is vulnerable to: RUSTSEC-2024-0436","Warn: Project is vulnerable to: GHSA-2gh3-rmm4-6rq5","Warn: Project is vulnerable to: RUSTSEC-2024-0437","Warn: Project is vulnerable to: RUSTSEC-2023-0071","Warn: Project is vulnerable to: RUSTSEC-2023-0056 / GHSA-49hh-fprx-m68g","Warn: Project is vulnerable to: RUSTSEC-2024-0002 / GHSA-875g-mfp6-g7f9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"Contributors","score":10,"reason":"project has 38 contributing companies or organizations","details":["Info: found contributions from: Azure, IBM, alibaba cloud (aliyun) alibaba group, alibaba.inc, ant group, cloud-hypervisor, confidential-containers, connectivity, deislabs, dgplug, edgelesssys, emojisum, flatcar, hygon company, ibm, ibm research, ibm t.j. watson research center, ibm united kingdom limited, inclavare-containers, intel, kata-containers, kedgeproject, kinvolk, kubernetes, microsoft, nix-community, nix-community-bochum, northflank, openanolis, opencontainers, openyurtio, red hat, redhatofficial, rivos, rust-vmm, sigstore, transylvaniasprint, zowe"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-21T03:38:26.311Z","repository_id":37767751,"created_at":"2025-08-21T03:38:26.312Z","updated_at":"2025-08-21T03:38:26.312Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":273373970,"owners_count":25093993,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-02T02:00:09.530Z","response_time":77,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"confidential-containers","name":"Confidential Containers","uuid":"90701811","kind":"organization","description":"","email":null,"website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/90701811?v=4","repositories_count":16,"last_synced_at":"2023-03-03T21:04:33.193Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/confidential-containers","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:34:06.623Z","updated_at":"2023-03-03T21:04:33.392Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/confidential-containers/repositories"},"tags":[{"name":"v0.13.0","sha":"0a06ef241190780840fbb0542e51b198f1f72b0b","kind":"commit","published_at":"2025-05-06T01:16:24.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.13.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.13.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.13.0/manifests"},{"name":"v0.12.0","sha":"1191f8257eb65f42892ab0328cec02e58d40de84","kind":"tag","published_at":"2025-03-28T18:47:17.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.12.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.12.0/manifests"},{"name":"v0.11.0","sha":"3df6c412059f29127715c3fdbac9fa41f56cfce4","kind":"commit","published_at":"2025-01-06T16:25:07.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.11.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.11.0/manifests"},{"name":"v0.10.0","sha":"075b9a9ee77227d9d92b6f3649ef69de5e72d204","kind":"commit","published_at":"2024-09-12T08:11:31.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.10.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.10.0/manifests"},{"name":"v0.9.0","sha":"df60725afe0ba452a25a740cf460c2855442c49a","kind":"commit","published_at":"2024-06-24T12:19:37.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.9.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.9.0/manifests"},{"name":"v0.8.0","sha":"e849dc8921d2a48bec915f1a7c02f8988721022d","kind":"commit","published_at":"2023-11-01T15:08:46.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.8.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.8.0/manifests"},{"name":"v0.7.0","sha":"88dcc147ba8ddf34e8425c98d5931df8a995f04a","kind":"commit","published_at":"2023-07-17T19:59:42.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.7.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.7.0/manifests"},{"name":"v0.6.0","sha":"62288ee4cd275c3c9d02c7f650d2cad8d8920b04","kind":"commit","published_at":"2023-06-05T16:26:01.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.6.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.6.0/manifests"},{"name":"v0.5.1","sha":"767800855738c559d54b3f84810876b669ec3b83","kind":"commit","published_at":"2023-04-14T13:16:08.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.5.1","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"f03174153d1a05ce95d0d4d2e7f01b91fd5b06ad","kind":"commit","published_at":"2023-04-14T09:10:22.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.5.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.5.0/manifests"},{"name":"v0.4.0","sha":"948db858579be538724266a650e840e75e7e824d","kind":"commit","published_at":"2023-02-21T08:03:48.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.4.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.4.0/manifests"},{"name":"v0.3.0","sha":"cf1f7f96eb60ec4cc4aaa671c04d574a4ea0e441","kind":"commit","published_at":"2022-12-31T06:19:14.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.3.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.3.0/manifests"},{"name":"v0.2.0","sha":"3aca6fd576f50b9e960309caddeb9d91573d4e69","kind":"commit","published_at":"2022-11-07T07:55:32.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.2.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.2.0/manifests"},{"name":"v0.1.0","sha":"a1d7ba31201d9d7a575d05c5fed1f2cb2142a842","kind":"commit","published_at":"2022-09-06T03:32:50.000Z","download_url":"https://codeload.github.com/confidential-containers/guest-components/tar.gz/v0.1.0","html_url":"https://github.com/confidential-containers/guest-components/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/confidential-containers/guest-components@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/tags/v0.1.0/manifests"}]},"repo_metadata_updated_at":"2025-09-03T01:13:12.960Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":6.808321414509642,"dependent_packages_count":6.377797149797286,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":6.5930592821534635},"purl":"pkg:golang/github.com/confidential-containers/guest-components/confidential-data-hub/golang","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/confidential-containers/guest-components/confidential-data-hub/golang","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/confidential-containers/guest-components/confidential-data-hub/golang","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/confidential-containers/guest-components/confidential-data-hub/golang/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2025-08-31T07:55:43.916Z","issues_count":20,"pull_requests_count":188,"avg_time_to_close_issue":9047350.916666666,"avg_time_to_close_pull_request":1110036.111111111,"issues_closed_count":12,"pull_requests_closed_count":135,"pull_request_authors_count":21,"issue_authors_count":16,"avg_comments_per_issue":2.1,"avg_comments_per_pull_request":0.7127659574468085,"merged_pull_requests_count":112,"bot_issues_count":0,"bot_pull_requests_count":117,"past_year_issues_count":16,"past_year_pull_requests_count":184,"past_year_avg_time_to_close_issue":2789353.5,"past_year_avg_time_to_close_pull_request":382028.8854961832,"past_year_issues_closed_count":8,"past_year_pull_requests_closed_count":131,"past_year_pull_request_authors_count":19,"past_year_issue_authors_count":14,"past_year_avg_comments_per_issue":1.625,"past_year_avg_comments_per_pull_request":0.7119565217391305,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":117,"past_year_merged_pull_requests_count":112,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/issues","maintainers":[{"login":"Xynnn007","count":122,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":20,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"jialez0","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jialez0"},{"login":"bpradipt","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"BbolroC","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"wainersm","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wainersm"},{"login":"portersrc","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"stevenhorsman","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/stevenhorsman"},{"login":"jodh-intel","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"},{"login":"fidencio","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"surajssd","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/surajssd"},{"login":"arronwy","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/arronwy"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"},{"login":"davidhadas","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/davidhadas"},{"login":"zvonkok","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zvonkok"}],"active_maintainers":[{"login":"Xynnn007","count":47,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"portersrc","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"bpradipt","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"jodh-intel","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"},{"login":"fidencio","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"BbolroC","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components%2Fconfidential-data-hub%2Fgolang/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components%2Fconfidential-data-hub%2Fgolang/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components%2Fconfidential-data-hub%2Fgolang/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fconfidential-containers%2Fguest-components%2Fconfidential-data-hub%2Fgolang/related_packages","maintainers":[],"registry":{"name":"proxy.golang.org","url":"https://proxy.golang.org","ecosystem":"go","default":true,"packages_count":1954776,"maintainers_count":0,"namespaces_count":741920,"keywords_count":109374,"github":"golang","metadata":{"funded_packages_count":49379},"icon_url":"https://github.com/golang.png","created_at":"2022-04-04T15:19:22.939Z","updated_at":"2025-09-09T06:45:13.065Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/namespaces"}}],"commits":{"id":10869506,"full_name":"confidential-containers/guest-components","default_branch":"master","committers":null,"total_commits":null,"total_committers":null,"total_bot_commits":null,"total_bot_committers":null,"mean_commits":null,"dds":null,"past_year_committers":null,"past_year_total_commits":null,"past_year_total_committers":null,"past_year_total_bot_commits":null,"past_year_total_bot_committers":null,"past_year_mean_commits":null,"past_year_dds":null,"last_synced_at":null,"last_synced_commit":null,"created_at":"2025-09-03T01:13:12.435Z","updated_at":"2025-09-03T01:13:12.435Z","commits_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/commits","host":{"name":"GitHub","url":"https://github.com","kind":"github","last_synced_at":"2025-09-10T00:25:43.995Z","repositories_count":5545114,"commits_count":878229909,"contributors_count":32458717,"owners_count":919815,"icon_url":"https://github.com/github.png","host_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub/repositories"}},"issues_stats":{"full_name":"confidential-containers/guest-components","html_url":"https://github.com/confidential-containers/guest-components","last_synced_at":"2025-09-10T02:13:46.126Z","status":null,"issues_count":98,"pull_requests_count":548,"avg_time_to_close_issue":9154935.742424242,"avg_time_to_close_pull_request":746892.9485981308,"issues_closed_count":66,"pull_requests_closed_count":428,"pull_request_authors_count":43,"issue_authors_count":40,"avg_comments_per_issue":2.295918367346939,"avg_comments_per_pull_request":0.8448905109489051,"merged_pull_requests_count":380,"bot_issues_count":0,"bot_pull_requests_count":274,"past_year_issues_count":26,"past_year_pull_requests_count":322,"past_year_avg_time_to_close_issue":1709930.8333333333,"past_year_avg_time_to_close_pull_request":273605.7172995781,"past_year_issues_closed_count":12,"past_year_pull_requests_closed_count":237,"past_year_pull_request_authors_count":27,"past_year_issue_authors_count":19,"past_year_avg_comments_per_issue":1.1923076923076923,"past_year_avg_comments_per_pull_request":0.5559006211180124,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":203,"past_year_merged_pull_requests_count":209,"created_at":"2025-07-16T12:45:49.250Z","updated_at":"2025-09-10T03:53:19.736Z","repository_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components","issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/confidential-containers%2Fguest-components/issues","issue_labels_count":{"bug":18,"image-rs":2,"enhancement":1,"cdh":1,"2hours":1,"mid_priority":1},"pull_request_labels_count":{"dependencies":274,"rust":262,"github_actions":13,"image-rs":2,"go":1,"do-not-merge":1,"cdh":1,"enhancement":1},"issue_author_associations_count":{"MEMBER":55,"NONE":23,"CONTRIBUTOR":20,"COLLABORATOR":1},"pull_request_author_associations_count":{"CONTRIBUTOR":359,"MEMBER":158,"NONE":30},"issue_authors":{"Xynnn007":28,"mkulke":7,"bpradipt":6,"fitzthum":6,"jialez0":4,"mythi":4,"ChengyuZhu6":4,"wainersm":3,"huoqifeng":2,"fu-ju":2,"prashant9394":2,"fidencio":2,"JakubLedworowski":1,"zvonkok":1,"Amulyam24":1,"reclock":1,"stevenhorsman":1,"Toyken-P":1,"billionairiam":1,"GabyCT":1,"zzzqwqw":1,"LiuSecone":1,"etrunko":1,"briansongdev":1,"binxing":1,"panpingsheng":1,"davidhadas":1,"Apokleos":1,"surajssd":1,"ZhangLimengLimeng":1,"liudalibj":1,"portersrc":1,"David9902":1,"uril":1,"raphael-ecora":1,"elliotmtx":1,"squarti":1,"kouzili77":1,"ssolit":1,"dongx1x":1,"hashimotor-ntt":1},"pull_request_authors":{"dependabot[bot]":274,"Xynnn007":102,"mythi":26,"mkulke":25,"fitzthum":16,"ChengyuZhu6":13,"1570005763":8,"jialez0":7,"BbolroC":7,"portersrc":5,"huoqifeng":5,"jodh-intel":4,"skaegi":4,"wainersm":3,"Apokleos":3,"zny666":3,"uril":3,"arronwy":3,"stevenhorsman":3,"fidencio":2,"DGonzalezVillal":2,"pawelpros":2,"bpradipt":2,"squarti":2,"EmmEff":2,"GabyCT":2,"seungukshin":2,"surajssd":2,"musicinmybrain":1,"mathias-arm":1,"ssolit":1,"Lu-Biao":1,"gauravkuredhat":1,"pmores":1,"chathuryaadapa":1,"burgerdev":1,"cclaudio":1,"Marshal1l":1,"vuquangthinh":1,"anakrish":1,"imlk0":1,"pingzhaozz":1,"eldios":1},"host":{"name":"GitHub","url":"https://github.com","kind":"github","last_synced_at":"2025-09-10T00:00:25.260Z","repositories_count":10197696,"issues_count":32183656,"pull_requests_count":101652770,"authors_count":10742159,"icon_url":"https://github.com/github.png","host_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories","owners_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/owners","authors_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors"},"past_year_issue_labels_count":{"bug":16},"past_year_pull_request_labels_count":{"dependencies":203,"rust":191,"github_actions":12,"go":1,"enhancement":1},"past_year_issue_author_associations_count":{"MEMBER":11,"NONE":10,"CONTRIBUTOR":5},"past_year_pull_request_author_associations_count":{"CONTRIBUTOR":235,"MEMBER":69,"NONE":18},"past_year_issue_authors":{"Xynnn007":7,"mythi":2,"zzzqwqw":1,"uril":1,"ssolit":1,"squarti":1,"raphael-ecora":1,"LiuSecone":1,"liudalibj":1,"kouzili77":1,"JakubLedworowski":1,"hashimotor-ntt":1,"fu-ju":1,"fitzthum":1,"fidencio":1,"bpradipt":1,"billionairiam":1,"Apokleos":1,"Amulyam24":1},"past_year_pull_request_authors":{"dependabot[bot]":203,"Xynnn007":48,"mkulke":13,"mythi":13,"fitzthum":11,"portersrc":4,"uril":3,"Apokleos":3,"ChengyuZhu6":2,"DGonzalezVillal":2,"seungukshin":2,"EmmEff":2,"GabyCT":2,"bpradipt":1,"gauravkuredhat":1,"musicinmybrain":1,"vuquangthinh":1,"jodh-intel":1,"zny666":1,"chathuryaadapa":1,"squarti":1,"eldios":1,"Marshal1l":1,"ssolit":1,"BbolroC":1,"pmores":1,"fidencio":1},"maintainers":[{"login":"Xynnn007","count":130,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":22,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"jialez0","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jialez0"},{"login":"bpradipt","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"BbolroC","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"wainersm","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wainersm"},{"login":"portersrc","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"jodh-intel","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"},{"login":"stevenhorsman","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/stevenhorsman"},{"login":"fidencio","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"arronwy","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/arronwy"},{"login":"surajssd","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/surajssd"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"briansongdev","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/briansongdev"},{"login":"davidhadas","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/davidhadas"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"},{"login":"zvonkok","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zvonkok"}],"active_maintainers":[{"login":"Xynnn007","count":55,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Xynnn007"},{"login":"fitzthum","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fitzthum"},{"login":"portersrc","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/portersrc"},{"login":"fidencio","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fidencio"},{"login":"ChengyuZhu6","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChengyuZhu6"},{"login":"bpradipt","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bpradipt"},{"login":"BbolroC","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BbolroC"},{"login":"liudalibj","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liudalibj"},{"login":"jodh-intel","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jodh-intel"}]},"events":{"total":{"CreateEvent":164,"CommitCommentEvent":1,"ReleaseEvent":3,"IssuesEvent":57,"WatchEvent":20,"DeleteEvent":161,"IssueCommentEvent":418,"PushEvent":267,"PullRequestEvent":507,"PullRequestReviewEvent":660,"PullRequestReviewCommentEvent":339,"ForkEvent":24},"last_year":{"CreateEvent":164,"CommitCommentEvent":1,"ReleaseEvent":3,"IssuesEvent":57,"WatchEvent":20,"DeleteEvent":161,"IssueCommentEvent":418,"PushEvent":267,"PullRequestEvent":507,"PullRequestReviewEvent":660,"PullRequestReviewCommentEvent":339,"ForkEvent":24}},"keywords":[],"dependencies":[{"ecosystem":"actions","filepath":".github/workflows/dco.yml","sha":null,"kind":"manifest","created_at":"2023-02-16T04:31:08.308Z","updated_at":"2023-02-16T04:31:08.308Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/dco.yml","dependencies":[{"id":7701896854,"package_name":"tim-actions/get-pr-commits","ecosystem":"actions","requirements":"master","direct":true,"kind":"composite","optional":false},{"id":7701896870,"package_name":"tim-actions/dco","ecosystem":"actions","requirements":"master","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"cargo","filepath":"Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-02-16T04:31:08.429Z","updated_at":"2023-02-16T04:31:08.429Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/Cargo.toml","dependencies":[{"id":7701896946,"package_name":"anyhow","ecosystem":"cargo","requirements":"1","direct":true,"kind":"runtime","optional":false},{"id":7701896947,"package_name":"async-compression","ecosystem":"cargo","requirements":"0.3.15","direct":true,"kind":"runtime","optional":false},{"id":7701896948,"package_name":"async-trait","ecosystem":"cargo","requirements":"0.1.56","direct":true,"kind":"runtime","optional":false},{"id":7701896949,"package_name":"base64","ecosystem":"cargo","requirements":"0.13.0","direct":true,"kind":"runtime","optional":false},{"id":7701896950,"package_name":"dircpy","ecosystem":"cargo","requirements":"0.3.12","direct":true,"kind":"runtime","optional":false},{"id":7701896951,"package_name":"flate2","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":7701896952,"package_name":"flume","ecosystem":"cargo","requirements":"0.10.14","direct":true,"kind":"runtime","optional":false},{"id":7701896953,"package_name":"fs_extra","ecosystem":"cargo","requirements":"1.2.0","direct":true,"kind":"runtime","optional":false},{"id":7701896954,"package_name":"futures-util","ecosystem":"cargo","requirements":"0.3","direct":true,"kind":"runtime","optional":false},{"id":7701896955,"package_name":"hex","ecosystem":"cargo","requirements":"0.4.3","direct":true,"kind":"runtime","optional":false},{"id":7701896956,"package_name":"libc","ecosystem":"cargo","requirements":"0.2","direct":true,"kind":"runtime","optional":false},{"id":7701896957,"package_name":"log","ecosystem":"cargo","requirements":"0.4.14","direct":true,"kind":"runtime","optional":false},{"id":7701896958,"package_name":"nix","ecosystem":"cargo","requirements":"0.26","direct":true,"kind":"runtime","optional":false},{"id":7701896959,"package_name":"oci-distribution","ecosystem":"cargo","requirements":"0.9.4","direct":true,"kind":"runtime","optional":false},{"id":7701896960,"package_name":"oci-spec","ecosystem":"cargo","requirements":"0.5.8","direct":true,"kind":"runtime","optional":false},{"id":7701896961,"package_name":"prost","ecosystem":"cargo","requirements":"0.11","direct":true,"kind":"runtime","optional":false},{"id":7701896962,"package_name":"sequoia-openpgp","ecosystem":"cargo","requirements":"1.7.0","direct":true,"kind":"runtime","optional":false},{"id":7701896963,"package_name":"protobuf","ecosystem":"cargo","requirements":"3.2.0","direct":true,"kind":"runtime","optional":false},{"id":7701896964,"package_name":"serde","ecosystem":"cargo","requirements":"\u003e=1.0.27","direct":true,"kind":"runtime","optional":false},{"id":7701896965,"package_name":"serde_json","ecosystem":"cargo","requirements":"\u003e=1.0.9","direct":true,"kind":"runtime","optional":false},{"id":7701896966,"package_name":"serde_yaml","ecosystem":"cargo","requirements":"0.8","direct":true,"kind":"runtime","optional":false},{"id":7701896967,"package_name":"sha2","ecosystem":"cargo","requirements":"\u003e=0.10","direct":true,"kind":"runtime","optional":false},{"id":7701896968,"package_name":"sigstore","ecosystem":"cargo","requirements":"0.3.0","direct":true,"kind":"runtime","optional":false},{"id":7701896969,"package_name":"strum","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"runtime","optional":false},{"id":7701896970,"package_name":"strum_macros","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"runtime","optional":false},{"id":7701896971,"package_name":"tar","ecosystem":"cargo","requirements":"0.4.37","direct":true,"kind":"runtime","optional":false},{"id":7701896972,"package_name":"tokio","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":7701896973,"package_name":"tonic","ecosystem":"cargo","requirements":"0.8","direct":true,"kind":"runtime","optional":false},{"id":7701896974,"package_name":"url","ecosystem":"cargo","requirements":"2.2.2","direct":true,"kind":"runtime","optional":false},{"id":7701896975,"package_name":"ttrpc","ecosystem":"cargo","requirements":"0.7.1","direct":true,"kind":"runtime","optional":false},{"id":7701896976,"package_name":"walkdir","ecosystem":"cargo","requirements":"2","direct":true,"kind":"runtime","optional":false},{"id":7701896977,"package_name":"zstd","ecosystem":"cargo","requirements":"0.11","direct":true,"kind":"runtime","optional":false},{"id":7701896978,"package_name":"filetime","ecosystem":"cargo","requirements":"0.2","direct":true,"kind":"development","optional":false},{"id":7701896979,"package_name":"nix","ecosystem":"cargo","requirements":"0.26","direct":true,"kind":"development","optional":false},{"id":7701896980,"package_name":"openssl","ecosystem":"cargo","requirements":"0.10.44","direct":true,"kind":"development","optional":false},{"id":7701896981,"package_name":"rstest","ecosystem":"cargo","requirements":"0.16.0","direct":true,"kind":"development","optional":false},{"id":7701896982,"package_name":"serial_test","ecosystem":"cargo","requirements":"0.9.0","direct":true,"kind":"development","optional":false},{"id":7701896983,"package_name":"strum","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"development","optional":false},{"id":7701896984,"package_name":"strum_macros","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"development","optional":false},{"id":7701896985,"package_name":"tempfile","ecosystem":"cargo","requirements":"3.2","direct":true,"kind":"development","optional":false},{"id":7701896986,"package_name":"tokio","ecosystem":"cargo","requirements":"1","direct":true,"kind":"development","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_basic.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:06.362Z","updated_at":"2023-07-12T21:16:06.362Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_basic.yml","dependencies":[{"id":11375744666,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375744667,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375744668,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_cc_kbc.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:06.661Z","updated_at":"2023-07-12T21:16:06.661Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_cc_kbc.yml","dependencies":[{"id":11375745839,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375745843,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375745845,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_crypto.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:06.828Z","updated_at":"2023-07-12T21:16:06.828Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_crypto.yml","dependencies":[{"id":11375745861,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375745862,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375745863,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_eaa_kbc.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:06.966Z","updated_at":"2023-07-12T21:16:06.966Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_eaa_kbc.yml","dependencies":[{"id":11375745958,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_occlum_sgx.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:07.072Z","updated_at":"2023-07-12T21:16:07.072Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_occlum_sgx.yml","dependencies":[{"id":11375746053,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_release.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:07.346Z","updated_at":"2023-07-12T21:16:07.346Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_release.yml","dependencies":[{"id":11375747113,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v3","direct":true,"kind":"composite","optional":false},{"id":11375747114,"package_name":"docker/login-action","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375747115,"package_name":"docker/build-push-action","ecosystem":"actions","requirements":"v4","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_sample_keyprovider.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:07.718Z","updated_at":"2023-07-12T21:16:07.718Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_sample_keyprovider.yml","dependencies":[{"id":11375750685,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375750686,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375750687,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/aa_sev_kbc.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:08.007Z","updated_at":"2023-07-12T21:16:08.007Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/aa_sev_kbc.yml","dependencies":[{"id":11375751374,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375751375,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375751376,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/image_rs_build.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:08.495Z","updated_at":"2023-07-12T21:16:08.495Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/image_rs_build.yml","dependencies":[{"id":11375754142,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v3","direct":true,"kind":"composite","optional":false},{"id":11375754148,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375754151,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/ocicrypt_rs_build.yml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:08.845Z","updated_at":"2023-07-12T21:16:08.845Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/.github/workflows/ocicrypt_rs_build.yml","dependencies":[{"id":11375757847,"package_name":"actions/checkout","ecosystem":"actions","requirements":"v2","direct":true,"kind":"composite","optional":false},{"id":11375757853,"package_name":"actions-rs/toolchain","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false},{"id":11375757857,"package_name":"actions-rs/cargo","ecosystem":"actions","requirements":"v1","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"cargo","filepath":"attestation-agent/coco_keyprovider/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:09.023Z","updated_at":"2023-07-12T21:16:09.023Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/attestation-agent/coco_keyprovider/Cargo.toml","dependencies":[{"id":11375759483,"package_name":"aes-gcm","ecosystem":"cargo","requirements":"0.10.1","direct":true,"kind":"runtime","optional":false},{"id":11375759484,"package_name":"clap","ecosystem":"cargo","requirements":"4.0.29","direct":true,"kind":"runtime","optional":false},{"id":11375759485,"package_name":"ctr","ecosystem":"cargo","requirements":"0.9.2","direct":true,"kind":"runtime","optional":false},{"id":11375759486,"package_name":"env_logger","ecosystem":"cargo","requirements":"0.9.0","direct":true,"kind":"runtime","optional":false},{"id":11375759487,"package_name":"futures","ecosystem":"cargo","requirements":"0.3.5","direct":true,"kind":"runtime","optional":false},{"id":11375759488,"package_name":"jwt-simple","ecosystem":"cargo","requirements":"0.11.4","direct":true,"kind":"runtime","optional":false},{"id":11375759491,"package_name":"prost","ecosystem":"cargo","requirements":"0.8","direct":true,"kind":"runtime","optional":false},{"id":11375759492,"package_name":"rand","ecosystem":"cargo","requirements":"0.8.4","direct":true,"kind":"runtime","optional":false},{"id":11375759493,"package_name":"reqwest","ecosystem":"cargo","requirements":"0.11.14","direct":true,"kind":"runtime","optional":false},{"id":11375759494,"package_name":"tokio","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":11375759495,"package_name":"tonic","ecosystem":"cargo","requirements":"0.5","direct":true,"kind":"runtime","optional":false},{"id":11375759496,"package_name":"uuid","ecosystem":"cargo","requirements":"1.3.0","direct":true,"kind":"runtime","optional":false},{"id":11375759497,"package_name":"rstest","ecosystem":"cargo","requirements":"0.17.0","direct":true,"kind":"development","optional":false}]},{"ecosystem":"cargo","filepath":"attestation-agent/deps/crypto/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:09.327Z","updated_at":"2023-07-12T21:16:09.327Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/attestation-agent/deps/crypto/Cargo.toml","dependencies":[{"id":11375759865,"package_name":"aes-gcm","ecosystem":"cargo","requirements":"0.10.1","direct":true,"kind":"runtime","optional":false},{"id":11375759867,"package_name":"rsa","ecosystem":"cargo","requirements":"0.6.1","direct":true,"kind":"runtime","optional":false},{"id":11375759870,"package_name":"openssl","ecosystem":"cargo","requirements":"0.10","direct":true,"kind":"runtime","optional":false},{"id":11375759872,"package_name":"ctr","ecosystem":"cargo","requirements":"0.9.2","direct":true,"kind":"runtime","optional":false},{"id":11375759874,"package_name":"rand","ecosystem":"cargo","requirements":"0.8.5","direct":true,"kind":"runtime","optional":false},{"id":11375759875,"package_name":"sha2","ecosystem":"cargo","requirements":"0.10","direct":true,"kind":"runtime","optional":false},{"id":11375759878,"package_name":"rstest","ecosystem":"cargo","requirements":"0.17.0","direct":true,"kind":"development","optional":false}]},{"ecosystem":"cargo","filepath":"attestation-agent/kbc/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:09.636Z","updated_at":"2023-07-12T21:16:09.636Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/attestation-agent/kbc/Cargo.toml","dependencies":[{"id":11375762612,"package_name":"bincode","ecosystem":"cargo","requirements":"1.3.3","direct":true,"kind":"runtime","optional":false},{"id":11375762617,"package_name":"foreign-types","ecosystem":"cargo","requirements":"0.5.0","direct":true,"kind":"runtime","optional":false},{"id":11375762621,"package_name":"prost","ecosystem":"cargo","requirements":"0.11.0","direct":true,"kind":"runtime","optional":false},{"id":11375762623,"package_name":"tokio","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":11375762625,"package_name":"tonic","ecosystem":"cargo","requirements":"0.8.0","direct":true,"kind":"runtime","optional":false},{"id":11375762627,"package_name":"uuid","ecosystem":"cargo","requirements":"1.1.2","direct":true,"kind":"runtime","optional":false},{"id":11375762630,"package_name":"tokio","ecosystem":"cargo","requirements":"1.20.1","direct":true,"kind":"development","optional":false},{"id":11375762632,"package_name":"rstest","ecosystem":"cargo","requirements":"0.16.0","direct":true,"kind":"development","optional":false}]},{"ecosystem":"cargo","filepath":"attestation-agent/lib/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:11.589Z","updated_at":"2023-07-12T21:16:11.589Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/attestation-agent/lib/Cargo.toml","dependencies":[{"id":11375766704,"package_name":"tokio","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":11375766705,"package_name":"tonic","ecosystem":"cargo","requirements":"0.8.0","direct":true,"kind":"runtime","optional":false},{"id":11375766706,"package_name":"tokio","ecosystem":"cargo","requirements":"1.20.1","direct":true,"kind":"development","optional":false}]},{"ecosystem":"cargo","filepath":"image-rs/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:12.655Z","updated_at":"2023-07-12T21:16:12.655Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/image-rs/Cargo.toml","dependencies":[{"id":11375766826,"package_name":"anyhow","ecosystem":"cargo","requirements":"1","direct":true,"kind":"runtime","optional":false},{"id":11375766827,"package_name":"async-compression","ecosystem":"cargo","requirements":"0.3.15","direct":true,"kind":"runtime","optional":false},{"id":11375766828,"package_name":"async-trait","ecosystem":"cargo","requirements":"0.1.56","direct":true,"kind":"runtime","optional":false},{"id":11375766829,"package_name":"base64","ecosystem":"cargo","requirements":"0.13.0","direct":true,"kind":"runtime","optional":false},{"id":11375766830,"package_name":"cfg-if","ecosystem":"cargo","requirements":"1.0.0","direct":true,"kind":"runtime","optional":false},{"id":11375766831,"package_name":"dircpy","ecosystem":"cargo","requirements":"0.3.12","direct":true,"kind":"runtime","optional":false},{"id":11375766832,"package_name":"flate2","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":11375766833,"package_name":"fs_extra","ecosystem":"cargo","requirements":"1.2.0","direct":true,"kind":"runtime","optional":false},{"id":11375766834,"package_name":"futures","ecosystem":"cargo","requirements":"0.3.28","direct":true,"kind":"runtime","optional":false},{"id":11375766835,"package_name":"futures-util","ecosystem":"cargo","requirements":"0.3","direct":true,"kind":"runtime","optional":false},{"id":11375766836,"package_name":"hex","ecosystem":"cargo","requirements":"0.4.3","direct":true,"kind":"runtime","optional":false},{"id":11375766837,"package_name":"lazy_static","ecosystem":"cargo","requirements":"1.4.0","direct":true,"kind":"runtime","optional":false},{"id":11375766838,"package_name":"libc","ecosystem":"cargo","requirements":"0.2","direct":true,"kind":"runtime","optional":false},{"id":11375766839,"package_name":"log","ecosystem":"cargo","requirements":"0.4.14","direct":true,"kind":"runtime","optional":false},{"id":11375766840,"package_name":"nix","ecosystem":"cargo","requirements":"0.26","direct":true,"kind":"runtime","optional":false},{"id":11375766841,"package_name":"oci-spec","ecosystem":"cargo","requirements":"0.5.8","direct":true,"kind":"runtime","optional":false},{"id":11375766842,"package_name":"prost","ecosystem":"cargo","requirements":"0.11","direct":true,"kind":"runtime","optional":false},{"id":11375766843,"package_name":"protobuf","ecosystem":"cargo","requirements":"3.2.0","direct":true,"kind":"runtime","optional":false},{"id":11375766844,"package_name":"sequoia-openpgp","ecosystem":"cargo","requirements":"1.7.0","direct":true,"kind":"runtime","optional":false},{"id":11375766845,"package_name":"serde","ecosystem":"cargo","requirements":"\u003e=1.0.27","direct":true,"kind":"runtime","optional":false},{"id":11375766846,"package_name":"serde_json","ecosystem":"cargo","requirements":"\u003e=1.0.9","direct":true,"kind":"runtime","optional":false},{"id":11375766847,"package_name":"serde_yaml","ecosystem":"cargo","requirements":"0.9","direct":true,"kind":"runtime","optional":false},{"id":11375766848,"package_name":"sha2","ecosystem":"cargo","requirements":"\u003e=0.10","direct":true,"kind":"runtime","optional":false},{"id":11375766849,"package_name":"strum","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"runtime","optional":false},{"id":11375766850,"package_name":"strum_macros","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"runtime","optional":false},{"id":11375766851,"package_name":"tar","ecosystem":"cargo","requirements":"0.4.37","direct":true,"kind":"runtime","optional":false},{"id":11375766852,"package_name":"tokio","ecosystem":"cargo","requirements":"1.0","direct":true,"kind":"runtime","optional":false},{"id":11375766853,"package_name":"tonic","ecosystem":"cargo","requirements":"0.8","direct":true,"kind":"runtime","optional":false},{"id":11375766854,"package_name":"ttrpc","ecosystem":"cargo","requirements":"0.7.1","direct":true,"kind":"runtime","optional":false},{"id":11375766855,"package_name":"url","ecosystem":"cargo","requirements":"2.2.2","direct":true,"kind":"runtime","optional":false},{"id":11375766856,"package_name":"walkdir","ecosystem":"cargo","requirements":"2","direct":true,"kind":"runtime","optional":false},{"id":11375766857,"package_name":"zstd","ecosystem":"cargo","requirements":"0.12","direct":true,"kind":"runtime","optional":false},{"id":11375766858,"package_name":"nydus-api","ecosystem":"cargo","requirements":"0.3.0","direct":true,"kind":"runtime","optional":false},{"id":11375766907,"package_name":"nydus-service","ecosystem":"cargo","requirements":"0.3.0","direct":true,"kind":"runtime","optional":false},{"id":11375767036,"package_name":"cfg-if","ecosystem":"cargo","requirements":"1.0.0","direct":true,"kind":"development","optional":false},{"id":11375767037,"package_name":"filetime","ecosystem":"cargo","requirements":"0.2","direct":true,"kind":"development","optional":false},{"id":11375767038,"package_name":"nix","ecosystem":"cargo","requirements":"0.26","direct":true,"kind":"development","optional":false},{"id":11375767039,"package_name":"openssl","ecosystem":"cargo","requirements":"0.10.44","direct":true,"kind":"development","optional":false},{"id":11375767040,"package_name":"rstest","ecosystem":"cargo","requirements":"0.17.0","direct":true,"kind":"development","optional":false},{"id":11375767041,"package_name":"serial_test","ecosystem":"cargo","requirements":"2.0.0","direct":true,"kind":"development","optional":false},{"id":11375767042,"package_name":"strum","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"development","optional":false},{"id":11375767043,"package_name":"strum_macros","ecosystem":"cargo","requirements":"0.24","direct":true,"kind":"development","optional":false},{"id":11375767044,"package_name":"tempfile","ecosystem":"cargo","requirements":"3.2","direct":true,"kind":"development","optional":false},{"id":11375767045,"package_name":"tokio","ecosystem":"cargo","requirements":"1","direct":true,"kind":"development","optional":false}]},{"ecosystem":"cargo","filepath":"ocicrypt-rs/Cargo.toml","sha":null,"kind":"manifest","created_at":"2023-07-12T21:16:12.838Z","updated_at":"2023-07-12T21:16:12.838Z","repository_link":"https://github.com/confidential-containers/guest-components/blob/main/ocicrypt-rs/Cargo.toml","dependencies":[{"id":11375767100,"package_name":"anyhow","ecosystem":"cargo","requirements":"\u003e=1.0","direct":true,"kind":"runtime","optional":false},{"id":11375767101,"package_name":"aes","ecosystem":"cargo","requirements":"\u003e=0.8","direct":true,"kind":"runtime","optional":false},{"id":11375767102,"package_name":"async-trait","ecosystem":"cargo","requirements":"0.1.61","direct":true,"kind":"runtime","optional":false},{"id":11375767103,"package_name":"base64","ecosystem":"cargo","requirements":"0.13","direct":true,"kind":"runtime","optional":false},{"id":11375767104,"package_name":"base64-serde","ecosystem":"cargo","requirements":"0.6","direct":true,"kind":"runtime","optional":false},{"id":11375767105,"package_name":"cfg-if","ecosystem":"cargo","requirements":"1.0.0","direct":true,"kind":"runtime","optional":false},{"id":11375767106,"package_name":"ctr","ecosystem":"cargo","requirements":"\u003e=0.9","direct":true,"kind":"runtime","optional":false},{"id":11375767107,"package_name":"hmac","ecosystem":"cargo","requirements":"\u003e=0.12","direct":true,"kind":"runtime","optional":false},{"id":11375767108,"package_name":"josekit","ecosystem":"cargo","requirements":"\u003e=0.7","direct":true,"kind":"runtime","optional":false},{"id":11375767109,"package_name":"lazy_static","ecosystem":"cargo","requirements":"\u003e=1.4","direct":true,"kind":"runtime","optional":false},{"id":11375767110,"package_name":"openssl","ecosystem":"cargo","requirements":"\u003e=0.10","direct":true,"kind":"runtime","optional":false},{"id":11375767111,"package_name":"pin-project-lite","ecosystem":"cargo","requirements":"0.2.9","direct":true,"kind":"runtime","optional":false},{"id":11375767112,"package_name":"protobuf","ecosystem":"cargo","requirements":"3.2.0","direct":true,"kind":"runtime","optional":false},{"id":11375767113,"package_name":"prost","ecosystem":"cargo","requirements":"\u003e=0.11.0","direct":true,"kind":"runtime","optional":false},{"id":11375767114,"package_name":"ring","ecosystem":"cargo","requirements":"0.16.20","direct":true,"kind":"runtime","optional":false},{"id":11375767115,"package_name":"serde","ecosystem":"cargo","requirements":"\u003e=1.0","direct":true,"kind":"runtime","optional":false},{"id":11375767116,"package_name":"serde_json","ecosystem":"cargo","requirements":"\u003e=1.0","direct":true,"kind":"runtime","optional":false},{"id":11375767117,"package_name":"sha2","ecosystem":"cargo","requirements":"\u003e=0.10","direct":true,"kind":"runtime","optional":false},{"id":11375767118,"package_name":"tokio","ecosystem":"cargo","requirements":"1.17.0","direct":true,"kind":"runtime","optional":false},{"id":11375767119,"package_name":"tonic","ecosystem":"cargo","requirements":"\u003e=0.8.0","direct":true,"kind":"runtime","optional":false},{"id":11375767120,"package_name":"ttrpc","ecosystem":"cargo","requirements":"0.7.1","direct":true,"kind":"runtime","optional":false},{"id":11375767121,"package_name":"aes-gcm","ecosystem":"cargo","requirements":"0.10","direct":true,"kind":"development","optional":false},{"id":11375767122,"package_name":"openssl","ecosystem":"cargo","requirements":"\u003e=0.10","direct":true,"kind":"development","optional":false},{"id":11375767123,"package_name":"tokio","ecosystem":"cargo","requirements":"1.17.0","direct":true,"kind":"development","optional":false}]}],"score":null,"created_at":"2025-09-09T03:11:47.259Z","updated_at":"2025-10-07T08:42:24.918Z","avatar_url":"https://github.com/confidential-containers.png","language":"Rust","category":null,"sub_category":null,"monthly_downloads":0,"funding_links":[],"readme_doi_urls":[],"works":{},"citation_counts":{},"total_citations":0,"keywords_from_contributors":[],"project_url":"https://science.ecosyste.ms/api/v1/projects/190660","html_url":"https://science.ecosyste.ms/projects/190660"}