Bump go.opentelemetry.io/collector/extension/xextension from 0.141.0 to 0.143.0 by dependabot[bot] ยท Pull Request #1484 ยท nginx/agent

PackageVersionScoreDetails
gomod/github.com/hashicorp/go-version 1.8.0 ๐ŸŸข 6.6
Details
CheckScoreReason
Code-Review๐ŸŸข 7Found 8/11 approved changesets -- score normalized to 7
Packagingโš ๏ธ -1packaging workflow not detected
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Dangerous-Workflow๐ŸŸข 10no dangerous workflow patterns detected
Maintained๐ŸŸข 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practicesโš ๏ธ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
Fuzzingโš ๏ธ 0project is not fuzzed
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 6branch protection is not maximal on development and all release branches
SASTโš ๏ธ 0SAST tool is not run on all commits -- score normalized to 0
gomod/go.opentelemetry.io/collector/component 1.49.0 ๐ŸŸข 7.6
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflowโš ๏ธ 0dangerous workflow patterns detected
Dependency-Update-Tool๐ŸŸข 10update tool detected
Code-Review๐ŸŸข 10all changesets reviewed
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
CII-Best-Practices๐ŸŸข 5badge detected: Passing
SAST๐ŸŸข 9SAST tool detected but not run on all commits
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Packaging๐ŸŸข 10packaging workflow detected
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 4branch protection is not maximal on development and all release branches
Fuzzing๐ŸŸข 10project is fuzzed
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
CI-Tests๐ŸŸข 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors๐ŸŸข 10project has 45 contributing companies or organizations
gomod/go.opentelemetry.io/collector/extension 1.49.0 ๐ŸŸข 7.6
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflowโš ๏ธ 0dangerous workflow patterns detected
Dependency-Update-Tool๐ŸŸข 10update tool detected
Code-Review๐ŸŸข 10all changesets reviewed
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
CII-Best-Practices๐ŸŸข 5badge detected: Passing
SAST๐ŸŸข 9SAST tool detected but not run on all commits
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Packaging๐ŸŸข 10packaging workflow detected
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 4branch protection is not maximal on development and all release branches
Fuzzing๐ŸŸข 10project is fuzzed
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
CI-Tests๐ŸŸข 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors๐ŸŸข 10project has 45 contributing companies or organizations
gomod/go.opentelemetry.io/collector/extension/xextension 0.143.0 ๐ŸŸข 7.6
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflowโš ๏ธ 0dangerous workflow patterns detected
Dependency-Update-Tool๐ŸŸข 10update tool detected
Code-Review๐ŸŸข 10all changesets reviewed
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
CII-Best-Practices๐ŸŸข 5badge detected: Passing
SAST๐ŸŸข 9SAST tool detected but not run on all commits
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Packaging๐ŸŸข 10packaging workflow detected
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 4branch protection is not maximal on development and all release branches
Fuzzing๐ŸŸข 10project is fuzzed
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
CI-Tests๐ŸŸข 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors๐ŸŸข 10project has 45 contributing companies or organizations
gomod/go.opentelemetry.io/collector/featuregate 1.49.0 ๐ŸŸข 7.6
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflowโš ๏ธ 0dangerous workflow patterns detected
Dependency-Update-Tool๐ŸŸข 10update tool detected
Code-Review๐ŸŸข 10all changesets reviewed
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
CII-Best-Practices๐ŸŸข 5badge detected: Passing
SAST๐ŸŸข 9SAST tool detected but not run on all commits
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Packaging๐ŸŸข 10packaging workflow detected
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 4branch protection is not maximal on development and all release branches
Fuzzing๐ŸŸข 10project is fuzzed
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
CI-Tests๐ŸŸข 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors๐ŸŸข 10project has 45 contributing companies or organizations
gomod/go.opentelemetry.io/collector/pdata 1.49.0 ๐ŸŸข 7.6
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflowโš ๏ธ 0dangerous workflow patterns detected
Dependency-Update-Tool๐ŸŸข 10update tool detected
Code-Review๐ŸŸข 10all changesets reviewed
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies๐ŸŸข 10all dependencies are pinned
CII-Best-Practices๐ŸŸข 5badge detected: Passing
SAST๐ŸŸข 9SAST tool detected but not run on all commits
License๐ŸŸข 10license file detected
Signed-Releasesโš ๏ธ -1no releases found
Packaging๐ŸŸข 10packaging workflow detected
Security-Policy๐ŸŸข 10security policy file detected
Branch-Protection๐ŸŸข 4branch protection is not maximal on development and all release branches
Fuzzing๐ŸŸข 10project is fuzzed
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
CI-Tests๐ŸŸข 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors๐ŸŸข 10project has 45 contributing companies or organizations
gomod/google.golang.org/genproto/googleapis/api 0.0.0-20251029180050-ab9386a59fda ๐ŸŸข 6.6
Details
CheckScoreReason
Packagingโš ๏ธ -1packaging workflow not detected
Maintained๐ŸŸข 1011 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow๐ŸŸข 10no dangerous workflow patterns detected
Code-Review๐ŸŸข 10all changesets reviewed
Security-Policy๐ŸŸข 10security policy file detected
CII-Best-Practicesโš ๏ธ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Fuzzingโš ๏ธ 0project is not fuzzed
License๐ŸŸข 10license file detected
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Signed-Releasesโš ๏ธ -1no releases found
Branch-Protectionโš ๏ธ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Pinned-Dependenciesโš ๏ธ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
SASTโš ๏ธ 1SAST tool is not run on all commits -- score normalized to 1
gomod/google.golang.org/genproto/googleapis/rpc 0.0.0-20251029180050-ab9386a59fda ๐ŸŸข 6.6
Details
CheckScoreReason
Packagingโš ๏ธ -1packaging workflow not detected
Maintained๐ŸŸข 1011 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow๐ŸŸข 10no dangerous workflow patterns detected
Code-Review๐ŸŸข 10all changesets reviewed
Security-Policy๐ŸŸข 10security policy file detected
CII-Best-Practicesโš ๏ธ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissionsโš ๏ธ 0detected GitHub workflow tokens with excessive permissions
Fuzzingโš ๏ธ 0project is not fuzzed
License๐ŸŸข 10license file detected
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
Signed-Releasesโš ๏ธ -1no releases found
Branch-Protectionโš ๏ธ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Pinned-Dependenciesโš ๏ธ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
SASTโš ๏ธ 1SAST tool is not run on all commits -- score normalized to 1
gomod/google.golang.org/grpc 1.78.0 ๐ŸŸข 7.9
Details
CheckScoreReason
Maintained๐ŸŸข 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow๐ŸŸข 10no dangerous workflow patterns detected
Packagingโš ๏ธ -1packaging workflow not detected
Code-Review๐ŸŸข 10all changesets reviewed
Security-Policy๐ŸŸข 9security policy file detected
CII-Best-Practicesโš ๏ธ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions๐ŸŸข 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts๐ŸŸข 10no binaries found in the repo
License๐ŸŸข 10license file detected
Fuzzing๐ŸŸข 10project is fuzzed
Signed-Releasesโš ๏ธ 0Project has not signed or included provenance with any releases.
Branch-Protectionโš ๏ธ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Pinned-Dependenciesโš ๏ธ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities๐ŸŸข 100 existing vulnerabilities detected
SAST๐ŸŸข 7SAST tool detected but not run on all commits
gomod/google.golang.org/protobuf 1.36.11 UnknownUnknown