Dependency Review
✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.
OpenSSF Scorecard
| Package | Version | Score | Details |
| pip/boto3-stubs | 1.34.149 |
:green_circle: 5 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :warning: 0 | Found 0/30 approved changesets -- score normalized to 0 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | SAST | :warning: 0 | no SAST tool detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected |
|
| pip/botocore | 1.34.149 |
:green_circle: 8.5 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 2/27 approved changesets -- score normalized to 0 | | Maintained | :green_circle: 10 | 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Fuzzing | :green_circle: 10 | project is fuzzed | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected | | Pinned-Dependencies | :green_circle: 8 | dependency not pinned by hash detected -- score normalized to 8 |
|
| pip/botocore-stubs | 1.34.149 |
Unknown | Unknown |
| pip/mypy-boto3-stepfunctions | 1.34.149 |
:green_circle: 5 | Details| Check | Score | Reason |
|---|
| Maintained | :green_circle: 10 | 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10 | | Code-Review | :warning: 0 | Found 0/30 approved changesets -- score normalized to 0 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Security-Policy | :green_circle: 10 | security policy file detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Signed-Releases | :warning: -1 | no releases found | | Packaging | :warning: -1 | packaging workflow not detected | | Branch-Protection | :warning: 0 | branch protection not enabled on development/release branches | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | SAST | :warning: 0 | no SAST tool detected | | Fuzzing | :warning: 0 | project is not fuzzed | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Vulnerabilities | :green_circle: 10 | 0 existing vulnerabilities detected |
|
| pip/protobuf | 4.25.4 |
:green_circle: 7.1 | Details| Check | Score | Reason |
|---|
| Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | CI-Tests | :green_circle: 10 | 21 out of 21 merged PRs checked by a CI test -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | Code-Review | :warning: 1 | found 26 unreviewed changesets out of 30 -- score normalized to 1 | | Contributors | :green_circle: 10 | 13 different organizations found -- score normalized to 10 | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Dependency-Update-Tool | :green_circle: 10 | update tool detected | | Fuzzing | :green_circle: 10 | project is fuzzed | | License | :green_circle: 9 | license file detected | | Maintained | :green_circle: 10 | 30 commit(s) out of 30 and 3 issue activity out of 30 found in the last 90 days -- score normalized to 10 | | Packaging | :warning: -1 | no published package detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | SAST | :green_circle: 4 | SAST tool is not run on all commits -- score normalized to 4 | | Security-Policy | :green_circle: 10 | security policy file detected | | Signed-Releases | :warning: 0 | 0 out of 5 artifacts are signed or have provenance | | Token-Permissions | :green_circle: 10 | GitHub workflow tokens follow principle of least privilege | | Vulnerabilities | :green_circle: 7 | 3 existing vulnerabilities detected |
|
| pip/pulumi | 3.127.0 |
:green_circle: 6.3 | Details| Check | Score | Reason |
|---|
| Code-Review | :green_circle: 10 | all changesets reviewed | | Maintained | :green_circle: 10 | 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :green_circle: 8 | 5 out of the last 5 releases have a total of 5 signed artifacts. | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Packaging | :warning: -1 | packaging workflow not detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Binary-Artifacts | :green_circle: 9 | binaries present in source code | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Security-Policy | :green_circle: 10 | security policy file detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :green_circle: 10 | project is fuzzed | | Vulnerabilities | :warning: 0 | 10 existing vulnerabilities detected |
|
| pip/pulumi-aws | 6.47.0 |
Unknown | Unknown |
| pip/pymdown-extensions | 10.9 |
:green_circle: 5.2 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 0 | Found 2/30 approved changesets -- score normalized to 0 | | Maintained | :green_circle: 10 | 9 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 9 | license file detected | | Signed-Releases | :warning: -1 | no releases found | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Security-Policy | :green_circle: 10 | security policy file detected | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :warning: 0 | project is not fuzzed | | Packaging | :green_circle: 10 | packaging workflow detected | | SAST | :warning: 0 | SAST tool is not run on all commits -- score normalized to 0 | | Vulnerabilities | :green_circle: 4 | 6 existing vulnerabilities detected |
|
| pip/typos | 1.23.5 |
:green_circle: 4.9 | Details| Check | Score | Reason |
|---|
| Code-Review | :warning: 1 | Found 2/15 approved changesets -- score normalized to 1 | | Maintained | :green_circle: 10 | 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10 | | CII-Best-Practices | :warning: 0 | no effort to earn an OpenSSF best practices badge detected | | License | :green_circle: 10 | license file detected | | Branch-Protection | :warning: -1 | internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration | | Signed-Releases | :warning: 0 | Project has not signed or included provenance with any releases. | | Packaging | :warning: -1 | packaging workflow not detected | | Dangerous-Workflow | :green_circle: 10 | no dangerous workflow patterns detected | | Binary-Artifacts | :green_circle: 10 | no binaries found in the repo | | Token-Permissions | :warning: 0 | detected GitHub workflow tokens with excessive permissions | | Security-Policy | :warning: 0 | security policy file not detected | | Pinned-Dependencies | :warning: 0 | dependency not pinned by hash detected -- score normalized to 0 | | Fuzzing | :warning: 0 | project is not fuzzed | | SAST | :green_circle: 10 | SAST tool is run on all commits | | Vulnerabilities | :green_circle: 8 | 2 existing vulnerabilities detected |
|
Scanned Manifest Files
poetry.lock
:wave: @TreyWW, Continue working on this
If you would like to ignore this message, please reply with the reference DELREPLY-XEBFXQUR (you may delete this reply afterwards)