{"id":11875455,"name":"@dotcms/mcp-server","ecosystem":"npm","description":"Model Context Protocol (MCP) server for dotCMS - enables AI agents to interact with dotCMS content management capabilities","homepage":"https://github.com/dotCMS/core/tree/main/core-web/apps/mcp-server","licenses":"GPL-3.0","normalized_licenses":["GPL-3.0"],"repository_url":"https://github.com/dotCMS/core","keywords_array":["dotcms","mcp","model-context-protocol","ai","claude","content-management","cms","artificial-intelligence","automation","workflow","headless-cms"],"namespace":"dotcms","versions_count":14,"first_release_published_at":"2025-07-04T00:42:30.743Z","latest_release_published_at":"2025-11-27T23:33:46.727Z","latest_release_number":"0.0.13","last_synced_at":"2026-05-11T19:01:54.597Z","created_at":"2025-07-04T00:42:43.386Z","updated_at":"2026-05-11T19:01:54.597Z","registry_url":"https://www.npmjs.com/package/@dotcms/mcp-server","install_command":"npm install @dotcms/mcp-server","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"0.0.13","beta":"0.1.0-beta.1"}},"repo_metadata":{"id":2734164,"uuid":"3729629","full_name":"dotCMS/core","owner":"dotCMS","description":"The Visual Headless Content Management System for Enterprises","archived":false,"fork":false,"pushed_at":"2026-05-08T18:17:56.000Z","size":1145424,"stargazers_count":944,"open_issues_count":839,"forks_count":479,"subscribers_count":82,"default_branch":"main","last_synced_at":"2026-05-08T18:23:10.011Z","etag":null,"topics":["cloud","cms","content","content-management-system","dotcms","dxp","graphql","headless-cms","java","opensouce"],"latest_commit_sha":null,"homepage":"http://dotcms.com","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dotCMS.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2012-03-15T15:24:14.000Z","updated_at":"2026-05-08T17:38:47.000Z","dependencies_parsed_at":"2023-09-22T03:45:38.993Z","dependency_job_id":"d6877113-4d69-46d7-99c7-c5b3ed92ef2c","html_url":"https://github.com/dotCMS/core","commit_stats":{"total_commits":18021,"total_committers":145,"mean_commits":"124.28275862068965","dds":0.897009045003052,"last_synced_commit":"aa4fe4b1029c4803f178e2d3d239b410a989ca08"},"previous_names":["dotcms/dotcms"],"tags_count":662,"template":false,"template_full_name":null,"purl":"pkg:github/dotCMS/core","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dotCMS","download_url":"https://codeload.github.com/dotCMS/core/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore/sbom","scorecard":{"id":36788,"data":{"date":"2025-08-11","repo":{"name":"github.com/dotCMS/core","commit":"023d34a8f8712e1d99848cc51ba97c48e862d5b7"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/cicd_manual_build-java-base.yml:20"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v25.08.11-1 not signed: https://api.github.com/repos/dotCMS/core/releases/239125227","Warn: release artifact dotcms-cli-25.08.11-1 not signed: https://api.github.com/repos/dotCMS/core/releases/239133075","Warn: release artifact v25.08.07-01 not signed: https://api.github.com/repos/dotCMS/core/releases/238412886","Warn: release artifact dotcms-cli-25.08.07-01 not signed: https://api.github.com/repos/dotCMS/core/releases/238420520","Warn: release artifact v25.08.11-1 does not have provenance: https://api.github.com/repos/dotCMS/core/releases/239125227","Warn: release artifact dotcms-cli-25.08.11-1 does not have provenance: https://api.github.com/repos/dotCMS/core/releases/239133075","Warn: release artifact v25.08.07-01 does not have provenance: https://api.github.com/repos/dotCMS/core/releases/238412886","Warn: release artifact dotcms-cli-25.08.07-01 does not have provenance: https://api.github.com/repos/dotCMS/core/releases/238420520"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Dangerous-Workflow","score":0,"reason":"dangerous workflow patterns detected","details":["Warn: script injection with untrusted input ' github.head_ref ': .github/workflows/cicd_comp_finalize-phase.yml:53","Warn: script injection with untrusted input ' github.event.pull_request.head.ref ': .github/workflows/cicd_comp_finalize-phase.yml:53"],"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_1-pr.yml:57","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_1-pr.yml:58","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_2-merge-queue.yml:16","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_2-merge-queue.yml:17","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_3-trunk.yml:61","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_3-trunk.yml:62","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_3-trunk.yml:76","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_3-trunk.yml:77","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_4-nightly.yml:54","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_4-nightly.yml:55","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_4-nightly.yml:69","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_4-nightly.yml:70","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_5-lts.yml:44","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_5-lts.yml:45","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_comp_build-phase.yml:56","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_comp_build-phase.yml:57","Warn: jobLevel 'packages' permission set to 'write': .github/workflows/cicd_release-cli.yml:137","Info: jobLevel 'contents' permission set to 'read': .github/workflows/cicd_release-cli.yml:136","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/issue_scheduled_stale-action.yml:13","Warn: jobLevel 'actions' permission set to 'write': .github/workflows/issue_scheduled_stale-action.yml:12","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/legacy-release_sbom-generator.yaml:16","Warn: no topLevel permission defined: .github/workflows/cicd_1-pr.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_2-merge-queue.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_3-trunk.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_4-nightly.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_5-lts.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_build-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_cli-native-build-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_deployment-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_finalize-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_initialize-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_pr-notifier.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_semgrep-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_comp_test-phase.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_manual_build-docker-context.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_manual_build-java-base.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_manual_publish-starter.yml:1","Warn: topLevel 'checks' permission set to 'write': .github/workflows/cicd_post-workflow-reporting.yml:45","Warn: no topLevel permission defined: .github/workflows/cicd_release-cli.yml:1","Warn: no topLevel permission defined: .github/workflows/cicd_scheduled_notify-seated-prs.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_frontend-notify.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_github-member-resolver.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_label-conditional-labeling.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_link-issue-to-pr.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_link-pr-to-issue.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_comp_release-labeling.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_manual_label-customer_deployed-issues.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_manual_label-issues.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_on-change_assign-issues-to-qa-project.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_on-change_post-issue-edited.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_open-pr.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_post-pr-merge.yml:1","Warn: no topLevel permission defined: .github/workflows/issue_scheduled_stale-action.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_maven-release-process.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_publish-docker-image-on-release.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_publish-dotcms-docker-image.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_release-candidate.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_release-trigger.yml:1","Warn: no topLevel permission defined: .github/workflows/legacy-release_sbom-generator.yaml:1","Warn: no topLevel permission defined: .github/workflows/publish_docs.yml:1","Warn: no topLevel permission defined: .github/workflows/security_scheduled_pentest.yml:1","Warn: no topLevel permission defined: .github/workflows/utility_discover-docker-tags.yml:1","Warn: no topLevel permission defined: .github/workflows/utility_slack-channel-resolver.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":0,"reason":"binaries present in source code","details":["Warn: binary detected: .mvn/wrapper/maven-wrapper.jar:1","Warn: binary detected: dotCMS/src/enterprise/java/com/dotcms/enterprise/achecker/tinymce/ACheckerDWR.class:1","Warn: binary detected: dotCMS/src/enterprise/java/com/dotcms/enterprise/achecker/tinymce/APIIndex.class:1","Warn: binary detected: dotCMS/src/enterprise/java/com/dotcms/enterprise/achecker/tinymce/DaoLocator.class:1","Warn: binary detected: dotCMS/src/main/resources/osgi-bundle/com.dotcms.actionlet-0.2.jar:1","Warn: binary detected: dotCMS/src/main/resources/osgi-bundle/com.dotcms.actionlet.fragment-0.2.jar:1","Warn: binary detected: dotCMS/src/main/resources/pg_dump_aarch64:1","Warn: binary detected: dotCMS/src/main/resources/pg_dump_amd64:1","Warn: binary detected: dotCMS/src/main/resources/pg_dump_x86_64:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-linux-arm64/sass:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-linux-x64/sass:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-macos-arm64/src/dart:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-macos-arm64/src/sass.snapshot:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-macos-x64/src/dart:1","Warn: binary detected: dotCMS/src/main/webapp/WEB-INF/bin/dart-sass-macos-x64/src/sass.snapshot:1","Warn: binary detected: dotcms-postman/src/main/resources/postman/resources/osgi-bundle/com.dotcms.actionlet-0.2.jar:1","Warn: binary detected: dotcms-postman/src/main/resources/postman/resources/osgi-bundle/com.dotcms.actionlet.fragment-0.2.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":10,"reason":"branch protection is fully enabled on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Info: required approving review count is 2 on branch 'main'","Info: codeowner review is required on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_build-phase.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_build-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_build-phase.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_build-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_cli-native-build-phase.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_cli-native-build-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_cli-native-build-phase.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_cli-native-build-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_deployment-phase.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_deployment-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_finalize-phase.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_finalize-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_finalize-phase.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_finalize-phase.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_comp_initialize-phase.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_initialize-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_initialize-phase.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_initialize-phase.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_comp_initialize-phase.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_initialize-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_semgrep-phase.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_semgrep-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_semgrep-phase.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_semgrep-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_semgrep-phase.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_semgrep-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_semgrep-phase.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_semgrep-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_test-phase.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_test-phase.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_comp_test-phase.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_test-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_test-phase.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_test-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_comp_test-phase.yml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_comp_test-phase.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-docker-context.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-docker-context.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-docker-context.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-docker-context.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-docker-context.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-docker-context.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-docker-context.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-docker-context.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-docker-context.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-docker-context.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-java-base.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-java-base.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-java-base.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-java-base.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-java-base.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-java-base.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-java-base.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-java-base.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_build-java-base.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_build-java-base.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_manual_publish-starter.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_manual_publish-starter.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_post-workflow-reporting.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_post-workflow-reporting.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_post-workflow-reporting.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_post-workflow-reporting.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_post-workflow-reporting.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_post-workflow-reporting.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_post-workflow-reporting.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_post-workflow-reporting.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:193: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:339: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:358: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_release-cli.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_release-cli.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_scheduled_notify-seated-prs.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_scheduled_notify-seated-prs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_scheduled_notify-seated-prs.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_scheduled_notify-seated-prs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd_scheduled_notify-seated-prs.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/cicd_scheduled_notify-seated-prs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_frontend-notify.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_frontend-notify.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_frontend-notify.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_frontend-notify.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_label-conditional-labeling.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_label-conditional-labeling.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_label-conditional-labeling.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_label-conditional-labeling.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/issue_comp_link-issue-to-pr.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_link-issue-to-pr.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/issue_comp_link-issue-to-pr.yml:225: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_link-issue-to-pr.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_release-labeling.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_release-labeling.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_comp_release-labeling.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_comp_release-labeling.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_manual_label-customer_deployed-issues.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_manual_label-customer_deployed-issues.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_manual_label-customer_deployed-issues.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_manual_label-customer_deployed-issues.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_manual_label-issues.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_manual_label-issues.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/issue_on-change_assign-issues-to-qa-project.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_on-change_assign-issues-to-qa-project.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_scheduled_stale-action.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/issue_scheduled_stale-action.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:224: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:240: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:259: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_comp_maven-build-docker-image.yml:274: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_comp_maven-build-docker-image.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:359: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:368: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:410: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:417: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:235: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:243: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:250: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:277: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_maven-release-process.yml:282: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_maven-release-process.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_publish-docker-image-on-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_publish-docker-image-on-release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_release-candidate.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_release-candidate.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/legacy-release_release-candidate.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_release-candidate.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_release-trigger.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_release-trigger.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/legacy-release_sbom-generator.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/legacy-release_sbom-generator.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_docs.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/publish_docs.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_docs.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/publish_docs.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish_docs.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/publish_docs.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/security_scheduled_pentest.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/security_scheduled_pentest.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/utility_discover-docker-tags.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/utility_discover-docker-tags.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/utility_discover-docker-tags.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/dotCMS/core/utility_discover-docker-tags.yml/main?enable=pin","Warn: containerImage not pinned by hash: docker/dev-env/Dockerfile:6","Warn: containerImage not pinned by hash: docker/dev-env/Dockerfile:8","Warn: containerImage not pinned by hash: docker/java-base/Dockerfile:4","Warn: containerImage not pinned by hash: docker/pg-base/Dockerfile:4","Warn: containerImage not pinned by hash: dotCMS/src/main/docker/original/Dockerfile:7","Warn: containerImage not pinned by hash: dotCMS/src/main/docker/original/Dockerfile:36: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:7c06e91f61fa88c08cc74f7e1b7c69ae24910d745357e0dfe1d2c0322aaf20f9","Warn: containerImage not pinned by hash: tools/dotcms-cli/cli/src/main/docker/Dockerfile.jvm:78: pin your Docker image by updating registry.access.redhat.com/ubi8/openjdk-11:1.11 to registry.access.redhat.com/ubi8/openjdk-11:1.11@sha256:f6d4c974e9ea0848846f965d963cfc6f9b31d22f5c4fbf81a727c1ab6a811cc5","Warn: containerImage not pinned by hash: tools/dotcms-cli/cli/src/main/docker/Dockerfile.legacy-jar:78: pin your Docker image by updating registry.access.redhat.com/ubi8/openjdk-11:1.11 to registry.access.redhat.com/ubi8/openjdk-11:1.11@sha256:f6d4c974e9ea0848846f965d963cfc6f9b31d22f5c4fbf81a727c1ab6a811cc5","Warn: containerImage not pinned by hash: tools/dotcms-cli/cli/src/main/docker/Dockerfile.native:17: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal:8.5 to registry.access.redhat.com/ubi8/ubi-minimal:8.5@sha256:3f32ebba0cbf3849a48372d4fc3a4ce70816f248d39eb50da7ea5f15c7f9d120","Warn: containerImage not pinned by hash: tools/dotcms-cli/cli/src/main/docker/Dockerfile.native-micro:20: pin your Docker image by updating quay.io/quarkus/quarkus-micro-image:1.0 to quay.io/quarkus/quarkus-micro-image:1.0@sha256:603ee696016035dc5f8b28fd007a41f89f464b7ce8ff92aaece824e8ad8478a2","Warn: containerImage not pinned by hash: tools/dotcms-cli/src/main/docker/Dockerfile.jvm:78: pin your Docker image by updating registry.access.redhat.com/ubi8/openjdk-11:1.11 to registry.access.redhat.com/ubi8/openjdk-11:1.11@sha256:f6d4c974e9ea0848846f965d963cfc6f9b31d22f5c4fbf81a727c1ab6a811cc5","Warn: containerImage not pinned by hash: tools/dotcms-cli/src/main/docker/Dockerfile.legacy-jar:78: pin your Docker image by updating registry.access.redhat.com/ubi8/openjdk-11:1.11 to registry.access.redhat.com/ubi8/openjdk-11:1.11@sha256:f6d4c974e9ea0848846f965d963cfc6f9b31d22f5c4fbf81a727c1ab6a811cc5","Warn: containerImage not pinned by hash: tools/dotcms-cli/src/main/docker/Dockerfile.native:17: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal:8.5 to registry.access.redhat.com/ubi8/ubi-minimal:8.5@sha256:3f32ebba0cbf3849a48372d4fc3a4ce70816f248d39eb50da7ea5f15c7f9d120","Warn: containerImage not pinned by hash: tools/dotcms-cli/src/main/docker/Dockerfile.native-micro:20: pin your Docker image by updating quay.io/quarkus/quarkus-micro-image:1.0 to quay.io/quarkus/quarkus-micro-image:1.0@sha256:603ee696016035dc5f8b28fd007a41f89f464b7ce8ff92aaece824e8ad8478a2","Warn: downloadThenRun not pinned by hash: docker/java-base/Dockerfile:18-30","Warn: npmCommand not pinned by hash: .github/actions/buildActions.sh:15","Warn: downloadThenRun not pinned by hash: core-web/.husky/pre-commit:48","Warn: downloadThenRun not pinned by hash: scripts/test-request-draining-auth.sh:60","Warn: downloadThenRun not pinned by hash: scripts/test-request-draining.sh:32","Warn: downloadThenRun not pinned by hash: scripts/test-request-draining.sh:40","Warn: pipCommand not pinned by hash: .github/workflows/cicd_release-cli.yml:206","Warn: pipCommand not pinned by hash: .github/workflows/issue_manual_label-customer_deployed-issues.yml:31","Warn: pipCommand not pinned by hash: .github/workflows/issue_manual_label-customer_deployed-issues.yml:32","Warn: pipCommand not pinned by hash: .github/workflows/legacy-release_sbom-generator.yaml:50","Warn: npmCommand not pinned by hash: .github/workflows/publish_docs.yml:23","Warn: downloadThenRun not pinned by hash: .github/workflows/utility_slack-channel-resolver.yml:104","Info:   0 out of  64 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  34 third-party GitHubAction dependencies pinned","Info:   0 out of  14 containerImage dependencies pinned","Info:   0 out of   6 downloadThenRun dependencies pinned","Info:   0 out of   2 npmCommand dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"46 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-x4c5-c7rf-jjgv","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-c76h-2ccp-4975","Warn: Project is vulnerable to: GHSA-cxrh-j4jr-qwg3","Warn: Project is vulnerable to: GHSA-c75v-2vq8-878f","Warn: Project is vulnerable to: GHSA-67mh-4wv8-2f99","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-pfrx-2q88-qq97","Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22","Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp","Warn: Project is vulnerable to: GHSA-x2rg-q646-7m2v","Warn: Project is vulnerable to: GHSA-jgmv-j7ww-jx2x","Warn: Project is vulnerable to: GHSA-9wv6-86v2-598j","Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6","Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36","Warn: Project is vulnerable to: GHSA-5359-pvf2-pw78","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3","Warn: Project is vulnerable to: GHSA-859w-5945-r5v3","Warn: Project is vulnerable to: GHSA-4v9v-hfq4-rm2v","Warn: Project is vulnerable to: GHSA-9jgg-88mc-972h","Warn: Project is vulnerable to: GHSA-776f-qx25-q3cc","Warn: Project is vulnerable to: GHSA-hhhv-q57g-882q","Warn: Project is vulnerable to: GHSA-xffm-g5w8-qvg7","Warn: Project is vulnerable to: GHSA-fq9m-v26v-2m4f","Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55","Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm","Warn: Project is vulnerable to: GHSA-8jhw-289h-jh2g","Warn: Project is vulnerable to: GHSA-64vr-g452-qvp3","Warn: Project is vulnerable to: GHSA-9cwx-2883-4wfx","Warn: Project is vulnerable to: GHSA-vg6x-rcgg-rjx6","Warn: Project is vulnerable to: GHSA-x574-m823-4x7w","Warn: Project is vulnerable to: GHSA-4r4m-qw57-chr8","Warn: Project is vulnerable to: GHSA-xcj6-pq6g-qj4x","Warn: Project is vulnerable to: GHSA-356w-63v5-8wf4","Warn: Project is vulnerable to: GHSA-7m27-7ghc-44w9","Warn: Project is vulnerable to: GHSA-qpjv-v59x-3qc4","Warn: Project is vulnerable to: GHSA-f82v-jwr5-mffw","Warn: Project is vulnerable to: GHSA-3h52-269p-cp9r"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-14T20:31:29.583Z","repository_id":2734164,"created_at":"2025-08-14T20:31:29.583Z","updated_at":"2025-08-14T20:31:29.583Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32799070,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-08T08:22:46.396Z","status":"ssl_error","status_checked_at":"2026-05-08T08:22:45.650Z","response_time":54,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"dotCMS","name":"dotCMS","uuid":"1005263","kind":"organization","description":"","email":"info@dotcms.com","website":"dotcms.com","location":"Miami, Boston, Charleston","twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/1005263?v=4","repositories_count":133,"last_synced_at":"2024-04-09T19:21:26.688Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/dotCMS","funding_links":[],"total_stars":901,"followers":29,"following":0,"created_at":"2022-11-03T14:08:51.653Z","updated_at":"2024-04-09T19:21:55.314Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dotCMS","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dotCMS/repositories"},"tags":[]},"repo_metadata_updated_at":"2026-05-09T01:14:56.162Z","dependent_packages_count":0,"downloads":72,"downloads_period":"last-month","dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":24.272902016367258,"dependent_packages_count":35.025896531952924,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":29.64939927416009},"purl":"pkg:npm/%40dotcms/mcp-server","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/@dotcms/mcp-server","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/npm/@dotcms/mcp-server","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/@dotcms/mcp-server/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-04-28T02:03:15.320Z","issues_count":3955,"pull_requests_count":3071,"avg_time_to_close_issue":16126001.08173641,"avg_time_to_close_pull_request":934937.1328560064,"issues_closed_count":2557,"pull_requests_closed_count":2514,"pull_request_authors_count":63,"issue_authors_count":95,"avg_comments_per_issue":1.1860935524652338,"avg_comments_per_pull_request":0.9036144578313253,"merged_pull_requests_count":1994,"bot_issues_count":1,"bot_pull_requests_count":92,"past_year_issues_count":765,"past_year_pull_requests_count":785,"past_year_avg_time_to_close_issue":1574266.0387323943,"past_year_avg_time_to_close_pull_request":545790.3308823529,"past_year_issues_closed_count":284,"past_year_pull_requests_closed_count":544,"past_year_pull_request_authors_count":37,"past_year_issue_authors_count":39,"past_year_avg_comments_per_issue":0.8065359477124183,"past_year_avg_comments_per_pull_request":0.8165605095541402,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":2,"past_year_merged_pull_requests_count":437,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/dotCMS%2Fcore/issues","maintainers":[{"login":"oidacra","count":400,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/oidacra"},{"login":"fmontes","count":373,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fmontes"},{"login":"bryanboza","count":175,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bryanboza"},{"login":"fishsmith","count":23,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fishsmith"},{"login":"dotCMS-Machine-User","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dotCMS-Machine-User"},{"login":"sfreudenthaler","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sfreudenthaler"},{"login":"freddyDOTCMS","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/freddyDOTCMS"},{"login":"wezell","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wezell"},{"login":"rjvelazco","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rjvelazco"},{"login":"erickgonzalez","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/erickgonzalez"},{"login":"zJaaal","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zJaaal"},{"login":"nicobytes","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/nicobytes"},{"login":"hassandotcms","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hassandotcms"},{"login":"OllieJC","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/OllieJC"},{"login":"hmoreras","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hmoreras"},{"login":"dsilvam","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dsilvam"},{"login":"dcolina","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dcolina"},{"login":"scripting","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/scripting"},{"login":"lizhineng","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lizhineng"},{"login":"ihoffmann-dot","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ihoffmann-dot"}],"active_maintainers":[{"login":"fmontes","count":79,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/fmontes"},{"login":"oidacra","count":72,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/oidacra"},{"login":"sfreudenthaler","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sfreudenthaler"},{"login":"freddyDOTCMS","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/freddyDOTCMS"},{"login":"wezell","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wezell"},{"login":"erickgonzalez","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/erickgonzalez"},{"login":"hassandotcms","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hassandotcms"},{"login":"nicobytes","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/nicobytes"},{"login":"rjvelazco","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rjvelazco"},{"login":"zJaaal","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zJaaal"},{"login":"dcolina","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dcolina"},{"login":"dotCMS-Machine-User","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dotCMS-Machine-User"},{"login":"dsilvam","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dsilvam"},{"login":"ihoffmann-dot","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ihoffmann-dot"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@dotcms%2Fmcp-server/codemeta","maintainers":[{"uuid":"devdotcms","login":"devdotcms","name":null,"email":"dev@dotcms.com","url":null,"packages_count":20,"html_url":"https://www.npmjs.com/~devdotcms","role":null,"created_at":"2025-07-04T00:42:44.247Z","updated_at":"2025-07-04T00:42:44.247Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/devdotcms/packages"},{"uuid":"nollymar","login":"nollymar","name":null,"email":"nollymar.longa@dotcms.com","url":null,"packages_count":17,"html_url":"https://www.npmjs.com/~nollymar","role":null,"created_at":"2025-11-16T11:37:59.843Z","updated_at":"2025-11-16T11:37:59.843Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/nollymar/packages"}]}