{"id":12558044,"name":"github.com/cloudfoundry/cli/v8","ecosystem":"go","description":null,"homepage":null,"licenses":"apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/cloudfoundry/cli","keywords_array":[],"namespace":null,"versions_count":42,"first_release_published_at":"2025-12-06T09:15:37.894Z","latest_release_published_at":"2026-04-15T20:17:36.000Z","latest_release_number":"v8.18.3","last_synced_at":"2026-05-27T13:46:20.345Z","created_at":"2025-12-06T09:12:22.848Z","updated_at":"2026-05-27T13:46:20.346Z","registry_url":"https://pkg.go.dev/github.com/cloudfoundry/cli/v8","install_command":"go get github.com/cloudfoundry/cli/v8","documentation_url":"https://pkg.go.dev/github.com/cloudfoundry/cli/v8#section-documentation","metadata":{},"repo_metadata":{"id":565384,"uuid":"12223350","full_name":"cloudfoundry/cli","owner":"cloudfoundry","description":"The official command line client for Cloud Foundry","archived":false,"fork":false,"pushed_at":"2026-02-11T05:23:12.000Z","size":179924,"stargazers_count":1897,"open_issues_count":75,"forks_count":992,"subscribers_count":224,"default_branch":"main","last_synced_at":"2026-02-11T12:14:46.170Z","etag":null,"topics":["cf-cli","cli","cloud-foundry","cloud-foundry-cli"],"latest_commit_sha":null,"homepage":"https://docs.cloudfoundry.org/cf-cli","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cloudfoundry.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":".github/CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2013-08-19T17:47:45.000Z","updated_at":"2026-02-11T05:22:40.000Z","dependencies_parsed_at":"2023-11-18T04:23:26.250Z","dependency_job_id":"e38ff15f-7bfd-436f-b2dc-63e6a805e967","html_url":"https://github.com/cloudfoundry/cli","commit_stats":{"total_commits":11780,"total_committers":456,"mean_commits":"25.833333333333332","dds":0.8852292020373514,"last_synced_commit":"eef705c5f6ec9c45de2e131b3b020fed0e18f8d0"},"previous_names":[],"tags_count":175,"template":false,"template_full_name":null,"purl":"pkg:github/cloudfoundry/cli","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cloudfoundry","download_url":"https://codeload.github.com/cloudfoundry/cli/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli/sbom","scorecard":{"id":292750,"data":{"date":"2025-08-11","repo":{"name":"github.com/cloudfoundry/cli","commit":"8b383a5c8a1131f711a29cd397c00d544b63a605"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.9,"checks":[{"name":"Maintained","score":10,"reason":"15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/release-build-sign-upload.yml:759","Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-build-sign-upload.yml:760","Info: jobLevel 'actions' permission set to 'read': .github/workflows/release-build-sign-upload.yml:1009","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-build-sign-upload.yml:1010","Warn: jobLevel 'actions' permission set to 'write': .github/workflows/stale-issues.yml:15","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/stale-issues.yml:12","Info: jobLevel 'contents' permission set to 'read': .github/workflows/util-code-quality.yml:19","Info: jobLevel 'actions' permission set to 'read': .github/workflows/util-code-quality.yml:18","Warn: no topLevel permission defined: .github/workflows/check-cves.yml:1","Warn: no topLevel permission defined: .github/workflows/create-bosh-lite.yml:1","Warn: no topLevel permission defined: .github/workflows/delete-bosh-lite.yml:1","Warn: no topLevel permission defined: .github/workflows/golangci-lint.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-build-sign-upload.yml:52","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-bump-gpg.yml:68","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-update-repos.yml:8","Warn: no topLevel permission defined: .github/workflows/stale-issues.yml:1","Warn: no topLevel permission defined: .github/workflows/test-latest-releases.yml:1","Warn: no topLevel permission defined: .github/workflows/tests-integration-reusable.yml:1","Warn: no topLevel permission defined: .github/workflows/tests-integration.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/tests-unit.yml:27","Warn: no topLevel permission defined: .github/workflows/util-code-quality.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: integration/assets/test_plugin_with_panic/test_plugin_with_panic:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/cloudfoundry/.github/SECURITY.md:1","Info: Found linked content: github.com/cloudfoundry/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/cloudfoundry/.github/SECURITY.md:1","Info: Found text in security policy: github.com/cloudfoundry/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v8.14.1 not signed: https://api.github.com/repos/cloudfoundry/cli/releases/224362747","Warn: release artifact v8.14.0 not signed: https://api.github.com/repos/cloudfoundry/cli/releases/218115994","Warn: release artifact v8.13.0 not signed: https://api.github.com/repos/cloudfoundry/cli/releases/211902201","Warn: release artifact v8.12.0 not signed: https://api.github.com/repos/cloudfoundry/cli/releases/208978707","Warn: release artifact v8.11.0 not signed: https://api.github.com/repos/cloudfoundry/cli/releases/205125834","Warn: release artifact v8.14.1 does not have provenance: https://api.github.com/repos/cloudfoundry/cli/releases/224362747","Warn: release artifact v8.14.0 does not have provenance: https://api.github.com/repos/cloudfoundry/cli/releases/218115994","Warn: release artifact v8.13.0 does not have provenance: https://api.github.com/repos/cloudfoundry/cli/releases/211902201","Warn: release artifact v8.12.0 does not have provenance: https://api.github.com/repos/cloudfoundry/cli/releases/208978707","Warn: release artifact v8.11.0 does not have provenance: https://api.github.com/repos/cloudfoundry/cli/releases/205125834"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Info: Possibly incomplete results: error parsing shell code: statements must be separated by \u0026, ; or a newline: .github/win/innosetup/Dockerfile:9","Info: Possibly incomplete results: error parsing shell code: statements must be separated by \u0026, ; or a newline: .github/win/innosetup/Dockerfile:10","Info: Possibly incomplete results: error parsing shell code: not a valid arithmetic operator: \\setup\\thumbprint: .github/win/innosetup/Dockerfile:11-13","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-cves.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/check-cves.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-cves.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/check-cves.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-cves.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/check-cves.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-bosh-lite.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/create-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/delete-bosh-lite.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/delete-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/delete-bosh-lite.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/delete-bosh-lite.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/delete-bosh-lite.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/delete-bosh-lite.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/delete-bosh-lite.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/delete-bosh-lite.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/golangci-lint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:1016: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:1022: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:1031: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:1062: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:399: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:402: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:409: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:420: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:431: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:451: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:468: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:608: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:628: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:632: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:694: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:739: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:924: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:952: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:976: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:986: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:154: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:277: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:378: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:771: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:774: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:860: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:867: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-build-sign-upload.yml:897: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-build-sign-upload.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-bump-gpg.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-bump-gpg.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:249: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:251: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:405: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:434: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-update-repos.yml:491: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/release-update-repos.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-issues.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/stale-issues.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-integration-reusable.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration-reusable.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-integration-reusable.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration-reusable.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-integration-reusable.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration-reusable.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-integration-reusable.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration-reusable.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-integration-reusable.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration-reusable.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-integration.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-integration.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-integration.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-unit.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-unit.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-unit.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/tests-unit.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/util-code-quality.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/util-code-quality.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/util-code-quality.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/util-code-quality.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/util-code-quality.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/util-code-quality.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/util-code-quality.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudfoundry/cli/util-code-quality.yml/main?enable=pin","Warn: containerImage not pinned by hash: .github/win/innosetup/Dockerfile:4: pin your Docker image by updating mcr.microsoft.com/windows/servercore:ltsc2019 to mcr.microsoft.com/windows/servercore:ltsc2019@sha256:0f967dbb28a1637e6fb8d6a552a3cca69121ccef4e0c6631f8231097016ec9f8","Warn: chocoCommand not pinned by hash: .github/win/innosetup/Dockerfile:19","Warn: goCommand not pinned by hash: bin/generate-language-resources:5","Warn: pipCommand not pinned by hash: .github/workflows/release-update-repos.yml:397","Info:   0 out of  61 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  13 third-party GitHubAction dependencies pinned","Info:   0 out of   1 goCommand dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   1 chocoCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":4,"reason":"6 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-7g2v-jj9q-g3rg","Warn: Project is vulnerable to: GHSA-7wqh-767x-r66v","Warn: Project is vulnerable to: GHSA-8cgq-6mh2-7j6v","Warn: Project is vulnerable to: GHSA-gjh7-p2fx-99vx","Warn: Project is vulnerable to: GHSA-vpfw-47h7-xj4g","Warn: Project is vulnerable to: GHSA-hxx2-7vcw-mqr3"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-17T18:42:57.829Z","repository_id":565384,"created_at":"2025-08-17T18:42:57.829Z","updated_at":"2025-08-17T18:42:57.829Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29340523,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-11T16:14:43.024Z","status":"ssl_error","status_checked_at":"2026-02-11T16:14:15.258Z","response_time":97,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"repo_metadata_updated_at":"2026-02-11T18:10:10.614Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":5.399900554133911,"dependent_packages_count":5.060019121135937,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":5.229959837634924},"purl":"pkg:golang/github.com/cloudfoundry/cli/v8","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/cloudfoundry/cli/v8","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/cloudfoundry/cli/v8","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/cloudfoundry/cli/v8/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-02-11T08:01:24.366Z","issues_count":256,"pull_requests_count":1694,"avg_time_to_close_issue":82296903.95744681,"avg_time_to_close_pull_request":1849978.418526031,"issues_closed_count":188,"pull_requests_closed_count":1478,"pull_request_authors_count":81,"issue_authors_count":207,"avg_comments_per_issue":3.99609375,"avg_comments_per_pull_request":0.7508854781582054,"merged_pull_requests_count":1150,"bot_issues_count":5,"bot_pull_requests_count":850,"past_year_issues_count":13,"past_year_pull_requests_count":278,"past_year_avg_time_to_close_issue":3581185.6666666665,"past_year_avg_time_to_close_pull_request":358319.8956521739,"past_year_issues_closed_count":3,"past_year_pull_requests_closed_count":230,"past_year_pull_request_authors_count":17,"past_year_issue_authors_count":13,"past_year_avg_comments_per_issue":0.5384615384615384,"past_year_avg_comments_per_pull_request":0.3776978417266187,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":92,"past_year_merged_pull_requests_count":180,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudfoundry%2Fcli/issues","maintainers":[{"login":"gururajsh","count":178,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gururajsh"},{"login":"a-b","count":100,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/a-b"},{"login":"moleske","count":69,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/moleske"},{"login":"Benjamintf1","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Benjamintf1"},{"login":"gmllt","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gmllt"},{"login":"philippthun","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/philippthun"},{"login":"strehle","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/strehle"},{"login":"ccjaimes","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ccjaimes"},{"login":"blgm","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/blgm"},{"login":"maxmoehl","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/maxmoehl"},{"login":"FelisiaM","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/FelisiaM"},{"login":"tcdowney","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tcdowney"},{"login":"evanfarrar","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/evanfarrar"},{"login":"mariash","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mariash"},{"login":"acrmp","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/acrmp"},{"login":"MerricdeLauney","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MerricdeLauney"},{"login":"ctlong","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ctlong"},{"login":"monamohebbi","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/monamohebbi"},{"login":"sethboyles","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sethboyles"},{"login":"beyhan","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/beyhan"},{"login":"reneighbor","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/reneighbor"},{"login":"matt-royal","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matt-royal"},{"login":"stephanme","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/stephanme"},{"login":"georgi-lozev","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/georgi-lozev"},{"login":"selzoc","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/selzoc"},{"login":"piyalibanerjee","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/piyalibanerjee"},{"login":"georgethebeatle","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/georgethebeatle"}],"active_maintainers":[{"login":"gururajsh","count":45,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gururajsh"},{"login":"a-b","count":37,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/a-b"},{"login":"Benjamintf1","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Benjamintf1"},{"login":"moleske","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/moleske"},{"login":"strehle","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/strehle"},{"login":"maxmoehl","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/maxmoehl"},{"login":"stephanme","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/stephanme"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fcloudfoundry%2Fcli%2Fv8/codemeta","maintainers":[]}