{"id":13551455,"url":"https://github.com/arvados/arvados","last_synced_at":"2026-04-02T01:29:24.618Z","repository":{"id":7961524,"uuid":"9359429","full_name":"arvados/arvados","owner":"arvados","description":"An open source platform for managing and analyzing biomedical big data","archived":false,"fork":false,"pushed_at":"2026-03-30T10:55:30.000Z","size":96216,"stargazers_count":415,"open_issues_count":19,"forks_count":127,"subscribers_count":32,"default_branch":"main","last_synced_at":"2026-03-30T12:28:58.484Z","etag":null,"topics":["arvados","aws","azure","bigdata","bioinformatics","cloud","cluster","cwl","docker","gcp","genomics","go","python","ruby","workflow","workflow-engine"],"latest_commit_sha":null,"homepage":"https://arvados.org","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/arvados.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"COPYING","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":"AUTHORS","dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2013-04-11T01:06:19.000Z","updated_at":"2026-03-26T15:47:16.000Z","dependencies_parsed_at":"2023-09-29T00:52:11.121Z","dependency_job_id":"be83f6dd-0064-46bb-8d68-908e4e31166f","html_url":"https://github.com/arvados/arvados","commit_stats":{"total_commits":18704,"total_committers":91,"mean_commits":"205.53846153846155","dds":0.8315333618477331,"last_synced_commit":"5dd128f5a57e704e3b3ea5225130ca85bd3bb84c"},"previous_names":[],"tags_count":52,"template":false,"template_full_name":null,"purl":"pkg:github/arvados/arvados","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/arvados%2Farvados","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/arvados%2Farvados/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/arvados%2Farvados/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/arvados%2Farvados/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/arvados","download_url":"https://codeload.github.com/arvados/arvados/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/arvados%2Farvados/sbom","scorecard":{"id":210251,"data":{"date":"2025-08-11","repo":{"name":"github.com/arvados/arvados","commit":"8848b751f80f2ebc8f76877de138fa2d0adf18d0"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.5,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/tests.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: COPYING:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/tests.yml:14"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Info: Possibly incomplete results: error parsing shell code: not a valid arithmetic operator: $: contrib/arvbash/arvbash.sh:0","Warn: containerImage not pinned by hash: build/docker/python-venv.Dockerfile:7: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:8f8e63bb364a33694362f38ee9a9e38b09eb9eb138584693800b87ca173bfd4a","Warn: containerImage not pinned by hash: build/docker/python-venv.Dockerfile:21: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:8f8e63bb364a33694362f38ee9a9e38b09eb9eb138584693800b87ca173bfd4a","Warn: containerImage not pinned by hash: services/workbench2/docker/Dockerfile:5: pin your Docker image by updating node:12.22.12-bullseye to node:12.22.12-bullseye@sha256:39a3111124caad4e785552f3dcb387caa1cd6749510530f289f107475be96b67","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:15","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:44","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:74","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:77: pin your Docker image by updating debian:12 to debian:12@sha256:731dd1380d6a8d170a695dbeb17fe0eade0e1c29f654cf0a3a07f372191c3f4b","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.demo:5","Warn: containerImage not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.dev:5","Warn: pipCommand not pinned by hash: build/docker/python-venv.Dockerfile:17-18","Warn: pipCommand not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:102-104","Warn: pipCommand not pinned by hash: tools/arvbox/lib/arvbox/docker/Dockerfile.base:102-104","Warn: pipCommand not pinned by hash: build/run-tests.sh:368","Warn: goCommand not pinned by hash: build/run-tests.sh:425","Warn: pipCommand not pinned by hash: build/run-tests.sh:629","Info:   1 out of   1 GitHub-owned GitHubAction dependencies pinned","Info:   4 out of   4 third-party GitHubAction dependencies pinned","Info:   3 out of   4 goCommand dependencies pinned","Info:   0 out of   9 containerImage dependencies pinned","Info:   0 out of   5 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":0,"reason":"36 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2021-437 / GHSA-5xp3-jfq3-5q8x","Warn: Project is vulnerable to: PYSEC-2023-228 / GHSA-mq26-g339-26xf","Warn: Project is vulnerable to: PYSEC-2025-49 / GHSA-5rjg-fvgr-3xxf","Warn: Project is vulnerable to: PYSEC-2022-43017 / GHSA-qwmp-2cf2-g9g6","Warn: Project is vulnerable to: GHSA-5vgj-ggm4-fg62","Warn: Project is vulnerable to: PYSEC-2021-142 / GHSA-8q59-q68h-6hv4","Warn: Project is vulnerable to: PYSEC-2018-49 / GHSA-rprw-h62v-c2w7","Warn: Project is vulnerable to: GHSA-2rxp-v6pw-ch6m","Warn: Project is vulnerable to: GHSA-4xqq-m2hx-25v8","Warn: Project is vulnerable to: GHSA-5866-49gr-22v4","Warn: Project is vulnerable to: GHSA-r55c-59qm-vjw6","Warn: Project is vulnerable to: GHSA-vg3r-rm7w-2xgh","Warn: Project is vulnerable to: GHSA-vmwr-mc7x-5vc3","Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2025-3829","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GHSA-h47h-mwp9-c6q6","Warn: Project is vulnerable to: GHSA-vfg9-r3fq-jvx4","Warn: Project is vulnerable to: GHSA-vfm5-rmrh-j26v","Warn: Project is vulnerable to: GHSA-x76w-6vjr-8xgj","Warn: Project is vulnerable to: GHSA-wwhv-wxv9-rpgw","Warn: Project is vulnerable to: GHSA-353f-x4gh-cqq8","Warn: Project is vulnerable to: GHSA-5w6v-399v-w3cc","Warn: Project is vulnerable to: GHSA-mrxw-mxhj-p664","Warn: Project is vulnerable to: GHSA-r95h-9x8f-r3f7","Warn: Project is vulnerable to: GHSA-vvfq-8hwr-qm4m","Warn: Project is vulnerable to: GHSA-9j94-67jr-4cqj","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-r683-j2x4-v87g","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-4v9v-hfq4-rm2v","Warn: Project is vulnerable to: GHSA-9jgg-88mc-972h","Warn: Project is vulnerable to: GHSA-99w6-3xph-cx78","Warn: Project is vulnerable to: GHSA-jpxc-vmjf-9fcj"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T00:38:42.025Z","repository_id":7961524,"created_at":"2025-08-17T00:38:42.026Z","updated_at":"2025-08-17T00:38:42.026Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31293902,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-02T01:05:07.454Z","status":"ssl_error","status_checked_at":"2026-04-02T00:56:46.496Z","response_time":53,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["arvados","aws","azure","bigdata","bioinformatics","cloud","cluster","cwl","docker","gcp","genomics","go","python","ruby","workflow","workflow-engine"],"created_at":"2024-08-01T12:01:48.583Z","updated_at":"2026-04-02T01:29:24.610Z","avatar_url":"https://github.com/arvados.png","language":"Go","funding_links":[],"categories":["Go","go","Full fledged product"],"sub_categories":[],"readme":"[comment]: # (Copyright © The Arvados Authors. All rights reserved.)\n[comment]: # ()\n[comment]: # (SPDX-License-Identifier: CC-BY-SA-3.0)\n\n[![Join the chat at https://gitter.im/arvados/community](https://badges.gitter.im/arvados/community.svg)](https://gitter.im/arvados/community?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge) | [Installing Arvados](https://doc.arvados.org/install/index.html) | [Installing Client SDKs](https://doc.arvados.org/sdk/index.html) | [Report a bug](https://dev.arvados.org/projects/arvados/issues/new) | [Development and Contributing](CONTRIBUTING.md)\n\n\u003cimg align=\"right\" src=\"doc/images/dax.png\" height=\"240px\"\u003e\n\n[Arvados](https://arvados.org) is an open source platform for\nmanaging, processing, and sharing genomic and other large scientific\nand biomedical data.  With Arvados, bioinformaticians run and scale\ncompute-intensive workflows, developers create biomedical\napplications, and IT administrators manage large compute and storage\nresources.\n\nThe key components of Arvados are:\n\n* *Keep*: Keep is the Arvados storage system for managing and storing large\ncollections of files.  Keep combines content addressing and a\ndistributed storage architecture resulting in both high reliability\nand high throughput.  Every file stored in Keep can be accurately\nverified every time it is retrieved.  Keep supports the creation of\ncollections as a flexible way to define data sets without having to\nre-organize or needlessly copy data. Keep works on a wide range of\nunderlying filesystems and object stores.\n\n* *Crunch*: Crunch is the orchestration system for running [Common Workflow Language](https://www.commonwl.org) workflows. It is\ndesigned to maintain data provenance and workflow\nreproducibility. Crunch automatically tracks data inputs and outputs\nthrough Keep and executes workflow processes in Docker containers.  In\na cloud environment, Crunch optimizes costs by scaling compute on demand.\n\n* *Workbench*: The Workbench web application allows users to interactively access\nArvados functionality.  It is especially helpful for querying and\nbrowsing data, visualizing provenance, and tracking the progress of\nworkflows.\n\n* *Command Line tools*: The command line interface (CLI) provides convenient access to Arvados\nfunctionality in the Arvados platform from the command line.\n\n* *API and SDKs*: Arvados is designed to be integrated with existing infrastructure. All\nthe services in Arvados are accessed through a RESTful API.  SDKs are\navailable for Python, Go, R, Perl, Ruby, and Java.\n\n# Documentation\n\nComplete documentation, including the [User Guide](https://doc.arvados.org/user/index.html), [Installation documentation](https://doc.arvados.org/install/index.html), [Administrator documentation](https://doc.arvados.org/admin/index.html) and\n[API documentation](https://doc.arvados.org/api/index.html) is available at http://doc.arvados.org/\n\nIf you wish to build the Arvados documentation from a local git clone, see\n[doc/README.textile](doc/README.textile) for instructions.\n\n# Community\n\n[![Join the chat at https://gitter.im/arvados/community](https://badges.gitter.im/arvados/community.svg)](https://gitter.im/arvados/community?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge)\n\nThe [Arvados community channel](https://gitter.im/arvados/community)\nchannel at [gitter.im](https://gitter.im) is available for live\ndiscussion and support.\n\nThe [Arvados developement channel](https://gitter.im/arvados/development)\nchannel at [gitter.im](https://gitter.im) is used to coordinate development.\n\nThe [Arvados user mailing list](http://lists.arvados.org/mailman/listinfo/arvados)\nis used to announce new versions and other news.\n\nAll participants are expected to abide by the [Arvados Code of Conduct](CODE_OF_CONDUCT.md).\n\n# Reporting bugs\n\n[Report a bug](https://dev.arvados.org/projects/arvados/issues/new) on [dev.arvados.org](https://dev.arvados.org).\n\n# Development and Contributing\n\nSee [CONTRIBUTING](CONTRIBUTING.md) for information about Arvados development and how to contribute to the Arvados project.\n\nThe [development road map](https://dev.arvados.org/issues/gantt?utf8=%E2%9C%93\u0026set_filter=1\u0026gantt=1\u0026f%5B%5D=project_id\u0026op%5Bproject_id%5D=%3D\u0026v%5Bproject_id%5D%5B%5D=49\u0026f%5B%5D=\u0026zoom=1) outlines some of the project priorities over the next twelve months.\n\n# Licensing\n\nArvados is Free Software.  See [COPYING](COPYING) for information about the open source licenses used in Arvados.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Farvados%2Farvados","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Farvados%2Farvados","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Farvados%2Farvados/lists"}