{"id":29016619,"url":"https://github.com/chef/ci-studio-common","last_synced_at":"2025-08-18T19:40:44.727Z","repository":{"id":25263646,"uuid":"103588413","full_name":"chef/ci-studio-common","owner":"chef","description":"Shared helpers for use inside CIs (like Travis) and a Habitat Studio","archived":false,"fork":false,"pushed_at":"2023-11-10T00:45:34.000Z","size":101769,"stargazers_count":5,"open_issues_count":3,"forks_count":3,"subscribers_count":56,"default_branch":"main","last_synced_at":"2025-08-12T18:50:56.743Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/chef.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-09-14T22:35:08.000Z","updated_at":"2021-11-27T17:52:58.000Z","dependencies_parsed_at":"2024-06-19T13:23:25.952Z","dependency_job_id":"ccb2c6f2-6876-4895-88d9-11e151dcd786","html_url":"https://github.com/chef/ci-studio-common","commit_stats":null,"previous_names":[],"tags_count":161,"template":false,"template_full_name":null,"purl":"pkg:github/chef/ci-studio-common","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/chef%2Fci-studio-common","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/chef%2Fci-studio-common/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/chef%2Fci-studio-common/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/chef%2Fci-studio-common/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/chef","download_url":"https://codeload.github.com/chef/ci-studio-common/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/chef%2Fci-studio-common/sbom","scorecard":{"id":275488,"data":{"date":"2025-08-11","repo":{"name":"github.com/chef/ci-studio-common","commit":"430414e688d68ae9861a213a8a5f98fab9cbb6a6"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.1,"checks":[{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":4,"reason":"Found 8/18 approved changesets -- score normalized to 4","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 2.0.12 not signed: https://api.github.com/repos/chef/ci-studio-common/releases/35439601","Warn: release artifact 2.0.11 not signed: https://api.github.com/repos/chef/ci-studio-common/releases/35438358","Warn: release artifact 2.0.8 not signed: https://api.github.com/repos/chef/ci-studio-common/releases/35257383","Warn: release artifact 2.0.7 not signed: https://api.github.com/repos/chef/ci-studio-common/releases/35256401","Warn: release artifact 2.0.12 does not have provenance: https://api.github.com/repos/chef/ci-studio-common/releases/35439601","Warn: release artifact 2.0.11 does not have provenance: https://api.github.com/repos/chef/ci-studio-common/releases/35438358","Warn: release artifact 2.0.8 does not have provenance: https://api.github.com/repos/chef/ci-studio-common/releases/35257383","Warn: release artifact 2.0.7 does not have provenance: https://api.github.com/repos/chef/ci-studio-common/releases/35256401"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/chef/.github/SECURITY.md:1","Info: Found linked content: github.com/chef/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/chef/.github/SECURITY.md:1","Info: Found text in security policy: github.com/chef/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 20 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"36 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2024-2508 / GHSA-rpgp-9hmg-j25x","Warn: Project is vulnerable to: GO-2024-2509 / GHSA-rq95-xf66-j689","Warn: Project is vulnerable to: GO-2022-0623 / GHSA-38j9-7pp9-2hjw","Warn: Project is vulnerable to: GO-2022-0632 / GHSA-6239-28c2-9mrm","Warn: Project is vulnerable to: GO-2022-0618 / GHSA-qv95-g3gm-x542","Warn: Project is vulnerable to: GO-2022-0611 / GHSA-pfmw-vj74-ph8g","Warn: Project is vulnerable to: GO-2022-0620 / GHSA-23fq-q7hc-993r","Warn: Project is vulnerable to: GO-2023-1897 / GHSA-9mh8-9j64-443f","Warn: Project is vulnerable to: GO-2023-1900 / GHSA-wmg5-g953-qqfw","Warn: Project is vulnerable to: GO-2023-1708 / GHSA-hwc3-3qh6-r4gg","Warn: Project is vulnerable to: GO-2023-1685 / GHSA-v3hp-mcj5-pg39","Warn: Project is vulnerable to: GO-2023-1709 / GHSA-vq4h-9ghm-qmrr","Warn: Project is vulnerable to: GO-2023-1849 / GHSA-gq98-53rq-qr5h","Warn: Project is vulnerable to: GO-2023-2063 / GHSA-v84f-6r39-cpfc","Warn: Project is vulnerable to: GO-2023-2088 / GHSA-86c6-3g63-5w64","Warn: Project is vulnerable to: GO-2023-1986 / GHSA-9v3w-w2jh-4hff","Warn: Project is vulnerable to: GO-2023-2329 / GHSA-4qhc-v8r6-8vwm","Warn: Project is vulnerable to: GO-2024-2617 / GHSA-r3w7-mfpm-c2vw","Warn: Project is vulnerable to: GO-2024-2921 / GHSA-32cj-5wx4-gq8p","Warn: Project is vulnerable to: GO-2024-2690 / GHSA-j2rp-gmqv-frhv","Warn: Project is vulnerable to: GO-2024-3191 / GHSA-rr8j-7w34-xp5j","Warn: Project is vulnerable to: GO-2024-3246 / GHSA-g233-2p4r-3q7v","Warn: Project is vulnerable to: GO-2025-3663 / GHSA-gcqf-f89c-68hv","Warn: Project is vulnerable to: GO-2025-3837 / GHSA-6h4p-m86h-hhgh","Warn: Project is vulnerable to: GO-2025-3836 / GHSA-6c5r-4wfc-3mcx","Warn: Project is vulnerable to: GO-2025-3838 / GHSA-mr4h-qf9j-f665","Warn: Project is vulnerable to: GO-2025-3839 / GHSA-mwgr-84fv-3jh9","Warn: Project is vulnerable to: GO-2025-3841 / GHSA-qv3p-fmv3-9hww","Warn: Project is vulnerable to: GO-2025-3848 / GHSA-7rx2-769v-hrwf","Warn: Project is vulnerable to: GHSA-h74j-692g-48mq","Warn: Project is vulnerable to: GO-2025-3605 / GHSA-7vpp-9cxj-q8gv","Warn: Project is vulnerable to: GO-2024-2698 / GHSA-rhh4-rh7c-7r5v","Warn: Project is vulnerable to: GO-2024-2456 / GHSA-449p-3h89-pw88","Warn: Project is vulnerable to: GO-2024-2466 / GHSA-mw99-9chc-xw7r","Warn: Project is vulnerable to: GO-2025-3367 / GHSA-r9px-m959-cxf4","Warn: Project is vulnerable to: GO-2025-3368 / GHSA-v725-9546-7q7m"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T14:17:43.747Z","repository_id":25263646,"created_at":"2025-08-17T14:17:43.748Z","updated_at":"2025-08-17T14:17:43.748Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271050429,"owners_count":24691183,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-18T02:00:08.743Z","response_time":89,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-06-25T22:30:57.852Z","updated_at":"2025-08-18T19:40:44.713Z","avatar_url":"https://github.com/chef.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Common CI / Habitat Studio Functionality\n\nThis repository houses some scripts / files that are used across various Chef projects. These are designed and intended to be used by Chef Developers who are working on some specific projects. We are keeping it public as to simplify the download process for our developers.\n\n\u003c!-- You don't need to modify this TOC. It will automatically update when a PR is merged using Expeditor. --\u003e\n\n\u003c!-- toc --\u003e\n\n- [Announcing the 2.0 release](#announcing-the-20-release)\n- [CI Services (Travis, Buildkite, etc)](#ci-services-travis-buildkite-etc)\n  * [Installation](#installation)\n  * [Commands](#commands)\n    + [`did-modify`](#did-modify)\n    + [`file-mod`](#file-mod)\n    + [`vault-util`](#vault-util)\n- [FAQ](#faq)\n  * [How do you determine a CI environment vs a non-CI environment?](#how-do-you-determine-a-ci-environment-vs-a-non-ci-environment)\n\n\u003c!-- tocstop --\u003e\n\n## Announcing the 2.0 release\n\nThe focus of the 2.0 release is to optimize ci-studio-common for use with multiple Buildkite platform. As such, we have made the breaking following changes:\n\n* Utilities are now being written in Go to ensure consistency and availability across supported platforms.\n* Some deprecated utilities have been removed, or are in the process of being removed.\n* We no longer ship the CI binaries as part of the Chef Habitat Package\n\n\n## CI Services (Travis, Buildkite, etc)\n\n### Installation\n\nYou can install each component individually or the entirety of ci-studio-common grouped per OS and Arch at https://github.com/chef/ci-studio-common/releases\n\nCurrently available for:\nOS | ARCH\n--- | ---\nDarwin | x86-64\nLinux | x86-64\nWindows | x86-64\n\n### Commands\n\u003c!--\n  Many of the Helpers are self-documenting. If you see the stdout comment tags, that means that documentation block\n  is automatically updated everytime a PR is merged by executing the .expeditor/update_readme.sh script. The implication\n  there is that you do not need to manually update those docs.\n--\u003e\n\n#### `did-modify`\n\n\u003c!-- stdout \"./build/linux/did-modify --help\" --\u003e\n```\nPrints \"true\" to STDOUT if any files matching GLOBS were modified between HEAD and GITREF. Otherwise, prints \"false\".\n\nUsage:\n  did-modify [flags]\n\nFlags:\n      --git-ref string   A valid Git reference (e.g. HEAD, master, origin/master, etc). (default \"HEAD~1\")\n      --globs strings    Comma-separated list of glob patterns to inspect to determine if there are changes. (default [*])\n  -h, --help             help for did-modify\n```\n\u003c!-- stdout --\u003e\n\n#### `file-mod`\n\n\u003c!-- stdout \"./build/linux/file-mod --help\" --\u003e\n```\nCommand line utility to modify files.\n\nUsage:\n  file-mod [command]\n\nAvailable Commands:\n  append-if-missing Append STRING to FILE if not already there.\n  find-and-replace  Replace REGEX_STR with STRING in FILE. Supports multiline replace.\n  help              Help about any command\n\nFlags:\n  -h, --help   help for file-mod\n\nUse \"file-mod [command] --help\" for more information about a command.\n```\n\u003c!-- stdout --\u003e\n\n#### `vault-util`\n\u003c!-- stdout \"./build/linux/vault-util --help\" --\u003e\n```\nUtility to access secrets and account information stored in Hashicorp Vault from CI.\n\nUsage:\n  vault-util [command]\n\nAvailable Commands:\n  configure-accounts    Configure the accounts specified in the VAULT_UTIL_ACCOUNTS environment variable.\n  fetch-secret-env      Fetch the secrets specified in the VAULT_UTIL_SECRETS environment variable from Vault.\n  help                  Help about any command\n  print-git-credentials Utility that will print credentials for a GitHub App from Vault in git-credential-helper format.\n\nFlags:\n  -h, --help   help for vault-util\n\nUse \"vault-util [command] --help\" for more information about a command.\n```\n\u003c!-- stdout --\u003e\n\n## FAQ\n\n### How do you determine a CI environment vs a non-CI environment?\n\n`ci-studio-common` determines whether it is operating in a CI environment by the presence of a `CI` environment variable.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fchef%2Fci-studio-common","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fchef%2Fci-studio-common","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fchef%2Fci-studio-common/lists"}