{"id":37163570,"url":"https://github.com/flant/negentropy","last_synced_at":"2026-01-14T19:27:13.698Z","repository":{"id":37825757,"uuid":"359499955","full_name":"flant/negentropy","owner":"flant","description":"S - security","archived":true,"fork":false,"pushed_at":"2022-12-20T12:01:19.000Z","size":9310,"stargazers_count":21,"open_issues_count":31,"forks_count":4,"subscribers_count":8,"default_branch":"main","last_synced_at":"2024-06-21T18:47:53.259Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/flant.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-04-19T15:02:21.000Z","updated_at":"2024-02-20T09:42:14.000Z","dependencies_parsed_at":"2023-01-30T00:31:07.408Z","dependency_job_id":null,"html_url":"https://github.com/flant/negentropy","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/flant/negentropy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flant%2Fnegentropy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flant%2Fnegentropy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flant%2Fnegentropy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flant%2Fnegentropy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/flant","download_url":"https://codeload.github.com/flant/negentropy/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flant%2Fnegentropy/sbom","scorecard":{"id":402566,"data":{"date":"2025-08-11","repo":{"name":"github.com/flant/negentropy","commit":"4892902c46c8f60e97b3f5f86ffe111a6809d115"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.4,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"project is archived","details":["Warn: Repository is archived."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/cleanup_gar.yaml:1","Warn: no topLevel permission defined: .github/workflows/converge.yaml:1","Warn: no topLevel permission defined: .github/workflows/e2e.yaml:1","Warn: no topLevel permission defined: .github/workflows/plugins.yaml:1","Warn: no topLevel permission defined: .github/workflows/rego.yaml:1","Warn: no topLevel permission defined: .github/workflows/server-access.yaml:1","Warn: no topLevel permission defined: .github/workflows/watcher.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: server-access/server-access-nss/lib/libnss_flantauth.so.2:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.0.1 not signed: https://api.github.com/repos/flant/negentropy/releases/84979776","Warn: release artifact v0.0.1 does not have provenance: https://api.github.com/repos/flant/negentropy/releases/84979776"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cleanup_gar.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/cleanup_gar.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cleanup_gar.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/cleanup_gar.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/converge.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/converge.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/converge.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/converge.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/e2e.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/plugins.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/plugins.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/plugins.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/plugins.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/rego.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/rego.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rego.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/rego.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-access.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/server-access.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-access.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/server-access.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-access.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/server-access.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/watcher.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/watcher.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/watcher.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/flant/negentropy/watcher.yaml/main?enable=pin","Warn: containerImage not pinned by hash: docker/Dockerfile.test-client:1: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8feb4d8ca5354def3d8fce243717141ce31e2c428701f6682bd2fafe15388214","Warn: containerImage not pinned by hash: docker/Dockerfile.test-server:1: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8feb4d8ca5354def3d8fce243717141ce31e2c428701f6682bd2fafe15388214","Warn: containerImage not pinned by hash: docker/Dockerfile.vault-debug:1","Warn: containerImage not pinned by hash: docker/Dockerfile.vault-debug:4: pin your Docker image by updating alpine:3.13 to alpine:3.13@sha256:469b6e04ee185740477efa44ed5bdd64a07bbdd6c7e5f5d169e540889597b911","Warn: containerImage not pinned by hash: e2e/tests/lib/oidc_mock/Dockerfile:2: pin your Docker image by updating golang:1.17-alpine to golang:1.17-alpine@sha256:99ddec1bbfd6d6bca3f9804c02363daee8c8524dae50df7942e8e60788fd17c9","Warn: containerImage not pinned by hash: server-access/server-access-nss/Dockerfile:1: pin your Docker image by updating debian/eol:wheezy to debian/eol:wheezy@sha256:bddcd5525189f4afeb098fba34e3131c1483fe7f54aebfad9befcb481bd8f9ed","Warn: downloadThenRun not pinned by hash: server-access/server-access-nss/Dockerfile:10","Warn: pipCommand not pinned by hash: infra/common/docker/install-dependencies.sh:25","Warn: pipCommand not pinned by hash: infra/main/packer/03-vault-auth/packer-scripts/02-nginx.sh:7","Warn: pipCommand not pinned by hash: start.sh:83","Warn: pipCommand not pinned by hash: start.sh:86","Warn: goCommand not pinned by hash: vault-plugins/flant_iam_auth/scripts/update_deps.sh:23","Warn: downloadThenRun not pinned by hash: .github/workflows/plugins.yaml:40","Warn: downloadThenRun not pinned by hash: .github/workflows/watcher.yaml:30","Info:   0 out of  17 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned","Info:   0 out of   6 containerImage dependencies pinned","Info:   1 out of   2 goCommand dependencies pinned","Info:   0 out of   3 downloadThenRun dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 25 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"84 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3770 / GHSA-vrw8-fxc6-2r93","Warn: Project is vulnerable to: GO-2024-2947 / GHSA-v6v8-xj6m-xwqh","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2022-0969 / GHSA-69cg-p879-7622","Warn: Project is vulnerable to: GO-2023-1495 / GHSA-fxg5-wq6x-vr4w","Warn: Project is vulnerable to: GO-2022-1144 / GHSA-xrjj-mj9h-534m","Warn: Project is vulnerable to: GO-2023-1571 / GHSA-vvpx-j8f3-3w6h","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GO-2023-2153 / GHSA-m425-mq94-257g / GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2022-1059 / GHSA-69ch-w2m2-3vjp","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37","Warn: Project is vulnerable to: GO-2024-2631 / GHSA-c5q2-7r4c-mv6g","Warn: Project is vulnerable to: GO-2022-0360 / GHSA-5j5w-g665-5m35","Warn: Project is vulnerable to: GO-2022-0278 / GHSA-mvff-h3cj-wj9c","Warn: Project is vulnerable to: GO-2022-0344 / GHSA-crp2-qrr5-8pq7","Warn: Project is vulnerable to: GO-2024-2846 / GHSA-c9cp-9c75-9v8c","Warn: Project is vulnerable to: GO-2022-0482 / GHSA-5ffw-gxpp-mxpf","Warn: Project is vulnerable to: GO-2022-1147 / GHSA-2qjp-425j-52j9","Warn: Project is vulnerable to: GO-2023-1573 / GHSA-259w-8hf6-59c2","Warn: Project is vulnerable to: GO-2023-1574 / GHSA-hmfx-3pcx-653p","Warn: Project is vulnerable to: GO-2023-2412 / GHSA-7ww5-4wqc-m92c","Warn: Project is vulnerable to: GO-2025-3528 / GHSA-265r-hfxg-fhmg","Warn: Project is vulnerable to: GO-2022-0379 / GHSA-qq97-vm5h-rrhg","Warn: Project is vulnerable to: GHSA-hqxw-f8mx-cpmw","Warn: Project is vulnerable to: GO-2024-2914 / GHSA-xmmx-7jpf-fx42","Warn: Project is vulnerable to: GO-2022-0390 / GHSA-2mm7-x5h6-5pvq","Warn: Project is vulnerable to: GO-2022-0985 / GHSA-rc4r-wh2q-q6c4","Warn: Project is vulnerable to: GO-2022-1107 / GHSA-vp35-85q5-9f25","Warn: Project is vulnerable to: GO-2023-1699 / GHSA-232p-vwff-86mp","Warn: Project is vulnerable to: GO-2023-1700 / GHSA-33pg-m6jh-5237","Warn: Project is vulnerable to: GO-2023-1701 / GHSA-6wrf-mxfj-pf5p","Warn: Project is vulnerable to: GHSA-jq35-85cj-fj4p","Warn: Project is vulnerable to: GHSA-mq39-4gv4-mvpx","Warn: Project is vulnerable to: GO-2024-3005 / GHSA-v23v-6jw2-98fq","Warn: Project is vulnerable to: GO-2024-2512 / GHSA-xw73-rw38-6vjc","Warn: Project is vulnerable to: GO-2025-3829 / GHSA-4vq8-7jfc-9cvp","Warn: Project is vulnerable to: GO-2025-3533 / GHSA-wq9g-9vfc-cfq9","Warn: Project is vulnerable to: GO-2022-0316 / GHSA-hcw3-j74m-qc58","Warn: Project is vulnerable to: GO-2022-0587 / GHSA-x7f3-62pm-9p38","Warn: Project is vulnerable to: GO-2022-0574 / GHSA-2m4x-4q9j-w97g","Warn: Project is vulnerable to: GO-2024-3141 / GHSA-c77r-fh37-x2px","Warn: Project is vulnerable to: GO-2025-3660 / GHSA-6m8w-jc87-6cr7","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GO-2024-2958 / GHSA-3669-72x9-r9p3","Warn: Project is vulnerable to: GO-2021-0227 / GHSA-3vm4-22fp-5rfm","Warn: Project is vulnerable to: GO-2022-0968 / GHSA-gwc9-m7rh-j2ww","Warn: Project is vulnerable to: GO-2021-0356 / GHSA-8c26-wmh5-6g9v","Warn: Project is vulnerable to: GO-2024-2961","Warn: Project is vulnerable to: GO-2022-0236 / GHSA-h86h-8ppg-mxmh","Warn: Project is vulnerable to: GO-2021-0238 / GHSA-83g2-8m93-v3w7","Warn: Project is vulnerable to: GO-2022-0288","Warn: Project is vulnerable to: GO-2022-0493 / GHSA-p782-xgp4-8hr8","Warn: Project is vulnerable to: PYSEC-2021-142 / GHSA-8q59-q68h-6hv4","Warn: Project is vulnerable to: PYSEC-2024-230 / GHSA-248v-346w-9cwc","Warn: Project is vulnerable to: PYSEC-2022-42986 / GHSA-43fp-rhv2-5gv8","Warn: Project is vulnerable to: PYSEC-2023-135 / GHSA-xqr8-7jwr-rhp7","Warn: Project is vulnerable to: PYSEC-2024-60 / GHSA-jjg7-2v4v-x38h","Warn: Project is vulnerable to: GHSA-9hjg-9r4m-mvj7","Warn: Project is vulnerable to: GHSA-9wx4-h78v-vm56","Warn: Project is vulnerable to: PYSEC-2023-74 / GHSA-j8r2-6x86-q33q","Warn: Project is vulnerable to: GHSA-34jh-p97f-mpxf","Warn: Project is vulnerable to: PYSEC-2023-212 / GHSA-g4mx-q9vg-27p4","Warn: Project is vulnerable to: GHSA-pq67-6m6q-mj2v","Warn: Project is vulnerable to: PYSEC-2023-192 / GHSA-v845-jxx5-vc9f","Warn: Project is vulnerable to: RUSTSEC-2022-0090 / GHSA-jw36-hf63-69r9","Warn: Project is vulnerable to: RUSTSEC-2024-0436","Warn: Project is vulnerable to: RUSTSEC-2023-0018 / GHSA-mc8h-8q98-g5hr","Warn: Project is vulnerable to: RUSTSEC-2020-0014 / GHSA-28ph-f7gx-fqj8 / GHSA-3cgf-9m6x-pwwr / GHSA-6q5w-m3c5-rv95 / GHSA-8h4j-vm3r-vcq3 / GHSA-8r7q-r9mx-35rh / GHSA-g4w7-3qr8-5623 / GHSA-q3cc-7p7g-392c / GHSA-rjh8-p66p-jrh5","Warn: Project is vulnerable to: RUSTSEC-2020-0071 / GHSA-wcg3-cvx6-7396","Warn: Project is vulnerable to: RUSTSEC-2023-0059 / GHSA-jcr6-4frq-9gjj","Warn: Project is vulnerable to: GHSA-m65q-v92h-cm7q","Warn: Project is vulnerable to: RUSTSEC-2023-0040","Warn: Project is vulnerable to: RUSTSEC-2025-0040","Warn: Project is vulnerable to: GO-2024-2456 / GHSA-449p-3h89-pw88","Warn: Project is vulnerable to: GO-2024-2466 / GHSA-mw99-9chc-xw7r","Warn: Project is vulnerable to: GO-2025-3367 / GHSA-r9px-m959-cxf4","Warn: Project is vulnerable to: GO-2025-3368 / GHSA-v725-9546-7q7m"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T20:24:27.721Z","repository_id":37825757,"created_at":"2025-08-18T20:24:27.721Z","updated_at":"2025-08-18T20:24:27.721Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28432604,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T18:57:19.464Z","status":"ssl_error","status_checked_at":"2026-01-14T18:52:48.501Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-14T19:27:12.957Z","updated_at":"2026-01-14T19:27:13.683Z","avatar_url":"https://github.com/flant.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Negentropy\n\nMulti tenant enterprise grade IAM implementation based on a geo-distributed layered Vault installation. Currently under\nactive development of initial version.\n \n# Build components for e2e tests\n\nneeds:\n\n1) linux or macos system (only intel processors, for apple silicone using needs some changes in scripts)\n2) docker\n\n```shell\n./build.sh\n```\n\npossible options for build:\n\n```shell\n./build.sh plugins # build separate plugins\n```\n\n```shell\n./build.sh authd  # builds authd component\n```\n\n```shell\n./build.sh cli # builds cli utility\n```\n\n```shell\n./build.sh server-accessd # builds server-accessd component\n```\n\n```shell\n./build.sh nss # builds nss component\n```\n\n```shell\n./build.sh oidc-mock # builds oidc-mock for e2e tests purposes only \n```\n\n```shell\n./build.sh vault          # builds complete vault with plugins onboard\n./build.sh vault --force  # builds complete vault with plugins onboard (use after first build)  \n```\n\n# Run environment for e2e tests\n\nThere are three possible modes of test and stage environment:\n\n1) One vault in dev mode, negentropy plugins are aside (SINGLE mode)\n2) Vaults with negentropy plugins onbоard (E2E mode, for E2E Tests in CI)\n3) Vaults with negentropy plugins onbоard, run under delve debugger (DEBUG mode)\n\n## SINGLE mode:\n\n```shell\n./start.sh single\n```\n\nruns one vault at docker container, uses separate plugin binaries, placed at vault-plugins/build\n\n## E2E mode:\n\n```shell\n./start.sh e2e\n```\n\nruns several vaults at docker-containers, uses complete vault binary with negentropy plugins onboard, placed at\ninfra/common/vault/vault/bin\n\n## DEBUG mode\n\n```shell\n./start.sh debug\n```\n\nruns several vaults at docker-containers, each docker run under delve debugger server uses complete vault binary with\nnegentropy plugins onboard, placed at infra/common/vault/vault/bin, need connection delve-client debuggers to localhost:\n2345 and localhost:2346 (see docker/docker-compose.debug.yml)\n\n## General components in other docker containers\n\n1) Zookepper, Kafka used to save data and communicate plugins.\n2) Kafdrop used to study Kafka\n3) test-server used as a sample of server under negentropy access control\n4) test-client used as a sample of user PC, accessing servers under negentropy access control\n5) oidc-mock provide mock of oidc-provider for tests\n\n## start.sh matter\n\n1) run all components containers\n2) configure negentropy plugins\n3) export data for running tests and unsealing vaults\n\n# E2E tests:\n\n```shell\n./run-e2e-tests.sh \n```\n\n# Review checklist\n\n1) No panic which can run at vault-plugins except:\n    - panic run (or not)  depends on code compositions only\n    - panic run (or not) in tests runs\n    - panic at flant-gitops plugin  \n      Check there is no panic with comment '// nolint:check_panic' at others places\n\n2) Each new category stored in memdb should be mentioned at:\n   - memdb schema\n   - ~kafka_destination/vault.go isValidObjectType()` func\n   - ~kafka_destination/metadata.go `isValidObjectType()` func\n   - ~kafka_source/self.go Restore() func (or ../root.go)\n   - checking of normal saving/restoration at e2e/tests/restoration/all_restoration_test.go\n\n# Install k8s\n\n1) Set configuration for your namespace in .helm/values.yaml (domain, balancer, bucket if needed)\n\nExample:\n```\nload_balancer:\n  mynamespace: enabled\ndomain:\n  mynamespace: mynamespace-negentropy.flant.dev\n```\n2) Go to teleport https://teleport.negentropy.flant.dev/ and connect to negentropy server console\n3) Set target namespace for negentropy (required)\n\nExample:\n```\nexport NS=mynamespace\n```\n4) Set git branch for watching (required)\n\nExample:\n```\nexport GIT_BRANCH=myBranch\n```\n5) Set INITIAL_LAST_SUCCESSFULL_COMMIT (required)\n\nExample:\n```\nexport INITIAL_LAST_SUCCESSFULL_COMMIT=49ddefbced3654c669f0d139be4690477d9bd5aa\n```\n\n6) Set optional params GIT_REPO, REQUIRED_NUMBER_OF_SIGNATURES, GIT_POLL_PERIOD\n\n```\nexport REQUIRED_NUMBER_OF_SIGNATURES=3 # default 0\nexport GIT_REPO=https://github.com/mygithub/negentropy.git # default https://github.com/flant/negentropy.git\nexport GIT_POLL_PERIOD=30m # default 1m\n```\n\n7) Run bootstrap script\n```\ncurl -s https://raw.githubusercontent.com/flant/negentropy/$GIT_BRANCH/bootstrap-kube.sh| bash\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fflant%2Fnegentropy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fflant%2Fnegentropy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fflant%2Fnegentropy/lists"}