{"id":13413771,"url":"https://github.com/mvmaasakkers/certificates","last_synced_at":"2026-01-28T09:00:38.773Z","repository":{"id":35044483,"uuid":"173694143","full_name":"mvmaasakkers/certificates","owner":"mvmaasakkers","description":"An opinionated helper for generating tls certificates","archived":false,"fork":false,"pushed_at":"2022-12-27T15:55:28.000Z","size":120,"stargazers_count":38,"open_issues_count":0,"forks_count":8,"subscribers_count":2,"default_branch":"master","last_synced_at":"2024-07-31T20:52:50.756Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mvmaasakkers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-03-04T07:20:36.000Z","updated_at":"2024-05-30T09:34:35.000Z","dependencies_parsed_at":"2023-01-15T12:39:51.998Z","dependency_job_id":null,"html_url":"https://github.com/mvmaasakkers/certificates","commit_stats":null,"previous_names":[],"tags_count":18,"template":false,"template_full_name":null,"purl":"pkg:github/mvmaasakkers/certificates","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mvmaasakkers%2Fcertificates","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mvmaasakkers%2Fcertificates/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mvmaasakkers%2Fcertificates/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mvmaasakkers%2Fcertificates/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mvmaasakkers","download_url":"https://codeload.github.com/mvmaasakkers/certificates/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mvmaasakkers%2Fcertificates/sbom","scorecard":{"id":669543,"data":{"date":"2025-08-11","repo":{"name":"github.com/mvmaasakkers/certificates","commit":"dd7ff0f3ed4dfc099984cb5b6c4b2855e606036b"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.9,"checks":[{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":1,"reason":"Found 3/23 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/mvmaasakkers/certificates/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/mvmaasakkers/certificates/build.yml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:11: pin your Docker image by updating alpine:3.9 to alpine:3.9@sha256:414e0518bb9228d35e4cd5165567fb91d26c6a214e9c95899e1e056fcd349011","Info:   0 out of   2 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: MIT License: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.7.2 not signed: https://api.github.com/repos/mvmaasakkers/certificates/releases/65651107","Warn: release artifact v0.7.1 not signed: https://api.github.com/repos/mvmaasakkers/certificates/releases/65629109","Warn: release artifact v0.7.0 not signed: https://api.github.com/repos/mvmaasakkers/certificates/releases/65628404","Warn: release artifact v0.6.0 not signed: https://api.github.com/repos/mvmaasakkers/certificates/releases/27783715","Warn: release artifact v0.5.0 not signed: https://api.github.com/repos/mvmaasakkers/certificates/releases/22672226","Warn: release artifact v0.7.2 does not have provenance: https://api.github.com/repos/mvmaasakkers/certificates/releases/65651107","Warn: release artifact v0.7.1 does not have provenance: https://api.github.com/repos/mvmaasakkers/certificates/releases/65629109","Warn: release artifact v0.7.0 does not have provenance: https://api.github.com/repos/mvmaasakkers/certificates/releases/65628404","Warn: release artifact v0.6.0 does not have provenance: https://api.github.com/repos/mvmaasakkers/certificates/releases/27783715","Warn: release artifact v0.5.0 does not have provenance: https://api.github.com/repos/mvmaasakkers/certificates/releases/22672226"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2024-2961","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 11 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-21T19:28:24.337Z","repository_id":35044483,"created_at":"2025-08-21T19:28:24.337Z","updated_at":"2025-08-21T19:28:24.337Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28843106,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-28T07:39:25.367Z","status":"ssl_error","status_checked_at":"2026-01-28T07:39:24.487Z","response_time":57,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T20:01:48.815Z","updated_at":"2026-01-28T09:00:38.754Z","avatar_url":"https://github.com/mvmaasakkers.png","language":"Go","funding_links":[],"categories":["Security","安全","安全领域相关库","Relational Databases"],"sub_categories":["HTTP Clients","HTTP客户端","查询语"],"readme":"# Certificates helper \n\n[![MIT license](http://img.shields.io/badge/license-MIT-brightgreen.svg)](http://opensource.org/licenses/MIT)\n[![GoDoc](https://godoc.org/github.com/mvmaasakkers/certificates?status.svg)](https://godoc.org/github.com/mvmaasakkers/certificates)\n[![Go Report Card](https://goreportcard.com/badge/github.com/mvmaasakkers/certificates)](https://goreportcard.com/report/github.com/mvmaasakkers/certificates)\n[![CodeFactor](https://www.codefactor.io/repository/github/mvmaasakkers/certificates/badge)](https://www.codefactor.io/repository/github/mvmaasakkers/certificates)\n[![Coverage Status](https://coveralls.io/repos/github/mvmaasakkers/certificates/badge.svg?branch=master)](https://coveralls.io/github/mvmaasakkers/certificates?branch=master)\n[![Mentioned in Awesome Go](https://awesome.re/mentioned-badge.svg)](https://github.com/avelino/awesome-go)  \n\n\nThis is an opinionated helper for generating tls certificates.\nIt outputs only in PEM format but this enables you easily generate certificate\nchains for MA TLS.\n\n## cert package\n\nThe cert package can be used directly in your application without the need of the command \nline interface, underlying database layer or external dependencies. This way certificate \ngeneration can be easily embedded. \n\nDocumentation can be found [here](https://godoc.org/github.com/mvmaasakkers/certificates/cert).\n\n# CLI Tool\n\n## Installation\n\nCurrently you can use it by building it locally, checking the [releases](https://github.com/mvmaasakkers/certificates/releases) or with docker:\n\n`docker run mvmaasakkers/certificates cert gen-ca --cn=*.test.domain --stdout`\n\n## Usage\n\n### Generate a CA set\n\nYou can generate a CA set by using the generate-ca subcommand like the following example:\n\n`certificates cert gen-ca --cn=*.test.domain --stdout`\n\nThis will output the key and certificate directly to stdout like this (parts are omitted for readability):\n\n```\n-----BEGIN RSA PRIVATE KEY-----\nMIIJJwIBAAKCAgEA0txN/brNlBcGrU8mAxL8V19pS1dWEVVTF82LDahI7FMsPPkM\nsg5iBCLwYJhnVRPucUmcGC1NyljCy/yW0Cbwl5aNWozAfEkiUpWsukn/ZcMuXvac\nqsPRK0Xswbr305NDRnlphoeutyzXAhW2P4FQGCwSfx/Mlaezphc7AreLKg==\n-----END RSA PRIVATE KEY-----\n\n-----BEGIN CERTIFICATE-----\nMIIE3zCCAsegAwIBAgIFANHEYb4wDQYJKoZIhvcNAQELBQAwDzENMAsGA1UEAxME\nP9g8SpNaf6jNS0ULG8+DJ7dwdHes7IWA0BtjDkur4Ya+ey/FwowgMeEnc/h10Adc\naz7b\n-----END CERTIFICATE-----\n\n```\n\nBy default the certificates are written to files `ca.key` and `ca.crt`.\n\n### Generate a certificate\n\nThis needs a pregenerated CA certificate and key (see \"Generate a CA set\").\n\nTo generate a signed certificate pair you can use the following example:\n\n`certificates cert gen --cn=local.test.domain --stdout`\n\nThis will output the key and certificate directly to stdout like this (parts are omitted for readability):\n\n```\n-----BEGIN RSA PRIVATE KEY-----\nMIIJFAIBAAKCAf0Z7/5ZYgOo4gHfAPAPN0vKWEVJ5D97wvnYUq00DcaRPCZZopXl\nXUcctgAb3kw27ohTm31KnVEnN8ibeUg2fz+LO/xYVvhD2BMkoe1gk/2JAogPUi1l\njWjI7fuKGwlyHimeYnUx1ADRlShBgHGr\n-----END RSA PRIVATE KEY-----\n\n-----BEGIN CERTIFICATE-----\nMIIE/TCCAuWgAwIBAgIFFPmGQ70wDQYJKoZIhvcNAQELBQAwDzENMAsGA1UEAxME\nV964wCgh6TgfUtt9RabcM3MWtAR18N0vedYg46jhxDa1b+/brQWLuxXDsKIVHrRP\nM6ZzVSUF1PH+Ok2Fm7EP26Yax3RkoPrgmlLqL/1fRJaJ\n-----END CERTIFICATE-----\n\n```\n\nBy default a file (file.db) database is created to keep track of unique certificate serialnumbers. \nThis is advised only for dev and test environments. The CA database can be one of the following flavours of sql: mysql, \npostgresql or mssql. \n\nTo change key generation bitsize use the `--bitsize` flag (default is 4096, options are 2048 and 4096).\n\nTo use a pre-existing csr to use during the generation give the path to the csr file using the `--csr` flag.\n\n## Development setup\n\nThis module uses [Go modules](https://github.com/golang/go/wiki/Modules) for dependency management.\nTo run: \n\n- `go run main.go`\n\nAnd this will output:\n\n```bash\nNAME:\n   Certificates - An opinionated TLS certificate generator.\n\nUSAGE:\n   main [global options] command [command options] [arguments...]\n\nVERSION:\n   v...\n\nDESCRIPTION:\n   An opinionated TLS certificate generator.\n\nCOMMANDS:\n     certificate, cert  certificate commands\n     help, h            Shows a list of commands or help for one command\n\nGLOBAL OPTIONS:\n   --help, -h     show help\n   --version, -v  print the version\n```\n\n## License\n[![FOSSA Status](https://app.fossa.io/api/projects/git%2Bgithub.com%2Fmvmaasakkers%2Fcertificates.svg?type=large)](https://app.fossa.io/projects/git%2Bgithub.com%2Fmvmaasakkers%2Fcertificates?ref=badge_large)","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmvmaasakkers%2Fcertificates","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmvmaasakkers%2Fcertificates","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmvmaasakkers%2Fcertificates/lists"}