{"id":22518404,"url":"https://github.com/nbari/policyd-rate-limit","last_synced_at":"2026-02-07T14:11:19.727Z","repository":{"id":37178149,"uuid":"237963396","full_name":"nbari/policyd-rate-limit","owner":"nbari","description":"Postfix rate limiter SMTP policy daemon","archived":false,"fork":false,"pushed_at":"2025-12-31T15:50:04.000Z","size":174,"stargazers_count":5,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-01-04T20:33:04.869Z","etag":null,"topics":["limit","postfix","postfix-policy-server","quota","rate","rate-limit","rate-limiting","smtp"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nbari.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":"nbari"}},"created_at":"2020-02-03T12:47:29.000Z","updated_at":"2025-12-31T15:43:50.000Z","dependencies_parsed_at":"2025-04-16T17:03:59.175Z","dependency_job_id":"59187256-2238-4823-affb-2fcb1394e835","html_url":"https://github.com/nbari/policyd-rate-limit","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"purl":"pkg:github/nbari/policyd-rate-limit","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nbari%2Fpolicyd-rate-limit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nbari%2Fpolicyd-rate-limit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nbari%2Fpolicyd-rate-limit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nbari%2Fpolicyd-rate-limit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nbari","download_url":"https://codeload.github.com/nbari/policyd-rate-limit/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nbari%2Fpolicyd-rate-limit/sbom","scorecard":{"id":676948,"data":{"date":"2025-08-11","repo":{"name":"github.com/nbari/policyd-rate-limit","commit":"70221484296ee33865f4360501413015bf893bcb"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.1,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/deploy.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/deploy.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/nbari/policyd-rate-limit/test.yml/main?enable=pin","Info:   0 out of   5 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   5 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: topLevel 'contents' permission set to 'write': .github/workflows/deploy.yml:11","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/deploy.yml:19"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":9,"reason":"1 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: RUSTSEC-2023-0071"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T21:50:00.106Z","repository_id":37178149,"created_at":"2025-08-21T21:50:00.106Z","updated_at":"2025-08-21T21:50:00.106Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29196792,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-07T12:38:28.597Z","status":"ssl_error","status_checked_at":"2026-02-07T12:38:23.888Z","response_time":63,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["limit","postfix","postfix-policy-server","quota","rate","rate-limit","rate-limiting","smtp"],"created_at":"2024-12-07T04:15:33.857Z","updated_at":"2026-02-07T14:11:19.717Z","avatar_url":"https://github.com/nbari.png","language":"Rust","funding_links":["https://github.com/sponsors/nbari"],"categories":[],"sub_categories":[],"readme":"# policyd-rate-limit\n\n[![crates.io](https://img.shields.io/crates/v/policyd-rate-limit.svg)](https://crates.io/crates/policyd-rate-limit)\n[![Test](https://github.com/nbari/policyd-rate-limit/actions/workflows/test.yml/badge.svg)](https://github.com/nbari/policyd-rate-limit/actions/workflows/test.yml)\n\nPostfix rate limiter SMTP policy daemon\n\n# How it works\n\nIt depends on the [Postfix policy delegation protocol](http://www.postfix.org/SMTPD_POLICY_README.html), it searches for the `sasl_username` and based on the defined limits stored in a SQL(MySQL/PostgreSQL/SQLite) database it rejects or allows `action=DUNNO` the email to be sent.\n\n```mermaid\nflowchart TD\n    A[Policy request] --\u003e B{Has sasl_username?}\n    B -- No --\u003e C[action=DUNNO]\n    B -- Yes --\u003e D[Fetch rate windows from DB]\n    D --\u003e E{User exists?}\n    E -- No --\u003e F[Create rate windows for user]\n    F --\u003e C\n    E -- Yes --\u003e G[Reset expired windows]\n    G --\u003e H{All windows within quota?}\n    H -- Yes --\u003e I[action=DUNNO]\n    H -- No --\u003e J[action=REJECT]\n    I --\u003e K[Increment used counters]\n    J --\u003e K\n```\n\n# How to use\n\n```txt\nPostfix policy daemon for rate limiting\n\nUsage: policyd-rate-limit [OPTIONS] --dsn \u003cdsn\u003e\n\nOptions:\n  -s, --socket \u003cSOCKET\u003e  Path to the Unix domain socket [default: /tmp/policy-rate-limit.sock]\n      --dsn \u003cdsn\u003e        Database connection string [env: DSN=]\n      --pool \u003cpool\u003e      Pool size for database connections [default: 5]\n  -l, --limit \u003climit\u003e    Maximum allowed messages per rate window (repeatable, default: 10)\n  -r, --rate \u003crate\u003e      rate in seconds for each window (repeatable, default: 86400)\n  -v, --verbose...       Increase verbosity, -vv for debug\n  -h, --help             Print help\n  -V, --version          Print version\n```\n\nRepeat `--limit` and `--rate` to configure multiple windows, for example:\n\n```\npolicyd-rate-limit --dsn ... -l 7 -r 3600 -l 100 -r 86400\n```\n\nAll configured windows are enforced together: a request is allowed only when *every* window\nis still under quota. This means the most restrictive window effectively caps traffic.\n\n## Migration notes (1.1.0+)\n\nThe `ratelimit` table now uses a composite primary key `(username, rate)` to support multiple\nwindows per user. Migrate existing tables as follows:\n\nPostgres:\n\n```sql\nALTER TABLE ratelimit ALTER COLUMN rate SET NOT NULL;\nALTER TABLE ratelimit DROP CONSTRAINT ratelimit_pkey;\nALTER TABLE ratelimit ADD PRIMARY KEY (username, rate);\n```\n\nMariaDB/MySQL:\n\n```sql\nALTER TABLE ratelimit MODIFY rate INT UNSIGNED NOT NULL DEFAULT 0;\nALTER TABLE ratelimit DROP PRIMARY KEY;\nALTER TABLE ratelimit ADD PRIMARY KEY (username, rate);\n```\n\nSQLite (recreate table):\n\n```sql\nCREATE TABLE ratelimit_new (\n  username TEXT NOT NULL,\n  quota INTEGER NOT NULL DEFAULT 0,\n  used INTEGER NOT NULL DEFAULT 0,\n  rate INTEGER NOT NULL DEFAULT 0,\n  rdate TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,\n  PRIMARY KEY (username, rate)\n);\nINSERT INTO ratelimit_new (username, quota, used, rate, rdate)\nSELECT username, quota, used, rate, rdate FROM ratelimit;\nDROP TABLE ratelimit;\nALTER TABLE ratelimit_new RENAME TO ratelimit;\n```\n\nThe database schema (postgres example, one row per rate window):\n\n```sql\nCREATE TABLE IF NOT EXISTS ratelimit (\n    username VARCHAR(128) NOT NULL, -- sender address (SASL username)\n    quota INTEGER NOT NULL DEFAULT 0, -- limit\n    used INTEGER NOT NULL DEFAULT 0, -- current recipient counter\n    rate INTEGER NOT NULL DEFAULT 0, -- seconds after which the counter gets reset\n    rdate TIMESTAMP WITHOUT TIME ZONE NOT NULL DEFAULT CURRENT_TIMESTAMP, -- datetime when counter was reset\n    PRIMARY KEY (username, rate)\n);\n```\n\n# Postfix configuration\n\nAdd the path of the policy-rate-limit socket to `smtpd_sender_restrictions` for example:\n\n    smtpd_sender_restrictions: check_policy_service { unix:/tmp/policy-rate-limit.sock, default_action=DUNNO }\n\n\u003e check the perms of the socket\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnbari%2Fpolicyd-rate-limit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnbari%2Fpolicyd-rate-limit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnbari%2Fpolicyd-rate-limit/lists"}