{"id":30779555,"url":"https://github.com/palmetto/palm-dbt","last_synced_at":"2025-09-05T06:43:50.253Z","repository":{"id":39609939,"uuid":"419044000","full_name":"palmetto/palm-dbt","owner":"palmetto","description":"dbt plugin for Palm CLI","archived":false,"fork":false,"pushed_at":"2024-03-20T16:57:37.000Z","size":260,"stargazers_count":21,"open_issues_count":6,"forks_count":10,"subscribers_count":6,"default_branch":"develop","last_synced_at":"2025-08-27T21:58:17.679Z","etag":null,"topics":["developer-tools","development-environment","palm","palm-cli"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/palmetto.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2021-10-19T18:21:06.000Z","updated_at":"2024-11-08T14:40:09.000Z","dependencies_parsed_at":"2024-03-05T23:27:12.908Z","dependency_job_id":"5e6f65d8-d582-46a6-8cc6-76ea25dab508","html_url":"https://github.com/palmetto/palm-dbt","commit_stats":{"total_commits":238,"total_committers":8,"mean_commits":29.75,"dds":0.3697478991596639,"last_synced_commit":"e6df9e3b2fb5370982a33bdfaf6c221263293b14"},"previous_names":[],"tags_count":17,"template":false,"template_full_name":null,"purl":"pkg:github/palmetto/palm-dbt","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/palmetto%2Fpalm-dbt","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/palmetto%2Fpalm-dbt/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/palmetto%2Fpalm-dbt/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/palmetto%2Fpalm-dbt/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/palmetto","download_url":"https://codeload.github.com/palmetto/palm-dbt/tar.gz/refs/heads/develop","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/palmetto%2Fpalm-dbt/sbom","scorecard":{"id":718496,"data":{"date":"2025-08-11","repo":{"name":"github.com/palmetto/palm-dbt","commit":"5200720f6b3d2feb6b1aa1a939771ab2b1e51b0f"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.6,"checks":[{"name":"Code-Review","score":7,"reason":"Found 7/10 approved changesets -- score normalized to 7","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/no-merge.yaml:1","Warn: no topLevel permission defined: .github/workflows/pull-request.yaml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/pypi-deploy.yaml:10","Info: topLevel 'pull-requests' permission set to 'read': .github/workflows/pypi-deploy.yaml:11","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/no-merge.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/no-merge.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pull-request.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pull-request.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pull-request.yaml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull-request.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pull-request.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi-deploy.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/palmetto/palm-dbt/pypi-deploy.yaml/develop?enable=pin","Warn: containerImage not pinned by hash: palm/plugins/dbt/templates/containerize/Dockerfile.txt:1","Warn: pipCommand not pinned by hash: .github/workflows/pull-request.yaml:28","Warn: pipCommand not pinned by hash: .github/workflows/pull-request.yaml:29","Warn: pipCommand not pinned by hash: .github/workflows/pypi-deploy.yaml:47","Warn: pipCommand not pinned by hash: .github/workflows/pypi-deploy.yaml:48","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 0.8.0 not signed: https://api.github.com/repos/palmetto/palm-dbt/releases/130409477","Warn: release artifact 0.7.0 not signed: https://api.github.com/repos/palmetto/palm-dbt/releases/108436140","Warn: release artifact 0.6.0 not signed: https://api.github.com/repos/palmetto/palm-dbt/releases/105851950","Warn: release artifact 0.5.0 not signed: https://api.github.com/repos/palmetto/palm-dbt/releases/95875144","Warn: release artifact 0.4.0 not signed: https://api.github.com/repos/palmetto/palm-dbt/releases/85592960","Warn: release artifact 0.8.0 does not have provenance: https://api.github.com/repos/palmetto/palm-dbt/releases/130409477","Warn: release artifact 0.7.0 does not have provenance: https://api.github.com/repos/palmetto/palm-dbt/releases/108436140","Warn: release artifact 0.6.0 does not have provenance: https://api.github.com/repos/palmetto/palm-dbt/releases/105851950","Warn: release artifact 0.5.0 does not have provenance: https://api.github.com/repos/palmetto/palm-dbt/releases/95875144","Warn: release artifact 0.4.0 does not have provenance: https://api.github.com/repos/palmetto/palm-dbt/releases/85592960"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":5,"reason":"5 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2024-48 / GHSA-fj7x-q9j7-g6q6","Warn: Project is vulnerable to: PYSEC-2021-142 / GHSA-8q59-q68h-6hv4","Warn: Project is vulnerable to: PYSEC-2018-49","Warn: Project is vulnerable to: GHSA-2m57-hf25-phgg","Warn: Project is vulnerable to: PYSEC-2023-87 / GHSA-rrm6-wvj7-cwh2"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-22T10:28:59.965Z","repository_id":39609939,"created_at":"2025-08-22T10:28:59.965Z","updated_at":"2025-08-22T10:28:59.965Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":273723199,"owners_count":25156303,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-05T02:00:09.113Z","response_time":402,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["developer-tools","development-environment","palm","palm-cli"],"created_at":"2025-09-05T06:43:48.161Z","updated_at":"2025-09-05T06:43:50.243Z","avatar_url":"https://github.com/palmetto.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Palm dbt\n\ndbt plugin for [Palm CLI](https://github.com/palmetto/palm-cli)\n\nThis plugin adds dbt-specific commands for use with Palm CLI\n\n## Installing\n\nInstall this plugin along with palm\n\n`pip install palm-dbt`\n\nOr from source\n\n`python3 -m pip install .`\n\n### Configuring your project\n\nTo configure your project to use the palm-dbt plugin, you will need a `.palm/config.yaml`\nthis can be created by running `palm init`, once you have your config file,\nadd the dbt-palm plugin with the following configuration:\n\n```yaml\nplugins:\n  - dbt\n```\n\n## Check dbt plugin version\n\nCheck the version of palm-dbt inside a project in which you have configured palm with the dbt plugin:\n`palm plugin versions`\n\n## Palm-ing an existing dbt project\n\npalm-dbt ships with a command to containerize and convert your existing dbt project.\n\nFor example, if you wanted to containerize your existing dbt project running on 0.21.0, you would run:\n\n```\n  palm containerize --version 0.21.0\n```\n\n### Adding palm dbt macros\n\npalm-dbt uses the git branch name to set the schema for all commands via env vars.\nThis allows palm to clean up test data after each run, ensuring that your data\nwarehouse stays clean and free of development/test data.\n\nTo enable this functionality, palm-dbt ships with 2 macros that handle schema naming\nand cleanup:\n\n* generate_schema_name - **This macro overrides the dbt-core macro** to auto-generate\na schema name based on your current git branch and PALM_DBT_ENV.\n\n* drop_branch_schemas - This macro uses the branch named schema and the TEST database\nto clean up any models generated by running dbt in development or test environments.\nCalls to this macro are baked in to many of the palm dbt commands.\n\nSee the section [about the palm dbt naming macros](#about-the-palm-dbt-branch-naming-macros)\nbelow for more information.\n\n\nTo install these macros, run `palm install` from within a project that is configured\nto use the palm-dbt plugin.\n\n### Recommended (optional) protected branch configuration\n\nIn order to ensure your runs are idempotent, we recommend that you do not run\npalm-dbt commands against `main`, `master` or any other production-like branches\nyou may be using.\n\nTo prevent palm running against specific branches, add the following config to\nyour project's `.palm/config.yaml`\n\n```yaml\nprotected_branches:\n  - main\n  - master\n  # Any other branches you want to protect\n```\n\n## About the palm dbt branch naming macros\n\nOne of the most painful parts of data testing is unfortunate\n[shared mutable state](https://stackoverflow.com/questions/44219903/why-is-shared-mutability-bad).\npalm-dbt provides a mechanism to eliminate this undesirable situation by namespacing\neach run of dbt. for git branches other than main or master, palm will prefix the\ncalculated schema name with a formatted version of your branch name. In CI, this\nwill be additionally prefixed with \"CI\". For example:\n\n- you open a branch FEATURE/DATA-100/update-widget\n- when you `palm run` in your local env, the schema `public` will be built as\n`feature_data_100_update_widget_public`. The schema `sales` will be built as\n`feature_data_100_update_widget_sales`.\n- in CI the schemas will be `ci_feature_data_100_update_widget_public`,\n`ci_feature_data_100_update_widget_sales` (respectively).\n- in prod the schemas will be 'public' and 'sales' (respectively).\n\nRefs will automatically update as well. This way, you can use a single test\ndatabase and not worry about conflicts between developers, or between branches\nfor the same developer (like during hotfixes).\n\n## palm-dbt and dbt deps\n\nIn palm-dbt we have determined that running `dbt deps` before every command is\nproblematic for a few reasons:\n\n1. It takes time, slowing down development, CI, and every production run.\n2. If dbt hub or github have an outage, our dbt commands fail and remain broken\nuntil the upstream error is resolved\n3. If you forget to run dbt deps, the resulting error messages can be quite confusing.\n\nTo solve these problems, we have decided that running `dbt clean \u0026\u0026 dbt deps` should\nhappen in the Dockerfile, when the image is being built.\n\nTo support this decision your project _must_ do the following:\n\n1. Include `RUN dbt clean \u0026\u0026 dbt deps` in the Dockerfile\n2. Include a `volume` entry in the docker-compose.yaml for the dbt_modules directory\nlike this `- /app/{{packages_dir}}`, which will prevent the `.:./app` volume from\nblowing away the deps generated when the image was built.\n\n_if you use `palm containerize` this will be done for you!_\n\nAdditionally, if you need to make changes to your deps you should use `palm build`\nto rebuild the image, which will update your deps!\n\n## Typical palm-dbt workflow\n\nFrom a non-protected branch, running `palm run` will:\n1. drop (if it exists) the namespaced schema in development\n2. create the namespaced schema in development\n3. seed and run\n4. drop the namespaced schema in development\n\nWhy drop it? so your testing is atomic.\n\nWant to persist it? use the flag `--persist`\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpalmetto%2Fpalm-dbt","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpalmetto%2Fpalm-dbt","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpalmetto%2Fpalm-dbt/lists"}