{"id":37114207,"url":"https://github.com/pravahio/go-mesh","last_synced_at":"2026-01-14T13:26:49.381Z","repository":{"id":73133007,"uuid":"193912747","full_name":"pravahio/go-mesh","owner":"pravahio","description":"Realtime data exchange platform for Smart Cities","archived":false,"fork":false,"pushed_at":"2020-09-06T18:31:47.000Z","size":15027,"stargazers_count":24,"open_issues_count":12,"forks_count":5,"subscribers_count":4,"default_branch":"master","last_synced_at":"2024-06-20T15:53:20.491Z","etag":null,"topics":["data","realtime","streaming-data"],"latest_commit_sha":null,"homepage":"https://pravah.io","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/pravahio.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2019-06-26T13:43:50.000Z","updated_at":"2024-03-07T14:07:34.000Z","dependencies_parsed_at":"2023-06-17T20:15:26.619Z","dependency_job_id":null,"html_url":"https://github.com/pravahio/go-mesh","commit_stats":null,"previous_names":["upperwal/go-mesh"],"tags_count":6,"template":false,"template_full_name":null,"purl":"pkg:github/pravahio/go-mesh","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pravahio%2Fgo-mesh","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pravahio%2Fgo-mesh/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pravahio%2Fgo-mesh/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pravahio%2Fgo-mesh/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/pravahio","download_url":"https://codeload.github.com/pravahio/go-mesh/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pravahio%2Fgo-mesh/sbom","scorecard":{"id":744061,"data":{"date":"2025-08-11","repo":{"name":"github.com/pravahio/go-mesh","commit":"95bb5b3029a91416f436de6fc4681bbfd3b4b77c"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.4,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/6 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/go.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/pravahio/go-mesh/go.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/pravahio/go-mesh/go.yml/master?enable=pin","Warn: downloadThenRun not pinned by hash: .github/workflows/go.yml:23","Info:   0 out of   2 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.1.0 not signed: https://api.github.com/repos/pravahio/go-mesh/releases/27239725","Warn: release artifact v0.0.5 not signed: https://api.github.com/repos/pravahio/go-mesh/releases/20106818","Warn: release artifact v0.0.4 not signed: https://api.github.com/repos/pravahio/go-mesh/releases/19657568","Warn: release artifact v0.0.3 not signed: https://api.github.com/repos/pravahio/go-mesh/releases/19561058","Warn: release artifact v0.0.2 not signed: https://api.github.com/repos/pravahio/go-mesh/releases/19554292","Warn: release artifact v0.1.0 does not have provenance: https://api.github.com/repos/pravahio/go-mesh/releases/27239725","Warn: release artifact v0.0.5 does not have provenance: https://api.github.com/repos/pravahio/go-mesh/releases/20106818","Warn: release artifact v0.0.4 does not have provenance: https://api.github.com/repos/pravahio/go-mesh/releases/19657568","Warn: release artifact v0.0.3 does not have provenance: https://api.github.com/repos/pravahio/go-mesh/releases/19561058","Warn: release artifact v0.0.2 does not have provenance: https://api.github.com/repos/pravahio/go-mesh/releases/19554292"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 25 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"51 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-qrqr-3x5j-2xw9","Warn: Project is vulnerable to: GHSA-j249-ghv5-7mxv","Warn: Project is vulnerable to: GHSA-6hwg-w5jg-9c6x","Warn: Project is vulnerable to: GO-2024-2521","Warn: Project is vulnerable to: GO-2024-2500 / GHSA-3fwx-pjgw-3558","Warn: Project is vulnerable to: GO-2024-2913 / GHSA-v994-f8vw-g7j4","Warn: Project is vulnerable to: GO-2024-2914 / GHSA-xmmx-7jpf-fx42","Warn: Project is vulnerable to: GO-2022-0390 / GHSA-2mm7-x5h6-5pvq","Warn: Project is vulnerable to: GO-2022-0985 / GHSA-rc4r-wh2q-q6c4","Warn: Project is vulnerable to: GO-2022-1107 / GHSA-vp35-85q5-9f25","Warn: Project is vulnerable to: GO-2023-1699 / GHSA-232p-vwff-86mp","Warn: Project is vulnerable to: GO-2023-1700 / GHSA-33pg-m6jh-5237","Warn: Project is vulnerable to: GO-2023-1701 / GHSA-6wrf-mxfj-pf5p","Warn: Project is vulnerable to: GHSA-jq35-85cj-fj4p","Warn: Project is vulnerable to: GHSA-mq39-4gv4-mvpx","Warn: Project is vulnerable to: GO-2024-2512 / GHSA-xw73-rw38-6vjc","Warn: Project is vulnerable to: GO-2025-3829 / GHSA-4vq8-7jfc-9cvp","Warn: Project is vulnerable to: GO-2022-0771 / GHSA-69v6-xc2j-r2jf","Warn: Project is vulnerable to: GO-2021-0105 / GHSA-xw37-57qp-9mm4","Warn: Project is vulnerable to: GO-2022-0392 / GHSA-m6gx-rhvj-fh52","Warn: Project is vulnerable to: GO-2022-0775 / GHSA-v592-xf75-856p","Warn: Project is vulnerable to: GO-2021-0063 / GHSA-r33q-22hv-j29q","Warn: Project is vulnerable to: GO-2022-0254","Warn: Project is vulnerable to: GO-2022-0256 / GHSA-59hh-656j-3p7v","Warn: Project is vulnerable to: GO-2022-0456 / GHSA-wjxw-gh3m-7pm5","Warn: Project is vulnerable to: GO-2023-2046 / GHSA-ppjg-v974-84cm","Warn: Project is vulnerable to: GO-2024-2819 / GHSA-4xc9-8hmq-j652","Warn: Project is vulnerable to: GHSA-5m8f-chrv-7rw5","Warn: Project is vulnerable to: GHSA-pvx3-gm3c-gmpr","Warn: Project is vulnerable to: GHSA-rqmg-hrg4-fm69","Warn: Project is vulnerable to: GHSA-v9jh-j8px-98vq","Warn: Project is vulnerable to: GHSA-vmf7-hmh6-vv57","Warn: Project is vulnerable to: GHSA-vrcc-g6vj-mh5w","Warn: Project is vulnerable to: GO-2022-1148 / GHSA-j7qp-mfxf-8xjw","Warn: Project is vulnerable to: GO-2023-2024 / GHSA-gcq9-qqwx-rgj3","Warn: Project is vulnerable to: GO-2023-2000 / GHSA-876p-8259-xjgg","Warn: Project is vulnerable to: GO-2024-3218 / GHSA-mqr9-hjr8-2m9w","Warn: Project is vulnerable to: GO-2022-0236 / GHSA-h86h-8ppg-mxmh","Warn: Project is vulnerable to: GO-2021-0238 / GHSA-83g2-8m93-v3w7","Warn: Project is vulnerable to: GO-2022-0288","Warn: Project is vulnerable to: GO-2022-0969 / GHSA-69cg-p879-7622","Warn: Project is vulnerable to: GO-2022-1144 / GHSA-xrjj-mj9h-534m","Warn: Project is vulnerable to: GO-2023-1571 / GHSA-vvpx-j8f3-3w6h","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GO-2023-2153 / GHSA-m425-mq94-257g / GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2022-0493 / GHSA-p782-xgp4-8hr8"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-22T18:15:29.998Z","repository_id":73133007,"created_at":"2025-08-22T18:15:29.998Z","updated_at":"2025-08-22T18:15:29.998Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28421176,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T10:47:48.104Z","status":"ssl_error","status_checked_at":"2026-01-14T10:46:19.031Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["data","realtime","streaming-data"],"created_at":"2026-01-14T13:26:48.799Z","updated_at":"2026-01-14T13:26:49.351Z","avatar_url":"https://github.com/pravahio.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"Pravah.io\n=========\n![](https://github.com/pravahio/go-mesh/workflows/Go/badge.svg)\n\nPravah is a decentralised open source data exchange platform for smart cities. It's built on top of [Libp2p](https://github.com/libp2p/go-libp2p) to support highly available and super scalable peer-to-peer network of data nodes. \n\nPravah connects different stakeholders in a smart city like data producers and consumers to each other to enable a data economy, improve collaboration and simplify access to real-time data. High data quality, low latency, well-defined [data sharing standards](https://github.com/pravahio/protocols) and easy deployability across different platforms are some of the design objectives. This would enable anyone to build applications on top of low latency data flowing from the smart city infrastructure. \n\n## Quick Starter Guide\n\nBeing a decentralised platform, a node needs to be deployed to interact with the Pravah network but it won't be a quick starter guide if you do the hard work. So, we did it for you. Let's directly dive into how you can subscribe and consume data from the network.\n\nBefore we move forward, you need to understand two important concepts:\n1. A **Channel** describes the kind of data you want to consume. Every **Channel** will have an associated data standard, defined in protobuf. This will help you know how the incoming data would look even before you start consuming it. An example is `/PublicBus` channel which gives you [GTFS-Realtime](https://github.com/google/transit/blob/master/gtfs-realtime/proto/gtfs-realtime.proto) data.\n2. Next up is a **Geospace** which describes the geobound of your dataset. Say you want realtime public buses data for Delhi, India then the geospace will be `/in/delhi`. Pravah combine the channel and the geospace (`/PublicBus/in/delhi`) to create a unique data stream. A list of all available channels and geospaces are available [here](https://github.com/pravahio/go-mesh/wiki/Geospaces)\n\nThat's it for theory, let's dive into the code.\n\nUse this key: `1cDpdkE2Qvq26OvUAxkXswmHcXEPUBS6Wcig6ERQvPrQ`\n\n```py\n# This example demonstrate how one can get access real-time data coming out of \n# various public buses from Delhi, India.\n\n# Setting up\n# pip3 install pravah\n\nimport pravah\n\np = pravah.Pravah(\n    '/PublicBus', \n    endpoint='rpc.pravah.io:6666',\n    auth_token='\u003cPRAVAH_API_KEY\u003e'\n)\n\nfeed = p.subscribe('/in/delhi')\n\nfor message, geospace in feed:\n    # message is a `FeedMessage` instance as given in https://github.com/pravahio/protocols/blob/master/protocols/gtfs/PublicBus.proto\n    # As we can subscribe to multiple geospaces at once. `geospace` will help us identify geospace of the currently received message.\n    \n    # Print the entire FeedMessage.\n    print(message)\n\n    # Access the first entity and print it.\n    print(m.entity[0])\n```\n\n## Prerequisite\n\n1. git\n2. go \u003e= v1.12.*\n3. make\n4. gcc\n_____________\n## Installation\n\n**Note:** You need not build it before installing. Program is build and installed in a single step.\n\n```\ngit clone https://github.com/pravahio/go-mesh.git\ncd go-mesh\nmake install\n```\n__________________\n\n## Creating a new account\n\nAn account is a public-private key pair which will be used to sign all the messages and transactions flowing out of your node.\n\nYou can create one by using the following command\n\n```\nmesh account -c -p -o account.msa\n```\n\n____________\n\n## Config file\n\n`mesh` has many configuration options all of which are available in `mesh --help`.\n\nInstead of passing them as flags we can use a json based config file `(config.json)` as given below:\n\n\n```json\n{\n  \"rnz\": \"publicBus\",\n  \"account\": \"account.msa\",\n  \"debug\": \"true\"\n}\n```\n\nThis config file tells the mesh client to find more peers at `publicBus` rendezvous point, use `account.msa` account file and print all debug logs `(\"debug\": \"true\")`.\n\nA sample config file is avaiable [here](docs/config.json)\n\n_______\n\n## For data subscribers\n\nYou can quickly test out the platform by following the guide in this repo.\n\n\u003eNote that by following the above guide you won't be able to obtain realtime data and it should only be used to try out the platform.\n\nTo get realtime data you need to fire up `mesh` as a subscriber and connect via RPC.\n\n**1. Running `mesh` as a subscriber node**\n\nThis can be done by running `mesh` with `en-sub` flag.\n```\nmesh -c docs/config.json --en-sub\n```\n\nThis will do multiple things. First of all it will find other peers at `rnz` point and connect to them. It will then start an RPC server at default port `5555`.\n\n\u003eNote: If you want to use js client for mesh-gtfsr, you need to enable web RPC using `--web-rpc` flag. Without this you won't be able to connect to mesh RPC through a browser. Web RPC runs on a different port (Default: `5556`)\n\n**2. Once `mesh` client is up and running we can connect with it via RPC**\n\nAssuming we want to consume GTFS-Realtime data. Python client for `mesh-gtfsr` can be found here.\n\nInstall it with \n```\npip3 install mesh-gtfsr\n```\n\nNow we can start consuming GTFS-Realtime data for some specific *geospace*. `Delhi` in the given example. [Here](https://github.com/pravahio/go-mesh/wiki/Geospaces) you can find a list of all available *geospaces*.\n```py\nfrom pravah import Pravah\n\ndef main():\n  m = Pravah(\n    '/PublicBus', \n    endpoint='endpoint',\n    auth_token='\u003cPRAVAH_API_KEY\u003e')\n\n  feed = m.subscribe([\n    '/in/delhi'\n  ])\n  \n  # You get feed in 'f'\n  # and geospace in 'g\n  for f, g in feed:\n    print('Geospace: ' + g)\n    print('Feed: ' + str(f)) \n\nif \"__main__\" == __name__:\n  main()\n```\n\n`feed` is a tuple of `(feed:FeedMessage, geospace:string)`  as defined in [GTFS-Realtime specs](https://github.com/google/transit/blob/master/gtfs-realtime/proto/gtfs-realtime.proto)\n\nIf you want to get the data directly in the browser use the following guide.\n\n_______\n\n## For data publishers\n\n**1. Running `mesh` as a publisher node**\n\nThis can be done by running `mesh` with `en-pub` flag.\n```\nmesh -c docs/config.json --en-pub\n```\n\n**2. Once `mesh` client is up and running we can connect to it via RPC and start publishing.**\n\nAssuming we want to publish GTFS-Realtime data. Python client for `mesh-gtfsr` can be found here.\n\nInstall it with \n```\npip3 install mesh-gtfsr\n```\n\nNow we can start publishing GTFS-Realtime data.\n\n```py\nimport time\nfrom pravah import Pravah\n\nGEOSPACE = [\n  '/your/geospace/test'\n]\n\ndef main():\n  m = Pravah(\n    '/PublicBusTest', \n    endpoint='endpoint',\n    auth_token='\u003cPRAVAH_API_KEY\u003e')\n\n  rt = {\n    \"header\": {\n      \"timestamp\": time.time()\n    },\n    \"entity\": [{\n      \"id\": \"VEHICLE_ID\",\n      \"vehicle\": {\n          \"position\": {\n          \"latitude\": 77.23524,\n          \"longitude\": 22.35343\n          }\n      }\n    }]\n  }\n\n  m.registerToPublish(GEOSPACE)\n  m.publish(GEOSPACE, rt)\n\nif \"__main__\" == __name__:\n  main()\n```","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpravahio%2Fgo-mesh","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpravahio%2Fgo-mesh","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpravahio%2Fgo-mesh/lists"}