{"id":13702850,"url":"https://github.com/ros-infrastructure/superflore","last_synced_at":"2025-10-04T09:53:44.368Z","repository":{"id":44624295,"uuid":"92099947","full_name":"ros-infrastructure/superflore","owner":"ros-infrastructure","description":"An extended platform release manager for Robot Operating System","archived":false,"fork":false,"pushed_at":"2025-08-12T19:17:59.000Z","size":530,"stargazers_count":57,"open_issues_count":22,"forks_count":37,"subscribers_count":11,"default_branch":"master","last_synced_at":"2025-09-04T13:52:55.029Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ros-infrastructure.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2017-05-22T21:13:25.000Z","updated_at":"2025-08-12T19:18:04.000Z","dependencies_parsed_at":"2025-08-01T18:02:17.415Z","dependency_job_id":"43c21c35-4da9-48c9-bc83-0f205b33382b","html_url":"https://github.com/ros-infrastructure/superflore","commit_stats":{"total_commits":275,"total_committers":16,"mean_commits":17.1875,"dds":"0.44727272727272727","last_synced_commit":"d475c34818c7f450acc0123f77480ea27d3051ee"},"previous_names":[],"tags_count":7,"template":false,"template_full_name":null,"purl":"pkg:github/ros-infrastructure/superflore","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ros-infrastructure%2Fsuperflore","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ros-infrastructure%2Fsuperflore/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ros-infrastructure%2Fsuperflore/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ros-infrastructure%2Fsuperflore/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ros-infrastructure","download_url":"https://codeload.github.com/ros-infrastructure/superflore/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ros-infrastructure%2Fsuperflore/sbom","scorecard":{"id":784884,"data":{"date":"2025-08-11","repo":{"name":"github.com/ros-infrastructure/superflore","commit":"392ca5d6256b695680cf457e803b3033d9dc86a9"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.3,"checks":[{"name":"Maintained","score":5,"reason":"6 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/ros-infrastructure/superflore/ci.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/ros-infrastructure/superflore/ci.yaml/master?enable=pin","Warn: containerImage not pinned by hash: docker/Dockerfile:7: pin your Docker image by updating osrf/ros2:devel to osrf/ros2:devel@sha256:94ef2af480c857f828f9ef5b90aea1e0b97c13258cdadfe56c4a6df47ea1742c","Warn: containerImage not pinned by hash: tests/docker/Dockerfile:1","Warn: pipCommand not pinned by hash: setup_superflore.sh:22","Warn: pipCommand not pinned by hash: .github/workflows/ci.yaml:43","Info:   0 out of   2 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned","Info:   0 out of   2 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":0,"reason":"16 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2024-4 / GHSA-2mqj-m65w-jghx","Warn: Project is vulnerable to: PYSEC-2023-165 / GHSA-cwvm-v4w8-q58c","Warn: Project is vulnerable to: PYSEC-2022-42992 / GHSA-hcpj-qp55-gfph","Warn: Project is vulnerable to: PYSEC-2023-137 / GHSA-pr76-5cm5-w9cj","Warn: Project is vulnerable to: PYSEC-2023-161 / GHSA-wfm5-v35h-vwf4","Warn: Project is vulnerable to: PYSEC-2021-142 / GHSA-8q59-q68h-6hv4","Warn: Project is vulnerable to: PYSEC-2018-49 / GHSA-rprw-h62v-c2w7","Warn: Project is vulnerable to: PYSEC-2014-14 / GHSA-652x-xj99-gmcc","Warn: Project is vulnerable to: GHSA-9hjg-9r4m-mvj7","Warn: Project is vulnerable to: GHSA-9wx4-h78v-vm56","Warn: Project is vulnerable to: PYSEC-2014-13 / GHSA-cfj3-7x9c-4p3h","Warn: Project is vulnerable to: PYSEC-2018-28 / GHSA-x84v-xcm2-53pg","Warn: Project is vulnerable to: PYSEC-2013-22 / GHSA-27x4-j476-jp5f","Warn: Project is vulnerable to: PYSEC-2025-49 / GHSA-5rjg-fvgr-3xxf","Warn: Project is vulnerable to: GHSA-cx63-2mw6-8hw5","Warn: Project is vulnerable to: PYSEC-2022-43012 / GHSA-r9hx-vwmv-q579"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-23T05:49:17.829Z","repository_id":44624295,"created_at":"2025-08-23T05:49:17.829Z","updated_at":"2025-08-23T05:49:17.829Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278295827,"owners_count":25963430,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-04T02:00:05.491Z","response_time":63,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T21:00:44.288Z","updated_at":"2025-10-04T09:53:44.329Z","avatar_url":"https://github.com/ros-infrastructure.png","language":"Python","funding_links":[],"categories":["Development Environment"],"sub_categories":["Build and Deploy"],"readme":"Super Flore:\n=================\nLatin for \"Super Bloom\", this is an extended release manager for\nROS.\n\nSupported Platforms:\n--------------------\n * Gentoo\n * OpenEmbedded\n * Nix\n\nInstallation:\n=============\n\nDependencies:\n--------------\n * Python 3\n * Docker\n * Git\n\nInstructions:\n-------------\nTo automatically create a pull-request, you need to generate an [OAuth token](https://help.github.com/articles/creating-a-personal-access-token-for-the-command-line/) for this application.\n\nAfter you have created the token, place it in the\nenvironment variable `SUPERFLORE_GITHUB_TOKEN`.\n\nIf you're running it with `--dry-run` enabled, then `SUPERFLORE_GITHUB_TOKEN` isn't needed.\n\nThen install and run the application.\n\n```\n $ sudo python3 ./setup.py install\n```\n\nGentoo Usage:\n=============\n\n### Generating Gentoo Ebuilds\n```\n$ superflore-gen-ebuilds -h\nusage: superflore-gen-ebuilds [-h] [--ros-distro ROS_DISTRO] [--all]\n                              [--dry-run] [--pr-only] [--no-branch]\n                              [--output-repository-path OUTPUT_REPOSITORY_PATH]\n                              [--only ONLY [ONLY ...]]\n                              [--pr-comment PR_COMMENT]\n                              [--upstream-repo UPSTREAM_REPO]\n                              [--upstream-branch UPSTREAM_BRANCH]\n                              [--skip-keys SKIP_KEYS [SKIP_KEYS ...]]\n\nDeploy ROS packages into Gentoo Linux\n\noptional arguments:\n  -h, --help            show this help message and exit\n  --ros-distro ROS_DISTRO\n                        regenerate packages for the specified distro\n  --all                 regenerate all packages in all distros\n  --dry-run             run without filing a PR to remote\n  --pr-only             ONLY file a PR to remote\n  --no-branch           Do not create a new branch automatically\n  --output-repository-path OUTPUT_REPOSITORY_PATH\n                        location of the Git repo\n  --only ONLY [ONLY ...]\n                        generate only the specified packages\n  --pr-comment PR_COMMENT\n                        comment to add to the PR\n  --upstream-repo UPSTREAM_REPO\n                        location of the upstream repository as in\n                        https://github.com/\u003cowner\u003e/\u003crepository\u003e\n  --upstream-branch UPSTREAM_BRANCH\n                        branch of the upstream repository\n  --skip-keys SKIP_KEYS [SKIP_KEYS ...]\n                        packages to skip during regeneration\n```\n\n### Testing Gentoo Ebuilds\n```\n$ superflore-check-ebuilds -h\nusage: superflore-check-ebuilds [-h]\n                                [--ros-distro ROS_DISTRO [ROS_DISTRO ...]]\n                                [--pkgs PKGS [PKGS ...]] [-f F] [-v]\n                                [--log-file LOG_FILE]\n\nCheck if ROS packages are building for Gentoo Linux\n\noptional arguments:\n  -h, --help            show this help message and exit\n  --ros-distro ROS_DISTRO [ROS_DISTRO ...]\n                        distro(s) to check\n  --pkgs PKGS [PKGS ...]\n                        packages to build\n  -f F                  build packages specified by the input file\n  -v, --verbose         show output from docker\n  --log-file LOG_FILE   location to store the log file\n```\n\nIf a file is to be passed as input, it is expected to be in proper yaml format, such as the below.\n\n```\nindigo:\n  - catkin\n  - p2os_msgs\nkinetic:\n  - catkin\nlunar:\n  - catkin\n```\n\nCommon Usage:\n--------------\nTo update the gentoo ebuilds, run the following:\n\n```\n$ superflore-gen-ebuilds\n```\n\nThis command will clone the `ros/ros-overlay` repo into\na subfolder within `/tmp`. This can be thought of as an\nupdate mode. *Note: this mode will file a PR with ros/ros-overlay.*\n\nIf you don't want to file a PR with ros/ros-overlay, you should add\nthe `--dry-run` flag. You can later decide to file the PR after inspection\nby using the `--pr-only` flag.\n\nTo regenerate only the specified packages, use the `--only [pkg1] [pkg2] ... [pkgn]` flag (**note:** you will need to also use the `--ros-distro [distro]` flag.\n\n*If you want to use an existing repo instead of cloning one,\nadd `--output-repository-path [path]`.*\n\nRegenerating:\n--------------\nIn the case that you wish to regenerate an entire rosdistro, you may do\nso by adding the `--ros-distro [distro name]` flag. *Note: this is very\ntime consuming.*\n\nIf you wish to regenerate _all_ installers for _all_ ros distros, you\nshould pass the `--all` flag in place of the `--ros-distro` flag. *Note:\nthis takes an _extremely_ long amount of time.*\n\n\nOpenEmbedded Usage:\n===================\n\n### Generating OpenEmbedded Recipes\n\n**NOTE:** The instructions\n[here](https://github.com/ros/meta-ros/wiki/Superflore-OE-Recipe-Generation-Scheme#usage)\nshould be followed to generate the OpenEmbedded recipes for `meta-ros`.\n\n```\n$ superflore-gen-oe-recipes -h\nusage: superflore-gen-oe-recipes [-h] --ros-distro ROS_DISTRO --dry-run\n                                 [--pr-only] [--no-branch]\n                                 [--output-repository-path OUTPUT_REPOSITORY_PATH]\n                                 [--only ONLY [ONLY ...]]\n                                 [--pr-comment PR_COMMENT]\n                                 [--upstream-repo UPSTREAM_REPO]\n                                 [--upstream-branch UPSTREAM_BRANCH]\n                                 [--skip-keys SKIP_KEYS [SKIP_KEYS ...]]\n                                 [--tar-archive-dir TAR_ARCHIVE_DIR]\n\nGenerate OpenEmbedded recipes for ROS packages\n\noptional arguments:\n  -h, --help            show this help message and exit\n  --ros-distro ROS_DISTRO\n                        regenerate packages for the specified distro\n  --dry-run             run without filing a PR to remote\n  --pr-only             ONLY file a PR to remote\n  --no-branch           Do not create a new branch automatically\n  --output-repository-path OUTPUT_REPOSITORY_PATH\n                        location of the Git repo\n  --only ONLY [ONLY ...]\n                        generate only the specified packages\n  --pr-comment PR_COMMENT\n                        comment to add to the PR\n  --upstream-repo UPSTREAM_REPO\n                        location of the upstream repository as in\n                        https://github.com/\u003cowner\u003e/\u003crepository\u003e\n  --upstream-branch UPSTREAM_BRANCH\n                        branch of the upstream repository\n  --skip-keys SKIP_KEYS [SKIP_KEYS ...]\n                        packages to skip during regeneration\n  --tar-archive-dir TAR_ARCHIVE_DIR\n                        location to store archived packages\n```\n\nCommon Usage:\n--------------\nTo update the OpenEmbedded recipes for a ROS distro, run the following:\n\n```\n$ superflore-gen-oe-recipes --ros-distro ROS_DISTRO\n```\n\nThis command will clone the `ros/meta-ros` repo into a subfolder under\n`/tmp/superflore`, generate the recipes and other files for the specified\ndistro, commit them, and issue a pull request for `ros/meta-ros`. The\n`--ros-distro` flag must be supplied. ROS 1 distros prior to \"melodic\" are\nnot supported.\n\nGenerating bitbake recipes without specifying `--dry-run` is not\nsupported. This is because it is almost inevitable that\nchanges to the metadata under recipes-bbappend will be required.\nOnly when these have been made and the images build and pass\nthe sanity test should a pull request be created.\nYou can issue the PR later by using the `--pr-only` flag.\n\nIf you want to use an existing repo instead of cloning one, specify\n`--output-repository-path OUTPUT_REPOSITORY_PATH`.\n\nNote that the `--only` flag currently generates bogus files under `conf` and\n`files`.\n\n\nF.A.Q.:\n=========\nHere are some specific use cases for Superflore.\n\nGentoo:\n--------\n\n**Q**: _I need to patch this package. What are the steps involved here?_\n\n**A**: It's relatively simple to generate a patch for a package. From a\ncontributor standpoint, superflore does most of the heavy lifting for you.\n\nWe'll assume you have already patched your source code, and your patch is\nnamed `fix-pkg.patch`. Also, we'll assume you're patching the package `foo`,\nand that you have a fork of ros/ros-overlay on its master branch within\nyou home directory.\n\n```\n$ cd ${HOME}/ros-overlay/ros-[distro]/foo\n$ mkdir files\n$ cp /path/to/patch/fix-pkg.patch ./files\n$ git add files\n$ git commit -m \"Add patch to fix package [foo] in [distro].\"\n```\n\nNext, use Superflore to regenerate the package.\n\n```\n$ superflore-gen-ebuilds --only [foo] --ros-distro [distro] --output-repository-path ~/ros-overlay\n```\n\nAfter that command runs, a pull request will be filed on your behalf into\nthe ROS overlay repository. **Note:** If you don't want a pull request to be\nfiled, add the `--dry-run` flag to the above command, and, after you are ready\nto file the pr, run `superflore-gen-ebuilds --pr-only`.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fros-infrastructure%2Fsuperflore","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fros-infrastructure%2Fsuperflore","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fros-infrastructure%2Fsuperflore/lists"}