{"id":20238526,"url":"https://github.com/smallstep/crypto","last_synced_at":"2026-06-12T23:03:01.861Z","repository":{"id":37074670,"uuid":"285380450","full_name":"smallstep/crypto","owner":"smallstep","description":"Crypto is a collection of packages used by Smallstep products","archived":false,"fork":false,"pushed_at":"2026-06-02T15:21:38.000Z","size":5132,"stargazers_count":104,"open_issues_count":23,"forks_count":30,"subscribers_count":10,"default_branch":"master","last_synced_at":"2026-06-02T17:16:46.622Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/smallstep.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-08-05T19:05:45.000Z","updated_at":"2026-05-27T09:29:12.000Z","dependencies_parsed_at":"2023-11-07T01:24:21.955Z","dependency_job_id":null,"html_url":"https://github.com/smallstep/crypto","commit_stats":null,"previous_names":[],"tags_count":153,"template":false,"template_full_name":null,"purl":"pkg:github/smallstep/crypto","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fcrypto","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fcrypto/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fcrypto/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fcrypto/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/smallstep","download_url":"https://codeload.github.com/smallstep/crypto/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fcrypto/sbom","scorecard":{"id":589873,"data":{"date":"2025-08-11","repo":{"name":"github.com/smallstep/crypto","commit":"50a9696edf2b5808466e7d1ba4ddc9140cf89dc3"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":7.2,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/code-scan-cron.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/dependabot-auto-merge.yml:5","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Warn: no topLevel permission defined: .github/workflows/triage.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-scan-cron.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/code-scan-cron.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/dependabot-auto-merge.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/triage.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/smallstep/crypto/triage.yml/master?enable=pin","Info:   0 out of   1 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   5 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-20T21:35:02.854Z","repository_id":37074670,"created_at":"2025-08-20T21:35:02.854Z","updated_at":"2025-08-20T21:35:02.854Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34265495,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-12T02:00:06.859Z","response_time":109,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T08:34:37.308Z","updated_at":"2026-06-12T23:03:01.730Z","avatar_url":"https://github.com/smallstep.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# crypto\n\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![Go Report Card](https://goreportcard.com/badge/github.com/smallstep/crypto)](https://goreportcard.com/report/github.com/smallstep/crypto)\n[![CI](https://github.com/smallstep/crypto/actions/workflows/ci.yml/badge.svg)](https://github.com/smallstep/crypto/actions/workflows/ci.yml)\n[![codecov](https://codecov.io/gh/smallstep/crypto/branch/master/graph/badge.svg)](https://codecov.io/gh/smallstep/crypto)\n[![Documentation](https://godoc.org/go.step.sm/crypto?status.svg)](https://pkg.go.dev/mod/go.step.sm/crypto)\n\nCrypto is a collection of packages used in [smallstep](https://smallstep.com) products. See:\n\n* [step](https://github.com/smallstep/cli): A zero trust swiss army knife for\n  working with X509, OAuth, JWT, OATH OTP, etc.\n* [step-ca](https://github.com/smallstep/certificates): A private certificate\n  authority (X.509 \u0026 SSH) \u0026 ACME server for secure automated certificate\n  management, so you can use TLS everywhere \u0026 SSO for SSH.\n\n## Usage\n\nTo add this to a project, just run:\n\n```sh\ngo get go.step.sm/crypto\n```\n\n## Packages\n\n### x509util\n\nPackage `x509util` implements utilities to build X.509 certificates based on JSON\ntemplates.\n\n### sshutil\n\nPackage `sshutil` implements utilities to build SSH certificates based on JSON\ntemplates.\n\n### keyutil\n\nPackage `keyutil` implements utilities to generate cryptographic keys.\n\n### pemutil\n\nPackage `pemutil` implements utilities to parse keys and certificates. It also\nincludes a method to serialize keys, X.509 certificates and certificate requests\nto PEM.\n\n### randutil\n\nPackage `randutil` provides methods to generate random strings and salts.\n\n### tlsutil\n\nPackage `tlsutil` provides utilities to configure tls client and servers.\n\n### jose\n\nPackage `jose` is a wrapper for `github.com/go-jose/go-jose/v3` and implements\nutilities to parse and generate JWT, JWK and JWKSets.\n\n### x25519\n\nPackage `x25519` adds support for X25519 keys and the\n[XEdDSA](https://signal.org/docs/specifications/xeddsa/) signature scheme.\n\n### minica\n\nPackage `minica` implements a simple certificate authority.\n\n### kms\n\nPackage `kms` implements interfaces to perform cryptographic operations like\nsigning certificates using cloud-based key management systems, PKCS #11 modules,\nor just a YubiKey or an ssh-agent. On the cloud it supports:\n\n* [Amazon AWS KMS](https://aws.amazon.com/kms/)\n* [Google Cloud Key Management](https://cloud.google.com/security-key-management)\n* [Microsoft Azure Key Vault](https://azure.microsoft.com/en-us/services/key-vault/)\n\n### fingerprint\n\nPackage `fingerprint` provides methods for creating and encoding X.509\ncertificate, SSH certificate and SSH key fingerprints.\n\n### tpm\n\nPackage `tpm` provides an abstraction over and utilities for interacting with\nTPMs. It can be used to retrieve TPM information, retrieve its Endorsement Keys\n(EK) and associated certificates, create and operate on Attestation Keys (AK),\nand create and operate on (attested) application keys. The `storage` subpackage\nprovides an interface and concrete implementations offering a transparent\npersistence mechanism for Attestation and application keys.\n\n### fipsutil\n\nPackage `fipsutil` reports whether the cryptography libraries are operating in\nFIPS 140-3 mode.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallstep%2Fcrypto","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsmallstep%2Fcrypto","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallstep%2Fcrypto/lists"}