{"id":20573827,"url":"https://github.com/soohoio/planetql","last_synced_at":"2026-04-17T18:31:56.641Z","repository":{"id":54436671,"uuid":"317775857","full_name":"soohoio/planetql","owner":"soohoio","description":null,"archived":false,"fork":false,"pushed_at":"2021-02-18T04:09:49.000Z","size":46,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-10-04T03:34:27.635Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C#","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/soohoio.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-12-02T06:53:41.000Z","updated_at":"2021-08-13T15:37:02.000Z","dependencies_parsed_at":"2022-08-13T15:40:21.513Z","dependency_job_id":null,"html_url":"https://github.com/soohoio/planetql","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/soohoio/planetql","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/soohoio%2Fplanetql","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/soohoio%2Fplanetql/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/soohoio%2Fplanetql/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/soohoio%2Fplanetql/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/soohoio","download_url":"https://codeload.github.com/soohoio/planetql/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/soohoio%2Fplanetql/sbom","scorecard":{"id":838205,"data":{"date":"2025-08-11","repo":{"name":"github.com/soohoio/planetql","commit":"63bef2435248515361d5ef6ea2434c340f8a5308"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.8,"checks":[{"name":"Code-Review","score":2,"reason":"Found 1/4 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: Dockerfile:1","Warn: npmCommand not pinned by hash: Dockerfile:41","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   1 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 2 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":0,"reason":"16 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-ww39-953v-wcq6","Warn: Project is vulnerable to: GHSA-29mw-wpgm-hmr9","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h","Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-pq67-2wwv-3xjx","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6","Warn: Project is vulnerable to: GHSA-j8xg-fqg3-53r7"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T19:44:56.254Z","repository_id":54436671,"created_at":"2025-08-23T19:44:56.254Z","updated_at":"2025-08-23T19:44:56.254Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31940760,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-17T17:29:20.459Z","status":"ssl_error","status_checked_at":"2026-04-17T17:28:47.801Z","response_time":62,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-16T05:29:16.167Z","updated_at":"2026-04-17T18:31:56.627Z","avatar_url":"https://github.com/soohoio.png","language":"C#","funding_links":[],"categories":[],"sub_categories":[],"readme":"# PlanetQL\n\nAnalyze C# project vunlerabilities\n\nPlanetQL provides analyzing service for c# project.  \nIt uses [codeQL](https://github.com/github/codeql) to analyzing project with our custom queries.  \nCurrently provides `Non-deterministic iteration search` query and more queries will be provided later on.  \nCodeQL environment is provided in docker image [soohoio/planetql](https://hub.docker.com/repository/docker/soohoio/planetql), image also provides CLI for easier use of codeQL.\n\n**Table of Contents**\n\n- [PlanetQL](#planetql)\n  - [Usage](#usage)\n    - [From scripts](#from-scripts)\n      - [Example](#example)\n    - [By scripts](#by-scripts)\n      - [Example](#example-1)\n  - [TroubleShooting](#troubleshooting)\n  - [Contributing](#contributing)\n\n## Usage\n\n### From scripts\n\ndownload planetQL container with command\n\n```\ndocker pull soohoio/planetql\n```\n\nRun container with mounting volumes of `c# project` and `output` directory. After specifying volumes, execute planetql CLI with command `planetql` you can see manual with command `planetql help`.\n\nYou can find more information of PlanetQL CLI command in [PlanetQL-CLI help](planetql-cli/README.md)\n\n```\ndocker run --rm --name planetql -v \"${PROJECT_TO_ANALYZE}:/opt/src\" -v \"${OUTPUT_DIRECTORY}:/opt/results\" soohoio/planetql planetql help\n```\n\n\u003e Default path of `c# project` inside container is `/opt/src` and Default path of `output` directory is `/opt/results`.  \n\u003e Planetql CLI uses default path if you don't provide path when running command of planetQL CLI. Specify path to planetql cli with flags when you mounted your project at different path inside of container.\n\n#### Example\n\n```zsh\n$ docker run --rm --name planetql -v \"$(pwd)/sample_project:/opt/src\" -v \"$(pwd)/results:/opt/results\" soohoio/planetql planetql setup\nInitializing database ...\n\n\n$ docker run --rm --name planetql -v \"$(pwd)/sample_project:/opt/src\" -v \"$(pwd)/results:/opt/results\" soohoio/planetql planetql analyze -f --format=csv\nCompiling query plan ...\n```\n\n### By scripts\n\nWe provide shell script automates pulling docker image and running container with planetql cli commands\n\nsetup script\n\n```\nsetup.sh \u003cc# project path\u003e \u003coutput directory\u003e\n```\n\nanalyze script\n\n```\nanalyze.sh \u003coutput directory\u003e\n```\n\n#### Example\n\n```zsh\n$ scripts/setup.sh sample_project results\n\n$ scripts/analyze.sh results -f --format=csv\n```\n\n## TroubleShooting\n\nDocker resource should be big enough to create codeql database. If you're stuck in `planetql set`(`codeql database create`) command, Try setting your docker environment to use more memory.\n\n## Contributing\n\nThis project welcomes contributions and suggestions. Please open issues and Pull Requests for new features or bugs.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsoohoio%2Fplanetql","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsoohoio%2Fplanetql","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsoohoio%2Fplanetql/lists"}