{"id":13571720,"url":"https://github.com/spring-io/initializr","last_synced_at":"2026-02-05T11:11:10.307Z","repository":{"id":8846910,"uuid":"10553586","full_name":"spring-io/initializr","owner":"spring-io","description":"A quickstart generator for Spring projects","archived":false,"fork":false,"pushed_at":"2026-01-26T16:00:22.000Z","size":11689,"stargazers_count":3640,"open_issues_count":45,"forks_count":1796,"subscribers_count":145,"default_branch":"main","last_synced_at":"2026-01-26T21:55:47.912Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://start.spring.io","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/spring-io.png","metadata":{"files":{"readme":"README.adoc","changelog":null,"contributing":"CONTRIBUTING.adoc","funding":null,"license":"LICENSE.txt","code_of_conduct":"CODE_OF_CONDUCT.adoc","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2013-06-07T16:02:22.000Z","updated_at":"2026-01-26T19:31:16.000Z","dependencies_parsed_at":"2023-10-10T22:57:55.404Z","dependency_job_id":"2494a0c6-1171-4ff9-9de8-abff7b7f0cb4","html_url":"https://github.com/spring-io/initializr","commit_stats":{"total_commits":2098,"total_committers":127,"mean_commits":"16.519685039370078","dds":0.3350810295519543,"last_synced_commit":"e62633adf7e13901b3be1701dd378459feb648db"},"previous_names":[],"tags_count":23,"template":false,"template_full_name":null,"purl":"pkg:github/spring-io/initializr","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spring-io%2Finitializr","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spring-io%2Finitializr/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spring-io%2Finitializr/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spring-io%2Finitializr/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/spring-io","download_url":"https://codeload.github.com/spring-io/initializr/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spring-io%2Finitializr/sbom","scorecard":{"id":634997,"data":{"date":"2025-08-11","repo":{"name":"github.com/spring-io/initializr","commit":"9fa21dd5e930134c5178962c355de8e551fdc69a"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":7.1,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:79","Info: jobLevel 'actions' permission set to 'read': .github/workflows/run-codeql-analysis.yml:12","Info: jobLevel 'contents' permission set to 'read': .github/workflows/run-codeql-analysis.yml:13","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/run-codeql-analysis.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/build-pull-request.yml:5","Info: topLevel 'contents' permission set to 'read': .github/workflows/build.yml:3","Info: topLevel 'contents' permission set to 'read': .github/workflows/release.yml:3","Info: topLevel permissions set to 'read-all': .github/workflows/run-codeql-analysis.yml:8"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.txt:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE.txt:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: initializr-generator-spring/src/main/resources/gradle/8/wrapper/gradle/wrapper/gradle-wrapper.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/spring-io/.github/SECURITY.md:1","Info: Found linked content: github.com/spring-io/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/spring-io/.github/SECURITY.md:1","Info: Found text in security policy: github.com/spring-io/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Info: Possibly incomplete results: error parsing shell code: invalid parameter name: .github/workflows/release.yml:75","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-pull-request.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/build-pull-request.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-pull-request.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/build-pull-request.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-io/initializr/release.yml/main?enable=pin","Info:   0 out of   8 GitHub-owned GitHubAction dependencies pinned","Info:   4 out of   4 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build.yml:12"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T08:53:29.464Z","repository_id":8846910,"created_at":"2025-08-21T08:53:29.464Z","updated_at":"2025-08-21T08:53:29.464Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29120485,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-05T10:47:47.471Z","status":"ssl_error","status_checked_at":"2026-02-05T10:45:08.119Z","response_time":65,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T14:01:05.294Z","updated_at":"2026-02-05T11:11:10.296Z","avatar_url":"https://github.com/spring-io.png","language":"Java","funding_links":[],"categories":["Java","企业软件开发"],"sub_categories":["文件同步"],"readme":"= Spring Initializr image:https://github.com/spring-io/initializr/actions/workflows/build.yml/badge.svg[\"Build status\", link=\"https://github.com/spring-io/initializr/actions/workflows/build.yml\"] image:https://badges.gitter.im/spring-io/initializr.svg[link=\"https://gitter.im/spring-io/initializr?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge\"]\n\n:boot-doc: https://docs.spring.io/spring-boot/docs/current/reference/htmlsingle\n:code: https://github.com/spring-io/initializr/blob/main\n:docs: https://docs.spring.io/initializr/docs/current-SNAPSHOT/reference\n:service: https://github.com/spring-io/start.spring.io\n\nSpring Initializr provides an extensible API to generate JVM-based projects with\nimplementations for several common concepts:\n\n* Basic language generation for Java, Kotlin and Groovy.\n* Build system abstraction with implementations for Apache Maven and Gradle.\n* `.gitignore` support.\n* Several hook-points for custom resources generations.\n\nThe various options for the projects are expressed in a metadata model that allows you to\nconfigure the list of dependencies, supported JVM and platform versions, etc.\n\nSpring Initializr also exposes web endpoints to generate an actual project and also\nserve its metadata in a well-known format to allow third-party clients to provide the\nnecessary assistance.\n\nA set of optional conventions for Spring Boot projects is provided and are used in our\nproduction instance at link:https://start.spring.io[]. To better understand how our\nservice is configured, you may want to check {service}[the companion project] and, in\nparticular, the\n{service}/blob/main/start-site/src/main/resources/application.yml[configuration of our\ninstance]. Such configuration is also described in details in the documentation.\n\nNOTE: While Spring Initializr is available on Maven Central, it is still in a pre 1.0\nstate and major refactoring are still possible. Check the\nhttps://github.com/spring-io/initializr/milestones[milestones page] for an overview of the\nchanges.\n\n== Installation and Getting Started\nThe reference documentation is available in {docs}/html/[HTML format].\n\n\n== Modules\nSpring Initializr has the following modules:\n\n* `initializr-actuator`: optional module to provide additional information and statistics\non project generation.\n* `initializr-bom`: provides a Bill of Materials for easier dependency management in your\nproject.\n* `initializr-docs`: documentation.\n* `initializr-generator`: core project generation library.\n* `initializr-generator-spring`: optional module defining the conventions for a typical\nSpring Boot project. Can be reused or replaced by your own conventions.\n* `initializr-generator-test`: test infrastructure for project generation.\n* `initializr-metadata`: metadata infrastructure for various aspects of the project.\n* `initializr-service-sample`: showcases a basic custom instance.\n* `initializr-version-resolver`: optional module to extract version numbers from an\narbitrary POM.\n* `initializr-web`: web endpoints for third party clients.\n\n== Supported interfaces\nSpring Initializr can be used as follows:\n\n* On the command-line with {boot-doc}/#cli-init[the Spring Boot CLI] or simply with\n`cURL` or `HTTPie`.\n* In your IDE if you are using STS, IntelliJ IDEA Ultimate, NetBeans (with\nhttps://github.com/AlexFalappa/nb-springboot[this plugin]) or VSCode (with\nhttps://github.com/microsoft/vscode-spring-initializr[the `vscode-spring-initializr`\nplugin]).\n* With a custom Web UI (check ours at link:https://start.spring.io[]).\n\nThere are other command-line integrations out there and you can also build your own!\n\n== Running your own instance\nYou can easily run your own instance. The `initializr-web` modules uses Spring Boot\nso when it is added to a project, it will trigger the necessary auto-configuration to\ndeploy the service.\n\nThe `initializr-service-sample` showcases a basic custom instance with dedicated metadata.\n\n\n[[build]]\n== Building from Source\nYou need Java 25 and a bash-like shell.\n\n[[building]]\n=== Building\nInvoke the build at the root of the project:\n\n[indent=0]\n----\n    $ ./mvnw clean install\n----\n\nTo generate the docs as well, you should enable the `full` profile:\n\n[indent=0]\n----\n    $ ./mvnw clean install -Pfull\n----\n\n== License\nSpring Initializr is Open Source software released under the\nhttps://www.apache.org/licenses/LICENSE-2.0.html[Apache 2.0 license].\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspring-io%2Finitializr","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fspring-io%2Finitializr","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspring-io%2Finitializr/lists"}