{"id":13627428,"url":"https://github.com/taboola/async-profiler-actuator-endpoint","last_synced_at":"2026-01-14T02:44:54.248Z","repository":{"id":43469950,"uuid":"313560145","full_name":"taboola/async-profiler-actuator-endpoint","owner":"taboola","description":null,"archived":false,"fork":false,"pushed_at":"2025-02-18T12:07:52.000Z","size":126,"stargazers_count":35,"open_issues_count":0,"forks_count":1,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-07-29T21:24:31.593Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/taboola.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2020-11-17T08:52:42.000Z","updated_at":"2025-07-12T10:18:37.000Z","dependencies_parsed_at":"2025-02-18T08:24:40.842Z","dependency_job_id":"70f40009-3894-49b7-8a17-13d146192553","html_url":"https://github.com/taboola/async-profiler-actuator-endpoint","commit_stats":null,"previous_names":[],"tags_count":12,"template":false,"template_full_name":null,"purl":"pkg:github/taboola/async-profiler-actuator-endpoint","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taboola%2Fasync-profiler-actuator-endpoint","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taboola%2Fasync-profiler-actuator-endpoint/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taboola%2Fasync-profiler-actuator-endpoint/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taboola%2Fasync-profiler-actuator-endpoint/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/taboola","download_url":"https://codeload.github.com/taboola/async-profiler-actuator-endpoint/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taboola%2Fasync-profiler-actuator-endpoint/sbom","scorecard":{"id":865149,"data":{"date":"2025-08-18","repo":{"name":"github.com/taboola/async-profiler-actuator-endpoint","commit":"cf1edb3fab94f80970d96655c1e0428516b6b62f"},"scorecard":{"version":"v5.2.1-41-g40576783","commit":"40576783fda6698350fcbbeaea760ff827433034"},"score":1.9,"checks":[{"name":"Code-Review","score":2,"reason":"Found 3/11 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#packaging"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v2.0.0 not signed: https://api.github.com/repos/taboola/async-profiler-actuator-endpoint/releases/60678245","Warn: release artifact v2.0.0 does not have provenance: https://api.github.com/repos/taboola/async-profiler-actuator-endpoint/releases/60678245"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 29 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-rc42-6c7j-7h5r","Warn: Project is vulnerable to: GHSA-4gc7-5j7h-4qph","Warn: Project is vulnerable to: GHSA-4wp7-92pw-q264","Warn: Project is vulnerable to: GHSA-9cmq-m9j5-mvww","Warn: Project is vulnerable to: GHSA-2rmj-mq67-h97g","Warn: Project is vulnerable to: GHSA-2wrp-6fg6-hmc5","Warn: Project is vulnerable to: GHSA-4wrc-f8pq-fpqp","Warn: Project is vulnerable to: GHSA-ccgv-vj62-xf9h","Warn: Project is vulnerable to: GHSA-hgjh-9rj2-g67j"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/40576783fda6698350fcbbeaea760ff827433034/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-24T02:29:37.182Z","repository_id":43469950,"created_at":"2025-08-24T02:29:37.182Z","updated_at":"2025-08-24T02:29:37.182Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28408733,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T01:52:23.358Z","status":"online","status_checked_at":"2026-01-14T02:00:06.678Z","response_time":107,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T22:00:33.977Z","updated_at":"2026-01-14T02:44:54.229Z","avatar_url":"https://github.com/taboola.png","language":"Java","funding_links":[],"categories":["Projects by main language"],"sub_categories":["java"],"readme":"# async-profiler-actuator-endpoint\n\n[![Maven Central](https://maven-badges.herokuapp.com/maven-central/com.taboola/async-profiler-actuator-endpoint/badge.svg?style=plastic)](https://maven-badges.herokuapp.com/maven-central/com.taboola/async-profiler-actuator-endpoint)\n[![Build Status](https://travis-ci.org/taboola/async-profiler-actuator-endpoint.svg?branch=master)](https://travis-ci.org/taboola/async-profiler-actuator-endpoint)\n\nThis project contains a spring boot actuator endpoint implementation which serves as a wrapper for [Async Profiler](https://github.com/jvm-profiling-tools/async-profiler).\n\nIt allows controlling the profiler via simple HTTP GET requests to the profiled service itself. \n\nYou can either send a blocking profile request and get the flame graph in the response, or send a non-blocking request to start a continuous-profiling session which will periodically report profile results to a dedicated reporter. \n\n#### Async Profiler Library\nThe profiler library is already bundled in this project.\n\n#### Continuous Profiling\nAs mentioned above, we also support continuous profiling to periodically run the profiler and report the results to a dedicated reporter.\nWe provide a default PyroscopeReporter, to report the snapshots to a configurable [Pyroscope](https://github.com/pyroscope-io/pyroscope) server, but you can also create a different ProfileResultsReporter bean to override the default one with your own custom implementation.\n\nYou can start/stop the session from the endpoint, but you can also configure it to start automatically when the service starts by configuring:\n```com.taboola.asyncProfiler.continuousProfiling.startOnInit=true```\n\n\n#### Getting Started\nAdd the dependency:\n```\n\u003cdependency\u003e\n  \u003cgroupId\u003ecom.taboola\u003c/groupId\u003e\n  \u003cartifactId\u003easync-profiler-actuator-endpoint\u003c/artifactId\u003e\n\u003c/dependency\u003e\n```\n\nWire it into your app by including the endpoint configuration class in your application context configuration class, e.g:\n```\n@Configuration\n@Import(AsyncProfilerEndpointConfig.class) \npublic class YourSpringConfigurationClass {\n}\n```\n\n#### Endpoints\n1. `/async-profiler/profile` - to profile the service and get the flame graph in the response (blocking call, default is cpu profiling for 60sec).\n    \n    Or, for example, profile multiple events together for 30 seconds and get it as a .jfr file attachment in the response:\n\n   `/async-profiler/profile?events=alloc,cpu,lock\u0026durationSeconds=30`\n\n    Check [ProfileRequest](https://github.com/taboola/async-profiler-actuator-endpoint/blob/main/src/main/java/com/taboola/async_profiler/api/facade/ProfileRequest.java) to see the possible request parameters.\n\n\n2. `/async-profiler/stop` - to stop a currently active profile request, if any, and get its profiling output in the response.\n\n\n3. `/async-profiler/start-continuous` - to start a continuous profiling session. \n\n    This will use the default parameters (cpu profiling in 10-seconds snapshots), you can override them with the same parameters that are available for profile requests.\n\n\n4. `/async-profiler/stop-continuous` - to stop a continuous profiling session.\n\n\n5. `/async-profiler/events` - to get the supported event types.\n\n\n6. `/async-profiler/version` - to get the loaded profiler version.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftaboola%2Fasync-profiler-actuator-endpoint","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftaboola%2Fasync-profiler-actuator-endpoint","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftaboola%2Fasync-profiler-actuator-endpoint/lists"}