{"id":47762768,"url":"https://github.com/taskcluster/slugid-go","last_synced_at":"2026-04-03T05:49:10.733Z","repository":{"id":57487507,"uuid":"43062565","full_name":"taskcluster/slugid-go","owner":"taskcluster","description":"A go (golang) port of https://github.com/taskcluster/slugid","archived":false,"fork":false,"pushed_at":"2020-11-10T21:57:14.000Z","size":65,"stargazers_count":25,"open_issues_count":0,"forks_count":8,"subscribers_count":6,"default_branch":"main","last_synced_at":"2024-06-18T17:03:21.003Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/taskcluster.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-09-24T11:22:24.000Z","updated_at":"2023-12-29T01:00:30.000Z","dependencies_parsed_at":"2022-09-01T22:52:02.368Z","dependency_job_id":null,"html_url":"https://github.com/taskcluster/slugid-go","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/taskcluster/slugid-go","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taskcluster%2Fslugid-go","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taskcluster%2Fslugid-go/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taskcluster%2Fslugid-go/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taskcluster%2Fslugid-go/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/taskcluster","download_url":"https://codeload.github.com/taskcluster/slugid-go/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/taskcluster%2Fslugid-go/sbom","scorecard":{"id":869263,"data":{"date":"2025-08-11","repo":{"name":"github.com/taskcluster/slugid-go","commit":"58334603d76139d499850828cd97b7fd25774ed8"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.2,"checks":[{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":2,"reason":"Found 6/23 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Maintained","score":0,"reason":"project is archived","details":["Warn: Repository is archived."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Mozilla Public License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v1.0.0 not signed: https://api.github.com/repos/taskcluster/slugid-go/releases/1876233","Warn: release artifact v1.0.0 does not have provenance: https://api.github.com/repos/taskcluster/slugid-go/releases/1876233"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/taskcluster/.github/SECURITY.md:1","Info: Found linked content: github.com/taskcluster/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/taskcluster/.github/SECURITY.md:1","Info: Found text in security policy: github.com/taskcluster/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 13 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-24T03:39:04.612Z","repository_id":57487507,"created_at":"2025-08-24T03:39:04.612Z","updated_at":"2025-08-24T03:39:04.612Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31337184,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-03T04:42:29.251Z","status":"ssl_error","status_checked_at":"2026-04-03T04:42:12.667Z","response_time":107,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-04-03T05:49:10.246Z","updated_at":"2026-04-03T05:49:10.722Z","avatar_url":"https://github.com/taskcluster.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cimg align=\"right\" src=\"http://media.taskcluster.net/logo/logo-96x120.png\" /\u003e\n\nslugid-go - Compressed UUIDs for go (golang)\n============================================\n\n[![GoDoc](https://godoc.org/github.com/taskcluster/slugid-go?status.svg)](https://godoc.org/github.com/taskcluster/slugid-go)\n[![Build Status](https://travis-ci.org/taskcluster/slugid-go.svg?branch=main)](http://travis-ci.org/taskcluster/slugid-go)\n[![Coverage Status](https://coveralls.io/repos/taskcluster/slugid-go/badge.svg?branch=main\u0026service=github)](https://coveralls.io/github/taskcluster/slugid-go?branch=master)\n[![License](https://img.shields.io/badge/license-MPL%202.0-orange.svg)](https://github.com/taskcluster/slugid-go/blob/main/LICENSE)\n\nslugid-go provides:\n\n* A go (golang) module for generating v4 UUIDs and encoding them into 22\ncharacter URL-safe base64 slug representation (see [RFC 4648 sec.\n5](http://tools.ietf.org/html/rfc4648#section-5)).\n* A command line tool to provides the same functions\n\nSlugs are url-safe base64 encoded v4 uuids, stripped of base64 `=` padding.\n\nThere are two methods for generating slugs - `slugid.V4()` and\n`slugid.Nice()`.\n\n* The `slugid.V4()` method returns a slug from a randomly generated v4 uuid.\n* The `slugid.Nice()` method returns a v4 slug which conforms to a set of\n  \"nice\" properties. At the moment the only \"nice\" property is that the slug\n  starts with `[A-Za-f]`, which in turn implies that the first (most\n  significant) bit of its associated uuid is set to 0.\n\nThe purpose of the `slugid.Nice()` method is to support having slugids which\ncan be used in more contexts safely. Regular slugids can safely be used in\nurls, and for example in AMQP routing keys. However, slugs beginning with `-`\nmay cause problems when used as command line parameters.\n\nIn contrast, slugids generated by the `slugid.Nice()` method can safely be\nused as command line parameters. This comes at a cost to entropy (121 bits vs\n122 bits for regular v4 slugs).\n\nSlug consumers should consider carefully which of these two slug generation\nmethods to call. Is it more important to have maximum entropy, or to have\nslugids that do not need special treatment when used as command line\nparameters? This is especially important if you are providing a service which\nsupplies slugs to unexpecting tool developers downstream, who may not realise\nthe risks of using your regular v4 slugs as command line parameters, especially\nsince this would arise only as an intermittent issue (one time in 64).\n\nGenerated slugs take the form `[A-Za-z0-9_-]{22}`, or more precisely:\n\n* `slugid.V4()` slugs conform to\n  `[A-Za-z0-9_-]{8}[Q-T][A-Za-z0-9_-][CGKOSWaeimquy26-][A-Za-z0-9_-]{10}[AQgw]`\n\n* `slugid.Nice()` slugs conform to\n  `[A-Za-f][A-Za-z0-9_-]{7}[Q-T][A-Za-z0-9_-][CGKOSWaeimquy26-][A-Za-z0-9_-]{10}[AQgw]`\n\nRFC 4122 defines the setting of 6 bits of the v4 UUID which implies v4 slugs\nprovide 128 - 6 = 122 bits entropy. Due to the (un)setting of the first bit\nof \"nice\" slugs, nice slugs provide therefore 121 bits entropy.\n\nThese are the fixed six bits:\n\n* bit 48: `0`\n* bit 49: `1`\n* bit 50: `0`\n* bit 51: `0`\n* bit 64: `1`\n* bit 65: `0`\n\nSplitting the 128 bits into groups of six to see the base64 character boundaries, we get:\n\n```\nposition:                                                                                                                 11 111111 111111 111111 111111 11\n                 11 111111 112222 222222 333333 333344 444444 445555 555555 666666 666677 777777 778888 888888 999999 999900 000000 001111 111111 222222 22\n      012345 678901 234567 890123 456789 012345 678901 234567 890123 456789 012345 678901 234567 890123 456789 012345 678901 234567 890123 456789 012345 67\nbin: |......|......|......|......|......|......|......|......|0100..|......|....10|......|......|......|......|......|......|......|......|......|......|..0000|\nb64: |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   β  |   α  |   γ  |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   α  |   δ  |\n```\n\nUsing the base64url encoding scheme, we can see which characters are allowed at each of the 22 positions.\n\n⇒\n\n* α = `0b......` ∈ {\n```\n000000 A\n000001 B\n000010 C\n000011 D\n000100 E\n000101 F\n000110 G\n000111 H\n001000 I\n001001 J\n001010 K\n001011 L\n001100 M\n001101 N\n001110 O\n001111 P\n010000 Q\n010001 R\n010010 S\n010011 T\n010100 U\n010101 V\n010110 W\n010111 X\n011000 Y\n011001 Z\n011010 a\n011011 b\n011100 c\n011101 d\n011110 e\n011111 f\n100000 g\n100001 h\n100010 i\n100011 j\n100100 k\n100101 l\n100110 m\n100111 n\n101000 o\n101001 p\n101010 q\n101011 r\n101100 s\n101101 t\n101110 u\n101111 v\n110000 w\n110001 x\n110010 y\n110011 z\n110100 0\n110101 1\n110110 2\n110111 3\n111000 4\n111001 5\n111010 6\n111011 7\n111100 8\n111101 9\n111110 -\n111111 _\n```\n}\n* β = `0b0100..` ∈ {\n```\n010000 Q\n010001 R\n010010 S\n010011 T\n```\n}\n* γ = `0b....10` ∈ {\n```\n000010 C\n000110 G\n001010 K\n001110 O\n010010 S\n010110 W\n011010 a\n011110 e\n100010 i\n100110 m\n101010 q\n101110 u\n110010 y\n110110 2\n111010 6\n111110 -\n```\n}\n* δ = `0b..0000` ∈ {\n```\n000000 A\n010000 Q\n100000 g\n110000 w\n```\n}\n\nThus we reach a 22 character encoding of:\n\n* α{8}βαγα{10}δ\n\nwhich denormalised becomes:\n\n* `^[A-Za-z0-9_-]{8}[Q-T][A-Za-z0-9_-][CGKOSWaeimquy26-][A-Za-z0-9_-]{10}[AQgw]$`\n\n\nGo library usage\n----------------\n\n```go\nimport \"github.com/taskcluster/slugid-go/slugid\"\n\n...\n\n// Generate \"nice\" URL-safe base64 encoded UUID version 4 (random)\nslug := slugid.Nice()  // a8_YezW8T7e1jLxG7evy-A\n\n// Alternative, if slugs will not be used as command line parameters\nslug := slugid.V4()    // -9OpXaCORAaFh4sJRk7PUA\n\n// Get [UUID](https://godoc.org/github.com/pborman/uuid#UUID) from slug\nuuid := slugid.Decode(slug)\n\n// Get slug from [UUID](https://godoc.org/github.com/pborman/uuid#UUID)\nslug := slugid.Encode(uuid)\n```\n\nInstalling command line tool\n----------------------------\n\n__Binary installation__\n\nDownload the slug command line tool for your platform from\n[here](https://github.com/taskcluster/slugid-go/releases).\n\n__Source installation__\n\nRequirements:\n\n  * go (golang) v1.11 or higher\n  * `${GOPATH}/bin` is in your path\n\nRun:\n\n```bash\ngo get github.com/taskcluster/slugid-go/cmd/slug\n```\n\nCommand line usage\n------------------\n\n\n```\nUsage:\n  slug [-n|--nice|-r|--v4] [COUNT]\n  slug encode [UUID...|-]\n  slug decode [SLUGID...|-]\n  slug -h|--help\n  slug -v|--version\n\n  slug [-n|--nice|-r|--v4] [COUNT]  Generates new slug(s). If -r or --v4 is\n                                    provided, regular v4 UUID are used for\n                                    generating the slug(s). In all other cases\n                                    (-n, --nice, or *no* option) \"nice\" slugs\n                                    are generated. COUNT specifies how many\n                                    slugs to generate, default is one. Slugs\n                                    are output on separate lines.\n\n  slug decode (-|[SLUGID...])       Outputs the v4 UUID(s) represented by the\n                                    given SLUGID(s), or slugid(s) passed via\n                                    standard in (one per line) if '-' is\n                                    provided. UUID(s) are output one per line,\n                                    in the order they were specified. If no\n                                    slugids are provided as command line options\n                                    or via '-' option, slug generates no output\n                                    and exits successfully.\n\n  slug encode (-|[UUID...])         Outputs the SLUGID(s) represented by the\n                                    given UUID(s), or UUID(s) passed via\n                                    standard in (one per line) if '-' is\n                                    provided. SLUGIDs are output one per line,\n                                    in the order they were specified. If no\n                                    UUIDs are provided as command line options\n                                    or via '-' option, slug generates no output\n                                    and exits successfully.\n\n  slug -h|--help                    Displays this help page.\n\n  slug -v|--version                 Displays the version of the slug command\n                                    line tool.\n\n\nExit Codes:\n\n   0: Success\n   1: Unrecognised command line options\n  64: Cannot decode invalid slug into a UUID\n  65: Problem reading standard input during slug decoding\n  66: Cannot encode invalid uuid into a slug\n  67: Problem reading standard input during slug encoding\n  68: Invalid value passed in for command line option COUNT\n```\n\n__Examples__\n\n```\n  $ slug 10\n  RDBdHcXuTUq5ghG1wMTArQ\n  BwwjV68MS3aQpkJynFZg9w\n  QjbIAaOlSK-in5Hveh0T4w\n  YGw68ONSR76wruU85RnvjA\n  M0eS8zm5RE2qKKURM_1q9g\n  ET23t51DSS2c57PA24QQGg\n  cu9mg-T6Rem9LuXBdHd9Ig\n  OxghknAoS9ORYPocd9HFUg\n  Yg6Yei4QQl-iqdZ3udJlLw\n  Ek924JDBRGeA6t6PiNz6UQ\n\n  $ slug --v4 2\n  -0eS8zm5RE2qKKURM_1q9g\n  OxghknAoS9ORYPocd9HFUg\n\n  $ slug decode OxghknAoS9ORYPocd9HFUg SJZbHUBSQLaichv2auLqGQ EChNNJAyS0SeUMlRWCnJ1A\n  3b182192-7028-4bd3-9160-fa1c77d1c552\n  48965b1d-4052-40b6-a272-1bf66ae2ea19\n  10284d34-9032-4b44-9e50-c9515829c9d4\n\n  $ echo 'f47ac10b-58cc-4372-a567-0e02b2c3d479 81d6bb7e-985c-409b-af6c-4721b4a38ec6' \\\n              | tr ' ' '\\n' | slug encode -\n  9HrBC1jMQ3KlZw4CssPUeQ\n  gda7fphcQJuvbEchtKOOxg\n\n  $ slug 5 | slug decode -\n  3405ed8e-e39f-4a3c-a0ea-e107950757f5\n  1df41b41-18a2-4d85-bdde-8a73f02a5014\n  5fe568dd-6bfd-4f58-8740-17bea665c2ac\n  2464a287-7f82-42ad-9b7d-1e26639d569a\n  1c936d1b-104c-4abf-97b4-f586371e8742\n\n  $ slug 5 | slug decode - | slug encode -\n  WLjW7XpJQ5ePycx6zWF8mw\n  dEOJgGpARrWBm9HX9MPBSA\n  fBIwjdHdRyGIk5WITyqxqA\n  bYuEpq-SQSaZimBDmTe4Kg\n  LLY3KZ05QWm0cBS4rfdTaQ\n```\n\nRNG Characteristics\n-------------------\nUUID generation is performed by the\n[github.com/pborman/uuid](https://godoc.org/github.com/pborman/uuid)\nlibrary which in turn uses the\n[crypto/rand](https://golang.org/pkg/crypto/rand/#pkg-variables) standard\nlibrary for generating entropy. This library declares:\n\n\u003e Reader is a global, shared instance of a cryptographically strong\n\u003e pseudo-random generator.\n\u003e\n\u003e On Unix-like systems, Reader reads from /dev/urandom. On Linux, Reader uses\n\u003e getrandom(2) if available, /dev/urandom otherwise. On Windows systems, Reader\n\u003e uses the CryptGenRandom API. \n\nThe slugid library inherits these RNG characteristics.\n\nLicense\n-------\nThe `slugid` library is released on the MPL 2.0 license, see file `LICENSE`\nfor the complete license.\n\nTesting\n-------\n\n```bash\ngo test ./...\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftaskcluster%2Fslugid-go","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftaskcluster%2Fslugid-go","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftaskcluster%2Fslugid-go/lists"}