{
  "repository": "n8n-io/n8n",
  "url": "https://github.com/n8n-io/n8n",
  "description": "Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.",
  "score": 76,
  "verdict": "未达到当前场景门槛，还差 14 分",
  "stars": 201029,
  "forks": 60204,
  "open_issues": 1306,
  "inactive_days": 0,
  "license": "NOASSERTION",
  "language": "TypeScript",
  "checks": [
    {
      "label": "许可证明确",
      "passed": false,
      "weight": 10
    },
    {
      "label": "90 天内持续维护",
      "passed": true,
      "weight": 10
    },
    {
      "label": "安装与依赖清单",
      "passed": true,
      "weight": 6
    },
    {
      "label": "README 文档",
      "passed": true,
      "weight": 4
    },
    {
      "label": "正式版本发布",
      "passed": true,
      "weight": 4
    },
    {
      "label": "持续集成线索",
      "passed": true,
      "weight": 5
    },
    {
      "label": "容器化入口",
      "passed": true,
      "weight": 3
    },
    {
      "label": "测试目录",
      "passed": true,
      "weight": 8
    }
  ],
  "pillars": [
    {
      "label": "供应链安全",
      "score": 26,
      "max": 40
    },
    {
      "label": "工程准备度",
      "score": 30,
      "max": 30
    },
    {
      "label": "维护与采用",
      "score": 20,
      "max": 20
    },
    {
      "label": "许可证清晰度",
      "score": 0,
      "max": 10
    }
  ],
  "openssf": {
    "score": 6.6,
    "date": "2026-08-10",
    "version": "v5.5.1-0.20260807204611-40c1e3599673",
    "checks": [
      {
        "name": "Code-Review",
        "score": 10,
        "reason": "all changesets reviewed",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#code-review"
      },
      {
        "name": "Maintained",
        "score": 10,
        "reason": "30 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#maintained"
      },
      {
        "name": "CII-Best-Practices",
        "score": 0,
        "reason": "no effort to earn an OpenSSF best practices badge detected",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#cii-best-practices"
      },
      {
        "name": "Security-Policy",
        "score": 10,
        "reason": "security policy file detected",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#security-policy"
      },
      {
        "name": "License",
        "score": 9,
        "reason": "license file detected",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#license"
      },
      {
        "name": "Dangerous-Workflow",
        "score": 10,
        "reason": "no dangerous workflow patterns detected",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#dangerous-workflow"
      },
      {
        "name": "Signed-Releases",
        "score": 0,
        "reason": "Project has not signed or included provenance with any releases.",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#signed-releases"
      },
      {
        "name": "Token-Permissions",
        "score": 0,
        "reason": "detected GitHub workflow tokens with excessive permissions",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#token-permissions"
      },
      {
        "name": "Packaging",
        "score": 10,
        "reason": "packaging workflow detected",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#packaging"
      },
      {
        "name": "Binary-Artifacts",
        "score": 10,
        "reason": "no binaries found in the repo",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#binary-artifacts"
      },
      {
        "name": "Pinned-Dependencies",
        "score": 7,
        "reason": "dependency not pinned by hash detected -- score normalized to 7",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#pinned-dependencies"
      },
      {
        "name": "Branch-Protection",
        "score": 4,
        "reason": "branch protection is not maximal on development and all release branches",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#branch-protection"
      },
      {
        "name": "Fuzzing",
        "score": 10,
        "reason": "project is fuzzed",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#fuzzing"
      },
      {
        "name": "SAST",
        "score": 0,
        "reason": "SAST tool is not run on all commits -- score normalized to 0",
        "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#sast"
      }
    ]
  },
  "security_failures": [
    {
      "name": "CII-Best-Practices",
      "score": 0,
      "reason": "no effort to earn an OpenSSF best practices badge detected",
      "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#cii-best-practices",
      "action": "依据 OpenSSF CII-Best-Practices 检查原因补齐安全控制",
      "priority": "P0"
    },
    {
      "name": "Signed-Releases",
      "score": 0,
      "reason": "Project has not signed or included provenance with any releases.",
      "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#signed-releases",
      "action": "为发布产物增加签名或 SLSA provenance",
      "priority": "P0"
    },
    {
      "name": "Token-Permissions",
      "score": 0,
      "reason": "detected GitHub workflow tokens with excessive permissions",
      "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#token-permissions",
      "action": "将 GitHub Actions token 默认权限降为只读并逐项授权",
      "priority": "P0"
    },
    {
      "name": "SAST",
      "score": 0,
      "reason": "SAST tool is not run on all commits -- score normalized to 0",
      "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#sast",
      "action": "在所有提交上运行静态安全扫描并阻断高危问题",
      "priority": "P0"
    },
    {
      "name": "Branch-Protection",
      "score": 4,
      "reason": "branch protection is not maximal on development and all release branches",
      "documentation": "https://github.com/ossf/scorecard/blob/40c1e35996730d4fdcbdb2e6a23917a2467e29b7/docs/checks.md#branch-protection",
      "action": "为默认分支启用必需审查、状态检查和管理员保护",
      "priority": "P1"
    }
  ],
  "remediation_plan": [
    {
      "day": 1,
      "priority": "P0",
      "task": "依据 OpenSSF CII-Best-Practices 检查原因补齐安全控制",
      "gate": "CII-Best-Practices 风险有负责人、证据和接受/修复结论"
    },
    {
      "day": 2,
      "priority": "P0",
      "task": "为发布产物增加签名或 SLSA provenance",
      "gate": "Signed-Releases 风险有负责人、证据和接受/修复结论"
    },
    {
      "day": 3,
      "priority": "P0",
      "task": "将 GitHub Actions token 默认权限降为只读并逐项授权",
      "gate": "Token-Permissions 风险有负责人、证据和接受/修复结论"
    },
    {
      "day": 4,
      "priority": "P0",
      "task": "用一个真实业务样例完成隔离环境验证",
      "gate": "输入、输出、失败路径和人工接管均有可复现证据"
    },
    {
      "day": 5,
      "priority": "P0",
      "task": "限制 Agent 工具权限并增加高风险操作确认",
      "gate": "越权、提示注入和失控循环测试全部通过"
    },
    {
      "day": 6,
      "priority": "P0",
      "task": "完成数据流、保存位置和第三方传输审查",
      "gate": "敏感字段有最小化、加密、删除和审计策略"
    },
    {
      "day": 7,
      "priority": "P1",
      "task": "准备单人可执行的备份、升级和故障手册",
      "gate": "无人协助时可在 30 分钟内恢复核心服务"
    }
  ],
  "adoption_context": {
    "scenario": "agent",
    "scenario_label": "可执行操作的 AI Agent",
    "sensitivity": "sensitive",
    "sensitivity_label": "敏感或受监管数据",
    "team_size": "solo",
    "team_size_label": "1 人"
  },
  "adoption_threshold": 90,
  "risks": [
    "确认许可证允许你的商业使用和修改方式",
    "OpenSSF CII-Best-Practices 0/10：no effort to earn an OpenSSF best practices badge detected",
    "OpenSSF Signed-Releases 0/10：Project has not signed or included provenance with any releases.",
    "OpenSSF Token-Permissions 0/10：detected GitHub workflow tokens with excessive permissions",
    "开放问题较多，需要抽样检查维护响应速度"
  ],
  "confidence": "高",
  "evidence_sources": [
    "GitHub REST API",
    "OpenSSF Scorecard"
  ],
  "evidence_time": "2026-08-18T06:42:52.932274+00:00"
}