View packages at a commit

Paste a `locked_commit` from your `minimal.toml`, or a recent commit from the list.

Back to search results
mkcert owner avatar

mkcert

Version: 1.4.4

A simple zero-config tool to make locally trusted development certificates with any names you'd like.

Install package

min add mkcert
Toolcertificateschromefirefox

OpenSSF Score

OpenSSF Scorecard — mkcert

Scored 0–10, as OpenSSF Scorecard reports them.N/A: not applicable or inconclusive.

Binary-Artifacts

No binaries found in the repo

10
Branch-Protection

Branch protection not enabled on development/release branches

0
CII-Best-Practices

No effort to earn an OpenSSF best practices badge detected

0
Code-Review

Found 9/30 approved changesets -- score normalized to 3

3
Dangerous-Workflow

No dangerous workflow patterns detected

10
Fuzzing

Project is not fuzzed

0
License

License file detected

10
Maintained

0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0

0
Packaging

Packaging workflow not detected

N/A
Pinned-Dependencies

Dependency not pinned by hash detected -- score normalized to 0

0
SAST

SAST tool is not run on all commits -- score normalized to 0

0
Security-Policy

Security policy file detected

9
Signed-Releases

Project has not signed or included provenance with any releases.

0
Token-Permissions

Detected GitHub workflow tokens with excessive permissions

0

Scored by OpenSSF Scorecard, from OpenSSF's weekly scan of public GitHub repositories.

FiloSottile/mkcertscanned

Last scored on

What is "mkcert"?

A simple zero-config tool to make locally trusted development certificates with any names you'd like.

How to use this package

Quick install

Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.

min add mkcert

Declare as a task dependency in minimal.toml

Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.

[tasks.dev]
packages = ["mkcert"]

Build-time vs runtime

Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.

min add --build mkcert
min add --runtime mkcert

Dependencies (4)

Dependencies
NameVersionKind
base—build
glibc2.44runtime
go1.27.1build
toolchain—build

No dependants

No other packages in the registry depend on this one.

  1. mkcert v1.4.4e179f84
    Diff
    Lines:+61Deps:4(+4)
    Released:

No known advisories

We don't track any active CVEs against this package.

Build provenance

Loading provenance

For the signed record of what the build used, see the Provenance tab.

Software Bill of Materials — every package this build depends on
PackagesVersion
mkcertROOT1.4.4
acl2.4.0
attr2.6.0
autoconf2.73
automake1.18.1
bash5.3
bash-bootstrap5.3
binutils2.47
bison3.8.2
bzip21.0.8
cmake4.4.2
coreutils9.12
curl8.22.0
diffutils3.12
expat2.8.5
file5.48
findutils4.11.0
flex2.6.4
gawk5.4.1
gawk-bootstrap5.4.1
gcc15.2.0
gdbm1.26
gettext1.0
git2.55.0
glibc2.44
gmp6.3.0
go1.27.1
grep3.12
gzip1.15
libcap2.78
libffi3.8.0
libidn22.3.8
libpsl0.23.3
libtool2.6.2
libunistring1.4.2
libuv1.52.1
linux_headers6.12.43
llvm21.1.8
llvm-bootstrap21.1.8
lz41.10.0
m41.4.21
make4.4.1
meson1.12.0
mpc1.4.1
mpfr4.2.2
ncurses6.6
ninja1.13.2
openssl3.6.4
patch2.8
pcre210.49
perl5.44.0
pkgconf3.0.5
python3.14.8
readline8.3
rust1.98.1
sed4.10
setuptools84.0.0
sqlite3.53.4
tar1.35
tzdata2026e
util-linux2.42.4
xz5.8.4
zlib1.3.2
zstd1.5.7

Join the waitlist

Confirm your identity by email or GitHub.

or