# z3-4.16.0 4.16.0

The Z3 Theorem Prover

Snapshot of gominimal/pkgs commit `c930e3121426c055f690867bf78f5bbd9c2c9826` (pushed 2026-10-11T00:34:22.000Z).

## Install

```sh
min add z3-4.16.0
```

## Direct advisories

None at this commit.

## Transitive advisories

None at this commit.

## Dependencies

- Build (5): base, cmake, ninja, python, toolchain
- Runtime (2): glibc, gcc

## OpenSSF Scorecard

Aggregate score: 4.7 / 10. Scored by OpenSSF Scorecard. Repository scored: Z3Prover/z3. Scanned 2026-10-05.

Result on OpenSSF's viewer: https://scorecard.dev/viewer/?uri=github.com/Z3Prover/z3

Checks, scored 0-10 as the Scorecard tool reports them (N/A: not applicable or inconclusive):

| Check | Score | Reason |
| --- | --- | --- |
| [Binary-Artifacts](https://minimal.dev/docs/reference/scorecard#check-binary-artifacts) | 10 | No binaries found in the repo |
| [Branch-Protection](https://minimal.dev/docs/reference/scorecard#check-branch-protection) | 0 | Branch protection not enabled on development/release branches |
| [CII-Best-Practices](https://minimal.dev/docs/reference/scorecard#check-cii-best-practices) | 0 | No effort to earn an OpenSSF best practices badge detected |
| [Code-Review](https://minimal.dev/docs/reference/scorecard#check-code-review) | 6 | Found 11/17 approved changesets -- score normalized to 6 |
| [Dangerous-Workflow](https://minimal.dev/docs/reference/scorecard#check-dangerous-workflow) | 10 | No dangerous workflow patterns detected |
| [Fuzzing](https://minimal.dev/docs/reference/scorecard#check-fuzzing) | 0 | Project is not fuzzed |
| [License](https://minimal.dev/docs/reference/scorecard#check-license) | 9 | License file detected |
| [Maintained](https://minimal.dev/docs/reference/scorecard#check-maintained) | 10 | 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 |
| [Packaging](https://minimal.dev/docs/reference/scorecard#check-packaging) | 10 | Packaging workflow detected |
| [Pinned-Dependencies](https://minimal.dev/docs/reference/scorecard#check-pinned-dependencies) | 6 | Dependency not pinned by hash detected -- score normalized to 6 |
| [SAST](https://minimal.dev/docs/reference/scorecard#check-sast) | 0 | SAST tool is not run on all commits -- score normalized to 0 |
| [Security-Policy](https://minimal.dev/docs/reference/scorecard#check-security-policy) | 0 | Security policy file not detected |
| [Signed-Releases](https://minimal.dev/docs/reference/scorecard#check-signed-releases) | 0 | Project has not signed or included provenance with any releases. |
| [Token-Permissions](https://minimal.dev/docs/reference/scorecard#check-token-permissions) | 0 | Detected GitHub workflow tokens with excessive permissions |

## Links

- Package page (HTML): https://minimal.dev/pkgs/z3-4.16.0
- JSON API (floats latest): https://minimal.dev/api/pkgs/z3-4.16.0.json
- SBOM (CycloneDX 1.5): https://minimal.dev/api/pkgs/z3-4.16.0/sbom.json
- Build attestations (JSON): https://minimal.dev/api/pkgs/z3-4.16.0/attestation.json
