https://github.com/mattermost/mattermost
collaboration golang hacktoberfest mattermost monorepo react react-native
Score: 31.17255578561214
Last synced: about 2 hours ago
JSON representation
Repository metadata:
Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..
- Host: GitHub
- URL: https://github.com/mattermost/mattermost
- Owner: mattermost
- License: other
- Created: 2015-06-15T06:50:02.000Z (about 11 years ago)
- Default Branch: master
- Last Pushed: 2026-06-16T06:00:49.000Z (7 days ago)
- Last Synced: 2026-06-16T06:06:20.149Z (7 days ago)
- Topics: collaboration, golang, hacktoberfest, mattermost, monorepo, react, react-native
- Language: TypeScript
- Homepage: https://mattermost.com
- Size: 1000 MB
- Stars: 37,922
- Watchers: 534
- Forks: 8,740
- Open Issues: 912
-
Metadata Files:
- Readme: README.md
- Changelog: CHANGELOG.md
- Contributing: CONTRIBUTING.md
- License: LICENSE.enterprise
- Codeowners: CODEOWNERS
- Security: SECURITY.md
- Notice: NOTICE.txt
- Agents: AGENTS.md
Package metadata
- Total packages: 20
-
Total downloads:
- npm: 196,660 last-month
- homebrew: 172 last-month
- Total docker downloads: 888,710,486
- Total dependent packages: 26 (may contain duplicates)
- Total dependent repositories: 645 (may contain duplicates)
- Total versions: 2,612
- Total maintainers: 15
- Total advisories: 101
proxy.golang.org: github.com/mattermost/mattermost/server/public
- Homepage: https://github.com/mattermost/mattermost
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/server/public#section-documentation
- Licenses: Apache-2.0
- Latest release: v0.4.2 (published 21 days ago)
- Last Synced: 2026-06-21T22:30:42.312Z (1 day ago)
- Versions: 48
- Dependent Packages: 13
- Dependent Repositories: 63
- Docker Downloads: 444,355,188
-
Rankings:
- Forks count: 0.038%
- Stargazers count: 0.055%
- Dependent repos count: 0.728%
- Average: 0.896%
- Dependent packages count: 1.419%
- Docker downloads count: 2.242%
- Advisories:
proxy.golang.org: github.com/mattermost/mattermost/server/v8
- Homepage: https://github.com/mattermost/mattermost
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/server/v8#section-documentation
- Licenses: other
- Latest release: v8.0.0-20260619183049-ee04f28e873d (published 3 days ago)
- Last Synced: 2026-06-22T04:12:34.858Z (about 20 hours ago)
- Versions: 996
- Dependent Packages: 2
- Dependent Repositories: 1
- Docker Downloads: 444,355,188
-
Rankings:
- Forks count: 0.038%
- Stargazers count: 0.055%
- Docker downloads count: 2.242%
- Average: 2.244%
- Dependent packages count: 4.177%
- Dependent repos count: 4.706%
-
Advisories:
- Mattermost doesn't prevent disclosure of created user password
- Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
- Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation
- Mattermost doesn't verify channel membership when processing AI-assisted message rewrites
- Mattermost doesn't check public/private permissions
- Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
- Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
- Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
- Mattermost does not verify remote cluster channel access when processing shared channel membership removals
- Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
- Mattermost doesn't check the create_post channel permission during post edit operations
- Mattermost doesn't escape some variables that could contain malicious content during error page composition
- Mattermost doesn't validate 7zip archive structure before processing
- Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
- Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement
- Mattermost doesn't validate CSRF tokens on an authentication endpoint
- Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration
- Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences
- Mattermost doesn't validate decompressed archive entry sizes during file extraction
- Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope
- Mattermost has an Incorrect Authorization issue
- Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
- Mattermost doesn't properly validate CSRF tokens
- Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds
- Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation
- Mattermost fails to properly enforce read permissions in search API endpoints
- Mattermost fails to validate user's authentication method when processing account auth type switch
- Mattermost fails to validate team-specific upload_file permissions
- Mattermost fails to use consistent error responses when handling the /mute command
- Mattermost fails to limit the size of responses from integration action endpoints
- Mattermost fails to filter invite IDs based on user permissions
- Mattermost allows a removed team member to enumerate all public channels within a private team
- Mattermost fails to preserve the redacted state of burn-on-read posts during deletion
- Mattermost fails to bound memory allocation when processing PSD image files
- Mattermost allows attackers to spoof permalink embeds
- Mattermost fails to properly validate User-Agent header tokens
- Mattermost fails to bound memory allocation when processing DOC files
- Mattermost fails to properly handle very long passwords
- Mattermost fails to enforce invite permissions when updating team settings
- Mattermost fails to properly validate team membership when processing channel mentions
- Mattermost fails to sanitize sensitive data in WebSocket messages
- Mattermost fails to properly validate login method restrictions
- Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
- Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
- Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm
- Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation
- Mattermost has missing redirect URL validation
- Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
- Mattermost fails to validate user permissions in Boards
- Mattermost fails to validate user permissions when deleting comments in Boards
- Mattermost fails to to verify the token used during code exchange
- Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
- Mattermost fails to sanitize team email addresses
- Mattermost allows other users to determine when users had read channels via channel member objects
- Mattermost allows system administrators to access password hashes and MFA secrets
- Mattermost does not enforce MFA on WebSocket connections
- Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
- Mattermost fails to properly restrict access to archived channel search API
- Mattermost allows regular users to access archived channel content and files
- Mattermost Incorrect Authorization vulnerability
- Mattermost has a Missing Authorization vulnerability
- Mattermost has a Missing Authorization vulnerability
- Mattermost has an Observable Timing Discrepancy vulnerability
- Mattermost has a Missing Authorization vulnerability
- Mattermost has a Missing Authorization vulnerability
- Mattermost has an Incorrect Authorization vulnerability
- Mattermost Path Traversal vulnerability
- Mattermost boards plugin fails to restrict download access to files
- Mattermost Open Redirect vulnerability
- Mattermost makes Use of Weak Hash
- Mattermost Open Redirect vulnerability
- Mattermost Missing Authorization vulnerability
- Mattermost Fails to Sanitize File Names
- Mattermost has Potential Server Crash due to Unvalidated Import Data
- Mattermost Fails to Sanitize Path Traversal Sequences
- Mattermost Fails to Properly Validate Team Role Modification
- Mattermost Lack of Access Control Validation
- Mattermost Server SSRF Vulnerability via the Agents Plugin
- Mattermost Does Not Sanitize the Team Invite ID
- Mattermost Fails to Validate Remote Cluster Upload Sessions
- Mattermost Fails to Validate File Paths
- Mattermost has Insufficiently Protected Credentials
- Mattermost Path Traversal vulnerability
- Mattermost Missing Authentication for Critical Function
- Mattermost Incorrect Authorization vulnerability
- Mattermost Incorrect Authorization vulnerability
- Mattermost allows unauthorized channel member management through playbook runs
- Mattermost allows an unauthorized Guest user access to Playbook
- Mattermost allows authenticated users to write files to arbitrary locations
- Mattermost allows guest users to view information about public teams they are not members of
- Mattermost allows authenticated administrator to execute LDAP search filter injection
- Mattermost fails to properly enforce access controls for guest users
- Mattermost fails to clear Google OAuth credentials
- Mattermost fails to properly invalidate personal access tokens upon user deactivation
- Mattermost fails to properly enforce access control restrictions for System Manager roles
- Mattermost improperly allows team administrators to modify team invites
- Mattermost Fails to Verify User's Permissions When Accessing Groups
- Mattermost Fails to Check User Access to `ExperimentalSettings`
- Mattermost Fails to Validate Team Invite Permissions
- Mattermost Fails to Lockout LDAP Users After Repeated Login Failures
npmjs.org: mattermost-redux
Common code (API client, Redux stores, logic, utility functions) for building a Mattermost client
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/mattermost-redux#readme
- Licenses: MIT
- Latest release: 11.7.0 (published 20 days ago)
- Last Synced: 2026-06-12T07:02:07.453Z (11 days ago)
- Versions: 71
- Dependent Packages: 7
- Dependent Repositories: 371
- Downloads: 5,002 Last month
- Docker Downloads: 91
-
Rankings:
- Dependent repos count: 0.864%
- Docker downloads count: 1.255%
- Forks count: 1.845%
- Average: 2.28%
- Dependent packages count: 2.788%
- Downloads: 2.879%
- Stargazers count: 4.05%
- Maintainers (14)
npmjs.org: @mattermost/types
Shared type definitions used by the Mattermost web app
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/types#readme
- Licenses: MIT
- Latest release: 11.7.0 (published 20 days ago)
- Last Synced: 2026-06-12T07:02:07.080Z (11 days ago)
- Versions: 51
- Dependent Packages: 2
- Dependent Repositories: 119
- Downloads: 94,405 Last month
-
Rankings:
- Forks count: 0.432%
- Stargazers count: 0.548%
- Dependent repos count: 1.338%
- Downloads: 1.65%
- Average: 2.563%
- Dependent packages count: 8.845%
- Maintainers (14)
npmjs.org: @mattermost/client
JavaScript/TypeScript client for Mattermost
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/client#readme
- Licenses: MIT
- Latest release: 11.7.0 (published 20 days ago)
- Last Synced: 2026-06-12T07:02:07.108Z (11 days ago)
- Versions: 51
- Dependent Packages: 2
- Dependent Repositories: 89
- Downloads: 91,213 Last month
-
Rankings:
- Forks count: 0.432%
- Stargazers count: 0.548%
- Dependent repos count: 1.49%
- Downloads: 1.745%
- Average: 2.612%
- Dependent packages count: 8.845%
- Maintainers (14)
proxy.golang.org: github.com/mattermost/mattermost/v5
- Homepage:
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/v5#section-documentation
- Licenses: other
- Latest release: v5.39.3 (published over 4 years ago)
- Last Synced: 2026-06-12T07:01:50.753Z (11 days ago)
- Versions: 392
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Forks count: 0.039%
- Stargazers count: 0.055%
- Average: 4.716%
- Dependent packages count: 8.463%
- Dependent repos count: 10.306%
proxy.golang.org: github.com/mattermost/mattermost/tools/mattermost-govet
- Homepage: https://github.com/mattermost/mattermost
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/tools/mattermost-govet#section-documentation
- Licenses:
- Latest release: (published 6 days ago)
- Last Synced: 2026-06-16T13:32:42.694Z (6 days ago)
- Versions: 0
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Dependent packages count: 4.674%
- Average: 4.831%
- Dependent repos count: 4.988%
proxy.golang.org: github.com/mattermost/mattermost/tools/mmgotool
- Homepage: https://github.com/mattermost/mattermost
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/tools/mmgotool#section-documentation
- Licenses: other
- Latest release: v0.0.0-20240124191417-8f0abc131673 (published over 2 years ago)
- Last Synced: 2026-06-12T07:01:44.585Z (11 days ago)
- Versions: 368
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Forks count: 0.039%
- Stargazers count: 0.055%
- Average: 4.89%
- Dependent packages count: 8.899%
- Dependent repos count: 10.567%
proxy.golang.org: github.com/mattermost/mattermost/v6
- Homepage: https://github.com/mattermost/mattermost-server
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/v6#section-documentation
- Licenses: AGPL-3.0, Apache-2.0
- Latest release: v6.7.2 (published about 4 years ago)
- Last Synced: 2026-06-12T07:01:48.785Z (11 days ago)
- Versions: 39
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Forks count: 0.039%
- Stargazers count: 0.055%
- Average: 4.89%
- Dependent packages count: 8.899%
- Dependent repos count: 10.567%
proxy.golang.org: github.com/mattermost/mattermost
- Homepage: https://github.com/mattermost/mattermost
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost#section-documentation
- Licenses: AGPL-3.0, Apache-2.0
- Latest release: v9.9.0+incompatible (published about 2 years ago)
- Last Synced: 2026-05-19T23:01:39.334Z (about 1 month ago)
- Versions: 504
- Dependent Packages: 0
- Dependent Repositories: 0
- Docker Downloads: 19
-
Rankings:
- Forks count: 0.039%
- Stargazers count: 0.055%
- Average: 4.89%
- Dependent packages count: 8.899%
- Dependent repos count: 10.567%
-
Advisories:
- Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation
- Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
- Mattermost has missing redirect URL validation
- Mattermost fails to validate user permissions in Boards
- Mattermost fails to validate user permissions when deleting comments in Boards
- Mattermost fails to properly restrict access to archived channel search API
- Mattermost Incorrect Authorization vulnerability
proxy.golang.org: github.com/mattermost/mattermost/server
- Homepage: https://github.com/mattermost/mattermost
- Status: removed
- Documentation: https://pkg.go.dev/github.com/mattermost/mattermost/server#section-documentation
- Licenses:
- Latest release: (published about 1 month ago)
- Last Synced: 2026-06-22T21:13:37.061Z (about 3 hours ago)
- Versions: 0
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Dependent packages count: 5.103%
- Average: 5.274%
- Dependent repos count: 5.445%
npmjs.org: @mattermost/shared
Shared components and utilities for use by the Mattermost web app and its plugins
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/shared#readme
- Licenses: MIT
- Latest release: 11.7.0 (published 20 days ago)
- Last Synced: 2026-06-12T07:02:05.869Z (11 days ago)
- Versions: 3
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 23 Last month
-
Rankings:
- Dependent repos count: 22.008%
- Average: 26.865%
- Dependent packages count: 31.723%
- Maintainers (14)
npmjs.org: @mattermost/testcontainers
CLI and library for managing Mattermost test environments using Docker containers with automatic port allocation, subpath routing, HA clustering, and isolated dependencies
- Homepage: https://github.com/mattermost/mattermost/tree/master/e2e-tests/testcontainers#readme
- Licenses:
- Latest release: 0.2.1 (published 4 months ago)
- Last Synced: 2026-06-12T07:02:06.128Z (11 days ago)
- Versions: 7
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 26 Last month
-
Rankings:
- Dependent repos count: 22.945%
- Average: 28.013%
- Dependent packages count: 33.081%
- Maintainers (14)
npmjs.org: @mattermost/playwright-lib
A comprehensive end-to-end testing library for Mattermost web, desktop and plugin applications using Playwright
- Homepage: https://github.com/mattermost/mattermost/tree/master/e2e-tests/playwright/lib#readme
- Licenses: MIT
- Latest release: 11.4.0 (published 5 months ago)
- Last Synced: 2026-06-12T07:02:05.004Z (11 days ago)
- Versions: 14
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 567 Last month
-
Rankings:
- Dependent repos count: 24.906%
- Average: 30.431%
- Dependent packages count: 35.956%
- Maintainers (14)
formulae.brew.sh: mmctl
Remote CLI tool for Mattermost server
- Homepage: https://github.com/mattermost/mattermost
- Licenses: AGPL-3.0-only AND Apache-2.0
- Latest release: 11.7.2 (published 11 days ago)
- Last Synced: 2026-06-12T07:01:53.800Z (11 days ago)
- Versions: 53
- Dependent Packages: 0
- Dependent Repositories: 2
- Downloads: 172 Last month
-
Rankings:
- Forks count: 13.492%
- Dependent packages count: 19.397%
- Dependent repos count: 24.558%
- Average: 30.502%
- Stargazers count: 32.202%
- Downloads: 62.861%
npmjs.org: mmtest_playwright-lib
A comprehensive end-to-end testing library for Mattermost web, desktop and plugin applications using Playwright
- Homepage:
- Licenses: MIT
- Latest release: 0.0.8 (published about 1 year ago)
- Last Synced: 2026-06-12T07:01:52.548Z (11 days ago)
- Versions: 9
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 50 Last month
-
Rankings:
- Dependent repos count: 25.063%
- Average: 30.658%
- Dependent packages count: 36.252%
- Maintainers (1)
npmjs.org: mmtest_types
Shared type definitions used by the Mattermost web app
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/types#readme
- Licenses: MIT
- Latest release: 10.5.0 (published over 1 year ago)
- Last Synced: 2026-06-12T07:01:51.469Z (11 days ago)
- Versions: 2
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 7 Last month
-
Rankings:
- Dependent repos count: 25.102%
- Average: 30.706%
- Dependent packages count: 36.309%
- Maintainers (1)
npmjs.org: mmtest_client
JavaScript/TypeScript client for Mattermost
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/client#readme
- Licenses: MIT
- Latest release: 10.5.0 (published over 1 year ago)
- Last Synced: 2026-06-12T07:01:50.813Z (11 days ago)
- Versions: 1
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 4 Last month
-
Rankings:
- Dependent repos count: 25.102%
- Average: 30.706%
- Dependent packages count: 36.309%
- Maintainers (1)
npmjs.org: @hmhealey/plugin-support
TODO
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/plugin-support#readme
- Licenses: MIT
- Latest release: 10.1.0 (published over 1 year ago)
- Last Synced: 2026-06-12T07:01:56.090Z (11 days ago)
- Versions: 1
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 21 Last month
-
Rankings:
- Dependent repos count: 25.559%
- Average: 31.292%
- Dependent packages count: 37.026%
- Maintainers (1)
npmjs.org: @mattermost/eslint-plugin
ESLint configuration and custom rules used by Mattermost
- Homepage: https://github.com/mattermost/mattermost/tree/master/webapp/platform/eslint-plugin#readme
- Licenses: Apache 2.0
- Latest release: 1.0.0 (published over 2 years ago)
- Last Synced: 2026-06-12T07:02:04.534Z (11 days ago)
- Versions: 2
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 5,342 Last month
-
Rankings:
- Dependent repos count: 32.861%
- Average: 40.001%
- Dependent packages count: 47.141%
- Maintainers (14)