https://github.com/zitadel/zitadel
2fa authentication authorization fido2 fips-140-3 identity login mfa multitenancy oauth2 oidc openid-connect passkeys saml scim sso user
Score: 20.324736937627502
Last synced: about 9 hours ago
JSON representation
Repository metadata:
ZITADEL - Identity infrastructure, simplified for you.
- Host: GitHub
- URL: https://github.com/zitadel/zitadel
- Owner: zitadel
- License: agpl-3.0
- Created: 2020-03-16T13:51:31.000Z (over 6 years ago)
- Default Branch: main
- Last Pushed: 2026-08-27T14:28:47.000Z (about 12 hours ago)
- Last Synced: 2026-08-27T15:12:18.960Z (about 12 hours ago)
- Topics: 2fa, authentication, authorization, fido2, fips-140-3, identity, login, mfa, multitenancy, oauth2, oidc, openid-connect, passkeys, saml, scim, sso, user
- Language: Go
- Homepage: https://zitadel.com
- Size: 566 MB
- Stars: 14,875
- Watchers: 62
- Forks: 1,252
- Open Issues: 1,139
-
Metadata Files:
- Readme: README.md
- Changelog: changelog.config.js
- Contributing: CONTRIBUTING.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.md
- Security: SECURITY.md
- Agents: AGENTS.md
- Cursor: .cursorrules
- Copilot: .github/copilot-instructions.md
Owner metadata:
- Name: ZITADEL
- Login: zitadel
- Email: hi@zitadel.com
- Kind: organization
- Description: Identity infrastructure, simplified for you.
- Website: https://zitadel.com
- Location:
- Twitter: zitadel
- Company:
- Icon url: https://avatars.githubusercontent.com/u/70011121?v=4
- Repositories: 89
- Last Synced at: 2026-08-23T13:39:06.814Z
- Profile URL: https://github.com/zitadel
Committers metadata
Last synced: 8 days ago
Total Commits: 4,525
Total Committers: 262
Avg Commits per committer: 17.271
Development Distribution Score (DDS): 0.77
Commits in past year: 712
Committers in past year: 76
Avg Commits per committer in past year: 9.368
Development Distribution Score (DDS) in past year: 0.846
| Name | Commits | |
|---|---|---|
| Livio Spring | l****a@g****m | 1043 |
| Max Peintner | m****x@c****h | 517 |
| Silvan | s****r@g****m | 506 |
| Fabi | 3****r | 302 |
| Elio Bischof | e****o@z****m | 251 |
| Tim Möhlmann | t****b@z****m | 233 |
| Stefan Benz | 4****z | 229 |
| Florian Forster | f****n@c****h | 175 |
| Fabi | f****e@z****m | 169 |
| mffap | m****a@z****m | 130 |
| dependabot[bot] | 4****] | 121 |
| Miguel Cabrerizo | 3****o | 93 |
| Gayathri Vijayan | 6****n | 60 |
| Federico Coppede | f****e@g****m | 50 |
| Ramon | m****l@c****e | 50 |
| Marco A. | m****o@z****m | 42 |
| Iraq | 6****e | 28 |
| Christian Jakob | 4****t | 27 |
| Mridang Agarwalla | m****g@z****m | 24 |
| Wim Van Laer | w****b@z****m | 22 |
| Dakshitha Ratnayake | d****a | 22 |
| Lars | l****s@r****h | 20 |
| dependabot-preview[bot] | 2****] | 20 |
| Rajat Singh | 1****g | 18 |
| mffap | m****a@c****h | 15 |
| Zach Hirschtritt | z****t@k****m | 11 |
| Matías Racedo | m****o@g****m | 9 |
| Vitor Bari Buccianti | v****b@z****m | 9 |
| Liam Neville | l****m@z****m | 7 |
| Kenta Yamaguchi | 5****8 | 7 |
| and 232 more... | ||
Issue and Pull Request metadata
Last synced: 1 day ago
Total issues: 1,528
Total pull requests: 2,435
Average time to close issues: 6 months
Average time to close pull requests: 17 days
Total issue authors: 479
Total pull request authors: 226
Average comments per issue: 2.07
Average comments per pull request: 2.26
Merged pull request: 1,214
Bot issues: 3
Bot pull requests: 499
Past year issues: 180
Past year pull requests: 252
Past year average time to close issues: 3 months
Past year average time to close pull requests: 16 days
Past year issue authors: 110
Past year pull request authors: 71
Past year average comments per issue: 1.49
Past year average comments per pull request: 2.84
Past year merged pull request: 79
Past year bot issues: 1
Past year bot pull requests: 23
Top Issue Authors
- hifabienne (187)
- mffap (98)
- muhlemmer (97)
- adlerhurst (77)
- eliobischof (75)
- livio-a (68)
- stebenz (33)
- peintnermax (29)
- elinashoko (22)
- matiasracedo (19)
- kkrime (17)
- juergrinaldi (15)
- fcoppede (14)
- fforootd (13)
- vs-gtadeu (12)
Top Pull Request Authors
- dependabot[bot] (494)
- livio-a (306)
- adlerhurst (238)
- stebenz (181)
- eliobischof (181)
- muhlemmer (172)
- peintnermax (96)
- kkrime (77)
- hifabienne (64)
- mffap (44)
- conblem (40)
- fforootd (36)
- doncicuto (35)
- latonz (33)
- zhirschtritt (18)
Top Issue Labels
- bug (482)
- resources (183)
- enhancement (166)
- auth (166)
- improvement (110)
- backend (93)
- frontend (91)
- docs (89)
- storage (80)
- good first issue (69)
- service-layer (63)
- To-be-closed (63)
- area/console (53)
- devops (50)
- customization (38)
- performance (37)
- waiting (24)
- to-be-reviewed (21)
- area/loginV1 (19)
- area/auth (17)
- area/loginV2 (17)
- devx (16)
- architecture (14)
- lang: go (13)
- tests (13)
- category: backend (12)
- area/api (12)
- epic (12)
- presentation-layer (12)
- ux (11)
Top Pull Request Labels
- dependencies (494)
- npm (373)
- os-contribution (314)
- javascript (64)
- github_actions (55)
- waiting (29)
- docs (25)
- bug (23)
- storage (16)
- marketing (14)
- backend (10)
- auth (9)
- resources (9)
- performance (8)
- presentation-layer (7)
- console (7)
- enhancement (7)
- devops (6)
- frontend (6)
- improvement (6)
- reviewer wanted (5)
- lang: go (4)
- fix (3)
- good first issue (3)
- ci (3)
- tests (2)
- area/docs (2)
- ng-v4-legacy (2)
- v3 (2)
- v2 API (1)
Package metadata
- Total packages: 3
- Total downloads: unknown
- Total docker downloads: 157
- Total dependent packages: 0 (may contain duplicates)
- Total dependent repositories: 0 (may contain duplicates)
- Total versions: 1,035
- Total advisories: 46
proxy.golang.org: github.com/zitadel/zitadel
- Homepage: https://github.com/zitadel/zitadel
- Documentation: https://pkg.go.dev/github.com/zitadel/zitadel#section-documentation
- Licenses: agpl-3.0
- Latest release: v1.87.5 (published over 3 years ago)
- Last Synced: 2026-08-26T17:35:19.813Z (1 day ago)
- Versions: 880
- Dependent Packages: 0
- Dependent Repositories: 0
- Docker Downloads: 157
-
Rankings:
- Stargazers count: 1.024%
- Forks count: 1.647%
- Average: 4.754%
- Dependent packages count: 6.999%
- Dependent repos count: 9.346%
-
Advisories:
- ZITADEL Users Can Self-Verify Email/Phone via API
- ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
- ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
- ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
- ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
- ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
- ZITADEL has LDAP Filter Injection in Login Flow
- Zitadel is missing enforcement of organization scopes
- ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover
- ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication
- ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
- ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API
- ZITADEL's truncated opaque tokens are still valid
- Zitadel has a user enumeration vulnerability in Login UIs
- Zitadel Discloses the Total Number of Instance Users
- ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login
- ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
- ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
- ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
- IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering
- Zitadel May Bypass Second Authentication Factor
- Zitadel allows brute-forcing authentication factors
- ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
- ZITADEL Allows IdP Intent Token Reuse
- IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
- User Registration Bypass in Zitadel
- Denied Host Validation Bypass in Zitadel Actions
- ZITADEL "ignoring unknown usernames" vulnerability
- ZITADEL has improper HTML sanitization in emails and Console UI
- ZITADEL Vulnerable to Session Information Leakage
- Zitadel exposing internal database user name and host information
- ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
- ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass
- ZITADEL's actions can overload reserved claims
- Improper HTML sanitization in ZITADEL
- Account Takeover via Session Fixation in Zitadel [Bypassing MFA]
- ZITADEL Account Takeover via Malicious Host Header Injection
- ZITADEL race condition in lockout policy execution
- ZITADEL's password reset does not respect the "Ignoring unknown usernames" setting
- Zitadel RefreshToken invalidation vulnerability
- Broken Authorization in ZITADEL Actions
proxy.golang.org: github.com/zitadel/zitadel/v2
- Homepage: https://github.com/zitadel/zitadel
- Documentation: https://pkg.go.dev/github.com/zitadel/zitadel/v2#section-documentation
- Licenses: agpl-3.0
- Latest release: (published 1 day ago)
- Last Synced: 2026-08-26T17:34:45.548Z (1 day ago)
- Versions: 0
- Dependent Packages: 0
- Dependent Repositories: 0
-
Rankings:
- Dependent packages count: 6.163%
- Average: 6.37%
- Dependent repos count: 6.576%
-
Advisories:
- ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover
- ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication
- ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
- ZITADEL has potential SSRF via Actions
- ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login
- ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
- ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
- Zitadel May Bypass Second Authentication Factor
- Zitadel allows brute-forcing authentication factors
- ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
- ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
- IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
- ZITADEL Allows Unauthorized Access After Organization or Project Deactivation
- ZITADEL's Service Users Deactivation not Working
- ZITADEL's User Grant Deactivation not Working
artifacthub.io: zitadel/zitadel
A Helm chart for ZITADEL
- Homepage: https://zitadel.com
- Documentation: https://artifacthub.io/packages/helm/zitadel/zitadel
- Licenses: Unknown
- Latest release: 10.0.4 (published 2 months ago)
- Last Synced: 2026-08-26T17:34:32.073Z (1 day ago)
- Versions: 155
- Dependent Packages: 0
- Dependent Repositories: 0
- Downloads: 0 Total
-
Rankings:
- Downloads: 0.0%
- Dependent repos count: 0.0%
- Dependent packages count: 0.0%
- Average: 100%
Dependencies
- actions/add-to-project v0.3.0 composite
- actions/checkout v4 composite
- actions/setup-go v5 composite
- actions/setup-node v4 composite
- actions/upload-artifact v4 composite
- codecov/codecov-action v4.3.0 composite
- docker/setup-buildx-action v3 composite
- docker/setup-compose-action v1 composite
- docker/setup-docker-action v4 composite
- nrwl/nx-set-shas v4 composite
- pnpm/action-setup v4 composite
- actions/checkout v4 composite
- actions/setup-go v5 composite
- actions/setup-node v4 composite
- actions/upload-artifact v4 composite
- docker/build-push-action v6 composite
- docker/login-action v3 composite
- docker/metadata-action v5 composite
- docker/setup-buildx-action v3 composite
- docker/setup-qemu-action v3 composite
- pnpm/action-setup v4 composite
- actions/github-script v7 composite
- debian latest build
- scratch latest build
- actions/checkout v3 composite
- github/codeql-action/analyze v2 composite
- github/codeql-action/autobuild v2 composite
- github/codeql-action/init v2 composite
- docker/login-action v2 composite
- docker/setup-buildx-action v2 composite
- docker/setup-qemu-action v2 composite
- actions/checkout v3 composite
- actions/download-artifact v3 composite
- cycjimmy/semantic-release-action v3 composite
- @eslint/js ^10.0.1 development
- @tailwindcss/postcss ^4.3.0 development
- @tailwindcss/typography ^0.5.19 development
- @types/mdx ^2.0.13 development
- @types/node ^25.7.0 development
- @types/react 19.2.14 development
- @types/react-dom 19.2.3 development
- @typescript-eslint/eslint-plugin ^8.59.3 development
- @typescript-eslint/parser ^8.59.3 development
- eslint ^10.3.0 development
- eslint-config-prettier ^10.1.8 development
- eslint-import-resolver-typescript ^4.4.4 development
- eslint-plugin-import ^2.32.0 development
- eslint-plugin-mdx ^3.7.0 development
- glob ^13.0.6 development
- globals ^17.6.0 development
- next-validate-link ^1.6.6 development
- postcss ^8.5.14 development
- raw-loader ^4.0.2 development
- remark-heading-id ^1.0.1 development
- semver ^7.8.0 development
- tailwindcss ^4.3.0 development
- tailwindcss-animate ^1.0.7 development
- tsx 4.21.0 development
- typescript ^5.9.3 development
- yaml-loader ^0.9.0 development
- @headlessui/react ^2.2.10
- @heroicons/react ^2.2.0
- @inkeep/cxkit-react ^0.5.117
- @scalar/api-reference ^1.55.3
- @shikijs/rehype ^4.0.2
- @shikijs/types ^4.0.2
- @types/js-yaml ^4.0.9
- clsx ^2.1.1
- fumadocs-core 16.8.10
- fumadocs-mdx 14.3.2
- fumadocs-openapi 10.8.2
- fumadocs-ui 16.8.10
- js-yaml ^4.2.0
- lucide-react ^0.577.0
- mixpanel-browser ^2.78.0
- next 16.2.6
- next-themes ^0.4.6
- react 19.2.6
- react-copy-to-clipboard ^5.1.1
- react-dom 19.2.6
- react-google-charts ^5.2.1
- shiki ^4.0.2
- tailwind-merge ^3.6.0
- vanilla-cookieconsent ^3.1.0
- zod ^4.4.3