Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-27 15:27 UTC

HodeTech / Leakwatch

High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.

GoMIT★ 2 Sterne⑂ 1 Forkseit März 2026Auf GitHub ansehen ↗

HodeTech/Leakwatch erreicht einen Gesundheitsindex von 62 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei AI Readiness (93/100) ab, am schwächsten bei Community & Adoption (37/100). Zuletzt vor 1 Tag aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

62
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

62
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

HODETECHOrganisation
1 Follower10 öffentliche Reposseit Sept. 2021

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
Gogithub.com/HodeTech/leakwatchv1.7.0-8vor 8 Tagen
npmleakwatch0.1.0461vor 98 Tagensecuritysecretspiigitpre-pushaadhaarupiapi-keysdevtoolsindia

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

77Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
4.2/36Commit-Rhythmus — 6/52 Wochen mit Commits
18/18Commit-Volumen — 183 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year183
human_commit_share1
days_since_last_push1
active_weeks_last_year6
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 8 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 6 Tagen
27/27Release-Rhythmus — ein Release etwa alle 16,9 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count8
latest_release_tagv1.7.0
releases_from_tagsnein
days_since_latest_release6
mean_days_between_releases16,9

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

37Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 2 Stars
0/25Forks — 1 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks1
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templatenein
Wie die Bewertung erfolgt
22.3/80Downloads pro Monat — 46 Downloads/Monat über go, npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesgithub.com/HodeTech/leakwatch, leakwatch
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads46
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

47Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
24.2/38.3PR-Annahme — 19/30 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/5 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs19
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs11
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
2.2/25Reichweite des Inhabers — 1 Follower von HodeTech
17.3/25Kontohistorie — 10 öffentliche Repos, Kontoalter ca. 4 Jahre
Verwendete Eingangsdaten
followers1
owner_typeOrganization
is_verified
owner_loginHodeTech
public_repos10
account_age_days1.767

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 2 Paket(e) auf go, npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
20/20Versionshistorie — 8 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/HodeTech/leakwatch, leakwatch
ecosystemsgo, npm
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

90Exzellent · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 5 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — .golangci.yml, eslint.config.mjs
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein

Dokumentation

100Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://hodetech.github.io/Leakwatch/
10/10Repository-Beschreibung
10/10Topics — 14 Topics
10/10Wiki
Verwendete Eingangsdaten
topicsappsec, cli, credential-scanner, devsecops, golang, leak-detection, sarif, secret-detection, secret-scanning, secrets-detection, secrets-management, security, security-tools, static-analysis
has_wikija
homepagehttps://hodetech.github.io/Leakwatch/
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

59Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
2.5/2.5CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/5 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3.8/7.5Vulnerabilities — 5 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
10/25Indirekte Abhängigkeiten ohne bekannte Advisories — 1 betroffen: brace-expansion 2.1.2 (high 7.5)
40/40Keine offenen Advisories — kein Advisory ist länger als 90 Tage öffentlich
Verwendete Eingangsdaten
sourceosv
advisories1
affected_packages1
assessed_packages16
unassessed_packages0
affected_by_severityhigh 1
direct_affected_packages0
Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:leakwatch@0.1.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 16 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

93Exzellent · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,99
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes8.329
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — .golangci.yml, eslint.config.mjs
11/11Statische Typprüfung — vscode/tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 83 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
5/8Automatisierte Wartung — Abhängigkeits-Automatisierung konfiguriert, in den erfassten Commits nicht beobachtet
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum, package-lock.json
has_dockerfileja
typed_languageja
bootstrap_filesMakefile
has_devcontainernein
has_linter_configja
typecheck_configsvscode/tsconfig.json
agent_commit_share0,83
toolchain_manifestsgo.mod, tools/site-build/go.mod
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
54.7/55Handhabbare Dateigrößen — 2/372 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes352.237
source_files_sampled372
oversized_source_files2

Eckdaten

2GitHub-Sterne
1Mitwirkende
183Commits, letzte 12 Monate
1Tage seit letztem Push
8Releases
1Bus-Faktor
0offene Issues
Go, npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 5.3 / 10
5.3Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-27 15:27 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/5 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
5Vulnerabilities5 existing vulnerabilities detected
Direkte Abhängigkeiten 17
RegistryPaketVersionsvorgabeManifest
Gocloud.google.com/go/storagev1.61.3go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.42.1go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.30go.mod
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.29go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.97.3go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.44.1go.mod
Gogithub.com/aws/smithy-gov1.27.4go.mod
Gogithub.com/cloudflare/ahocorasickv0.0.0-20240916140611-054963ec9396go.mod
Gogithub.com/go-git/go-git/v5v5.19.1go.mod
Gogithub.com/google/go-containerregistryv0.21.3go.mod
Gogithub.com/slack-go/slackv0.20.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.10go.mod
Gogithub.com/spf13/viperv1.21.0go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogolang.org/x/timev0.15.0go.mod
Gogoogle.golang.org/apiv0.289.0go.mod
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 1

Die Installation von npm:leakwatch@0.1.0 zieht 16 Pakete nach sich, direkt und transitiv: 1 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
brace-expansion2.1.2indirekthoch15.0.8

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "appsec",
        "cli",
        "credential-scanner",
        "devsecops",
        "golang",
        "leak-detection",
        "sarif",
        "secret-detection",
        "secret-scanning",
        "secrets-detection",
        "secrets-management",
        "security",
        "security-tools",
        "static-analysis"
      ],
      "is_fork": false,
      "size_kb": 3144,
      "has_wiki": true,
      "homepage": "https://hodetech.github.io/Leakwatch/",
      "languages": {
        "Go": 1461758,
        "CSS": 28414,
        "HTML": 53585,
        "Makefile": 567,
        "Dockerfile": 1278,
        "JavaScript": 56510,
        "TypeScript": 26507
      },
      "pushed_at": "2026-07-26T03:49:40Z",
      "created_at": "2026-03-23T23:24:14Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T18:14:56Z",
      "description": "High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "HODETECH",
      "type": "Organization",
      "login": "HodeTech",
      "company": null,
      "location": "Turkey",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/91323970?v=4",
      "created_at": "2021-09-24T11:43:24Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 1767
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-07-20T19:44:14Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-05-25T08:43:30Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-04-09T11:46:17Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-04-08T12:27:38Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-03-25T04:58:16Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-03-25T04:19:55Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-03-25T03:53:18Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-03-24T17:35:31Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "228431637ef4c5f41f9f34fc585771a66e2dbc64",
          "body": "chore(ci): group Dependabot minor/patch updates and cap open PRs",
          "is_bot": false,
          "headline": "Merge pull request #37 from HodeTech/development",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-20T20:13:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dee467f29a97bb1a04012703f80adf7c343ffb94",
          "body": "Enabling Dependabot opened 17 PRs at once, and because branch protection\nrequires branches to be up to date, each merge invalidated the rest —\n7 safe updates needed a single hand-rolled batch PR to land.\n\nGroups minor and patch updates per ecosystem (AWS SDK and Google Cloud\nget their own groups in \n[…]\ncloud captures both Google\nmodules, and the catch-all covers the remaining nine with no dependency\nleft unintentionally ungrouped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ci): group Dependabot minor/patch updates and cap open PRs",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-20T20:07:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67bff93983d78d6145dfd917d4a5b0836ef181a7",
          "body": "chore(deps): batch the safe dependency updates",
          "is_bot": false,
          "headline": "Merge pull request #36 from HodeTech/development",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-20T19:55:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e642092da25e6383f7b8f2742f44ea7af2a8533e",
          "body": "Rolls up the low-risk Dependabot updates into one change so they share a\nsingle CI run instead of each invalidating the others under the\n\"branch must be up to date\" rule:\n\n- github.com/aws/aws-sdk-go-v2        1.41.5  -> 1.42.1   (#27)\n- github.com/aws/aws-sdk-go-v2/config 1.32.12 -> 1.32.30  (#31)\n\n[…]\nk-cli 7, @types/node 26, the\nGitHub Action v3->v4/v6->v7 bumps and golang 1.26) are intentionally\nleft open for individual review.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): batch the safe dependency updates",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-20T19:50:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1535f9d9d74bfab8629a6740ac5f1c5c25951bfe",
          "body": "fix(release): sign with a Sigstore bundle for cosign 3.x",
          "is_bot": false,
          "headline": "Merge pull request #35 from HodeTech/development",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-20T19:37:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "040933c55c72634d82a5ec83ebfccda13b055b64",
          "body": "The v1.7.0 release pipeline failed at \"signing artifacts\": cosign 3.0.6\n(from cosign-installer) deprecates --output-signature/--output-certificate\nand ignores them under its default --new-bundle-format, then aborts with\n\"create bundle file: open : no such file or directory\" because no\n--bundle path \n[…]\ns unaffected. Nothing was published by the failed run — no release, no\ntap update, and the floating v1 tag still points at v1.6.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): sign with a Sigstore bundle for cosign 3.x",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T07:02:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "210f4cd5ae041c9e79525e851344eac7e911a600",
          "body": "docs(changelog): cut v1.7.0 and backfill the missing v1.6.0 section",
          "is_bot": false,
          "headline": "Merge pull request #32 from HodeTech/development",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T06:51:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c411ae46e1819db572f21dd9b6afaa0df8f1c2a",
          "body": "The Unreleased section had accumulated both the work that actually\nshipped in v1.6.0 (Marketplace action, github output format, config\nwiring, line numbers, inline ignore, SARIF fingerprints, dbconn\nplaceholder fix) and everything since. v1.6.0 was tagged without ever\nmoving its entries down, so the\n[…]\non, single-source counts and the toolchain\nbump) and the missing [v1.6.0] - 2026-05-25. Entries at v1.5.0 and\nolder are untouched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): cut v1.7.0 and record the missing v1.6.0 section",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T06:46:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d02fcccb03309d547e1e12c92aca06117f53e329",
          "body": "Comprehensive review remediation: security, correctness, architecture & docs",
          "is_bot": false,
          "headline": "Merge pull request #16 from HodeTech/development",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T06:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25c4aded6e0af6842ec4754ef5c60ea5a8565881",
          "body": "CodeFactor flagged walkRoot, scanTarLayer and emitCommitChanges as\ncomplex methods after they gained real functionality in this branch\n(non-regular-file guard, decompression-bomb caps, per-commit diff\nattribution). Extracted cohesive helpers with no behavior change:\n\n- filesystem: classifyEntry (wit\n[…]\nGuard order, error wrapping, log messages and short-circuit semantics\nare unchanged; coverage rose slightly in all three packages.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(source): split three complex scan methods into named helpers",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T06:00:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ed8552920e24290b6b1f0192329b83587d66ab9b",
          "body": "Running each detector scan in its own goroutine with a channel only\nallowed abandoning an in-flight scan; Go's RE2 regexp engine is\nlinear-time with no catastrophic backtracking, so a scan always\nterminates, and the worker already checks ctx before every detector.\nRemoving it measurably helps: 14.5m\n[…]\n a bytes.ToLower copy per candidate in the generic\ndetector's vowel-ratio check and an intermediate string per JWT\nsegment decode.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf: drop the per-scan goroutine and two hot-path allocations",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T05:50:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c185487d70175cf954da1b281d1c472377bcd343",
          "body": "- AWS secret pairing: awsSecretBarePattern's ^/$ alternatives anchor to\n  the sliced pairing window, not the buffer, so a window edge landing\n  inside a longer base64-like token could carve a spurious 40-char\n  \"Secret Access Key\" out of its middle. The capture is now mapped back\n  to absolute offse\n[…]\nesolveRevision (it silently picks one of several prefix candidates\n  with no ambiguity signal; we report ambiguity like git does).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: address PR review — AWS pairing boundary, file types, SARIF URI",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T05:50:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ff6cee4ad1738d3039061ae40bd18e06fbdfdac3",
          "body": "The `cli-github-format` and `run-action` fixtures seeded the canonical\nAWS documentation key `AKIAIOSFODNN7EXAMPLE`, which this branch now\ncorrectly treats as a known placeholder and skips. The jobs therefore\nfound nothing and failed. Swapped in a synthetic key that is not in the\nplaceholder allowlist; verified locally that `--format github` emits the\nexpected ::error annotation and exits 1.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: use a non-allowlisted AWS key in the action-test fixtures",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-19T05:50:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4ca92a1867dd8ac09e51cb6558da786764ae2396",
          "body": "Summarizes the security, fix, addition, and change entries from the\ncomprehensive review remediation.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record the review-remediation changes under Unreleased",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T03:11:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e0696cc4f0503a6d13ff6e8b3ca6af10120ac023",
          "body": "Regenerates site/js/manuals/{en,tr}.js so the website's rendered manuals\nmatch the reconciled documentation (github format, exit code 3, 64\ndetectors, corrected verification coverage, etc.).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(site): regenerate manual bundles from the corrected EN/TR docs",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T03:03:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a4bab228e3e5c932ad66290bef37a01ab10736f2",
          "body": "… English\n\nMirrors the English reconciliation into Turkish across all 26 pages\n(identical heading and line structure): the github format, underscore\nverification-status enums, exit code 3, --exclude-detectors/--exclude,\nsingle/multi-file scan fs, 64-detector catalog with discord-webhook-url,\nrecompu\n[…]\nerity\"\nand \"See also\" and \"redacted\" use one consistent term each, and the\nremediation page's extra section is removed for parity.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(manuals): bring Turkish manuals to 1:1 parity with the corrected…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T03:03:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c77f10739198c159017958ff5c50b03572eb27ce",
          "body": "Adds the github output format to every --format list, replaces the\nverified:active colon status with the real underscore enums, documents\nexit code 3 (interrupted), --exclude-detectors, --exclude on all\nsubcommands, and single/multi-file scan fs. Corrects the --config\ndiscovery description, .leakwat\n[…]\nthe git/slack/container Finding-metadata tables; the detector catalog is\nreconciled to 64 detectors including discord-webhook-url.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(manuals): reconcile English user manuals with the current CLI",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T02:41:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbd2e2fea5840dd08f2a61dff3fa021ebf86a50b",
          "body": "…t code\n\nVerifies every command, flag, count, endpoint and example against the\npost-remediation code (and the built binary): the README first-command\nexample now shows the real JSON default; the download filename, CI/CD\nAction input table (16 inputs), and pinned versions are corrected; the\narchitect\n[…]\ns to the removed\nFormula/leakwatch.rb are replaced with the GoReleaser tap. Also bumps\nthe registry-count comment to 64 detectors.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reconcile README, guides, ADRs and architecture with the curren…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T02:41:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a94763c68af2a413cd51ab48dcad69630f8542e",
          "body": "…lint\n\nFlips the detector-coverage CI step from reporting-only to a hard gate\nnow that every detector package meets 95%, and excludes vendored\nthird-party Go files under vscode/node_modules from golangci-lint.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: enforce the 95% detector-coverage floor and skip node_modules in …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T02:10:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a140ff5fd73aa459a7eb58044b23f79a52f7393",
          "body": "Brings the four packages that were below the CLAUDE.md-mandated 95%\ndetector-coverage floor up to it via meaningful tests (fail-safe\nredaction branches, multi-match behavior, the generic detector's\nentropy-based marker) — heroku/snowflake/stripe reach 100% and generic\n97.4%. Also removes a mathematically-unreachable length guard in the\nheroku detector.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(detector): raise heroku/snowflake/stripe/generic coverage to >=95%",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T02:10:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e72431eb43f2f246edc8049fe46794b5877ed4f5",
          "body": "…F version\n\n`scan fs` now accepts one or more path arguments, each a file OR a\ndirectory (the filesystem source is multi-root and scans a single file\nwhen given one). This makes the pre-commit hook scan only staged files\n(it now passes filenames) and the VS Code \"Scan Current File\" scan just\nthat fi\n[…]\nv\",\nauto-suffixes a bare `--output` path with the format's extension, and\naligns the Slack `--rate-limit` default with the source.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): scan individual files, add --exclude-detectors, stamp SARI…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T02:10:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "590ad275e8b05c08af982d6f6c0d0b9214d79f54",
          "body": "…indings\n\nRestores cmd/ as a thin Cobra wiring layer (ADR-0002): the scan pipeline,\nengine-config building, .leakwatchignore discovery, and multi-repo\norchestration move into a new internal/scanner package (Cobra-free and\nrace-testable). Multi-repo scans now share ONE engine/rate-limiter\ninstead of \n[…]\nose() error is surfaced, parseSeverity is unified into\nfinding.ParseSeverity, and RunE test coverage is added for six\nsubcommands.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(cmd): extract scan pipeline into internal/scanner; fix cmd f…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T01:50:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b61559a028097542f88064cc12b71162c45e246e",
          "body": "Regression fix: making the entropy threshold a global gate dropped valid\nbut low-entropy secrets found by structural detectors — e.g. an AWS\naccess-key ID (~3.9 bits) was silently missed on a default scan with\nentropy analysis enabled. The Shannon-entropy floor now applies ONLY to\ndetectors that opt\n[…]\ningful as the engine floor for\nheuristic detectors. Adds a regression test asserting a structural\ndetector is never entropy-gated.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(engine): only entropy-gate heuristic detectors, not structural ones",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T01:50:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d179591197dc3f3c175a0ae76bb10b260b899a63",
          "body": "High: the playground revealed the full un-redacted secret via the\nnative title tooltip — removed. Fixes the broken mobile case-file table,\nWCAG AA contrast, hover-only reveal on touch, missing aria-live and menu\nkeyboard handling, adds canonical/OG/robots.txt/sitemap.xml, noscript\nfallbacks, a contact-form fetch timeout, pins the Mermaid CDN, and\nupdates detector counts to 64.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(site): stop leaking raw secret in playground, fix a11y and metadata",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T01:08:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b9a3bcc31fde9af279b92b0baacee7829b725292",
          "body": "The generator converted AND-gated detection into OR'd standalone\npatterns (e.g. gcp-service-account), producing playground false\npositives; it now preserves the gate or skips with a warning/count\ncheck, converts/rejects the Go (?U) flag, and no longer swallows page\ntails on unterminated callouts. Ad\n[…]\nodule's\nfirst tests. rules/examples.yaml is reconciled with the real\ncustom-rules loading mechanism and its ID collisions removed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tools): stop site-build emitting false-positive patterns; add tests",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T01:08:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b4b81d1d67ec68c1aafb6f7e293546a4b88c55a",
          "body": "…rage\n\nAdds cosign keyless signing + syft SBOMs to releases, enables gosec in\ngolangci-lint (with triaged, documented exclusions), SHA-pins the\nsite-deploy actions, adds concurrency groups and a Windows cross-compile\nsmoke test, pins govulncheck, and adds a site/js drift guard plus a\nreporting-mode \n[…]\nages, and fix the commit-hash arg.\nRemoves the dead Formula/leakwatch.rb (the real formula is generated by\nGoReleaser to the tap).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: harden supply chain, add SBOM/signing, gosec, and missing CI cove…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T01:08:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce74b0d1997135fe3ab6867d827401aa35e66a56",
          "body": "Adds the unicode Redact test and the -race concurrent RegisterIfAbsent\ntests backing the shared-helper and registry changes.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(detector): rune-aware redaction and concurrent registry tests",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:34:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fb8398dbc1c725a73b11d71c480e4a669dc738f5",
          "body": "Several detectors returned Raw as a sub-slice of the input chunk, which\npins the whole chunk in memory per finding and risks mutation on buffer\nreuse. Raw/RawV2 are now bytes.Clone()d in infura, launchdarkly,\nlinear, newrelic, postmark, npm, and pagerduty, matching the pattern\nalready used by mailgun/okta. Adds mutate-after-scan regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(detector): clone Raw to stop aliasing the scanned chunk buffer",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:33:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0006eea2fd194e57fb8d2ad63c3e2a3e4e26524e",
          "body": "Medium/low: grafana and npm now hit correct endpoints; dockerhub uses\nthe proper auth exchange; stripe handles the restricted-key 403 path;\nmailgun supports the EU region host. Adopts the shared vtest.Run safety\nsuite in the owned live-HTTP verifiers and adds a cancelled-context\ntest to the Teams verifier.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): correct endpoints/regions and broaden vtest safety suite",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:33:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cb5ae41d467ab5e286beb7ae46daa66c044677db",
          "body": "The matcher no longer allocates a full lowercased copy of every chunk\non every scan (per-worker reusable buffer). The entropy hot-path doc\ncomment is corrected to English. New guards keep meta.Sources/\nOutputFormats and per-detector remediation coverage from silently\ndrifting, mirroring the existing count guard. .leakwatchignore now\nexcludes rules/**.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(matcher): reuse lowercase buffer; add meta/remediation drift guards",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:33:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2fb804505442d6f15559f137db2c9fd18cbb5cba",
          "body": "Adds fail-safe detector.RedactURLPassword and detector.HasAnyKeyword\nhelpers and routes the duplicated rabbitmq/redis redaction and notion's\nkeyword check through them. Redact/RedactBytes are now rune-aware (no\nsplit UTF-8); azure Storage redaction uses the shared helper and drops\ndead code; doppler\n[…]\n; ftp bounds its segments;\nthe Teams webhook redaction derives from the real match. Adds\ndirect/concurrent RegisterIfAbsent tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(detector): share URL-password redaction and keyword helpers",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:33:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f672acca40bf30e6585744cd2e1ced56dd73660",
          "body": "Medium: several detectors over- or under-matched. dbconn now requires a\ncolon-delimited password (no fabricated redaction for bare user@host),\napplies the placeholder allowlist to URI matches, matches Password/Pwd\nregardless of ADO.NET field order, and compiles its regex once. JWT\ngains structural v\n[…]\nok-URL detector (distinct from bot tokens) in the existing\npackage, with meta count, remediation, and generated assets reconciled.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(detector): tighten precision and add Discord webhook detection",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:33:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e278c862eb234dad5e67e01f0ad61d9e32e4045e",
          "body": "High: Source.Chunks() had no error channel, so a fatal failure (clone,\nauth, pull, walk, or a decompression-limit trip) was indistinguishable\nfrom a clean, empty scan. Added an Err() method to the Source interface;\nevery source captures its first terminal error (credential-redacted for\ngit/slack) be\n[…]\n signature is\nunchanged. Tests cover git/filesystem/s3 Err() capture and the engine\nturning a failed source into a returned error.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): surface fatal scan errors instead of a silent empty scan",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-16T00:07:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ba406176a2265adb71589b5d42bf73243ebbe4cd",
          "body": "… heuristic\n\nHigh: filter.exclude-paths was missing from setDefaults, so\nLEAKWATCH_FILTER_EXCLUDE_PATHS was silently ignored; it is now bound.\nThe recursive ** glob matcher is bounded against algorithmic blow-up on\nadversarial patterns. IsBinaryFile no longer misclassifies UTF-16 text,\n'/'-globs match on Windows, the inline-ignore detector marker is matched\nexactly (no prefix false-match), and matchSegments surfaces its error.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(config): honor exclude-paths env, bound glob matching, fix UTF-16…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1707f9ec770962b1afeed9d87f2f64bcdfa5d82a",
          "body": "Med: the filesystem source scanned the .git object store as files; it\nis now excluded by default. Binary detection reads a bounded prefix\nbefore loading the whole file, and tests move to fstest.MapFS.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): exclude .git by default and probe binary before full read",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fd13a1e0ee166f016a7b8b617f8e081c0f36d722",
          "body": "High: Slack 429 responses were neither detected nor retried, so\npagination silently aborted and dropped messages. The source now\ndetects 429, honors Retry-After with bounded backoff, and lowers the\ndefault rate limit to a safe tier. Adds 429/retry and multi-page cursor\npagination tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): honor Slack 429 rate limiting during pagination",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1877efaeb460f51ecb3ce52d7a7b06ccbe9c407d",
          "body": "…ion test\n\nMed: the GCS storage client was never closed (resource leak); it now\ncloses via defer. S3/GCS WithMaxFileSize gain the <=0 guard container\nalready had, Validate() threads the caller context where possible, and\nS3's manual ContinuationToken pagination gains multi-page test coverage.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): close GCS client, guard cloud max-file-size, add paginat…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6b30247deb0376c2f767852dca2d247d30158dd6",
          "body": "High: nothing capped decompressed bytes, so a malicious image could\nforce unbounded decompression (zip-bomb DoS). Per-layer (2 GiB) and\nper-image (10 GiB) decompressed-byte ceilings now abort the offending\nlayer. The image config blob (ENV/LABEL/CMD/ENTRYPOINT) is now scanned\nfor baked-in secrets, sanitizeTarPath is corrected cross-platform, and\nChunks() gains full in-memory orchestration test coverage.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): defend container scanning against decompression bombs",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4c87302119532be03f373490682221f20542fb9e",
          "body": "…ministic order\n\nHigh: raw secrets accumulated for the whole scan before verification;\nthe collector now streams pairs through a bounded in-flight batch and\nreleases raw bytes per batch (resolves the ENG-M-02 memory ceiling). A\nnew engine-level runDetector safeguard abandons a non-returning\ndetector\n[…]\n actually\napplied. Line-number and inline-ignore now share a single pass. Adds\npipeline/line benchmarks and a goroutine-leak test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(engine): bound scan memory, add cancellation safeguard and deter…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:53:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "70cc17d2cea1c1527d10381ccd9d117f64ccaeb9",
          "body": "High: no formatter stripped control/ANSI bytes, so attacker-controlled\nfile paths and redacted values reached a real terminal unescaped; a\nshared sanitizer now cleans them in the table formatter. SARIF gets a\nreal driver version field and a synthetic stable location for non-file\n(e.g. Slack) sources\n[…]\n-raw JSON wire type re-adds extra_data (Finding.ExtraData is now\njson:\"-\"), so non-secret metadata surfaces only under --show-raw.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(output): sanitize terminal output and harden SARIF/CSV/JSON",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:37:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f291805af97f7a0091d0ebeeec3ded2fc77b8e92",
          "body": "High: several detectors missed real secret formats or over-matched.\nAdded github_pat_ fine-grained PATs, legacy/service-account OpenAI\nkeys, and PKCS8 \"ENCRYPTED PRIVATE KEY\" armor to their existing\npackages (no new packages). The generic detector's placeholder filter\nhad a case bug (5/13 patterns u\n[…]\nts.\nMailgun is now gated behind a context keyword. Adopted the\nScanViaMatcher keyword/regex-alignment guard in the owned packages.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(detector): expand token coverage and cut generic false positives",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:37:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fdca82e4de153a5f5711bed9dc7560473411d58",
          "body": "High: the Twilio verifier authenticated with a credential pair its own\ndetector could never produce; pairing is corrected and fixtures aligned\nto real detector output. The Twilio detector now runs its SK-key regex\non every chunk (empty Keywords) to close a silent detection gap and\nscopes the Account-SID search near each key. SendGrid no longer folds a\n403 (a valid but scope-restricted key) into invalid/revoked.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): fix twilio credential pairing and sendgrid 403 handling",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:37:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1efd3bd3b2421882e0b89c745002fc0d55ef4a1c",
          "body": "High: all three misreported live credentials. Auth0 now decodes the\nJWT iss claim and calls the tenant's Management API instead of a fixed\ngeneric host. Okta's detector captures the org domain into ExtraData\nand the verifier uses it (indeterminate when absent). GitLab derives\nits host from a co-loca\n[…]\nitLab detector also gains the newer routable token prefixes\n(gldt-/glrt-/glcbt-/glptt-/gloas-/glft-) and an open-ended PAT length.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): route auth0/okta/gitlab verification to the real host",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:37:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f0dc01d08fbb21c21b564f57154876c46a014afc",
          "body": "High: three verifiers gave wrong triage signal. Bitbucket verification\nwas dead code (no username); the detector now captures a co-located\nusername into ExtraData and its bare \"bitbucket\" regex alternative\n(broad false positives) was dropped (kept in Keywords only). Databricks\ncalled the account API\n[…]\ned Bearer auth for an\nHMAC-signed key; it is now an honest format-only (Tier-3) verifier\ninstead of a confidently-wrong live call.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): correct bitbucket/coinbase/databricks live verification",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:37:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e6d7859524e530784df7600e361c8bc2328386e7",
          "body": "…detector\n\nBlocker: aws_verifier's STS GetCallerIdentity path was dead code because\nno detector supplied the Secret Access Key it requires. The existing\nAWS access-key detector now captures a co-located secret access key\n(within a bounded window) into RawV2 — mirroring the Twilio pattern, no\nnew det\n[…]\ned into output. Also: trailing boundary on the\naccess-key pattern, an AKIAIOSFODNN7EXAMPLE allowlist, and redacted SDK\nerror text.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): make AWS live verification reachable by enriching the …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae8dc55a6484a61c3917e322e353c11410106e41",
          "body": "…ling\n\nBlocker (RCE): a workspace-settable executablePath/customRulesPath let\nan untrusted repository run arbitrary code; both settings are now\nmachine-overridable and honored only when vscode.workspace.isTrusted.\nHigh: diagnostics are cleared per-file instead of wiping every file on\na single-file s\n[…]\ns-bar reset, and a working toolchain (ESLint 9 flat\nconfig, regenerated lockfile, real unit tests, extracted parse/paths\nhelpers).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(vscode): gate binary execution behind workspace trust and fix too…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd7bda6fd3ceac5eef04247253e54f91a1be474f",
          "body": "…ient\n\nBlocker: a panic inside any verifier.Verify() crashed the entire scan\nand silently lost every finding; verification now runs under a\ndefer/recover that converts a panic to StatusVerifyError, logs the\nverifier type and stack (never the secret) via slog, and lets the\nworker pool continue. Also:\n[…]\nlicit TLS floor; body drain before\nClose; 429/Retry-After distinction; duplicate-Type detection; and a\nde-flaked concurrency test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): recover from verifier panics and harden shared HTTP cl…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d520dba1c1744e8efa136d843a882bb5007fdf84",
          "body": "Blocker: cloneRemote wrapped the raw go-git error unsanitized, leaking\nan embedded user:password@host credential to stderr on every clone\nfailure; added a local sanitizeCloneError that strips credentials\nbefore wrapping. High: full-history scans now diff each commit against\nits first parent so blobs\n[…]\ner silently ignored alongside --since-commit.\nPlus blob-dedup, IsBinary logging, DetectDotGit, errors.Is, and\nallocation cleanups.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(source): sanitize git clone errors and correct history attribution",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad792cc2a87dbe22218ce51f39be905e832ee863",
          "body": "…edaction\n\nBlocker: the RabbitMQ verifier logged err.Error() from url.Parse, whose\n*url.Error message re-embeds the full raw connection string (plaintext\ncredentials). It now logs a generic message plus the already-redacted\nvalue. High: redactPassword in the rabbitmq and redis detectors fell\nback to\n[…]\net/url found no\nuserinfo; both now mask fail-safe to <scheme>://****. Also lowered a\nper-hit host/username log from Info to Debug.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): never log raw RabbitMQ connection strings, fail-safe r…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d4dd6b8386a21054d0e5653775880d5ffb6222e",
          "body": "Blocker (3 review lenses): the Snowflake detector wrote the plaintext\npassword into Finding.ExtraData, which serialized into default\n(ShowRaw=false) output. Removed it from the detector and, as\ndefense-in-depth, marked Finding.ExtraData as json:\"-\" so no stray\nsecret in ExtraData can ever reach defa\n[…]\n;\nbounded the previously unbounded prefix wildcard; and fixed\nSourceMetadata.Date to omit a zero timestamp via custom MarshalJSON.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): stop leaking Snowflake password via Finding.ExtraData",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T23:16:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7a593aad4843672a8edf1c3f22cef4142f56ca9",
          "body": "feat(detector): detect GitHub stateless (JWT-format) ghs_ installation tokens",
          "is_bot": false,
          "headline": "Merge pull request #15 from HodeTech/feat/github-stateless-ghs-token",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T22:45:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e85a9431acc8ebb7620b63e87afb077ef627e862",
          "body": "Resolve all govulncheck findings on the branch:\n- crypto/tls stdlib (GO-2026-5856): Go 1.25.10 -> 1.25.12 across go.mod,\n  CI/release/action-test workflows, and the Docker build image\n- aws-sdk-go-v2/service/s3 (GO-2026-5764): v1.97.2 -> v1.97.3\n- go-git/v5 (GO-2026-5496): v5.17.1 -> v5.19.1\n- go-jose/go-jose/v4 (GO-2026-4945): v4.1.3 -> v4.1.4\n\ngovulncheck ./... now reports 0 vulnerabilities; build, vet and\nrace tests pass.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): bump Go 1.25.12 and deps to clear govulncheck",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T22:22:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e63238044983959eae8ffcc7dc5f0d61dad65e70",
          "body": "The repoRoot helper returned the raw os.Getwd error, dropping call-site\ncontext and violating the repo error-wrapping rule. Wrap it with\nfmt.Errorf so failures surface where they originate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(test): wrap os.Getwd error in registry_count_test repoRoot",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-07-15T22:14:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a4fbebd113ac5db43a97d98d188350da20364b6",
          "body": "GH-02: tools/site-build extracts each detector's regex from the AST and only\nemits a detector with a single regexp.MustCompile(`literal`); a concatenated /\nconst / fmt.Sprintf pattern silently vanishes from the web playground while the\nregistry count test still passes. Add TestDetectorsJS_CoversEver\n[…]\nor —\ndocumenting that it is never mislabelled active or \"invalid or revoked\".\n\nBoth are test-only; no production behavior changes.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(detector): guard generated detectors.js and pin github 403 verify",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T11:40:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a3bc7522fcfcf56451cdc2a95646c33770211515",
          "body": "isGitHubStatelessBody required the contiguous token run before a JWT to BEGIN\nwith \"ghs_\". When a base64url char is glued directly in front (e.g.\n\"xghs_APPID_eyJ...eyJ...sig\" with no delimiter), the run was \"xghs_APPID_\" so\nthe JWT was not recognised as a ghs_ body and was reported again — while the\n[…]\nte, never a\nsecret. Realistic delimiters (=, \", space, newline, :, /) are not token bytes,\nso this only tightens a contrived edge.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(jwt): suppress stateless ghs_ bodies glued to a preceding token char",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T11:40:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "524a172c479b79eb7754138f6a87d22d1d512c7b",
          "body": "… tokens\n\nFrom April 2026 GitHub issues installation tokens (including the Actions\nGITHUB_TOKEN) in a new ghs_APPID_<jwt> format: a ghs_-prefixed JWT of ~520\nchars containing exactly two dots. The previous github-oauth-token pattern\n`gh[orus]_[A-Za-z0-9_]{36,}` had no dot in its body class, so it tr\n[…]\ntable, en/tr detector catalogs, and CHANGELOG updated;\nsite bundle regenerated (site/js/manuals/{en,tr}.js, site/js/detectors.js).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(detector): detect GitHub stateless (JWT-format) ghs_ installation…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T10:59:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbe8c4d97fad5cee11d257224cdae50bfe8afc58",
          "body": "docs(readme): first-impression rewrite (banner, demo, verification) + v1.6.0 currency",
          "is_bot": false,
          "headline": "Merge pull request #14 from HodeTech/docs/readme-currency",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c2dc041f0237a090e2fba7b8f8180b510c9b80c",
          "body": "The detector/verifier/source/format counts were duplicated by hand across\nthe README banner, the social-preview SVG, and docs, with nothing keeping\nthem honest — adding a detector silently left every published \"63\" stale.\n\nIntroduce internal/meta as the single source of truth for the four\npublished \n[…]\ned a manual re-render when a number changes\n(no test can read pixels); the re-render command lives in each asset's\nheader comment.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(meta): single-source project counts with generate + CI guard",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:45:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8082aabd4bcae1210214c66eebb43b7d0de52aaa",
          "body": "Consistency with the rest of the README and GitHub's terminology\n(review nit from gemini-code-assist on PR #14).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): use \"pull request\" (no hyphen) in output-formats table",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:33:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bddea3bdec4deec7ab63d7c59d1690c988893c9e",
          "body": "The redaction wordplay (\"Some secrets shouldn't be [redacted]\") relied on\na hover/animation reveal that only works on the website — in a static\nREADME PNG the key word was simply invisible, leaving an incomplete\nsentence. Replace it with a direct headline (\"Find leaked secrets before\nattackers do.\"), a subtitle that names the scanned surfaces, and a thin\nbrand accent rule in place of the gimmicky CLASSIFIED bar.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): clearer banner with direct messaging",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:31:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3efc36fb13aa1104ba33ddfddf0dc702600789ec",
          "body": "v1.6.0 shipped the GitHub Marketplace Action, the github output format,\nand config wiring (not the planned Phase 9 detection-accuracy work).\nRecord it as completed Phase 8.5 with its own highlights, and shift every\nplanned phase up one version (Phase 9 -> v1.7.0 ... Phase 14 -> v1.12.0)\nacross the status table, gantt chart, phase headers/exit criteria, and the\nrelease plan.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(roadmap): record v1.6.0 release and shift planned phase versions",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:20:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7beb79d3b58cb9774a71f01cc7937e32ce34e8ef",
          "body": "Re-render the banner from a self-contained HTML source using the real\nbrand fonts (Space Grotesk 700 + JetBrains Mono 400/700) instead of\nfallback fonts, with a visible striped redaction bar. Strip decorative\nemoji from headings and feature bullets, and fix the resulting nav/inline\nanchors (#-quick-start -> #quick-start, etc.).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): font-accurate banner and remove decorative emoji",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:18:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4f14582a7de0a8ce7a6e6b36ec4958fb72bd385a",
          "body": "…talog\n\nReworked the README for repo + Marketplace first impression:\n- Brand banner (rendered from the site's og.svg) + sharper tagline + release badge.\n- \"What is Leakwatch?\" with a real terminal-output demo near the top.\n- Crisp feature list; prominent GitHub Action section (Marketplace audience) \n[…]\nutput-formats table includes the github format.\n- Added a Security/secret-safety note; condensed the docs link section; nav links.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): first-impression rewrite — banner, demo, collapsible ca…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:10:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "53158cbed11076c92601ce3831ea54685ceebe1e",
          "body": "- Bump the pre-commit `rev` and the binary-download example to v1.6.0 (latest).\n- Architecture diagram output node now lists all formats (JSON / SARIF / CSV /\n  Table / GitHub) instead of just three.\n- Note the `github` output format (inline PR annotations) in the CI/CD section.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): refresh for v1.6.0 and the github output format",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T09:02:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fd0a361eee3ec75d6475217805af23cc94b9a647",
          "body": "fix(action): scope exit-code capture instead of disabling errexit globally",
          "is_bot": false,
          "headline": "Merge pull request #13 from HodeTech/fix/action-errexit-scope",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T08:35:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4d56256a29f17c0b284f5d55725da3db5d4631e",
          "body": "…e fallback\n\nPiping jq into `head -50` gives jq a SIGPIPE once head closes after 50 lines;\nunder pipefail that non-zero status tripped the `|| echo fallback` even when the\ntable rendered fine (reproducible once jq's output exceeds the ~64KB pipe buffer,\ni.e. very many findings). Write jq output to a temp file, then `head -n 50` it,\nand emit the fallback only when jq fails or the file is empty.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): render summary table via temp file to avoid SIGPIPE fals…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T08:32:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4f9fa2f324da57a0f3ccea403de0f7040981b2cb",
          "body": "Follow-up to the PR #13 review:\n- action.yml: replace the job-summary `|| true` with a visible fallback note so a\n  (theoretical) render failure isn't silently swallowed. The jq filter already\n  handles location-less findings via `// \"-\"` (verified jq returns \"-\" without\n  erroring), so the `?` oper\n[…]\nmake the semantics obvious. (The reviewer's `if ! out=…; then rc=$?`\n  form is incorrect — it captures 0, not the real exit code.)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): non-silent summary fallback; clearer test exit-code capture",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T08:25:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a276e89e3c8a3399e832defbd22d82ff0f8e6fd",
          "body": "…bally\n\nAddresses the Sourcery review on #12 (the set +e change is already in main via #11,\nreleased in v1.6.0):\n\n- action.yml: replace `set +e` + direct call with\n  `EXIT_CODE=0; leakwatch \"${ARGS[@]}\" || EXIT_CODE=$?`, so errexit stays enabled\n  for the rest of the step (later failures still fail \n[…]\nified under `bash -e -o pipefail`: the mapping runs and a subsequent failing\ncommand still aborts (errexit not globally disabled).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): scope exit-code capture instead of disabling errexit glo…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T08:16:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c8e476e96ad5d9aab287dc155a332a19a217cd09",
          "body": "fix(action): honor exit codes under bash -e (restore set +e)",
          "is_bot": false,
          "headline": "Merge pull request #11 from HodeTech/fix/action-errexit-handling",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T07:17:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98d105784c3b7d544a506e73ddb189c899f82394",
          "body": "…r bash -e\n\nGitHub runs `shell: bash` steps with -e (`bash --noprofile --norc -e -o pipefail`).\nleakwatch legitimately exits 1 when it reports findings, so the scan aborted the\nstep *before* the exit-code mapping — meaning fail-on-findings: false was ignored\nand the action failed on any findings. (T\n[…]\np\nhonors fail-on-findings. The run-action self-test (fail-on-findings: false) and\ncli-github-format job are the regression guards.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): restore set +e so a findings exit (1) doesn't abort unde…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T07:16:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "11758001fce1b5b76ac0d061871c627b80c0c4a9",
          "body": "feat(action): Marketplace-ready GitHub Action (prebuilt-binary) + `github` output format",
          "is_bot": false,
          "headline": "Merge pull request #10 from cemililik/feat/github-marketplace-action",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T07:03:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47d2642b9a550aadc2d2be8f56918647c4af62df",
          "body": "…gs, sarif path\n\nValid findings fixed:\n- Add `persist-credentials: false` to every actions/checkout step in\n  action-test.yml and ci.yml (don't persist GITHUB_TOKEN; matches release.yml).\n- action.yml: `set -f` around the extra-args word-split so a bare glob token\n  (e.g. `--exclude *.go`) isn't pat\n[…]\nPA) convention used by ~140 sibling manual links;\n  switching one to a .md path would break portal navigation and be inconsistent.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): review round 3 — persist-credentials, glob-safe extra-ar…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T06:48:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8726065396f4ead0570d28d736d159ae3fb8eac1",
          "body": "…de, doc/bundle sync\n\n- extra-args guard now prefix-matches (-f*/-o*/--format*/--output*/--config*/\n  --show-raw*), so combined shorthand like `-fcsv` or `-o/tmp/x` can no longer\n  override the action's managed flags (the previous exact-token guard was\n  bypassable; -f/-o are format/output only in t\n[…]\ns render).\n- Regenerate site/js/manuals/{en,tr}.js so the updated CI/CD manuals ship\n  (the generated bundle was stale vs source).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): second-review fixes — extra-args bypass, scan-diff degra…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-25T06:13:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9cdc2ac495ffa48eb6608cdfd4efb557dee18402",
          "body": "…ive secrets\n\nSecurity:\n- Stop echoing the assembled scan command (path/extra-args may carry tokens or\n  authenticated URLs that GitHub log masking would not catch).\n- Reject action-managed flags (--format/--output/--config/--show-raw) in\n  extra-args so the action's output/summary/upload bookkeepin\n[…]\nt release-repo and the extra-args\n  restriction; soften ADR-0009's checksum claim and record provenance as a\n  future enhancement.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): address review — harden install/run, SHA-pin, escalate l…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T22:13:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "91a2c0d348dd7244e5f01c597f9a29adb1287c65",
          "body": "…clarifications",
          "is_bot": false,
          "headline": "fix(docs): update competitive analysis with feature enhancements and …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T21:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "898e646bc383947a5d2aaa907945fa36073e1bb0",
          "body": "…ce-action",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into feat/github-marketpla…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T21:06:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d35f4bd104237bb554475ddcb17cb6dd4512416e",
          "body": "feat: Redacted website + bilingual user manuals; migrate to HodeTech org",
          "is_bot": false,
          "headline": "Merge pull request #9 from cemililik/feat/website-and-user-manuals",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T21:04:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac130feb0b84631ecb17a8704e77c5cce88f38a9",
          "body": "…stall\n\nMake Leakwatch usable from the GitHub Marketplace as\n`uses: HodeTech/Leakwatch@v1`, matching the low-friction adoption path of\ncomparable tools.\n\nAction (action.yml, moved to repo root from action/):\n- Composite action that downloads the prebuilt release archive for the runner\n  and verifies\n[…]\ntched to `Leakwatch`.\n\nLinux/macOS runners only for now (composite + prebuilt binary); Windows is a\ndocumented future enhancement.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(action): Marketplace-ready GitHub Action with prebuilt-binary in…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T21:01:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e01fe13f370a3961695f40dde34429eb9ebfb7ae",
          "body": "- Delegate the redaction hover-peek from document instead of binding\n  per-node, so it survives i18n re-renders that replace nodes via\n  innerHTML on a language switch (the headline word stopped revealing\n  after switching languages).\n- Replace the now-redundant 'hover a redaction to reveal it' hint\n[…]\nintained by HodeTech' attribution to the footer tagline,\n  copyright, and hero eyebrow (EN + TR, across index/contact/playground).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(site): keep redaction hover working across language switches",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-24T20:14:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "11e134e01903fe93e2b07ccef2fe095417103a32",
          "body": "Add a /playground page where visitors paste text and run Leakwatch's real\ndetection patterns entirely client-side — nothing is uploaded.\n\n- Patterns are auto-extracted from internal/detector by tools/site-build\n  (go/ast -> site/js/detectors.js); Go RE2 ports cleanly to JS regex.\n- js/scanner.js app\n[…]\nlace the empty\nredaction boxes in the detector index with real redacted detector names\nthat reveal on hover (+ count fixed to 44).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(site): add in-browser playground (real client-side scanner)",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T19:38:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e2144a14199a080657e971aedf71c61f062579a",
          "body": "Two internal links pointed at non-existent pages (caught by gemini-code-assist):\n\n- how-it-works (EN+TR): #/configuration/custom-rules -> #/detectors/custom-rules\n- installation (EN+TR): #/guides/docker -> #/ci-cd/docker-usage\n\nRegenerated the compiled manual bags. All 278 #/section/page cross-links now\nresolve against _meta.yaml.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): correct broken manual cross-links flagged in review",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T17:59:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "31423275cf809a23961b60a502dadc3d358bceb8",
          "body": "Address SonarCloud findings on the website:\n\n- site-deploy.yml: move GITHUB_TOKEN permissions from workflow level to the\n  jobs that need them (build: contents:read; deploy: pages:write, id-token:write)\n  and drop the unused configure-pages step (least privilege).\n- Self-host JetBrains Mono + Space \n[…]\ncs/contact. No third-party requests, no missing-SRI\n  hotspot, and the site works offline. latin-ext keeps Turkish glyphs correct.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(site): job-scoped Pages permissions and self-hosted fonts",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T17:55:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "89b834279dfb4f28db7b6e2fcc7c5dfd4b7c93d7",
          "body": null,
          "is_bot": false,
          "headline": "feat(contact): update form action URL for contact submissions",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T17:51:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5798dfd746d575f2c33c44d65427fc08b9147b2d",
          "body": "Add a GitHub Pages site and a complete bilingual user manual.\n\nSite (site/): vanilla HTML/CSS/JS, no build step, dark-only \"Redacted\"\nclassified-dossier theme. Landing page with an animated scan-reveal hero,\na docs portal (left nav, hash routing, search, Mermaid diagrams, right-hand\non-this-page TOC\n[…]\nml\nrecompiles and deploys site/ to GitHub Pages.\n\nNote: contact.html posts to Formspree; replace YOUR_FORM_ID with a real form ID.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(site): add Redacted website, bilingual manuals, and Pages deploy",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T17:44:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f75a6a11e14e9077da4c36e9c00889efce0abd23",
          "body": "Move the project to the HodeTech organization:\n\n- Go module github.com/cemililik/leakwatch -> github.com/HodeTech/leakwatch\n  (go.mod + all internal imports / blank imports)\n- Web URLs -> github.com/HodeTech/Leakwatch (README, CLAUDE.md, CONTRIBUTING,\n  CODE_OF_CONDUCT, docs/guides, architecture, RO\n[…]\n.properties (org=hodetech),\n  vscode/package.json (publisher=HodeTech)\n\ngo build ./... , go vet ./... and detector+cmd tests pass.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: migrate module path and references to HodeTech org",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T17:44:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0d849ec01ad8d1b57aa705af9dd58918b0bfb9b",
          "body": "…fication, and clarify Slack scanning capabilities\n\n- Clarified IAM permissions for S3 bucket scanning in cloud-scanning.md, noting that `s3:ListBucket` also covers `HeadBucket` checks.\n- Added `rate-limit` configuration option for verification in configuration.md.\n- Updated custom rules documentati\n[…]\nret verification documentation to reflect the addition of new verifiers and clarify verification methods.\n- Adjusted Slack scanning documentation to indicate that file scanning is not yet implemented.",
          "is_bot": false,
          "headline": "feat(docs): update cloud scanning permissions, add rate limit to veri…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T05:41:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b130ac1a5b6b6457c19615403bc45f898acc53d",
          "body": "…2026-05-22\n\nfix: address 2026-05-22 full-project review (security, correctness, docs)",
          "is_bot": false,
          "headline": "Merge pull request #8 from cemililik/fix/address-full-project-review-…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T00:12:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22ff634e05667679e0b316cd1ddfc21cf85fa529",
          "body": "…cation\n\nAdd httpx.VerifyToken + TokenSpec, which centralize the request-build,\ntransport/redirect/build error handling, status-to-result mapping, body\ndecoding, and error redaction that every HTTP verifier previously duplicated.\nEach verifier now declares only what is provider-specific (URL, auth h\n[…]\nve probe.\n\nA direct unit test for verify.go gives the new shared helper 100% coverage so it\nis not reported as uncovered new code.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(verifier): extract shared HTTP-verify helper to remove dupli…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T00:10:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9024859f713741007bc6d672b9d9a0f96c6d3dda",
          "body": "Replace the repeated \"show-raw\" and \"include-files\" string literals with\npackage constants (flagShowRaw, flagIncludeFiles), resolving the SonarCloud\n\"define a constant instead of duplicating this literal\" findings in\nscan_common.go and scan_slack.go. show-raw is referenced by every scan\ncommand, so the constant is centralized in scan_common.go and reused across\nall scan_*.go files.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(cmd): define constants for duplicated scan flag literals",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-23T00:10:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c78f9b986cbeccb64e0ae40ab2530c9df92e6ab8",
          "body": "- detector/gcp: split enclosingObject into findEnclosingOpenBrace and\n  findMatchingCloseBrace to bring cognitive complexity from 16 under 15\n  (behavior preserved)\n- verifier/vtest: document why the closed-server handler is intentionally\n  empty (it is never invoked; the server is closed to force a\n[…]\nreword the TODO(planned) markers as \"Planned (see ROADMAP)\"\n  notes; the work is tracked in the roadmap, not as an inline TODO tag\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: resolve SonarCloud code-quality findings on PR #8",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T23:27:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d445631510ab06f6f98dc90a9296e1d78d0c49e",
          "body": "…on docs\n\n- Coverage: the binding overall gate is the 70% CI enforces. Update\n  04-DEVELOPMENT-STANDARDS, 02-RELEASE-STANDARDS and 01-CODE-REVIEW-STANDARDS\n  from 80% to 70% (per-package figures kept as labelled-aspirational targets).\n- configuration.md: the entropy threshold is display-only for bui\n[…]\nifier issues a non-destructive POST).\n- ROADMAP: record the engine's unbounded in-memory result buffering as a known\n  limitation.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: align coverage gate to 70% and correct entropy/slack/verificati…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T22:02:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65b4abfd5812c9459d543bb48583571bdfbfbbdc",
          "body": "The release builds linux/arm64 via buildx and Dockerfile.goreleaser runs\n`apk add` inside the target-arch container, which needs emulation. Add\ndocker/setup-qemu-action and docker/setup-buildx-action before goreleaser, and\npin docker/login-action to an immutable SHA to match the file's hardening style.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: build the arm64 image with QEMU/buildx and pin docker actions",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T22:02:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "87d79037b1e59d7428c26b8fa69db6b1647b2d95",
          "body": "…file scanning\n\n- gcp verifier validated json.Unmarshal(raw.Raw), but the detector now puts only\n  the private_key_id in Raw and the redacted JSON block in RawV2, so the verifier\n  always reported \"format invalid\". Validate RawV2 (fall back to Raw); add a\n  detector->verifier contract test so the sh\n[…]\nlp no longer claims it scans uploaded files and no longer\n  requests the files:read scope; file scanning is documented as planned.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): gcp verifier reads RawV2; stop slack help advertising …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T22:02:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c18de5e4a672e1106e0c22fe3dcf05f6a1564381",
          "body": "…errors\n\nAddresses two credential-leak findings from the PR review.\n\n- git source: a scan target like https://user:TOKEN@host/repo.git leaked the\n  credential into JSON output (SourceMetadata.Repository), the stderr scan\n  summary, and logs/errors. Export SafeDisplayURL() (credential-stripped) and\n \n[…]\nRL stripping + Repository non-leak; per-verifier\n  transport-error tests asserting the token/webhook never appears in the message.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): redact credentials in git URLs and verifier transport …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T22:02:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "16a2e64a12859cb581bfa4eac222b4f9543d1b77",
          "body": "Resolves SYS-05, SYS-06, SYS-09, SYS-10, SYS-11, SYS-12, SYS-13, SYS-14 and\nDGDA-C-01/C-03 from the 2026-05-22 full-project review.\n\n- Correct counts everywhere: 63 detectors (60 packages), 6 sources,\n  54 verifiers (51 packages), verification coverage 85.7% (54/63).\n- Verifier tiers match the code:\n[…]\n.\n- Add a \"Master Review — Documented-but-Unimplemented Gaps\" section to the\n  ROADMAP recording the features deferred as planned.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: align documentation with code and record unimplemented gaps",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T17:27:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "59d91ed1a448b76697c5f44cc534f0564f4860bd",
          "body": "Resolves SYS-07, SYS-08, SYS-18, SRCA-M-01, OUT-M-03, OUT-m-04 and\nCMD-M-04 from the 2026-05-22 full-project review.\n\n- config/cmd: build a per-command viper.New() and load via config.LoadFrom,\n  fixing the global BindPFlag pointer-overwrite bug — --concurrency,\n  --max-file-size, output.format and \n[…]\n  config; route scan repos through the shared render pipeline; honor\n  cmd.Context(); fix gitignore-style trailing-slash matching.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cmd): honor scan flags via isolated Viper and harden sources",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T17:26:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "92ed6d00e06997e6237f0f0d53a9ba38af4f6e4d",
          "body": "… semantics\n\nResolves SYS-01, SYS-02, the teams side-effect, and VERB-M-03/M-04,\nVERA-m-01/m-04, SYS-17 from the 2026-05-22 full-project review.\n\n- Add internal/verifier/internal/httpx: a shared client that does NOT follow\n  redirects (CheckRedirect -> ErrUseLastResponse), sets an explicit Timeout,\n\n[…]\nmed 200 bodies now map to VerifyError, never VerifiedActive.\n- Add a reusable timeout/transport/malformed-body test suite (vtest).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verifier): stop credential leakage on redirect and correct status…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T17:26:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ce052e2eacef75d0b5329c58aa173da91813a8d",
          "body": "…output model\n\nResolves ENG-C-01, SYS-04, DETA-C-01, OUT-M-01/M-02, DETA-M-02 and\nSYS-05/SYS-16 from the 2026-05-22 full-project review.\n\n- matcher: switch the shared automaton from the non-thread-safe Match()\n  to MatchThreadSafe(); workers shared one matcher and could silently drop\n  matches (fals\n[…]\ntly.\n- output: make ShowRaw actually surface raw in csv/table/sarif (was a no-op);\n  sanitize CSV cells against formula injection.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(engine): harden detection core — matcher race, secret redaction, …",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T17:26:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f5c3d7a3832b281bc324f0373878a3a358198df",
          "body": "… publish to GHCR\n\nResolves SYS-15 and SYS-10 from the 2026-05-22 full-project review.\n\n- Bump golang.org/x/crypto v0.49.0 -> v0.52.0 (7 SSH CVEs) and\n  golang.org/x/net v0.52.0 -> v0.55.0; raise the Go directive/toolchain\n  and CI pins to 1.25.10. govulncheck now reports 0 called vulnerabilities\n  \n[…]\nR login step and packages: write permission in the release workflow,\n  publishing the canonical image ghcr.io/cemililik/leakwatch.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build(deps): patch dependency CVEs, pin Go 1.25.10, gate govulncheck,…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T17:26:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fafa4ea1e2754eeac7f58696c17a44308a9634d",
          "body": "…-ignore\n\nWire up custom-rules, inline ignore, verification & filter config (P0/P1)",
          "is_bot": false,
          "headline": "Merge pull request #7 from cemililik/fix/wire-custom-rules-and-inline…",
          "author_name": "Cemil ILIK",
          "author_login": "cemililik",
          "committed_at": "2026-05-22T14:32:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 8,
      "commits_last_year": 183,
      "latest_release_at": "2026-07-20T19:44:14Z",
      "latest_release_tag": "v1.7.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 16.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/HodeTech/leakwatch",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/HodeTech/leakwatch",
          "is_deprecated": false,
          "latest_version": "v1.7.0",
          "repository_url": "https://github.com/HodeTech/leakwatch",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-19T06:51:02Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        },
        {
          "name": "leakwatch",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "security",
            "secrets",
            "pii",
            "git",
            "pre-push",
            "aadhaar",
            "upi",
            "api-keys",
            "devtools",
            "india"
          ],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/leakwatch",
          "is_deprecated": false,
          "latest_version": "0.1.0",
          "repository_url": null,
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 46,
          "first_published_at": "2026-04-20T05:20:01.219000Z",
          "latest_published_at": "2026-04-20T05:20:01.387000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 98
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-26",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 14
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "vscode/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod",
        "tools/site-build/go.mod"
      ],
      "largest_source_bytes": 352237,
      "source_files_sampled": 372,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 8329
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "vscode/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 2
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 16,
        "malicious_count": 0,
        "assessed_package": "npm:leakwatch@0.1.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "cloud.google.com/go/storage",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.61.3"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.30"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/credentials",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.29"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/s3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.97.3"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.1"
        },
        {
          "name": "github.com/aws/smithy-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.4"
        },
        {
          "name": "github.com/cloudflare/ahocorasick",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240916140611-054963ec9396"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.19.1"
        },
        {
          "name": "github.com/google/go-containerregistry",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.3"
        },
        {
          "name": "github.com/slack-go/slack",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.10"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.0"
        },
        {
          "name": "google.golang.org/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.289.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 14,
        "merged_prs": 19,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 11
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "cemililik",
          "commits": 183,
          "avatar_url": "https://avatars.githubusercontent.com/u/10156320?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "action-test.yml",
        "ci.yml",
        "release.yml",
        "site-deploy.yml",
        "vscode-ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml",
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/5 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 5,
            "reason": "5 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "228431637ef4c5f41f9f34fc585771a66e2dbc64",
        "ran_at": "2026-07-27T15:27:30Z",
        "aggregate_score": 5.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T03:42:55Z",
      "oldest_open_prs": [
        {
          "number": 19,
          "created_at": "2026-07-19T06:37:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 20,
          "created_at": "2026-07-19T06:37:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 21,
          "created_at": "2026-07-19T06:37:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 22,
          "created_at": "2026-07-19T06:37:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 23,
          "created_at": "2026-07-19T06:37:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 24,
          "created_at": "2026-07-19T06:37:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 25,
          "created_at": "2026-07-19T06:37:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 26,
          "created_at": "2026-07-19T06:38:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 33,
          "created_at": "2026-07-19T06:55:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 34,
          "created_at": "2026-07-19T06:55:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-07-20T20:16:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 42,
          "created_at": "2026-07-26T03:43:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 43,
          "created_at": "2026-07-26T03:43:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 44,
          "created_at": "2026-07-26T03:49:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-20T20:13:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/HodeTech/Leakwatch",
    "host": "github.com",
    "name": "Leakwatch",
    "owner": "HodeTech"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 59,
        "vitality": 77,
        "community": 37,
        "governance": 47,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "commits_last_year": 183,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "183 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 183
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 8,
              "latest_release_tag": "v1.7.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 16.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "8 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~16.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 16.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 37,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "critical",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 28,
            "inputs": {
              "packages": [
                "github.com/HodeTech/leakwatch",
                "leakwatch"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 46
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "46 downloads/month across go, npm",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 46,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 47,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 45,
            "inputs": {
              "merged_prs": 19,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 11
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "19/30 decided PRs merged",
                "points": 24.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 19,
                      "decided": 30
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "HodeTech",
              "public_repos": 10,
              "account_age_days": 1767
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of HodeTech",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "HodeTech"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~4 yr old",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/HodeTech/leakwatch",
                "leakwatch"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "8 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml, eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml, eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "appsec",
                "cli",
                "credential-scanner",
                "devsecops",
                "golang",
                "leak-detection",
                "sarif",
                "secret-detection",
                "secret-scanning",
                "secrets-detection",
                "secrets-management",
                "security",
                "security-tools",
                "static-analysis"
              ],
              "has_wiki": true,
              "homepage": "https://hodetech.github.io/Leakwatch/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://hodetech.github.io/Leakwatch/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "14 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "5 existing vulnerabilities detected",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:leakwatch@0.1.0 runtime dependency closure — what installing the published package pulls in — 16 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:leakwatch@0.1.0",
                  "assessed": 16
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 16,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: brace-expansion 2.1.2 (high 7.5)",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "brace-expansion 2.1.2 (high 7.5)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 16,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 93,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 8329
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "vscode/tsconfig.json"
              ],
              "agent_commit_share": 0.83,
              "toolchain_manifests": [
                "go.mod",
                "tools/site-build/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml, eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml, eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "vscode/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vscode/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "83 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 83,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 352237,
              "source_files_sampled": 372,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/372 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 372,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T15:27:47.877496Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/h/HodeTech/Leakwatch.svg",
  "full_name": "HodeTech/Leakwatch",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo, npm.