Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 03:31 UTC

chainguard-dev / omnibump

Universal declarative dependency bump tool

GoApache-2.0★ 13 Sterne⑂ 10 Forksseit Feb. 2026Auf GitHub ansehen ↗

chainguard-dev/omnibump erreicht einen Gesundheitsindex von 73 von 100 und liegt damit im Bereich Gut. Am stärksten schneidet es bei Vitality (88/100) ab, am schwächsten bei Community & Adoption (38/100). Zuletzt vor 1 Tag aktualisiert. 2 Mitwirkende tragen den Großteil der jüngsten Arbeit.

73
gesamt / 100
Gut

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

73
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

ChainguardOrganisation
844 Follower116 öffentliche Reposseit Juli 2021

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/chainguard-dev/omnibumpv0.23.1-51vor 3 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

88Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
16.6/36Commit-Rhythmus — 24/52 Wochen mit Commits
18/18Commit-Volumen — 133 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year133
human_commit_share0,67
days_since_last_push1
active_weeks_last_year24
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 42 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 1 Tagen
27/27Release-Rhythmus — ein Release etwa alle 3,8 Tage
8/10OpenSSF Scorecard: Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
Verwendete Eingangsdaten
releases_count42
latest_release_tagv0.23.1
releases_from_tagsnein
days_since_latest_release1
mean_days_between_releases3,8

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

38Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
17.5/60Stars — 13 Stars
8/25Forks — 10 Forks
1.7/15Watcher — 3 Watcher
Verwendete Eingangsdaten
forks10
stars13
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

71Gut · 24 % des Gesamtindex
Wie die Bewertung erfolgt
25.2/54Bus-Faktor — 2 Beitragende decken die Hälfte aller Commits ab
15.5/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 31 % der Commits
9.5/13.5Breite der Beitragenden — 7 Beitragende
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Verwendete Eingangsdaten
bus_factor2
contributors_sampled7
top_contributor_share0,31
Wie die Bewertung erfolgt
18.7/46.8Issue-Lösungsquote — 40 % der Issues geschlossen
30.8/38.3PR-Annahme — 129/160 entschiedene PRs gemergt
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Verwendete Eingangsdaten
merged_prs129
open_issues3
closed_issues2
issue_closed_ratio0,4
closed_unmerged_prs31
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
21/25Reichweite des Inhabers — 844 Follower von chainguard-dev
23.1/25Kontohistorie — 116 öffentliche Repos, Kontoalter ca. 5 Jahre
Verwendete Eingangsdaten
followers844
owner_typeOrganization
is_verified
owner_loginchainguard-dev
public_repos116
account_age_days1.839

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 3 Tagen
20/20Versionshistorie — 51 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/chainguard-dev/omnibump
ecosystemsgo
any_deprecatednein
min_days_since_publish3

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

80Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 7 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — .golangci.yaml
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
10/10Topics — 4 Topics
0/10Wiki
Verwendete Eingangsdaten
topicscargo, go, gradle, maven
has_wikinein
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

84Gut · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 152 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate8
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories1
affected_packages1
assessed_packages50
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories, Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. 50 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

79Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 67 von 67 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — .golangci.yaml
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 19 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 33 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilescomposer.lock, go.sum, uv.lock
has_dockerfilenein
typed_languageja
bootstrap_filesMakefile
has_devcontainernein
has_linter_configja
typecheck_configs
agent_commit_share0,19
toolchain_manifestsgo.mod, pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod, pkg/languages/golang/testdata/bye/go.mod, pkg/languages/golang/testdata/confd/go.mod, pkg/languages/golang/testdata/hello/go.mod, pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod, pkg/languages/golang/testdata/tidy-compat/go.mod, pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle, pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle, pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-style/build.gradle, pkg/languages/java/gradle/testdata/kayenta-style/build.gradle, pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts, pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts, pkg/languages/java/gradle/testdata/opensearch-style/build.gradle, pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle, pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts, pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts, pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts, testdata/maven-simple/pom.xml
dependency_bot_commit_share0,33
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
54.6/55Handhabbare Dateigrößen — 1/157 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes88.710
source_files_sampled157
oversized_source_files1

Eckdaten

13GitHub-Sterne
7Mitwirkende
133Commits, letzte 12 Monate
1Tage seit letztem Push
42Releases
2Bus-Faktor
3offene Issues
GoPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 10 ⇿
0Sterne
10Forks
33Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

02468101012026-022026-042026-07
Major 0Minor 8Patch 25
OpenSSF Scorecard 8.0 / 10
8.0Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 03:30 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
8Signed-Releases3 out of the last 3 releases have a total of 3 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities152 existing vulnerabilities detected
Direkte Abhängigkeiten 18
RegistryPaketVersionsvorgabeManifest
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1go.mod
Gogithub.com/chainguard-dev/clogv1.8.1go.mod
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263go.mod
Gogithub.com/charmbracelet/logv1.0.0go.mod
Gogithub.com/ghodss/yamlv1.0.0go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/v75v75.0.0go.mod
Gogithub.com/samber/lov1.53.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tidwall/gjsonv1.19.0go.mod
Gogithub.com/tidwall/sjsonv1.2.5go.mod
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742dgo.mod
Gogolang.org/x/modv0.38.0go.mod
Gogolang.org/x/toolsv0.48.0go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gosigs.k8s.io/release-utilsv0.12.4go.mod
Alle Abhängigkeiten 50

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 18 direkte und 32 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1direkt
Gogithub.com/burntsushi/tomlv1.6.0direkt
Gogithub.com/chainguard-dev/clogv1.8.1direkt
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263direkt
Gogithub.com/charmbracelet/logv1.0.0direkt
Gogithub.com/ghodss/yamlv1.0.0direkt
Gogithub.com/google/go-cmpv0.7.0direkt
Gogithub.com/google/go-github/v75v75.0.0direkt
Gogithub.com/samber/lov1.53.0direkt
Gogithub.com/spf13/cobrav1.10.2direkt
Gogithub.com/stretchr/testifyv1.11.1direkt
Gogithub.com/tidwall/gjsonv1.19.0direkt
Gogithub.com/tidwall/sjsonv1.2.5direkt
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742ddirekt
Gogolang.org/x/modv0.38.0direkt
Gogolang.org/x/toolsv0.48.0direkt
Gok8s.io/apimachineryv0.36.2direkt
Gosigs.k8s.io/release-utilsv0.12.4direkt
Gogithub.com/aquasecurity/go-versionv0.0.1indirekt
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1indirekt
Gogithub.com/charmbracelet/colorprofilev0.2.3-0.20250311203215-f60798e515dcindirekt
Gogithub.com/charmbracelet/lipglossv1.1.0indirekt
Gogithub.com/charmbracelet/x/ansiv0.8.0indirekt
Gogithub.com/charmbracelet/x/cellbufv0.0.13-0.20250311204145-2c3ea96c31ddindirekt
Gogithub.com/charmbracelet/x/termv0.2.1indirekt
Gogithub.com/clipperhouse/uax29/v2v2.6.0indirekt
Gogithub.com/common-nighthawk/go-figurev0.0.0-20210622060536-734e95fb86beindirekt
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirekt
Gogithub.com/go-logfmt/logfmtv0.6.1indirekt
Gogithub.com/google/go-querystringv1.1.0indirekt
Gogithub.com/inconshreveable/mousetrapv1.1.0indirekt
Gogithub.com/kr/textv0.2.0indirekt
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0indirekt
Gogithub.com/mattn/go-isattyv0.0.20indirekt
Gogithub.com/mattn/go-runewidthv0.0.19indirekt
Gogithub.com/muesli/termenvv0.16.0indirekt
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirekt
Gogithub.com/rivo/unisegv0.4.7indirekt
Gogithub.com/spf13/pflagv1.0.9indirekt
Gogithub.com/tidwall/matchv1.1.1indirekt
Gogithub.com/tidwall/prettyv1.2.0indirekt
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41eindirekt
Gogolang.org/x/syncv0.22.0indirekt
Gogolang.org/x/sysv0.47.0indirekt
Gogolang.org/x/textv0.33.0indirekt
Gogolang.org/x/tools/go/packages/packagestestv0.1.1-deprecatedindirekt
Gogolang.org/x/xerrorsv0.0.0-20231012003039-104605ab7028indirekt
Gogopkg.in/check.v1v1.0.0-20180628173108-788fd7840127indirekt
Gogopkg.in/yaml.v2v2.4.0indirekt
Gogopkg.in/yaml.v3v3.0.1indirekt
Abhängigkeits-Advisories 1

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 50 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 1 tragen bekannte Advisories, davon 0 direkte.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
golang.org/x/textv0.33.0indirektunbekannt10.39.0

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "cargo",
        "go",
        "gradle",
        "maven"
      ],
      "is_fork": false,
      "size_kb": 3343,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1439590,
        "Makefile": 3870
      },
      "pushed_at": "2026-07-27T00:19:13Z",
      "created_at": "2026-02-12T17:41:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T08:14:18Z",
      "description": "Universal declarative dependency bump tool",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://chainguard.dev",
      "name": "Chainguard",
      "type": "Organization",
      "login": "chainguard-dev",
      "company": null,
      "location": "United States of America",
      "followers": 844,
      "avatar_url": "https://avatars.githubusercontent.com/u/87436699?v=4",
      "created_at": "2021-07-14T15:25:28Z",
      "is_verified": null,
      "public_repos": 116,
      "account_age_days": 1839
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.23.1",
          "kind": "patch",
          "published_at": "2026-07-27T00:21:30Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-22T15:56:58Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-20T16:35:30Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:12:23Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-07-07T16:05:43Z"
        },
        {
          "tag": "v0.18.6",
          "kind": "patch",
          "published_at": "2026-07-01T14:26:24Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-06-26T15:47:53Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-06-23T15:11:02Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:30:05Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:29:35Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-16T07:27:50Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-06-12T07:44:35Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-11T16:11:31Z"
        },
        {
          "tag": "v0.14.4",
          "kind": "patch",
          "published_at": "2026-06-10T07:43:39Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2026-06-09T14:28:16Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-06-05T12:59:00Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-06-04T14:54:04Z"
        },
        {
          "tag": "v0.12.5",
          "kind": "patch",
          "published_at": "2026-06-01T07:45:34Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:36Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:03Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-05-20T12:17:12Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-05-18T14:01:54Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-14T14:37:04Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-05-07T18:31:14Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-05-05T22:06:48Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-05-04T21:49:18Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-04-22T18:31:16Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-04-15T16:58:56Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-04-15T16:32:06Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-04-03T14:08:09Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-03-20T16:26:33Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-16T00:08:21Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-10T18:32:45Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-09T14:21:15Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-06T23:11:06Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-03-02T00:05:29Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-02-25T20:42:33Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-02-24T14:16:47Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-02-23T18:00:17Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-02-19T19:03:43Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-19T17:57:03Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-18T21:34:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#168)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a00441b1767210c423f86077bb4de041d82e32f4",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.7 to 0.6.0.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/192e21d79ab29983730a13d1382995c2307fbcaa...6599ee8b7a49aef6a770f6\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#166)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5f183a1149e4df649a6930b5c2c250b4ce6f1d4",
          "body": "…(#142)\n\nBumps [github.com/chainguard-dev/clog](https://github.com/chainguard-dev/clog) from 1.8.0 to 1.8.1.\n- [Release notes](https://github.com/chainguard-dev/clog/releases)\n- [Commits](https://github.com/chainguard-dev/clog/compare/v1.8.0...v1.8.1)\n\n---\nupdated-dependencies:\n- dependency-name: gi\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github.com/chainguard-dev/clog from 1.8.0 to 1.8.1 …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:41:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abbfd95893391f21a1141c017066208f6b30aea",
          "body": "…#144)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.1 to 9.3.0.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:40:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e73c3feedd05e36d937731fc43676ad95fcbfe4a",
          "body": "…145)\n\nBumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89..\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18a97210520f6ae8449c30a852ce75a48829fccd",
          "body": "…#154)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.4 to 2.20.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/9af89fc71515a100421586dfdb3dc9c984fbf411...\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5604124d31877b827a250df09164bdd3b0d342e8",
          "body": "…ersions (#164)\n\nOn a cold Go module cache, `omnibump --replaces` could write\n`<module>@downloading` into go.mod and then fail to re-parse the file.\n`resolveVersionQuery` runs `go list -m <module>@<query>` with\nCombinedOutput(), which merges stderr into stdout. On a cold cache go\nemits progress to s\n[…]\neach go.mod. Concrete requested\nversions keep flowing through resolvePackageVersion's existing verbatim\nfallback.\n\nCloses AUTO-953\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): reject download-progress output when resolving replace-pin v…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T15:38:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4aed8419ea7846eda02846b0b7b98897d7e7321",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.46.0 to 0.48.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.46.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.46.0 to 0.48.0 (#159)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:37:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6dd36b76db0563042635b30d577079e20c203087",
          "body": "…e (#163)\n\nIn Go workspace mode omnibump only applied replace pins for modules\nalready declared in a sub-module's go.mod. A purely transitive module —\npresent in no go.mod, only in the module graph — was filtered out of\nevery module and silently dropped, so an explicitly-requested pin never\ntook eff\n[…]\nmodules already\nbeing updated, mirroring the add-if-missing behaviour omnibump already\nhas in single-module mode.\n\nCloses AUTO-954\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): apply replace pins for transitive-only deps in workspace mod…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T13:56:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04819df76159dead4d278eff0dbd1c7fac7267e3",
          "body": "…lution edge cases (AUTO-525) (#162)\n\n* fix(rust): correct reverse-dependency resolution for real-world edge cases\n\nHarden the revdep resolver so coordinated upgrades stop aborting on phantom\nconflicts:\n\n- Group a parent's requirements by dependency rename key: a crate that renames a\n  second copy o\n[…]\nhe boundary loop and landedVersion read Cargo.lock (GetCurrentPackages) instead\n   of exec'ing `cargo metadata` per call.\nF10 ParseVersion and parseTerm share splitPre for the pre-release/build split.",
          "is_bot": false,
          "headline": "feat(rust): coordinate crate families and fix reverse-dependency reso…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-20T14:43:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0722ce5bc8e796d7cfbb65dc62f5dab246dbf3b",
          "body": "… bumps (#157)\n\n* feat(gradle): scan typed String vars and `<<` map appends for version bumps (AUTO-761)\n\nThe Gradle scanner only recognized a fixed set of version-definition\nsyntaxes. Two constructs in real Elasticsearch build scripts fell outside\nit, so omnibump could not rewrite the source litera\n[…]\n the\n  coordinate-literal scan still records the dependency\n\nAdds a multi-module cross-aliasing regression test plus parser edge-case\ntests for the DSL gating, annotation, and coordinate-value guards.",
          "is_bot": false,
          "headline": "feat(gradle): scan typed String vars and `<<` map appends for version…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-15T15:22:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "014583d6d081ff74c7bb72729dbbf7a118350939",
          "body": "…(#156)\n\n* fix(rust): validate and land dependency upgrades within SemVer lines\n\nTwo related fixes for updating a crate that is (or coexists with) multiple\nSemVer-incompatible versions in one Cargo.lock:\n\n- Validate: only compare the target against the locked instance in the same\n  Cargo caret line.\n[…]\nin (name@from=to)\nhandling -- the @from marker only supplies the base name, and the\nexact-match / refused-downgrade case is owned by pinPrecise and\nverifyTransitiveUpgrade, so Validate defers to them.",
          "is_bot": false,
          "headline": "fix(rust): validate and land dependency upgrades within SemVer lines …",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-14T15:46:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "127737bb840067cbd549fff03f549260817573bb",
          "body": "…toml (#155)\n\n* feat(rust): edit Cargo.toml for SemVer-breaking direct dependency bumps\n\nWhen a direct dependency must be upgraded across a SemVer boundary (e.g.\ntracing-subscriber 0.2 -> 0.3, rand 0.8 -> 0.9), cargo update alone cannot\ncross the caret line, so operators fell back to a fragile exter\n[…]\nr =precise) via invertedTreeSpec; a request matching no\nlocked line is ErrAmbiguousTarget. As a safety net, ParseTree now refuses multiple\ndepth-0 roots instead of silently dropping all but the first.",
          "is_bot": false,
          "headline": "feat(rust): resolve SemVer-constrained CVE upgrades by editing Cargo.…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-13T14:06:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41d8008f844653060e84e95b5a896ad2d12dc2a4",
          "body": "…allow-list (#150)\n\nAdd two missing endpoints to the harden-runner egress allow-list:\n\n- goreleaser.com:443 — goreleaser-action resolves download URLs through\n  this host (EAI_AGAIN failure)\n- uploads.github.com:443 — goreleaser uploads release artifacts through\n  this host, separate from api.github.com\n\nFollow-up to #147 and #148.",
          "is_bot": false,
          "headline": "fix(ci): add goreleaser.com and uploads.github.com to release egress …",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4859c6498ed4cb2df255e9de94c7d5db1f8abf",
          "body": "Add tuf-repo-cdn.sigstore.dev, fulcio.sigstore.dev, and rekor.sigstore.dev\nto the harden-runner egress allow-list. The release workflow uses cosign\nkeyless signing (sign-blob via goreleaser) which contacts Fulcio for\ncertificates and Rekor for the transparency log, and the cosign installer\nuses the TUF CDN for trust root verification.\n\nFollow-up to #147 which added raw.githubusercontent.com.",
          "is_bot": false,
          "headline": "fix(ci): add sigstore endpoints to release workflow egress allow-list",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f612a78d32bc72fcc0958a9cb3fcf150666baa59",
          "body": "…149)\n\nDerive direct dependencies from the Cargo.lock graph: a local/workspace\ncrate (no source) has a dependencies array that lists exactly the crates\ndeclared in Cargo.toml. Those are direct; everything reachable only\ntransitively is indirect.\n\n- parse the source field from Cargo.lock\n- set Depend\n[…]\n and\n  record directCount/indirectCount metadata\n- report direct/indirect counts in analyze text output; per-package\n  classification is available via the Transitive flag in json/yaml\n\nCloses AUTO-824",
          "is_bot": false,
          "headline": "feat(rust): distinguish direct vs indirect dependencies in analyze (#…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-07T14:57:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d07c8e0ac9ae13366a5d5a2a8e47f6d9c2253685",
          "body": "Add raw.githubusercontent.com:443 to the harden-runner egress allow-list.\nThe cosign-installer v4.1.2 (bumped in #70) downloads its public key from\nthis host for signature verification, causing the release workflow to fail\nwith 'Could not resolve host: raw.githubusercontent.com'.\n\nRemove attacker.example.com:443, which was auto-captured from the\nStepSecurity baseline in #41 — it's a test fixture URL from go-tests\nthat was erroneously copied into the release workflow.",
          "is_bot": false,
          "headline": "fix(ci): fix release workflow egress allow-list for cosign installer",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T20:58:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90b4995839ae2038938284776bfca20bea79b569",
          "body": "What:\n\nWhen a language ecosystem has multiple potential build tools to choose\nfrom (java, python), standardize the metadata as `buildTool` and display\nit in the text output of `omnibump analyze` and `omnibump\nanalyze-remote`. The `language` should always show the ecosystem the package belongs to.\n\nWhy:\n\nIt's useful information to have, especially when developing CVE\nremediation features, to know if the correct build tool has been\nselected.",
          "is_bot": false,
          "headline": "chore(analyze): Add build tool to text output, if set (#146)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-06T19:53:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d383de5bb22b765dd48982c1cf16aa5a993228f",
          "body": null,
          "is_bot": false,
          "headline": "docs(ruby): add Ruby language documentation to README and usage examples",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T14:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "121127028a9dd7d6d76523cf5488f8f7214afcdf",
          "body": "…n (#141)\n\npinPrecise previously pinned name@version=precise targets unconditionally, even when the precise version was older than what's currently locked. Compare against SemVer and skip the pin with a warning instead.",
          "is_bot": false,
          "headline": "fix(rust): refuse to downgrade packages when pinning a precise versio…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-02T14:39:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3c72a509911ee71b976f169a1e243fc8e0e6f59",
          "body": "Add gem-dir overlay mode to the Ruby plugin, mirroring the Python --venv\npattern. When --gem-dir is specified, omnibump installs patched gems\ndirectly into an existing gem directory using gem install --install-dir,\nreplacing freeform runs: steps in melange YAML files.\n\nKey design decisions:\n- Valida\n[…]\nrsion comparison uses segment-by-segment numeric comparison matching\n  RubyGems Gem::Version behavior, with pre-release segment ordering\n- Same-version gems are skipped to avoid unnecessary reinstalls",
          "is_bot": false,
          "headline": "feat(ruby): add --gem-dir overlay mode for CVE remediation",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-01T21:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aed36f3f49b543f567dbfb080adfc7e50a64599d",
          "body": "…ons (#135)\n\n* feat(gradle): force managed pins on bundled non-classpath configurations\n\nomnibump's managed resolutionStrategy.force block only matched the compile\nand runtime classpaths — the configurations that normally ship. A fat-jar\nbuild can bundle an extra, custom-named configuration into the\n[…]\ned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): force managed pins on bundled non-classpath configurati…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-01T14:24:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e2d05055abe858afaffee5c8c73f3866bbb2840",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#131)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T21:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ba0fee429ffac6377a3d661a171ef3a2ee7959d",
          "body": "…y matches (#139)\n\nWhen a caller passes --replaces pkg=pkg@vX with no existing replace\ndirective in go.mod, resolveAndFilterPackages was silently dropping the\npackage because semver.Compare(currentVersion, resolvedVersion) == 0.\nThe version-equality skip exists to avoid no-op require updates, but a\n\n[…]\nFilterPackagesForTest helper with\na call to the real function, stubbing resolveListCommand via a new\nresolveListCommand variable (same pattern as commandContext) so no\nexternal go list calls are made.",
          "is_bot": false,
          "headline": "fix(golang): apply new replace directives when require version alread…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-06-30T21:26:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46a62a8a64c1a00099869ca3b3f860e3954b0a03",
          "body": "…xamples\n\nAdd Python to the supported languages table, features list, and quick start\nsection in README.md. Add comprehensive Python section to usage-examples.md\nwith 10 examples covering pyproject.toml, requirements.txt, setup.cfg,\nPipfile, inline updates, venv mode, build tool override, analyze, CVE\nremediation, and version resolution.\n\nCloses AUTO-429",
          "is_bot": false,
          "headline": "docs(python): add Python language documentation to README and usage e…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-30T20:56:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c894405758fb12f42f90c813047bbeff3d394f8e",
          "body": "…ategy (#138)\n\n* fix(rust): show upgrade-from version in analyze output and harden strategy\n\nWhat:\nFix `omnibump analyze` mislabeling existing Rust crates as \"(new)\" in the\nDirect Dependency Updates section, and make RecommendStrategy resolve the fix\nversion from the crates.io index without sacrific\n[…]\nindirect resolver).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rust): show upgrade-from version in analyze output and harden str…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-30T20:15:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d80b4920ef62715102b684eb6af39026126c3890",
          "body": "…ate (#133)\n\nDo a better job when we can't find an inline version to upgrade to\ncleanly. If the SemVer is incompatible and the crate can't be upgraded, `omnibump`\nshould fail. Otherwise, proceed with the upgrade.",
          "is_bot": false,
          "headline": "fix(rust): Fix issue where Rust is passing when it can't upgrade a cr…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-26T15:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5a60228c5b11049dbe952bca819e81ed52451e2",
          "body": "* fix(ci): set persist-credentials false on checkout steps\n\nEvery actions/checkout step now explicitly sets persist-credentials: false. None of the affected jobs perform git writes relying on the persisted GITHUB_TOKEN credential store: build, go-tests, and verify run read-only operations, and relea\n[…]\n be restored into the signed-release build and\ncontaminate published artifacts. Set cache: false so the release build pulls\nno PR-writable cache (zizmor cache-poisoning, release.yaml).\n\nRefs: PSEC-923",
          "is_bot": false,
          "headline": "fix(ci): GitHub Actions security hardening (#130)",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-06-26T06:37:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c4c4b6757c9440c76597350b656574eb6c596af",
          "body": "…rgeting (#129)\n\nWhat:\nTurn the `classifier` field on a Maven dependency pin into a three-way selector:\n- unset/empty: match every variant — the classifier-less dependency and all\n  classifier'd ones (a wildcard)\n- \"none\": match only the classifier-less dependency, leaving classifier'd\n  siblings un\n[…]\nrgets one classifier, and \"none\" targets only the classifier-less dependency.\n\nCloses https://linear.app/chainguard/issue/AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): match all classifier variants by default, with opt-in ta…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-23T13:58:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4671d3855b0419de3a0b1a84f2bb2fae1cb8584a",
          "body": "…ncy graph rather than taking it directly from the advisory. (#127)\n\n* feat(rust): upgrade reverse dependencies and support precise pins\n\nReplace the per-crate updatePackage loop with upgradeReverseDependencies,\nwhich routes Rust CVE remediation through cargo's own resolver. For a given\ntarget it di\n[…]\n Wrap the ambiguous-target error with a static ErrAmbiguousTarget sentinel\n  (err113), add scoped //nolint:gosec on the cargo subprocess calls (G204),\n  and reformat utils_test.go (gofmt/gci/gofumpt).",
          "is_bot": false,
          "headline": "feat(rust): resolves the fix version using the upstream Cargo depende…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T15:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6becebfe07904b314b432f4629ef1fc1e1b7bfd",
          "body": "Maven keys dependencyManagement by groupId:artifactId:type:classifier, but\nomnibump matched and wrote dependencies by groupId:artifactId only. As a\nresult a deps entry could not pin a classifier'd artifact (e.g. the native\nnetty transports netty-transport-native-kqueue:osx-x86_64 /\n-epoll:linux-x86_\n[…]\nement entry. Validate, the version-conflict dedup key,\nand the analyzer/precedence keys are all classifier-aware.\n\nCloses AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): support <classifier> in dependency bumping (#126)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:42:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0932d8c811d336fbcfd75615ee929af01d69604",
          "body": "…ings (#122)\n\n* feat(gradle): manage pins via settings block (constraints + substitution)\n\nRework Gradle transitive/coordinate pinning: emit dependency constraints\n(require) and dependencySubstitution rules in the root settings script via\ngradle.beforeProject, so they apply before any configuration \n[…]\n to match renderManagedBlock. No behavior change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gradle): pin versions via a before-resolution force block in sett…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:33:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd44e0e6c051b4dcde59f1b36653b6dfeeaf6de7",
          "body": "For unit tests added in PR #127, we'll need access to `static.crates.io`\nin order to run live `cargo update` and `cargo metadata` commands.",
          "is_bot": false,
          "headline": "chore(go-tests): Add static.crates.io to allowed-endpoints (#128)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T13:17:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c966108f19ae8f83603a0f24205af96ecbb61f0",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:46:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "345aa6242c02dc6e50d73321884bd41fe0aaa45e",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.36.1 to 0.36.2.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.36.1...v0.36.2)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#124)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9e7a1a845e5e704df6b1ab8c53976e1cde7c9db",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.45.0 to 0.46.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.45.0...v0.46.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.45.0 to 0.46.0 (#123)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:44:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0c98e344bea347d9ac2a1c3f39161a6cf4f0ebd",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#99)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4595705eee3281aba38cf20dc3ecbf623c45e948",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 (#113)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc1f53fe73aa0e9f3cb6a4e77e9a03ac76c04d3b",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.36.0 to 0.37.0.\n- [Commits](https://github.com/golang/mod/compare/v0.36.0...v0.37.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.37.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.36.0 to 0.37.0 (#114)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f1585bac858926556f8608a4a9f7a5ad9923c",
          "body": "analyze-remote returned almost no information for Gradle projects. The\nJava case always used the Maven analyzer with the aggregated Java\nmanifest set, so a Gradle repository's build files were XML-parsed and\ndiscarded, and GradleAnalyzer.AnalyzeRemote was an unimplemented stub.\n\nBuild the Gradle pro\n[…]\n and variables the same way local analyze does, and route\nJava repositories to the correct build tool with a paths-based detector\nso each tool searches only its own manifest patterns.\n\nCloses AUTO-728",
          "is_bot": false,
          "headline": "feat(gradle): support analyze-remote for Gradle projects (#119)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-17T20:16:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6be57d2ef600cd4c33e2ba7445aef7055d745ecb",
          "body": "Match the sentinel error value instead of its message string so the\ntest stays valid if the wording changes.",
          "is_bot": false,
          "headline": "test(rust): assert ErrCargoLockNotFound with errors.Is (#121)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T19:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0727b87dd4fb6cf0a620fddbeb8460b70dc45f86",
          "body": "If we run a `cargo update`, we need to re-read the `Cargo.lock` so we're\nnot working against a stale list of packages. This is a bug that leads\nto `omnibump` failures w/ `--update`\n\n- Refactors the code that reads `Cargo.lock` so that it's reusable\n- Re-read `Cargo.lock` post-update\n- Update test data to verify fix",
          "is_bot": false,
          "headline": "fix(rust): Re-read Cargo.lock after `cargo update` (#120)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T15:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6ac23996628e6ffaab83f40f75397a8ce16499a",
          "body": "Adds Gemfile.lock parsing, direct text-based version updates (no Bundler\nCLI dependency), analysis, and validation for Ruby projects.\n\n- ruby.go: Language interface (Detect, Update, Validate, --show-diff)\n- analyzer.go: Analyzer interface (Analyze, AnalyzeRemote, RecommendStrategy)\n- parser.go: Gemf\n[…]\n performed via direct Gemfile.lock text editing — no\nRuby/Bundler CLI required — matching the deployment model where omnibump\nruns in melange build sandboxes without guaranteed toolchain availability.",
          "is_bot": false,
          "headline": "feat: implement Ruby language plugin for omnibump",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-16T15:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81d611c45bbbad6aa428d8698fa113526336da1b",
          "body": "* feat(gradlefile): add Gradle file parsing and editing library\n\nWhat: introduce pkg/gradlefile, a self-contained parsing and editing\nlibrary for the Gradle files omnibump patches - the Gradle analog of\nthe gopom library Maven support builds on. Files parse into typed\nmodels with byte spans; edits a\n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): bring Gradle support to parity with Maven (#108)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-16T07:09:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5119b4d7af90c36ae79580e2e0f67be0a596f080",
          "body": "* fix(rust): Handle package names pinned to specific versions\n\nWith Cargo, you can depend on multiple versions of a crate by pinning\nthe version to the crate name, i.e., `rand@0.9.2` to only upgrade that\nversion of the crate.\n\nThese upgrades were silently failing because we were matching on the\nenti\n[…]\nstring (`rand@0.9.2`) instead of looking for the crate by\nname (`rand`) and then checking its version.\n\n* Move function call outside of loop\n\nThe `strings.Cut(...)` doesn't need to be inside the loop.",
          "is_bot": false,
          "headline": "fix(rust): Handle package names pinned to specific crate versions (#117)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-16T02:11:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "061adbd8174891cafe0c13b09f7e5f5579e3f15e",
          "body": "…rements-pinned.txt\n\nParseInlinePackages now handles Python's == separator (e.g. urllib3==2.7.0)\nbefore the JS single-= path. Venv mode no longer requires == prefix in the\nversion field. The --manifest flag is supported via resolveManifest which\nskips auto-detection when a path is provided. resolveLanguage no longer\nassumes Maven when --manifest is set. requirements-pinned.txt is recognized\nas a valid manifest filename.",
          "is_bot": false,
          "headline": "fix(python): support == version separator, --manifest flag, and requi…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-15T14:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6532afc0842b11afbf7c4e4969f002765ddd8a60",
          "body": "…s (#110)\n\n* fix(cli): merge file and inline inputs instead of dropping inline ones\n\nWhat: loadUpdateConfig now loads file inputs (--deps/--properties files)\nand inline inputs (--packages/--replaces/--props) and merges them,\ninstead of returning only the file inputs whenever a file flag is set.\nAdds\n[…]\nionally, and quoted error values survive empty or\nwhitespace strings legibly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): merge file and inline inputs instead of dropping inline one…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:45:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8b3f3de97c4b69350339c40cb68b76557d408c7",
          "body": "… requested ref (#109)\n\n* fix(analyze-remote): discover manifest files from the git tree at the requested ref\n\nWhat: GitHubFetcher.SearchFiles now sources candidate paths from\nListFilePaths (Git Tree API at the exact ref) and filters them by\nfilename, instead of querying the GitHub Code Search API. \n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyze-remote): discover manifest files from the git tree at the…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ef89d04c4ed980275fc2a0ef7e46f12d111c879",
          "body": "* AUTO-692: Add an explicit `update` flag\n\nAdd a distinct `--update` flag to `omnibump` to handle dependency\nupdates, to disambiguate between `--tidy`, which performs a\nfundamentally different task (version bumping versus correctness and\nhygiene).\n\n* fix(omnibump): Allow endpoint for index.crates.io\n\nAllow the `index.crates.io` endpoint so we can run/test `cargo update`.\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>",
          "is_bot": false,
          "headline": "AUTO-692: Add an explicit `update` flag (#111)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-11T15:38:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33e300d1d06704cacdc26007a7ac3e73a6ddc938",
          "body": null,
          "is_bot": false,
          "headline": "feat: parse optional-dependencies and PEP 735 dependency-groups",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdf429bd0fb9df00c24a31ecd82f1c1c635bedcb",
          "body": null,
          "is_bot": false,
          "headline": "feat: wire Python language plugin and CLI flags",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd814eda9c4d02ff957eeb750f31453667e6db05",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python venv mode with PEP 440 version ordering",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01497aba38c5788ac31c3ff30e460a40b0bcc029",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python manifest parsing, updating, and build tool detection",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6eb3afbb45e822d822873e1dcdae27dbd4d93dc",
          "body": "To avoid future code duplication as support for more build tools is\nadded, extract ValidatePathWithinRoot into a new pkg/utils package so\nthe logic lives in one place.\n\nErrUnsafePomPath in the maven package is kept as an alias for\nutils.ErrUnsafePath so existing errors.Is checks continue to work\nwithout any caller changes.\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(utils): centralise path boundary validation (#107)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T16:11:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "88567739ce5cabeb6867eb8e7bc4f3576cbb7dbe",
          "body": "…e CLI (#103)\n\n* feat(maven): implement AnalyzeRemote and wire Java into analyze-remote CLI\n\nWhat:\n- Implement MavenAnalyzer.AnalyzeRemote(ctx, files map[string][]byte) to analyse\n  pom.xml files fetched by the existing remote fetcher infrastructure. Parsing\n  uses xml.Unmarshal directly (gopom.Pars\n[…]\n-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): implement AnalyzeRemote and wire Java into analyze-remot…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T15:12:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98909521b34c0c4bb0351e787eabcce604c311bb",
          "body": "* test: add failing test for non-existent path in validatePathWithinRoot\n\n* fix: skip non-existent parent POM paths instead of crashing\n\nWhen a module POM declares a <parent> whose resolved path does not\nexist on disk (e.g. a corporate super-POM not present in the build\ntree), filepath.EvalSymlinks \n[…]\nhard failure instead of letting\nthe sibling-walk fallback run.\n\nCheck os.Stat before calling validatePathWithinRoot. A non-existent\nparent path means the chain ended, not that a boundary was violated.",
          "is_bot": false,
          "headline": "fix: skip non-existent parent POM paths instead of crashing (#106)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-09T07:56:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "460b52918e0fd3395a6e22db363bc1d9a3f8660b",
          "body": "* test: add failing test for sibling module property resolution\n\nAdd test case for property resolution across sibling Maven modules.\nUpdate error text expectations to match the new fallback behavior.\nThese tests will fail until the updater gains project-tree-walk support.\n\n* fix: fall back to projec\n[…]\nthe project tree via findProjectRoot + findMavenPoms for sibling\nmodules that define it. Preserves the root-boundary security invariant\nby surfacing ErrUnsafePomPath if the parent chain was cut short.",
          "is_bot": false,
          "headline": "fix: resolve Maven properties defined in sibling modules (#105)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-08T22:53:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a8464e863689c63e48cb1da7ac5aa2e02f3c630",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/7\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 (#98)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-08T14:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0647c91c9f8dd2652524e96ac56a40bb06f6bed",
          "body": "Signed-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(README): update information about contributions (#102)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-08T12:49:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a46e11d8bb64fda4a352cb9a0d5aa55c8f931877",
          "body": "Summary\nThe --show-diff flag was only implemented for Go. Rust, PHP, and JS all copied the flag into their internal config types but never read it — --show-diff was silently ignored.\n\nThis adds the same before/after snapshot + cmp.Diff pattern to all three:\n\nRust: diffs Cargo.lock before and after D\n[…]\n\nPHP: diffs all manifest files (from the detected build tool) before and after buildTool.Update\nFollows the existing Go implementation in pkg/languages/golang/updater.go.\n\n🤖 Generated with Claude Code",
          "is_bot": false,
          "headline": "feat: implement --show-diff for rust, php, and js languages (#100)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-05T18:22:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80250b9966017d3d99afd53ac79e3c8a44b9973d",
          "body": "…sal boundary (#97)\n\nMaven projects commonly declare version properties in a parent POM\nreferenced via <parent><relativePath>. Before this change the analyzer\nhad no concept of where a property came from, showing properties in\nparent POMs as '(new)' with a warning, even though the update command\nfou\n[…]\n shows [manifest: X] next to each property in Property\n  Usage and manifest: above each property update in the Strategy section.\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven/analyze): surface property source file and add path traver…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-04T15:51:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7aed66d7c1a7819aa297e1cc7df2db98305f748c",
          "body": "….0 (#55)\n\nBumps [step-security/action-actionlint](https://github.com/step-security/action-actionlint) from 1.69.1 to 1.72.0.\n- [Release notes](https://github.com/step-security/action-actionlint/releases)\n- [Commits](https://github.com/step-security/action-actionlint/compare/d364e70a116a460ed220d67b\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/action-actionlint from 1.69.1 to 1.72…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:19:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "685c4ab1725bf595f096c2e1447da83efccee295",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003...6f9f17788090df1f26\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#70)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:18:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b07df3d107a615da6c8cd5a60c2537403fa5a32a",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.35.0 to 0.36.0.\n- [Commits](https://github.com/golang/mod/compare/v0.35.0...v0.36.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.36.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.35.0 to 0.36.0 (#76)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12535b80743b591ac7366d37115b32c48a0cde7f",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.3 to 0.36.1.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.3...v0.36.1)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.3 to 0.36.1 (#77)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f06247b15ac31f1ea26291cdee4071ef45b875c",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.0.0 to 7.2.2.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...5daf1e\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.2 (#84)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fa4d3f1a18fbbc41ef95bc69102143ba1ffac84",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.3 to 0.5.6.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...5f14fd08f7cf1cb1609c1e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 (#86)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:15:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25bf7b196fae4d9ce2b3abacf2e09ac557f6d386",
          "body": "…#91)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.0 to 9.2.1.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/1e7e51e771db61008b38414a730f564565cf7c\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:14:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "386464b48dd197b8f5025368b4c0ebf82f969dd0",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.1 to 4.36.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/c\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.35.1 to 4.36.0 (#92)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af25208e6988be721a7e0150a6c7275615440563",
          "body": "…#93)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.0 to 2.19.4.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47e3ca2831bcf2e551771a632a8361f6edf9ab1e",
          "body": "…iling (#96)\n\nWhen a dependency version references \\${project.version}, omnibump was failing\nwith an error because it could not locate where the property is set. \\${project.version}\nis a Maven built-in that refers to the project's own <version> tag, not a\nconfigurable property, so the dependency cannot be bumped this way. Instead of\nerroring, log an informational message and continue.\n\nCloses https://linear.app/chainguard/issue/AUTO-655/",
          "is_bot": false,
          "headline": "fix(maven): skip dependencies using \\${project.version} instead of fa…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-03T13:12:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfbb6e3ef25e95a0b153c54c5c4f234414e2c082",
          "body": "* feat: Wire up support for tidy-compat\n\nAdd and wire up the `--tidy-compat` flag.\n\n* chore(tests): Add Unit + Integration tests, plus supporting changes\n\nThe biggest change here is to use an interface to call\n`exec.CommandContext` in `runner.go`, so that the call can be mocked by\nthe new unit test.\n\nAlso adds an integration test, w/ test go project, to verify Go is doing\nwhat we expect it to.",
          "is_bot": false,
          "headline": "feat: add go tidy compat support to omnibump (#95)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-01T14:39:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88629f453e84633fecb6bfbb57a23f88223b1442",
          "body": "omnibump doesn't support JS right now. There's no pipeline in `melange`\nfor bumping JS dependencies either. This means that JS users have to\nmanually update their package.json with error-prone scripts or direct\ncalls to the package managers.\n\nHere we add `js` as a first-class language. JS is detecte\n[…]\nually specifying, a list may be given, for cases when there is more\nthan one manager involved (e.g. in a migration).\n\nThe updater tries to make minimal edits: to preserve existing keys and\nformatting.",
          "is_bot": false,
          "headline": "feat(js): add JavaScript language support (#72)",
          "author_name": "Iain Lane",
          "author_login": "iainlane",
          "committed_at": "2026-06-01T12:45:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbbf87765dda27715b80bee46e3e72c3cfa3773a",
          "body": "* fix(maven): update properties in the POM that defines them\n\nWhat:\n- Resolve Maven property updates to the POM where the property is declared.\n- Check the current POM first, then the direct parent POM, including parent relativePath values that point to a directory.\n- Route dependency patches that u\n[…]\neira@chainguard.dev>\n\n* fix(maven): add mavenLanguageName const\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "fix(maven): resolve property updates from parent POMs (#90)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-01T07:39:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2bee3b7985626d4dd62a0353a08c41f72007f25f",
          "body": "… manifests (#87)\n\nDetectLanguage iterates a Go map, so when multiple languages match the\nsame directory, which one wins depends on map iteration order — which is\nrandomized per-process in Go. This is currently masked for omnibump's own\nrepo by PR #79 (testdata skip), but any project where two langu\n[…]\ninel error.\n\nBoth callers (analyze.go, root.go) now handle the case where\nDetectLanguage returns a valid language name alongside a warning error,\nlogging the ambiguity instead of treating it as fatal.",
          "is_bot": false,
          "headline": "fix: make language auto-detection deterministic and prefer root-level…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-05-26T17:13:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26ff3a82dc3a052c6fd8b8678059d25d321c010d",
          "body": "…t (#82)\n\nWhat: walkXMLFiles now guards the isSkippableDirectory check with\npath != rootDir, ensuring the root of each walk is never filtered out\nregardless of its directory name. Adds regression tests for\nwalkXMLFiles, Detect(), and Analyze() covering projects rooted in\ndirectories named build, tar\n[…]\nvenPom fast-path\nbut Analyze() — which always calls analyzeAllPoms then walkXMLFiles —\nreturned ErrNoPOMsFound for every file in the project.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): do not skip walk root when its name matches skip lis…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T18:54:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6c07db24d92534d167d4ff8c69dbd2dafd668faa",
          "body": "* feat(maven): auto-resolve property refs when patching deps\n\nWhen a dependency's version is a Maven property reference (e.g.\n${log4j2.version}), omnibump now automatically updates the backing\nproperty to the target version instead of warning and skipping the\npatch entirely. If the caller already su\n[…]\n https://linear.app/chainguard/issue/AUTO-628\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): auto-resolve property references when patching deps (#80)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T12:13:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25c832f3051c8fc5ca29f417907888900c630c68",
          "body": "…ction (#79)\n\nWhat: isSkippableDirectory now includes \"testdata\", \"vendor\", and \"test\",\npreventing hasMavenPom() from scanning those directories during recursive\nPOM detection. Adds TestMavenDetect_SkippedDirectories to assert that a\nvalid pom.xml inside any skipped directory does not trigger Maven \n[…]\n, causing omnibump to fail with\n\"pom.xml not found\" on a valid Go project.\n\nCloses https://linear.app/chainguard/issue/AUTO-619/\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): skip testdata, vendor, and test dirs during POM dete…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-18T13:55:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1251778a4cfe240f21512e0efea7bdff97eb7fb8",
          "body": "…om.xml (#73)\n\nMaven.Detect() now falls back to a recursive directory scan when no root\npom.xml is found, allowing projects like Apache Cassandra (Ant-based, with\nPOMs under .build/) to be identified as Maven projects automatically.\n\nMavenAnalyzer.Analyze() now always delegates to analyzeAllPoms() w\n[…]\ntory, findMavenPoms,\nMaven.Detect() recursive cases, and MavenAnalyzer.Analyze() multi-POM\naggregation (702 total, all passing).\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(java/maven): recursive POM discovery for projects without root p…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-14T13:55:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ba57225cb9f650ec31922a22cee980fbc287597",
          "body": "When fetchFromProxy receives a 404, it now returns ErrModuleVersionNotFound\nrather than ErrProxyRequestFailed. This lets callers use errors.Is to detect\nthat a version simply does not exist on the proxy, as opposed to a transient\nnetwork failure, without changing omnibump update behavior (DetectCoUpdates\ncontinues to warn and continue on any CheckTransitiveRequirements error).",
          "is_bot": false,
          "headline": "fix(golang): distinguish proxy 404 as ErrModuleVersionNotFound (#71)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-07T17:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "106c534838a3ebefe590d279d35aff57f1df3b49",
          "body": "* feat(java/maven): content-based Maven POM detection via IsMavenPom\n\nReplace filename-only detection with XML parsing:\n- Add IsMavenPom() that parses XML and validates the root element is\n  <project> with namespace http://maven.apache.org/POM/4.0.0\n- Thread manifestFile through Language.Detect() an\n[…]\na.go to flatten nested blocks (nestif)\n- Split manifest pre-detection and directory detection into separate if blocks (nestif)\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "feat(java/maven): content-based Maven POM detection via IsMavenPom (#67)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-07T17:09:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3a3e57595be7bf57eebd2eae55f1b0eb2a636e",
          "body": "Some Maven projects use a non-standard manifest filename. Add a\n--manifest flag that lets callers specify the exact path to the\nmanifest file to update, falling back to <dir>/pom.xml when unset.\n\nResolves SUS-596",
          "is_bot": false,
          "headline": "feat(java/maven): add --manifest flag for custom pom.xml path (#66)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-06T13:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d4886c89991ebe81860ff7fc4bbd64fe5a020df",
          "body": "…rom being co-updated (#65)\n\n* fix(golang): prevent independent golang.org/x and gopkg.in packages from being co-updated\n\nTwo layered fixes for the golang.org/x/* family bug where bumping\ngolang.org/x/net pulled every other golang.org/x/* package as a co-update\nat the same target version, causing un\n[…]\n cases and trim verbose comment\n\n* fix: address golangci-lint findings\n\nFlatten else-if to remove extra nesting (nestif complexity 5→3).\nAcknowledge fmt.Fprint return value in test handler (errcheck).",
          "is_bot": false,
          "headline": "fix(golang): prevent independent golang.org/x and gopkg.in packages f…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-05T22:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3186cf086064973ca214cedf67ea6886d8601d2",
          "body": "Both functions are needed by callers (e.g. cve-remediation bot) that want\nto perform pre-creation viability checks without reimplementing the\ndetection logic:\n\n- DetectCoUpdates: runs the full co-update analysis against a go.mod,\n  returning required missing deps and API compat alerts with recommend\n[…]\nd\n  minimum compatible versions.\n- FindMinCompatibleVersion: finds the lowest version of a package above\n  its current version whose go.mod requires a given dependency at or\n  above a minimum version.",
          "is_bot": false,
          "headline": "feat(golang): export DetectCoUpdates and FindMinCompatibleVersion (#64)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:44:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5392beefc43b0aca18747fa1decd47a43a8ecdc9",
          "body": "…set (#63)\n\n* feat(golang): reduce required co-package updates to minimal necessary set\n\n- Filter CheckTransitiveRequirements to only flag direct project deps;\n  indirect deps are resolved automatically by Go's MVS and cannot cause\n  API breakage in the project's own code\n- Add FindVersionGroupPacka\n[…]\nanch where it is used\n- Remove duplicate familyRoot argument from log message\n- Use distinct Reason string for cross-major packages so it doesn't\n  incorrectly say 'both at X' when the versions differ",
          "is_bot": false,
          "headline": "fix(golang): reduce required co-package updates to minimal necessary …",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:16:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96a8f2ef03e7758ea4738fa3354c89a074d2bc8f",
          "body": "…ts (#60)\n\n* fix(golang): warn instead of error on transitive co-update requirements\n\n* fix(lint): remove unused nolint directives and convert checkMissingTransitiveDeps to void\n\n* fix(security): resolve gosec G703/G704/prealloc lint findings\n\n* fix(security): construct proxy URL from struct fields to eliminate G704 taint path\n\n* fix(security): parse proxy path through url.Parse to break G704 taint chain",
          "is_bot": false,
          "headline": "fix(golang): warn instead of error on transitive co-update requiremen…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-22T18:25:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d6ae7c44329db2040d15feba2897e5d7c6df186",
          "body": "…#59)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.18.0 to 2.19.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/6c3c2f2c1c457b00c10c4848d6f5491db3b629df...8\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.18.0 to 2.19.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe28291046b7208e29b7f20821eec2f551d94905",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.2 to 0.5.3.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f3159\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 (#52)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:20:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6e703f2374cf01e5bdd2ce46e57766956a8971b",
          "body": "…#56)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.18.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/v2.16.0...6c3c2f2c1c457b00c10c4848d6f5491db3\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.18.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T00:17:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3a25bae26d8699e66e5b5efdf93966101ab87a1",
          "body": "…y (#57)\n\n* fix(golang): dedup suggested command packages and reduce log verbosity\n\nFixes a bug where the same package appeared twice in the suggested update\ncommand when it existed in both the filtered update set and the transitive\nco-update requirements at different versions. The command builder n\n[…]\nedundant internal-step messages\n(go get, AddRequire, replace) and downgrading per-package skip and analysis\nlogs to Debug level.\n\n* fix(golang): use map[string]struct{} for set type and fix formatting",
          "is_bot": false,
          "headline": "fix(golang): dedup suggested command packages and reduce log verbosit…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-21T19:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29c353c59acecb4db901f884def22ecea3dab834",
          "body": "* fix: handle +incompatible versions and vendor go.sum updates\n\nFixes issues where packages with +incompatible suffix were not resolved correctly,\nand vendor directories failed due to missing go.sum entries.\n\n- Resolve all semantic versions through go list to get canonical forms\n- Handles +incompati\n[…]\nline in indirect_resolver_test.go\n\n* fix: use go 1.25 in test go.mod fixtures\n\n* fix: restore go 1.26 in downgrade test fixture\n\n* fix: extract resolvePackageVersion helper to reduce nestif complexity",
          "is_bot": false,
          "headline": "feat: detect transitive dependency requirements  (#26)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-15T16:46:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c0b14475020d8a3642e6cb83e74c141ce236705",
          "body": "* feat: add PHP language support with Composer build tool\n\nRestructure to match Java pattern where PHP is the language and Composer\nis a build tool underneath it. This allows for future addition of other\nPHP build tools.\n\n- Add pkg/languages/php/ with language detection and build tool interface\n- Ad\n[…]\n package-level documentation\nand Example functions demonstrating the public API for both the\nphp and composer packages.\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add PHP language support with Composer build tool (#50)",
          "author_name": "Thomas Bechtold",
          "author_login": "toabctl",
          "committed_at": "2026-04-14T14:03:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c9785986745c30cb047b291351d72c7e5974c4a",
          "body": "…] (#47)\n\nSigned-off-by: Steve Beattie <steve.beattie@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(workflows): add actionlint and zizmor action linters [SECINT-75…",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-04-07T12:28:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c1997b9c829e3e100ab5ffe81018ea1fab3bbec",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.2 to 0.35.3.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.2...v0.35.3)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.35.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.2 to 0.35.3 (#35)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf8678c0e978cd7a3a166978600c6c8d6870510a",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.0 to 4.1.1.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/ba7bc0a3fef59531c69a25acd34668d6d3fe6f22...cad07c2e89fa2edd6e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 (#39)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ffeb5a6e760f3f3fdbfcd3eca68c9f61e9fa0f1",
          "body": "Bumps [sigs.k8s.io/release-utils](https://github.com/kubernetes-sigs/release-utils) from 0.12.3 to 0.12.4.\n- [Release notes](https://github.com/kubernetes-sigs/release-utils/releases)\n- [Commits](https://github.com/kubernetes-sigs/release-utils/compare/v0.12.3...v0.12.4)\n\n---\nupdated-dependencies:\n-\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigs.k8s.io/release-utils from 0.12.3 to 0.12.4 (#43)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e97c6510110dc859501de949a5a2ed578e76a3",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.32.6 to 4.35.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/0\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.32.6 to 4.35.1 (#45)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a2bd14d17fff9dd99838f4bcb6307439bb6713",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.3.0 to 6.4.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c)\n\n---\nupdated\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#46)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f22d33724321a115f747691421590076327c5d1a",
          "body": "…#44)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.16.1.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594...f\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.16.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:30:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f3487913b86ce427152d1c7eef3819b9a4139d0",
          "body": "…oring (#42)\n\n* fix(golang): warn and skip packages superseded by major version upgrades after tidy\n\nWhen go mod tidy runs after updating a batch of dependencies, packages\nthat migrated to a new major version path (e.g. containerd/v2 replacing\ncontainerd) are legitimately removed from go.mod. Previo\n[…]\nire passes into separate helper functions to reduce\nDoUpdate complexity from 36 to acceptable levels. Remove unused ctx parameter\nfrom addRequirePackage function to satisfy revive and unparam linters.",
          "is_bot": false,
          "headline": "fix(golang): warn and skip missing packages after tidy instead of err…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-01T21:57:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 42,
      "commits_last_year": 133,
      "latest_release_at": "2026-07-27T00:21:30Z",
      "latest_release_tag": "v0.23.1",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 3.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chainguard-dev/omnibump",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chainguard-dev/omnibump",
          "is_deprecated": false,
          "latest_version": "v0.23.1",
          "repository_url": "https://github.com/chainguard-dev/omnibump",
          "versions_count": 51,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-24T08:13:59Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 10,
      "stars": 13,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-05",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-25",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-07-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 10,
        "total_forks": 10
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
        "pkg/languages/golang/testdata/bye/go.mod",
        "pkg/languages/golang/testdata/confd/go.mod",
        "pkg/languages/golang/testdata/hello/go.mod",
        "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
        "pkg/languages/golang/testdata/tidy-compat/go.mod",
        "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
        "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
        "testdata/maven-simple/pom.xml"
      ],
      "largest_source_bytes": 88710,
      "source_files_sampled": 157,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 13
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 50,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/aquasecurity/go-pep440-version",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.1"
        },
        {
          "name": "github.com/chainguard-dev/clog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        },
        {
          "name": "github.com/chainguard-dev/gopom",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250828200639-b1a78ac4b263"
        },
        {
          "name": "github.com/charmbracelet/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ghodss/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/v75",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v75.0.0"
        },
        {
          "name": "github.com/samber/lo",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tidwall/gjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.0"
        },
        {
          "name": "github.com/tidwall/sjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.5"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231006140011-7918f672742d"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.38.0"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.48.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "sigs.k8s.io/release-utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.4"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aquasecurity/go-pep440-version",
            "direct": true,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/clog",
            "direct": true,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/gopom",
            "direct": true,
            "version": "v0.0.0-20250828200639-b1a78ac4b263",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/log",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ghodss/yaml",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v75",
            "direct": true,
            "version": "v75.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/samber/lo",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/gjson",
            "direct": true,
            "version": "v1.19.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/sjson",
            "direct": true,
            "version": "v1.2.5",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20231006140011-7918f672742d",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": true,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": true,
            "version": "v0.48.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/release-utils",
            "direct": true,
            "version": "v0.12.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquasecurity/go-version",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.2.3-0.20250311203215-f60798e515dc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13-0.20250311204145-2c3ea96c31dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/common-nighthawk/go-figure",
            "direct": false,
            "version": "v0.0.0-20210622060536-734e95fb86be",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logfmt/logfmt",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kr/text",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/match",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/pretty",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools/go/packages/packagestest",
            "direct": false,
            "version": "v0.1.1-deprecated",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20231012003039-104605ab7028",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/check.v1",
            "direct": false,
            "version": "v1.0.0-20180628173108-788fd7840127",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 50,
        "direct_count": 18,
        "indirect_count": 32
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 129,
        "open_issues": 3,
        "closed_ratio": 0.4,
        "closed_issues": 2,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "kbsteere",
          "commits": 27,
          "avatar_url": "https://avatars.githubusercontent.com/u/13925027?v=4"
        },
        {
          "type": "User",
          "login": "dnegreira",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/5215383?v=4"
        },
        {
          "type": "User",
          "login": "AdamIsrael",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/125008?v=4"
        },
        {
          "type": "User",
          "login": "justinvreeland",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/3758821?v=4"
        },
        {
          "type": "User",
          "login": "stevebeattie",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/1686002?v=4"
        },
        {
          "type": "User",
          "login": "iainlane",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/321014?v=4"
        },
        {
          "type": "User",
          "login": "toabctl",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/276317?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.31
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "actionlint.yaml",
        "build.yaml",
        "codeql.yaml",
        "go-tests.yaml",
        "release.yaml",
        "verify.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "composer.lock",
        "go.sum",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "3 out of the last 3 releases have a total of 3 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "152 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
        "ran_at": "2026-07-28T03:30:54Z",
        "aggregate_score": 8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T00:21:36Z",
      "oldest_open_prs": [
        {
          "number": 151,
          "created_at": "2026-07-07T16:03:50Z",
          "last_comment_at": "2026-07-22T15:36:22Z",
          "last_comment_author": "kbsteere"
        },
        {
          "number": 165,
          "created_at": "2026-07-23T14:25:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 167,
          "created_at": "2026-07-23T14:25:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 169,
          "created_at": "2026-07-23T14:27:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T08:14:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 112,
          "created_at": "2026-06-11T08:51:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 118,
          "created_at": "2026-06-16T07:33:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 134,
          "created_at": "2026-06-28T15:02:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chainguard-dev/omnibump",
    "host": "github.com",
    "name": "omnibump",
    "owner": "chainguard-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 73,
      "inputs": {
        "security": 84,
        "vitality": 88,
        "community": 38,
        "governance": 71,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 133,
              "human_commit_share": 0.67,
              "days_since_last_push": 1,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "133 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 133
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 42,
              "latest_release_tag": "v0.23.1",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 3.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "42 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 42
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 38,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 27,
            "inputs": {
              "forks": 10,
              "stars": 13,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "10 forks",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 71,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 7,
              "top_contributor_share": 0.31
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 31% of commits",
                "points": 15.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 31
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 129,
              "open_issues": 3,
              "closed_issues": 2,
              "issue_closed_ratio": 0.4,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "129/160 decided PRs merged",
                "points": 30.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 129,
                      "decided": 160
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "followers": 844,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chainguard-dev",
              "public_repos": 116,
              "account_age_days": 1839
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "844 followers of chainguard-dev",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 844,
                      "login": "chainguard-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "116 public repos, account ~5 yr old",
                "points": 23.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 116
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/chainguard-dev/omnibump"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "51 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "cargo",
                "go",
                "gradle",
                "maven"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 84,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "152 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 50 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 50
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 50,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 50,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 79,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 67,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "composer.lock",
                "go.sum",
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.19,
              "toolchain_manifests": [
                "go.mod",
                "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
                "pkg/languages/golang/testdata/bye/go.mod",
                "pkg/languages/golang/testdata/confd/go.mod",
                "pkg/languages/golang/testdata/hello/go.mod",
                "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
                "pkg/languages/golang/testdata/tidy-compat/go.mod",
                "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
                "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
                "testdata/maven-simple/pom.xml"
              ],
              "dependency_bot_commit_share": 0.33
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "19 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 19,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "33 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 33,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 88710,
              "source_files_sampled": 157,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/157 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 157,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T03:31:20.595249Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chainguard-dev/omnibump.svg",
  "full_name": "chainguard-dev/omnibump",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.