Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 15:00 UTC

composer / package-versions-deprecated

:package: Composer addon to efficiently get installed packages' version numbers

PHPMIT★ 1.524 Sterne⑂ 8 Forksseit Apr. 2020archiviertForkAuf GitHub ansehen ↗

composer/package-versions-deprecated erreicht einen Gesundheitsindex von 15 von 100 und liegt damit im Bereich Kritisch. Am stärksten schneidet es bei Sustainability & Governance (61/100) ab, am schwächsten bei Engineering Quality (15/100). Das Repository ist archiviert, weitere Wartung ist daher nicht zu erwarten.

15
gesamt / 100
Kritisch

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

15
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Abandonment Policy applies a 40% multiplier to weighted overall health and gives it a ceiling of 29.

Eigentümerschaft

ComposerOrganisation
577 Follower21 öffentliche Reposseit Juni 2011

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Packagistcomposer/package-versions-deprecated⚠ veraltet1.11.99.51.835.56511vor 1653 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

21Kritisch · 22 % des Gesamtindex
Wie die Bewertung erfolgt
0/36Push-Aktualität — letzter Push vor 1.653 Tagen
0/36Commit-Rhythmus — 0/52 Wochen mit Commits
0/18Commit-Volumen — 0 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project is archived
Verwendete Eingangsdaten
commits_last_year0
human_commit_share1
days_since_last_push1.653
active_weeks_last_year0
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 10 Releases veröffentlicht
0/36Release-Aktualität — letztes Release vor 1.653 Tagen
19.8/27Release-Rhythmus — ein Release etwa alle 64,1 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count10
latest_release_tag1.11.99.5
releases_from_tagsnein
days_since_latest_release1.653
mean_days_between_releases64,1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

56Mittel · 18 % des Gesamtindex
Wie die Bewertung erfolgt
51.6/60Stars — 1.524 Stars
7/25Forks — 8 Forks
0/15Watcher — 2 Watcher
Verwendete Eingangsdaten
forks8
stars1.524
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
0/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmenein
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
80/80Downloads pro Monat — 1.835.565 Downloads/Monat über packagist
15.8/20Abhängige in der Registry — 234 Pakete hängen davon ab
Verwendete Eingangsdaten
packagescomposer/package-versions-deprecated
dependents234
ecosystemspackagist
total_downloads198.229.208
monthly_downloads1.835.565

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

61Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
7.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 66 % der Commits
13.5/13.5Breite der Beitragenden — 25 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 34 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled25
top_contributor_share0,661
Wie die Bewertung erfolgt
44.3/46.8Issue-Lösungsquote — 95 % der Issues geschlossen
32.4/38.3PR-Annahme — 11/13 entschiedene PRs gemergt
9/15OpenSSF Scorecard: Code-Review — Found 11/18 approved changesets -- score normalized to 6
Verwendete Eingangsdaten
merged_prs11
open_issues1
closed_issues18
issue_closed_ratio0,947
closed_unmerged_prs2
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
19.9/25Reichweite des Inhabers — 577 Follower von composer
21.8/25Kontohistorie — 21 öffentliche Repos, Kontoalter ca. 15 Jahre
Verwendete Eingangsdaten
followers577
owner_typeOrganization
is_verified
owner_logincomposer
public_repos21
account_age_days5.529

Paketpflege

49Gefährdet
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf packagist
4/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 1.653 Tagen
20/20Versionshistorie — 11 veröffentlichte Versionen
0/20Nicht veraltet — composer/package-versions-deprecated: in der Registry als veraltet/zurückgezogen markiert
Verwendete Eingangsdaten
packagescomposer/package-versions-deprecated
ecosystemspackagist
any_deprecatedja
min_days_since_publish1.653

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

15Kritisch · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 11 merged PRs checked by a CI test -- score normalized to 0
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

1Kritisch
Wie die Bewertung erfolgt
0/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
0/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepage
has_readmenein
has_docs_dirnein
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

34Gefährdet · 16 % des Gesamtindex

Sicherheitslage

34Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 11 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
4.5/7.5Code-Review — Found 11/18 approved changesets -- score normalized to 6
2.5/2.5Contributors — project has 34 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project is archived
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
1.5/7.5Vulnerabilities — 8 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate3,4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

35Gefährdet · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
22.9/40Lesbare Commit-Historie — 43 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,43
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
10/10Reproduzierbare Umgebung — lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilescomposer.lock
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — PHP ohne Typprüfungs-Konfiguration
55/55Handhabbare Dateigrößen — 0/9 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePHP
largest_source_bytes43.941
source_files_sampled9
oversized_source_files0

Eckdaten

1.524GitHub-Sterne
25Mitwirkende
0Commits, letzte 12 Monate
1.653Tage seit letztem Push
10Releases
1Bus-Faktor
1offene Issues
PackagistPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Community profile unavailable

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 8 ⇿
0Sterne
8Forks
8Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

02468822020-062021-012021-09
Major 0Minor 0Patch 4

Jeder Punkt umfasst 2 Tage.

OpenSSF Scorecard 3.4 / 10
3.4Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 15:00 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 11 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
6Code-ReviewFound 11/18 approved changesets -- score normalized to 6
10Contributorsproject has 34 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject is archived
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
2Vulnerabilities8 existing vulnerabilities detected
Alle Abhängigkeiten 0

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 0 direkte und 0 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Abhängigkeits-Advisories nicht bewertet

Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies to assess

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 304,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "PHP": 78161
      },
      "pushed_at": "2022-01-17T14:15:51Z",
      "created_at": "2020-04-02T13:12:22Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T16:02:00Z",
      "description": " :package: Composer addon to efficiently get installed packages' version numbers",
      "is_archived": true,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://getcomposer.org/",
      "name": "Composer",
      "type": "Organization",
      "login": "composer",
      "company": null,
      "location": "Germany",
      "followers": 577,
      "avatar_url": "https://avatars.githubusercontent.com/u/837015?v=4",
      "created_at": "2011-06-08T08:38:20Z",
      "is_verified": null,
      "public_repos": 21,
      "account_age_days": 5529
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "1.11.99.5",
          "kind": "other",
          "published_at": "2022-01-17T14:15:51Z"
        },
        {
          "tag": "1.11.99.4",
          "kind": "other",
          "published_at": "2021-09-13T08:42:56Z"
        },
        {
          "tag": "1.11.99.3",
          "kind": "other",
          "published_at": "2021-08-25T08:07:53Z"
        },
        {
          "tag": "1.11.99.2",
          "kind": "other",
          "published_at": "2021-05-24T07:47:52Z"
        },
        {
          "tag": "1.11.99.1",
          "kind": "other",
          "published_at": "2020-11-11T10:28:44Z"
        },
        {
          "tag": "1.11.99",
          "kind": "patch",
          "published_at": "2020-08-25T05:54:51Z"
        },
        {
          "tag": "1.10.99.1",
          "kind": "other",
          "published_at": "2020-08-13T13:00:05Z"
        },
        {
          "tag": "1.10.99",
          "kind": "patch",
          "published_at": "2020-07-15T08:40:28Z"
        },
        {
          "tag": "1.8.2",
          "kind": "patch",
          "published_at": "2020-07-10T14:13:32Z"
        },
        {
          "tag": "1.8.1",
          "kind": "patch",
          "published_at": "2020-06-19T08:00:52Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "b4f54f74ef3453349c24a845d22392cd31e65f1d",
          "body": "Add the deprecated annotation in the stub class",
          "is_bot": false,
          "headline": "Merge pull request #33 from stof/patch-1",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2022-01-17T14:14:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "054d0dcb32af11188fddd5c0eef1c1c4ecb0809c",
          "body": "This ensures that the class is properly marked as deprecated even when the plugin has not replaced it with the generated one.",
          "is_bot": false,
          "headline": "Add the deprecated annotation in the stub class",
          "author_name": "Christophe Coevoet",
          "author_login": "stof",
          "committed_at": "2022-01-14T16:09:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1927b0a81e48643ca45c4a55b34a7645b04f3acc",
          "body": null,
          "is_bot": false,
          "headline": "Update readme, fixes #31",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2021-09-16T13:11:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b174585d1fe49ceed21928a945138948cb394600",
          "body": "Fix composer v1 ClassLoader getRegisteredLoaders method missing",
          "is_bot": false,
          "headline": "Merge pull request #29 from dejwCake/fix-c1",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2021-09-13T08:41:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "192176aed8ac633f6103ea829c57c285d35e0a48",
          "body": null,
          "is_bot": false,
          "headline": "Add compare also to installer",
          "author_name": "David Běhal",
          "author_login": "dejwCake",
          "committed_at": "2021-09-08T08:34:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a51c590affb1a294697eb16eef97667e325f6304",
          "body": null,
          "is_bot": false,
          "headline": "Fix composer v1 ClassLoader getRegisteredLoaders method missing",
          "author_name": "David Běhal",
          "author_login": "dejwCake",
          "committed_at": "2021-09-07T13:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fff576ac850c045158a250e7e27666e146e78d18",
          "body": "…n vendor but project was installed with Composer 1, fixes #27",
          "is_bot": false,
          "headline": "Fix more deprecations warnings and fix edge case when Composer 2 is i…",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2021-08-17T13:49:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6522afe5540d5fc46675043d3ed5a45a740b27c",
          "body": "Avoid calling deprecated getRawData()",
          "is_bot": false,
          "headline": "Merge pull request #25 from derrabus/bugfix/composer-deprecated",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2021-05-24T07:46:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07fa61fa7947f6526e0ee0149f40bcaadb7521fe",
          "body": null,
          "is_bot": false,
          "headline": "Avoid calling deprecated getRawData()",
          "author_name": "Alexander M. Turek",
          "author_login": "derrabus",
          "committed_at": "2021-05-23T12:27:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f921205948ab93bb19f86327c793a81edb62f236",
          "body": "Update .gitattributes",
          "is_bot": false,
          "headline": "Merge pull request #22 from reedy/patch-2",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-12-27T20:11:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ca35a1492f0946c89087b444ee9222fc14a9adc",
          "body": null,
          "is_bot": false,
          "headline": "Update .gitattributes",
          "author_name": "Sam Reed",
          "author_login": "reedy",
          "committed_at": "2020-12-23T03:11:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64291c788b9a18272346decf566931e33a317399",
          "body": "Fix class name in readme",
          "is_bot": false,
          "headline": "Merge pull request #19 from gharlan/patch-1",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-11-12T09:39:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65589e82ea7f29318f9fbaaf8b455c28013f732d",
          "body": null,
          "is_bot": false,
          "headline": "Fix class name in readme",
          "author_name": "Gregor Harlan",
          "author_login": "gharlan",
          "committed_at": "2020-11-11T22:22:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7413f0b55a051e89485c5cb9f765fe24bb02a7b6",
          "body": "… to --no-dev, fixes #17",
          "is_bot": false,
          "headline": "Avoid listing packages in PackageVersions which are not installed due…",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-11-11T10:22:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8c9aa8a14cc3d3bec86d0a8c3fa52ea79936855",
          "body": "Sync with v1.11.0",
          "is_bot": false,
          "headline": "Merge pull request #9 from nicolas-grekas/sync-upstream",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-08-25T05:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3969dabc7c5b603902b919dd0c4c07178a8f9bf7",
          "body": null,
          "is_bot": false,
          "headline": "Sync with v1.11.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2020-08-24T14:01:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68c9b502036e820c33445ff4d174327f6bb87486",
          "body": "This reverts commit b89d5b10392fa9feef750cf3e860778ac2150828.",
          "is_bot": false,
          "headline": "Revert \"Add php 8 build\"",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-08-13T12:55:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b89d5b10392fa9feef750cf3e860778ac2150828",
          "body": null,
          "is_bot": false,
          "headline": "Add php 8 build",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-08-13T09:28:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d338f7a9cc051bc8651c5896d496c40dc08b5ad",
          "body": null,
          "is_bot": false,
          "headline": "Allow install on php8",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-08-13T09:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd51b4443d58b34b6d9344cf4c288e621c9a826f",
          "body": "Sync with v1.10 of upstream package",
          "is_bot": false,
          "headline": "Merge pull request #6 from nicolas-grekas/sync-upstream",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-07-15T08:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1778079f392a5127fd50b462384a05ce1ea6397c",
          "body": null,
          "is_bot": false,
          "headline": "Sync with v1.10 of upstream package",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2020-07-13T08:57:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a8001fe2c9befad9d001bf54ef0b4a17d950d0f",
          "body": "Replace runtime warning by docblock annotation",
          "is_bot": false,
          "headline": "Merge pull request #5 from nicolas-grekas/deprec-annot",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-07-10T14:10:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53232fc52a0f18baae4cfdeafbbac6f68b83d4f5",
          "body": null,
          "is_bot": false,
          "headline": "Replace runtime warning by docblock annotation",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2020-07-08T14:14:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9805885293f3957ee0dd42616ac6915c4ac9a4b",
          "body": "Narrow range in \"replace\" section of composer.json",
          "is_bot": false,
          "headline": "Merge pull request #3 from nicolas-grekas/patch-1",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-06-19T07:59:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a0de2bfa7bec74377b82672cdba6821ba62f0f1",
          "body": "Fix unhelpful exception message",
          "is_bot": false,
          "headline": "Merge pull request #2 from alcaeus/fix-exception-message",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-06-19T07:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84477b21cb12991430562f4a65a1c4ad127cc847",
          "body": "Fix markdown and link parsing in README.md",
          "is_bot": false,
          "headline": "Merge pull request #1 from Jean85/patch-1",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-06-19T07:54:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97f2c999fb7398ae25755ec63fe092521f0b0b7b",
          "body": null,
          "is_bot": false,
          "headline": "Narrow range in \"replace\" section of composer.json",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2020-06-18T10:57:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d03d815b2f4204f7f31cb7ef6b59c2a9ec2c8e8",
          "body": null,
          "is_bot": false,
          "headline": "Fix readme",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-06-17T10:37:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "836db4bd214ef8014299fc961cbbaf03d7856e75",
          "body": null,
          "is_bot": false,
          "headline": "Fix unhelpful exception message",
          "author_name": "Andreas Braun",
          "author_login": "alcaeus",
          "committed_at": "2020-05-19T12:55:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af68a652856983556b0630ca5c958c66014cfc66",
          "body": null,
          "is_bot": false,
          "headline": "Fix markdown and link parsing in README.md",
          "author_name": "Alessandro Lai",
          "author_login": "Jean85",
          "committed_at": "2020-04-24T13:28:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11f0f3739d0c19fcf872810bf83cde1e8892f804",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-04-23T13:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98df7f1b293c0550bd5b1ce6b60b59bdda23aa47",
          "body": null,
          "is_bot": false,
          "headline": "Add deprecation warning",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-04-23T11:49:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f102c7427db8d4ff0651e8b5937d62710d581d45",
          "body": null,
          "is_bot": false,
          "headline": "Bring back PHP 7.0+ support",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-04-23T11:20:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed4df24d312ff9dcb1aeb454e83efe7aa91de2ea",
          "body": "PHPUnit update - use better assertion names, remove deprecations",
          "is_bot": false,
          "headline": "Merge pull request #136 from michalbundyra/hotfix/phpunit-deps",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-04-07T15:27:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff667452934f40c6dc8ac170dd5a9179fcf74227",
          "body": null,
          "is_bot": false,
          "headline": "Uses self:: instead of $this-> for assertion calls",
          "author_name": "Michał Bundyra",
          "author_login": "michalbundyra",
          "committed_at": "2020-04-07T15:13:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ab1f1f7c1206f4c189f9b08df07f4c025d9c3cb",
          "body": null,
          "is_bot": false,
          "headline": "PHPUnit update - use better assertion names, remove deprecations",
          "author_name": "Michał Bundyra",
          "author_login": "michalbundyra",
          "committed_at": "2020-04-07T14:59:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "421679846270a5772534828013a93be709fb13df",
          "body": null,
          "is_bot": false,
          "headline": "Dropping `Interface` suffix from newly introduced plugin polyfill",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-04-06T17:43:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a0430f49d7264ca1b299119b98384eb4dc0bb18",
          "body": "Fixes #133",
          "is_bot": false,
          "headline": "Merge branch 'feature/composer-2.0-support'",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-04-06T17:36:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fc2e1b9a3372e320de5b277a5d9625f4467c921",
          "body": "This also brings back MSI to 100%",
          "is_bot": false,
          "headline": "Polyfill for declaring the Composer V2 plugin API explicitly",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-04-06T17:35:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0b137cb5b150ebfe69e40cea63fe8d6caa5a536",
          "body": null,
          "is_bot": false,
          "headline": "Add support for Composer 2.x",
          "author_name": "Jordi Boggiano",
          "author_login": "Seldaek",
          "committed_at": "2020-04-02T13:08:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "651c372efc914aea8223e049f85afaf65e09ba23",
          "body": "…enerated-version\n\nEnsure that, when generated, `PackageVersions\\Versions::getVersion()` is `@psalm-pure`",
          "is_bot": false,
          "headline": "Merge pull request #120 from Ocramius/feature/pure-package-versions-g…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-06T11:34:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e5aa2251bdffaf56e7627c2ee24635ce48609fe",
          "body": null,
          "is_bot": false,
          "headline": "Sacrificed the lamb, found a missing `then`",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-06T11:30:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd570b27acd49607ec71f1b3169776589d95956",
          "body": "… gods",
          "is_bot": false,
          "headline": "Trying to quote `\"$DEPENDENCIES\"` and to sacrifice a lamb to the BASH…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-06T11:27:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e51f5232282bc2bb05732c00b224b97fcc306fba",
          "body": "We don't care for static analysis when `--no-scripts` is used: there\nbe dragons, and we're already at our best level of effort to support\nfolks with weird setup requirements there",
          "is_bot": false,
          "headline": "Run psalm only when `--no-scripts` is enabled",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T11:54:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd191c5e0c686d5876108e4cf85048fe8f418039",
          "body": "… is `@psalm-pure`\n\nNote: the fallback version is **NOT** pure, because it does perform filesystem access.",
          "is_bot": false,
          "headline": "Ensure that, when generated, `PackageVersions\\Versions::getVersion()`…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T11:48:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e511a3fd8a8796c92ea78dd7c447423463966298",
          "body": "Upgrade dependencies, minimum PHP version upgraded to 7.4",
          "is_bot": false,
          "headline": "Merge pull request #118 from Ocramius/feature/upgrade-dependencies",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T11:23:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3901c044caf75d8fafd921f3776cb6737706d06",
          "body": null,
          "is_bot": false,
          "headline": "Switch branch to `master` *BEFORE* installing analysis dependencies",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T10:58:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5b38448a4c52d7db937aa8de416c95f67cdb3e6",
          "body": "…anch-alias` works correctly",
          "is_bot": false,
          "headline": "Ensure that scrutinizer installs the package as `master`, so that `br…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T10:46:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0adb3b228d991e355aebafd92f3d9c682850ac54",
          "body": "Ref: https://scrutinizer-ci.com/docs/tools/php/php-analyzer/guides/migrate_to_new_php_analysis",
          "is_bot": false,
          "headline": "Upgrade to the new scrutinizer-ci analysis engine",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T10:07:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83cb9d7d56b18f25439bbaacd4c126783c9e7812",
          "body": "…allation on its own",
          "is_bot": false,
          "headline": "Removed `before_commands` from scrutinizer-ci: it can figure out inst…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T10:00:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4d8ee522f2fc42b772d346f67861f0140c2790f",
          "body": null,
          "is_bot": false,
          "headline": "Removed PHPCS from scrutinizer-ci",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T10:00:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d380281c1bea2d9de385abb4f1820cb0fac98293",
          "body": null,
          "is_bot": false,
          "headline": "Upload travis coverage when running on locked dependencies",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:57:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dd4fa019f3c733d153ec0c59c505b37e42be253",
          "body": "…ways generated",
          "is_bot": false,
          "headline": "Ignore CS analysis of `src/PackageVersions/Versions.php`, which is al…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "473c60571a1ed97a7fb49ae3f3810692633a0799",
          "body": null,
          "is_bot": false,
          "headline": "Add a CI run that verifies the package with locked dependencies",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:46:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5c9f2c5a0c1b40db6766fa2ad2e2481c16664b1",
          "body": "Without this, we can't really see mutations unless we check\nout the project locally.",
          "is_bot": false,
          "headline": "Add infection report to STDERR to show mutations in CI",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:45:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41b59d8615d1562af10f80a8980505eefc44fb37",
          "body": "…`7.0.2`",
          "is_bot": false,
          "headline": "Upgraded sources and tests to comply with `doctrine/coding-standard` …",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:44:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5aa7c42368ca53d3350d2d0703a2e9e4c8eb08a5",
          "body": null,
          "is_bot": false,
          "headline": "Upgraded dependencies, bumped minimum PHP version to 7.4",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-03-05T09:43:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4b240dfe1106a1306e321e9c9c691e1baadaae0",
          "body": "…-in-tests\n\nAllow using internal/deprecated symbols, but only in the test suite",
          "is_bot": false,
          "headline": "Merge pull request #115 from Ocramius/fix/allow-deprecated-code-usage…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-01-15T09:36:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "061f9cf499feda2b9e3d42d578baefade5a07325",
          "body": null,
          "is_bot": false,
          "headline": "Allow using internal/deprecated symbols, but only in the test suite",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2020-01-15T09:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "715868757a51b1888de49be51ec463c5e70915cb",
          "body": "Travis CI config - PHP 7.4 stable builds",
          "is_bot": false,
          "headline": "Merge pull request #114 from michalbundyra/php-7.4-stable",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-12-09T23:17:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b29371d3bd5dd70c9ca211d6c7466df5503f0be2",
          "body": null,
          "is_bot": false,
          "headline": "Travis CI config - PHP 7.4 stable builds",
          "author_name": "Michał Bundyra",
          "author_login": "michalbundyra",
          "committed_at": "2019-12-09T12:44:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a7ca6eafde0eec1b964cf967e6e71bf27ecc737",
          "body": "Update .gitattributes",
          "is_bot": false,
          "headline": "Merge pull request #111 from reedy/reedy-patch-1",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-11-09T22:36:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1851d36003978cd0aa2dbe1f4e68ac51ce7a11e5",
          "body": null,
          "is_bot": false,
          "headline": "Update .gitattributes",
          "author_name": "Sam Reed",
          "author_login": "reedy",
          "committed_at": "2019-11-09T22:35:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e9ddfbbbb1683df71cee3c7751a82edd26f92a1",
          "body": null,
          "is_bot": false,
          "headline": "Using \"enterprisey\" wording for Tidelift in `README.md`",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-10-29T22:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6bd79274c9be7d019079963c731e4b4bd83ce35",
          "body": null,
          "is_bot": false,
          "headline": "Updated funding URI with correct package name",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-10-29T21:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "412be6335148fed92f35cda5c8d7e237d94ba4ae",
          "body": "Allows for reporting security issues without actually disclosing my email address",
          "is_bot": false,
          "headline": "Created SECURITY.md for security disclosures",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-10-29T21:54:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d32342b8c1eb27353c8887c366147b4c2da673c",
          "body": "…ons-behavior-with-no-scripts-installation\n\n#101 corrected scanned locations for `installed.json` and `composer.json`",
          "is_bot": false,
          "headline": "Merge pull request #102 from Ocramius/fix/#101-correct-fallback-versi…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T15:49:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1053ea09de1dceec6eba3b472e0bba852af23274",
          "body": null,
          "is_bot": false,
          "headline": "CS (spacing, imports)",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T15:38:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cc612c98693679328d8627234fabe82d161ac6a",
          "body": "Otherwise, composer cannot determine the current branch-alias, and fails\nearly during installation.",
          "is_bot": false,
          "headline": "Aliasing current branch as `master` in CI",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T15:25:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e58a3f33699ae00822f00580b7a6881cf2a7126",
          "body": "…son`\n\nDue to `getcwd()` returning an empty string in some environments, (or even\n`\".\"`, a dot, sometimes), this fallback versions logic was too fragile.\n\nAdding hardcoded paths that are supposed to be constant (relative to the\ninstallation path of `FallbackVersions.php`) gives us more stability.",
          "is_bot": false,
          "headline": "#101 corrected scanned locations for `installed.json` and `composer.j…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T15:09:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da0d9d34cd5df6b35756a00827aaeca7d903868d",
          "body": "Bumped dependencies, dropped PHP 7.2.0 support, simplified build matrix",
          "is_bot": false,
          "headline": "Merge pull request #99 from Ocramius/chore/bump-dependencies",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T05:00:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad24dbba2bfc7fbc7ab612ed0046b7a2855a7296",
          "body": null,
          "is_bot": false,
          "headline": "Bumped dependencies, dropped PHP 7.2.0 support, simplified build matrix",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T04:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5be0adfef1e5c5708b8584ff348d3e0a29ff1c2a",
          "body": "…sis-tests\n\n#90 add psalm static analysis tests",
          "is_bot": false,
          "headline": "Merge pull request #96 from Ocramius/chore/#90-add-psalm-static-analy…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T04:49:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89ae9d334b8cedadade67ca581d7aec44c93d731",
          "body": "Scripts are used to set up coding standards, so we cannot test exotic\nconfigurations such as `--no-scripts`.",
          "is_bot": false,
          "headline": "#90 disable PHPCS when running with setups such as `--no-scripts`",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T04:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81c583aa9de75f19e862bf0e8c34da61632b6e0c",
          "body": "To be re-enabled after:\n\n * https://github.com/vimeo/psalm/issues/1881\n * https://github.com/Ocramius/PackageVersions/issues/90",
          "is_bot": false,
          "headline": "#90 disable failing build entry (for now)",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-07-17T04:30:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3ce5a595aca41b9a9b9a9ade6e4cdbbf2dd8f83",
          "body": null,
          "is_bot": false,
          "headline": "#90 CS fixes and type error fixes amongst the whole codebase",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T16:00:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca3076f22a98549755656ef2376a96ef3b4f3c86",
          "body": null,
          "is_bot": false,
          "headline": "#90 automated CS fixes",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:52:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd3e28fd6e2ad4bd0beae114ebff291759cf7f35",
          "body": "Still needs https://github.com/vimeo/psalm/issues/1881 to run",
          "is_bot": false,
          "headline": "#90 verify happy and unhappy path in CI",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:51:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2c09413a522355a35eb05b94a6879a354c5596e",
          "body": null,
          "is_bot": false,
          "headline": "#90 happy path for the static analysis tests",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:39:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca1faec48170d83a5bf74bdf92e1d1e66f07db93",
          "body": "…olved",
          "is_bot": false,
          "headline": "#90 configured `vimeo/psalm` and made sure known basic issues are res…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:39:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ea54bf4d125feca1081b87b3b65e82b583201e9",
          "body": null,
          "is_bot": false,
          "headline": "#90 installed latest `vimeo/psalm`",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:29:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "289d9eb4bc5a7f939a2c5e32b6b48ef98f4fe8d4",
          "body": "…ith `vimeo/psalm`",
          "is_bot": false,
          "headline": "#90 made the `master` branch `1.6.x` to allow installation together w…",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T15:29:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08fb5f1b1f5b6325686485ae80a61c6f1430bce6",
          "body": "Use vendor/composer/installed.json and fallback to using composer.lock",
          "is_bot": false,
          "headline": "Merge pull request #82 from 9ae8sdf76/feature/composer-installed-json",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-30T14:22:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "917d293bc9d6989c36aa11d9817117b42e919cd4",
          "body": null,
          "is_bot": false,
          "headline": "Remove unnecessary logic testing installed.json",
          "author_name": "Ken Stanley",
          "author_login": "d42ohpaz",
          "committed_at": "2019-06-30T13:49:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "668ec4e5febbb74e657b973b700389fd047b814b",
          "body": null,
          "is_bot": false,
          "headline": "Remove use of empty()",
          "author_name": "Ken Stanley",
          "author_login": "d42ohpaz",
          "committed_at": "2019-06-30T13:35:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "594c8b3e42f96b54001fa73d1cff8e396c5f1a88",
          "body": "The `installed.json` could contain an empty array for packages (like this one) that only use `require-dev` and have nothing in `require`. This will address that by merging both the json and lock files.\n\nAs a consequence, the FallbackVersionsTest::testValidVersionsWithoutComposerLock() will need to be skipped when the installed.json is empty.",
          "is_bot": false,
          "headline": "Handle when `composer install —no-dev` was used",
          "author_name": "Ken Stanley",
          "author_login": "d42ohpaz",
          "committed_at": "2019-06-30T13:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8afd7e5d50286adb7279ffce3d3c56075bdf39f8",
          "body": "Rename test method to reflect ambiguity.\nAdd test validating missing installed.json\nRefactor to remove ambiguity of versions data\nRename FallbackVersions::getComposerLockPath() to FallbackVersions::getPackageData().\nInstead of returning a string, FallbackVersions::getPackageData() will return the expected data structure needed for FallbackVersions::getVersions().\nCleanup FallbackVersions::getVersions() so it parses the given data structure.\nRename variables to allow for ambiguity.",
          "is_bot": false,
          "headline": "Address data ambiguity / variable naming feedback",
          "author_name": "Ken Stanley",
          "author_login": "d42ohpaz",
          "committed_at": "2019-06-30T12:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ae11fa471fa042ebc650d6116b08dad7c23219b",
          "body": null,
          "is_bot": false,
          "headline": "Add test to validate when composer.lock does not exist",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ff41d1591e63c8f5b59d5ebf12b4f3649fb3e7d",
          "body": null,
          "is_bot": false,
          "headline": "Add helpers to backup and revert files",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8161c5de0afbc48dbe4d9bc3290e0ceabaf4d8ad",
          "body": null,
          "is_bot": false,
          "headline": "Fixed php-cs sniff violations",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bc0709f0a2c7dee9b14a5de3da035628ea530a2",
          "body": null,
          "is_bot": false,
          "headline": "Update unit tests",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af7a3760865858fff4f88b7a1f46c87d4fc38aa3",
          "body": null,
          "is_bot": false,
          "headline": "Add missing @param and @return annotations",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31d611d7ae0c862eeaef387d45fca60972c92d33",
          "body": null,
          "is_bot": false,
          "headline": "Logic to determine how to parse the installed packages",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9813fa998d3cae33f9dba250bbe32ed3c2d5dc39",
          "body": "Also use getcwd() when the expectation is to look in the project directory.",
          "is_bot": false,
          "headline": "Add the installed.json to the search path",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a6360acd2ebeaa23826cdc17d1b9f7f4e155ba6",
          "body": null,
          "is_bot": false,
          "headline": "Update exception to be more specific about failure",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "914a6e1d79d61b0b30645d82cbb008f9222e2f25",
          "body": null,
          "is_bot": false,
          "headline": "Be specific about why the OutOfBoundsException is thrown",
          "author_name": "Ken Stanley",
          "author_login": "kstanley-UNCC",
          "committed_at": "2019-06-30T11:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e799c526c987c0b88f1f55bb81f0a7cd0d87c8bf",
          "body": "the POST_AUTOLOAD_DUMP event also happens on composer install/update",
          "is_bot": false,
          "headline": "Merge pull request #95 from staabm/patch-1",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-21T10:37:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30161808a0d754ad69b7ff9e81ed75eac6f950b9",
          "body": null,
          "is_bot": false,
          "headline": "adjust test expectations",
          "author_name": "Markus Staab",
          "author_login": "staabm",
          "committed_at": "2019-06-21T06:54:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa374fd74e1fdc4bc7373ad3a95fbe7f73d13c02",
          "body": "no need to subscribe to install/update and autoload-dump.",
          "is_bot": false,
          "headline": "the POST_AUTOLOAD_DUMP event also happens on composer install/update",
          "author_name": "Markus Staab",
          "author_login": "staabm",
          "committed_at": "2019-06-21T06:52:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a8966e663af4eed64edcfcfc937e005e4545cf5",
          "body": "updated dependencies",
          "is_bot": false,
          "headline": "Merge pull request #93 from staabm/upd-phpunit",
          "author_name": "Marco Pivetta",
          "author_login": "Ocramius",
          "committed_at": "2019-06-18T17:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 10,
      "commits_last_year": 0,
      "latest_release_at": "2022-01-17T14:15:51Z",
      "latest_release_tag": "1.11.99.5",
      "releases_from_tags": false,
      "days_since_last_push": 1653,
      "active_weeks_last_year": 0,
      "days_since_latest_release": 1653,
      "mean_days_between_releases": 64.1
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "composer/package-versions-deprecated",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/composer/package-versions-deprecated",
          "is_deprecated": true,
          "latest_version": "1.11.99.5",
          "repository_url": "https://github.com/composer/package-versions-deprecated",
          "versions_count": 11,
          "total_downloads": 198229208,
          "dependents_count": 234,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1835565,
          "first_published_at": null,
          "latest_published_at": "2022-01-17T14:14:24Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1653
        }
      ]
    },
    "popularity": {
      "forks": 8,
      "stars": 1524,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2020-06-18",
            "count": 1
          },
          {
            "date": "2020-10-18",
            "count": 1
          },
          {
            "date": "2020-10-29",
            "count": 1
          },
          {
            "date": "2020-11-09",
            "count": 1
          },
          {
            "date": "2020-11-10",
            "count": 1
          },
          {
            "date": "2021-07-15",
            "count": 1
          },
          {
            "date": "2021-09-06",
            "count": 1
          },
          {
            "date": "2021-09-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 8,
        "total_forks": 8
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 43941,
      "source_files_sampled": 9,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 11,
        "open_issues": 1,
        "closed_ratio": 0.947,
        "closed_issues": 18,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Ocramius",
          "commits": 216,
          "avatar_url": "https://avatars.githubusercontent.com/u/154256?v=4"
        },
        {
          "type": "User",
          "login": "Seldaek",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/183678?v=4"
        },
        {
          "type": "User",
          "login": "AydinHassan",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/2817002?v=4"
        },
        {
          "type": "User",
          "login": "staabm",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/120441?v=4"
        },
        {
          "type": "User",
          "login": "Jean85",
          "commits": 11,
          "avatar_url": "https://avatars.githubusercontent.com/u/6729988?v=4"
        },
        {
          "type": "User",
          "login": "kstanley-UNCC",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/98065928?v=4"
        },
        {
          "type": "User",
          "login": "d42ohpaz",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/2528463?v=4"
        },
        {
          "type": "User",
          "login": "nicolas-grekas",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/243674?v=4"
        },
        {
          "type": "User",
          "login": "stof",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/439401?v=4"
        },
        {
          "type": "User",
          "login": "michalbundyra",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/7423207?v=4"
        }
      ],
      "contributors_sampled": 25,
      "top_contributor_share": 0.661
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "composer.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 11 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 6,
            "reason": "Found 11/18 approved changesets -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 34 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project is archived",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 2,
            "reason": "8 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "b4f54f74ef3453349c24a845d22392cd31e65f1d",
        "ran_at": "2026-07-28T15:00:23Z",
        "aggregate_score": 3.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": "2022-01-17T14:14:25Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 32,
          "created_at": "2021-12-29T15:52:22Z",
          "last_comment_at": "2022-01-03T12:18:25Z",
          "last_comment_author": "Seldaek"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/composer/package-versions-deprecated",
    "host": "github.com",
    "name": "package-versions-deprecated",
    "owner": "composer"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "critical",
      "name": "Overall health",
      "note": "Abandonment Policy applies a 40% multiplier to weighted overall health and gives it a ceiling of 29.",
      "notes": [
        {
          "code": "abandonment_overall_adjustment",
          "params": {
            "cap": 29,
            "pct": 40
          }
        }
      ],
      "value": 15,
      "inputs": {
        "security": 34,
        "vitality": 21,
        "community": 56,
        "governance": 61,
        "engineering": 15,
        "abandonment_cap": 29,
        "abandonment_state": "declared",
        "abandonment_multiplier": 40,
        "weighted_overall_before_abandonment": 38,
        "overall_after_abandonment_multiplier": 15
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "critical",
        "name": "Vitality",
        "value": 21,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "critical",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "commits_last_year": 0,
              "human_commit_share": 1,
              "days_since_last_push": 1653,
              "active_weeks_last_year": 0
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1653 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1653
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "0/52 weeks with commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "0 commits in the last year",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project is archived",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "moderate",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "1.11.99.5",
              "releases_from_tags": false,
              "days_since_latest_release": 1653,
              "mean_days_between_releases": 64.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1653 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1653
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~64.1 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 64.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "at_risk",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "cap": 29,
              "state": "declared",
              "guards": [],
              "signals": [],
              "red_flag": true,
              "multiplier_pct": 40,
              "declared_reason": "archived",
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "the repository is archived on GitHub",
                "points": 40,
                "status": "partial",
                "details": [
                  {
                    "code": "abandonment_archived",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "forks": 8,
              "stars": 1524,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,524 stars",
                "points": 51.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1524
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "8 forks",
                "points": 7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "packages": [
                "composer/package-versions-deprecated"
              ],
              "dependents": 234,
              "ecosystems": "packagist",
              "total_downloads": 198229208,
              "monthly_downloads": 1835565
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "1,835,565 downloads/month across packagist",
                "points": 80,
                "status": "met",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 1835565,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "234 packages depend on it",
                "points": 15.8,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 234
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 61,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 25,
              "top_contributor_share": 0.661
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 66% of commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 66
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "25 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 34 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "merged_prs": 11,
              "open_issues": 1,
              "closed_issues": 18,
              "issue_closed_ratio": 0.947,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "95% of issues closed",
                "points": 44.3,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 95
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "11/13 decided PRs merged",
                "points": 32.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 11,
                      "decided": 13
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 11/18 approved changesets -- score normalized to 6",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "followers": 577,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "composer",
              "public_repos": 21,
              "account_age_days": 5529
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "577 followers of composer",
                "points": 19.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 577,
                      "login": "composer"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "21 public repos, account ~15 yr old",
                "points": 21.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 21
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "at_risk",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 49,
            "inputs": {
              "packages": [
                "composer/package-versions-deprecated"
              ],
              "ecosystems": "packagist",
              "any_deprecated": true,
              "min_days_since_publish": 1653
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1653 days ago",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1653
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "11 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "composer/package-versions-deprecated: deprecated/yanked on the registry",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "package_deprecated",
                    "params": {
                      "name": "composer/package-versions-deprecated"
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "critical",
        "name": "Engineering Quality",
        "value": 15,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "critical",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 11 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 34,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 34,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 3.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 11 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 11/18 approved changesets -- score normalized to 6",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 34 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project is archived",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "8 existing vulnerabilities detected",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 34
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 35,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.43,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "43 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 22.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 43,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "composer.lock"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 43941,
              "source_files_sampled": 9,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/9 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 9,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Community profile unavailable"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T15:00:49.689921Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/composer/package-versions-deprecated.svg",
  "full_name": "composer/package-versions-deprecated",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenPackagist.