Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-25 10:35 UTC

demoiselle / signer

Repositório que contém os componentes para facilitar a implementação de assinatura digital nos padrões da ICP-BRASIL

JavaLGPL-3.0★ 172 Sterne⑂ 80 Forksseit Nov. 2016Auf GitHub ansehen ↗

demoiselle/signer erreicht einen Gesundheitsindex von 59 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Sustainability & Governance (66/100) ab, am schwächsten bei Security (49/100). Zuletzt vor 1 Tag aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

59
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

59
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

DemoiselleOrganisation
28 Follower29 öffentliche Reposseit Dez. 2010

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Mavenorg.demoiselle.signer:signer-core4.6.1-10vor 9 Tagen
Mavenorg.demoiselle.signer:chain-iti4.6.1-6vor 9 Tagen
Mavenorg.demoiselle.signer:signer-timestamp4.6.1-10vor 9 Tagen
Mavenorg.demoiselle.signer:signer-cryptography4.6.1-10vor 9 Tagen
Mavenorg.demoiselle.signer:policy-engine4.6.1-45vor 9 Tagen
Mavenorg.demoiselle.signer:signer-xmldsig4.6.1-4vor 9 Tagen
Mavenorg.demoiselle.signer:chain-icp-brasil4.6.1-45vor 9 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

64Mittel · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
13.8/36Commit-Rhythmus — 20/52 Wochen mit Commits
18/18Commit-Volumen — 113 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year113
human_commit_share1
days_since_last_push1
active_weeks_last_year20

Release-Disziplin

42Gefährdet
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 3 Versions-Tags (keine GitHub-Releases)
16.2/36Release-Aktualität — letztes Release vor 245 Tagen
5.4/27Release-Rhythmus — ein Release etwa alle 1.569,5 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count3
latest_release_tag4.5.0
releases_from_tagsja
days_since_latest_release245
mean_days_between_releases1.569,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

55Mittel · 18 % des Gesamtindex
Wie die Bewertung erfolgt
36.2/60Stars — 172 Stars
15.8/25Forks — 80 Forks
8.1/15Watcher — 30 Watcher
Verwendete Eingangsdaten
forks80
stars172
watchers30
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (LGPL-3.0)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

66Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
7.9/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 65 % der Commits
13.5/13.5Breite der Beitragenden — 20 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 6 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled20
top_contributor_share0,649
Wie die Bewertung erfolgt
42.1/46.8Issue-Lösungsquote — 90 % der Issues geschlossen
28.7/38.3PR-Annahme — 33/44 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/2 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs33
open_issues40
closed_issues362
issue_closed_ratio0,9
closed_unmerged_prs11
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
10.5/25Reichweite des Inhabers — 28 Follower von demoiselle
22.8/25Kontohistorie — 29 öffentliche Repos, Kontoalter ca. 15 Jahre
Verwendete Eingangsdaten
followers28
owner_typeOrganization
is_verified
owner_logindemoiselle
public_repos29
account_age_days5.685

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 7 Paket(e) auf maven
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 9 Tagen
20/20Versionshistorie — 45 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesorg.demoiselle.signer:signer-core, org.demoiselle.signer:chain-iti, org.demoiselle.signer:signer-timestamp, org.demoiselle.signer:signer-cryptography, org.demoiselle.signer:policy-engine, org.demoiselle.signer:signer-xmldsig, org.demoiselle.signer:chain-icp-brasil
ecosystemsmaven
any_deprecatednein
min_days_since_publish9

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

58Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
6.4/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 2 merged PRs checked by a CI test -- score normalized to 0
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfigja
has_linter_confignein
has_precommit_confignein

Dokumentation

100Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://www.frameworkdemoiselle.gov.br/v3/signer/
10/10Repository-Beschreibung
10/10Topics — 8 Topics
10/10Wiki
Verwendete Eingangsdaten
topicsicp-brasil, digital-signature, cryptography, timestamp, pki, certificates, x509certificates, x509
has_wikija
homepagehttps://www.frameworkdemoiselle.gov.br/v3/signer/
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

49Gefährdet · 16 % des Gesamtindex

Sicherheitslage

36Gefährdet
Wie die Bewertung erfolgt
5.2/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 2 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/2 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 6 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
0/7.5Vulnerabilities — 16 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate3,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages9
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von maven:org.demoiselle.signer:signer-core@4.6.1 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 9 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

62Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
39.5/40Lesbare Commit-Historie — 74 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,74
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — automacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Java (statisch typisiert)
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 16 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,16
toolchain_manifestsautomacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod, chain-icp-brasil-homolog/pom.xml, chain-icp-brasil/pom.xml, chain-iti-homolog/pom.xml, chain-iti/pom.xml, chain-serpro-neosigner/pom.xml, core/pom.xml, cryptography/pom.xml, documentation/reference/pom.xml, parent/pom.xml, policy-engine/pom.xml, policy-impl-cades/pom.xml, policy-impl-pades/pom.xml, policy-impl-xades/pom.xml, pom.xml, signer-examples/pom.xml, signer-xmldsig/pom.xml, timestamp/pom.xml
dependency_bot_commit_share0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Java (statisch typisiert)
54.9/55Handhabbare Dateigrößen — 1/370 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageJava
largest_source_bytes208.648
source_files_sampled370
oversized_source_files1
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

172GitHub-Sterne
20Mitwirkende
113Commits, letzte 12 Monate
1Tage seit letztem Push
3Releases
1Bus-Faktor
40offene Issues
Go, MavenPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch maven package 'org.demoiselle.signer:signer-examples' from its registry

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 80 ⇿
0Sterne
80Forks
3Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

0204060807732017-012021-092026-05
Major 1Minor 1Patch 1

Jeder Punkt umfasst 9 Tage.

OpenSSF Scorecard 3.6 / 10
3.6Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-25 10:35 UTC

7Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 2 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/2 approved changesets -- score normalized to 0
10Contributorsproject has 6 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
0Vulnerabilities16 existing vulnerabilities detected
Direkte Abhängigkeiten 67
RegistryPaketVersionsvorgabeManifest
Gogolang.org/x/netv0.17.0automacao-importador/go.mod
Mavenorg.demoiselle.signer:chain-icp-brasil${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:chain-icp-brasil-homolog${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:signer-core${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:signer-cryptography${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:policy-engine${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:policy-impl-cades${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:policy-impl-xades${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:policy-impl-pades${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:signer-timestamp${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:chain-serpro-neosigner${demoiselle.signer.version}bom/pom.xml
Mavenorg.demoiselle.signer:chain-iti${demoiselle.signer.version}bom/pom.xml
Mavenorg.apache.logging.log4j:log4j-api2.25.4bom/pom.xml
Mavenorg.apache.logging.log4j:log4j-core2.25.4bom/pom.xml
Mavenorg.apache.logging.log4j:log4j-1.2-api2.25.4bom/pom.xml
Mavenorg.slf4j:slf4j-log4j121.7.32bom/pom.xml
Mavenorg.bouncycastle:bcmail-lts8on2.73.11bom/pom.xml
Mavenorg.bouncycastle:bcpkix-lts8on2.73.11bom/pom.xml
Mavenorg.bouncycastle:bcprov-lts8on2.73.11bom/pom.xml
Mavenorg.bouncycastle:bcutil-lts8on2.73.11bom/pom.xml
Mavencommons-io:commons-io2.15.1bom/pom.xml
Gogolang.org/x/netv0.42.0chain-icp-brasil-homolog/go.mod
Mavenorg.demoiselle.signer:signer-core4.6.1chain-icp-brasil-homolog/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1chain-icp-brasil/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1chain-iti-homolog/pom.xml
Mavenorg.demoiselle.signer:chain-icp-brasil-homolog4.6.1chain-iti-homolog/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1chain-iti/pom.xml
Mavenorg.demoiselle.signer:chain-icp-brasil4.6.1chain-iti/pom.xml
Mavenorg.demoiselle.signer:chain-serpro-neosigner4.6.1chain-iti/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1chain-serpro-neosigner/pom.xml
Mavenorg.demoiselle.signer:chain-icp-brasil4.6.1chain-serpro-neosigner/pom.xml
Mavenorg.apache.logging.log4j:log4j-api2.25.4core/pom.xml
Mavenorg.apache.logging.log4j:log4j-core2.25.4core/pom.xml
Mavenorg.apache.logging.log4j:log4j-1.2-api2.25.4core/pom.xml
Mavenorg.slf4j:slf4j-log4j121.7.32core/pom.xml
Mavencom.sun.xml.bind:jaxb-core2.3.0.1core/pom.xml
Mavenjavax.xml.bind:jaxb-api2.3.1core/pom.xml
Mavencom.sun.xml.bind:jaxb-impl2.3.1core/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1cryptography/pom.xml
Mavenorg.demoiselle.signer:bom4.6.1parent/pom.xml
Mavenorg.apache.logging.log4j:log4j-1.2-api2.25.4parent/pom.xml
Mavenorg.slf4j:slf4j-log4j121.7.32parent/pom.xml
Mavenorg.bouncycastle:bcmail-lts8on2.73.11parent/pom.xml
Mavenorg.demoiselle.signer:signer-core${project.version}policy-engine/pom.xml
Mavencommons-io:commons-io2.15.1policy-engine/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1policy-impl-cades/pom.xml
Mavenorg.demoiselle.signer:signer-cryptography4.6.1policy-impl-cades/pom.xml
Mavenorg.demoiselle.signer:policy-engine4.6.1policy-impl-cades/pom.xml
Mavenorg.demoiselle.signer:signer-timestamp4.6.1policy-impl-cades/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1policy-impl-pades/pom.xml
Mavenorg.demoiselle.signer:signer-cryptography4.6.1policy-impl-pades/pom.xml
Mavenorg.demoiselle.signer:policy-engine4.6.1policy-impl-pades/pom.xml
Mavenorg.demoiselle.signer:policy-impl-cades4.6.1policy-impl-pades/pom.xml
Mavenorg.apache.santuario:xmlsec2.3.5policy-impl-xades/pom.xml
Mavenorg.demoiselle.signer:policy-impl-cades4.6.1policy-impl-xades/pom.xml
Mavencommons-io:commons-io2.15.1policy-impl-xades/pom.xml
Mavenorg.demoiselle.signer:core3.7.1signer-examples/pom.xml
Mavenorg.demoiselle.signer:chain-icp-brasil3.7.1signer-examples/pom.xml
Mavenorg.demoiselle.signer:policy-impl-cades3.7.1signer-examples/pom.xml
Mavencommons-io:commons-io2.15.1signer-examples/pom.xml
Mavenorg.apache.santuario:xmlsec2.2.6signer-xmldsig/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1signer-xmldsig/pom.xml
Mavencommons-io:commons-io2.15.1signer-xmldsig/pom.xml
Mavenorg.demoiselle.signer:signer-cryptography4.6.1timestamp/pom.xml
Mavenorg.demoiselle.signer:signer-core4.6.1timestamp/pom.xml
Mavencom.mashape.unirest:unirest-java1.4.9timestamp/pom.xml
Mavencom.fasterxml.jackson.core:jackson-databind2.22.0timestamp/pom.xml
Alle Abhängigkeiten 57

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 33 direkte und 24 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Gogolang.org/x/netv0.17.0direkt
Gogolang.org/x/netv0.42.0direkt
Mavencom.fasterxml.jackson.core:jackson-databind2.22.0direkt
Mavencom.mashape.unirest:unirest-java1.4.9direkt
Mavencom.sun.xml.bind:jaxb-core2.3.0.1direkt
Mavencom.sun.xml.bind:jaxb-impl2.3.1direkt
Mavencommons-io:commons-io2.15.1direkt
Mavenjavax.xml.bind:jaxb-api2.3.1direkt
Mavenorg.apache.logging.log4j:log4j-1.2-api2.25.4direkt
Mavenorg.apache.logging.log4j:log4j-api2.25.4direkt
Mavenorg.apache.logging.log4j:log4j-core2.25.4direkt
Mavenorg.apache.santuario:xmlsec2.2.6direkt
Mavenorg.apache.santuario:xmlsec2.3.5direkt
Mavenorg.bouncycastle:bcmail-lts8on2.73.11direkt
Mavenorg.bouncycastle:bcpkix-lts8on2.73.11direkt
Mavenorg.bouncycastle:bcprov-lts8on2.73.11direkt
Mavenorg.bouncycastle:bcutil-lts8on2.73.11direkt
Mavenorg.demoiselle.signer:bom4.6.1direkt
Mavenorg.demoiselle.signer:chain-icp-brasil3.7.1direkt
Mavenorg.demoiselle.signer:chain-icp-brasil4.6.1direkt
Mavenorg.demoiselle.signer:chain-icp-brasil-homolog4.6.1direkt
Mavenorg.demoiselle.signer:chain-iti4.6.1direkt
Mavenorg.demoiselle.signer:chain-serpro-neosigner4.6.1direkt
Mavenorg.demoiselle.signer:core3.7.1direkt
Mavenorg.demoiselle.signer:policy-engine4.6.1direkt
Mavenorg.demoiselle.signer:policy-impl-cades3.7.1direkt
Mavenorg.demoiselle.signer:policy-impl-cades4.6.1direkt
Mavenorg.demoiselle.signer:policy-impl-pades4.6.1direkt
Mavenorg.demoiselle.signer:policy-impl-xades4.6.1direkt
Mavenorg.demoiselle.signer:signer-core4.6.1direkt
Mavenorg.demoiselle.signer:signer-cryptography4.6.1direkt
Mavenorg.demoiselle.signer:signer-timestamp4.6.1direkt
Mavenorg.slf4j:slf4j-log4j121.7.32direkt
Mavenbr.gov.frameworkdemoiselle.documentation:demoiselle-docbook-xslt2.0.2indirekt
Mavenbr.gov.frameworkdemoiselle.documentation:demoiselle-jdocbook-style2.0.2indirekt
Mavencommons-codec:commons-codec1.10indirekt
Mavencommons-codec:commons-codec1.14indirekt
Mavenjunit:junit4.13.1indirekt
Mavenorg.apache.maven.plugins:maven-assembly-plugin2.6indirekt
Mavenorg.apache.maven.plugins:maven-compiler-pluginindirekt
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.5.1indirekt
Mavenorg.apache.maven.plugins:maven-deploy-plugin1.0indirekt
Mavenorg.apache.maven.plugins:maven-failsafe-plugin2.22.2indirekt
Mavenorg.apache.maven.plugins:maven-gpg-plugin3.0.1indirekt
Mavenorg.apache.maven.plugins:maven-jar-plugin3.0.2indirekt
Mavenorg.apache.maven.plugins:maven-javadoc-plugin3.10.1indirekt
Mavenorg.apache.maven.plugins:maven-scm-plugin1.4indirekt
Mavenorg.apache.maven.plugins:maven-source-plugin2.2.1indirekt
Mavenorg.apache.maven.wagon:wagon-ssh1.0indirekt
Mavenorg.apache.pdfbox:pdfbox2.0.24indirekt
Mavenorg.jboss.maven.plugins:maven-jdocbook-plugin2.3.5indirekt
Mavenorg.jboss.seam:seam-docbook-xslt1.1.0indirekt
Mavenorg.jboss.seam:seam-jdocbook-style1.1.0indirekt
Mavenorg.jboss.weld:weld-docbook-xslt1.1.1-Beta5indirekt
Mavenorg.jboss:jbossorg-jdocbook-style1.1.1indirekt
Mavenorg.junit.jupiter:junit-jupiter5.10.2indirekt
Mavenorg.sonatype.central:central-publishing-maven-plugin0.6.0indirekt
Abhängigkeits-Advisories 0

Die Installation von maven:org.demoiselle.signer:signer-core@4.6.1 zieht 9 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "icp-brasil",
        "digital-signature",
        "cryptography",
        "timestamp",
        "pki",
        "certificates",
        "x509certificates",
        "x509"
      ],
      "is_fork": false,
      "size_kb": 55889,
      "has_wiki": true,
      "homepage": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
      "languages": {
        "Go": 20616,
        "HTML": 517,
        "Java": 1853557,
        "Shell": 4505
      },
      "pushed_at": "2026-07-24T07:22:05Z",
      "created_at": "2016-11-08T18:23:40Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-15T21:35:50Z",
      "description": "Repositório que contém os componentes para facilitar a implementação de assinatura digital nos padrões da ICP-BRASIL",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "LGPL-3.0",
      "default_branch": "master",
      "license_spdx_raw": "LGPL-3.0",
      "primary_language": "Java",
      "significant_languages": [
        "Java"
      ]
    },
    "owner": {
      "blog": "https://www.frameworkdemoiselle.gov.br/",
      "name": "Demoiselle",
      "type": "Organization",
      "login": "demoiselle",
      "company": null,
      "location": "Brazil",
      "followers": 28,
      "avatar_url": "https://avatars.githubusercontent.com/u/541492?v=4",
      "created_at": "2010-12-30T11:49:11Z",
      "is_verified": null,
      "public_repos": 29,
      "account_age_days": 5685
    },
    "license": {
      "state": "standard",
      "spdx_id": "LGPL-3.0",
      "raw_spdx": "LGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "4.5.0",
          "kind": "minor",
          "published_at": "2025-11-21T14:01:49Z"
        },
        {
          "tag": "3.0.1",
          "kind": "patch",
          "published_at": "2017-04-26T18:56:53Z"
        },
        {
          "tag": "3.0.0",
          "kind": "major",
          "published_at": "2017-04-18T15:05:39Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "89c54a31fd05b8a7a410bb9c5c5e9c0ebe4a9d7c",
          "body": "Versão 4.6.1 para o master",
          "is_bot": false,
          "headline": "Merge pull request #451 from demoiselle/4.6.1",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T20:42:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4348c53e3c33fff5e749186dfc0a690ef49454d0",
          "body": "Versão 4.6.1 para ramo 4.6.1",
          "is_bot": false,
          "headline": "Merge pull request #450 from evandrojr/4.6.1",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T20:40:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "175dcc48d77292ec4ec4da57f55acfe59f6b37f2",
          "body": "…vhistory.xml; correct release notes for 4.5.1",
          "is_bot": false,
          "headline": "fix: update version numbers to 4.6.1 in pom.xml, bookinfo.xml, and re…",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T20:37:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22a87308af011e3225c2c24746b0a3b1f36b3197",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove VSCode settings file",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T20:34:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e7d14f83c97760f5e010c45f18f8d480112314c",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove obsolete deployment scripts and logs",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T20:33:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a16064549face2e0d0d0527375d9430e363a920",
          "body": null,
          "is_bot": false,
          "headline": "fix: update policy-engine version to 4.6.1 and fix dependencies",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T18:17:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1920632fd96a970b8919bc60ca729a651a0d216b",
          "body": null,
          "is_bot": false,
          "headline": "fix: correct strings.Repeat in publicador.go",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T18:09:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69b4300558426208084a91a28614bbd952c3eec9",
          "body": null,
          "is_bot": false,
          "headline": "build: fix Sonatype Central publication and add Go deploy script",
          "author_name": "Evandro Junior",
          "author_login": "evandrojr",
          "committed_at": "2026-07-15T17:00:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "034652b11754966bfc7d77e1a863775d324a36eb",
          "body": null,
          "is_bot": false,
          "headline": "docs: update TESTING.md, integration tests moved to external project",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-09T20:59:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2437351072993a65cc8d58dc4dbc3733a8a3107d",
          "body": null,
          "is_bot": false,
          "headline": "docs: update README to version 4.6.1",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-09T20:58:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2515312595c9e0178d88a5f7f9c330e5da7dc8e6",
          "body": null,
          "is_bot": false,
          "headline": "release: version 4.6.1, update deploy script and cleanup tests",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-09T19:38:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79a6b338b4f70c93b1146060c3d863e130a43a2f",
          "body": "- Bumped log4j-api, log4j-core, and log4j-1.2-api from 2.11.2 to 2.25.4\n- Bumped jackson-databind from 2.0.6 to 2.22.0\n- Bumped xmlsec from 2.0.10 to 2.2.6",
          "is_bot": false,
          "headline": "chore(security): bump dependencies for vulnerabilities",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-07T11:18:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deed98e93ac75e6d1f35945e8ba4fd59f4c0d44a",
          "body": "…atibility\n\n- Replaced explicit casts to DERTaggedObject, DEROctetString, DLSequence, and DERIA5String with generic ASN1* classes and .getInstance() methods.\n- Fixed ClassCastException in BasicCertificate.getAuthorityKeyIdentifier() and related methods.\n- Updated policy-engine parsing logic (LPA, PolicyInfo, etc.) to use generic ASN1Sequence and ASN1OctetString.\n- Added unit and integration tests (AuthorityKeyIdentifierTest/IT) to verify fixes.\n- Updated version to 4.6.1-SNAPSHOT in all modules.",
          "is_bot": false,
          "headline": "fix(core,policy): refactor ASN.1 parsing for Bouncy Castle 1.7x+ comp…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-06T17:37:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "534176a576ca386b868eb213c60be002dc0e4219",
          "body": null,
          "is_bot": false,
          "headline": "Release 4.6.0",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-07-03T10:08:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "917c37e7745a0e845bd93788c35e32032bdd946d",
          "body": "- Converte classe com método main para um caso de teste JUnit 4 (@Test).\n- Remove blocos de texto (Java 15+) incompatíveis com o -source 8 do projeto.\n- Remove caracteres ocultos/inválidos que causavam falha na compilação.\n- Remove chamada a método getCnpjAR() inexistente em BasicCertificate.",
          "is_bot": false,
          "headline": "test(core): adapta Resolution211CertificateDataTest para JUnit 4",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-23T13:14:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb68818bc920797d96339e886e726ac8ae1500e7",
          "body": "…cateExtra\n\n- Atualiza o metodo isCertificatePJ() para verificar a presenca tanto do OID de CEI (2.16.76.1.3.7) quanto do OID de CNPJ (2.16.76.1.3.3), alinhando a validacao aos padroes da ICP-Brasil e a implementacao em ICPBRSubjectAlternativeNames.",
          "is_bot": false,
          "headline": "fix: corrige identificacao inconsistente de certificado PJ em Certifi…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-22T15:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d353525ee5ffe1ea89cbfa05376d74bafb1d95fe",
          "body": "- PolicyUtils.getPolicyByOid(): retorna null com warn para OID nulo/vazio ou nao mapeado\n- XMLChecker.verifyPolicy(): early return null se policyOID for nulo ou\n  politica nao reconhecida, evitando NPE e aceitacao de politica incorreta",
          "is_bot": false,
          "headline": "fix: rejeita OID de politica nao mapeado em vez de aceitar silentemente",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-19T16:10:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2129e3981d6ea19f2555efaf9983041b438f1ac2",
          "body": "…ação",
          "is_bot": false,
          "headline": "fix: torna detecção de AC Raiz leniente apenas em ambiente de homolog…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-19T16:00:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44cfc2b063808a152f7fe05f5f77f2c42b4bc702",
          "body": null,
          "is_bot": false,
          "headline": "fix: melhora detecção de AC Raiz e comparação de Principals no CAManager",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-19T15:33:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "963fede9fd0ad064ba5ca715006d2735fe10a9ed",
          "body": "…cação",
          "is_bot": false,
          "headline": "fix: refatora CAManager para construção robusta de cadeias de certifi…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-19T15:18:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc05dd9ab7f66398e964b24f17239f0dcecbc419",
          "body": "…s XAdES",
          "is_bot": false,
          "headline": "fix: corrige erro de sintaxe e melhora robustez no lookup de elemento…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T23:11:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0a3631372d744d4c485f18fe8d325e6503a8620",
          "body": "…orar validação",
          "is_bot": false,
          "headline": "fix: torna a busca de elementos XAdES flexível a namespaces para melh…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T23:07:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f540b271e1987ecf27ac346ba5734dc70875231",
          "body": "…a de carregamento",
          "is_bot": false,
          "headline": "fix: garante retorno do identificador da política XAdES mesmo em falh…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T23:00:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b0cf713084e455bb99507a9eaedd51c01743405",
          "body": "…olitica v2.5\n\nO PolicyUtils estava falhando ao resolver OIDs da v2.5 (.2.5) e caindo no fallback que tambem estava incorreto ou retornando string invalida. Agora o parser OID -> PolicyFactory resolve as politicas da Raiz v12 com seguranca.",
          "is_bot": false,
          "headline": "fix(policy): corrige NullPointerException no XAdES mapeando OIDs da p…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T19:49:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8ca92964fd8cb47c8e5b7d36523f23812ea79f9",
          "body": "Incorpora as variacoes de versoes de politicas PAdES (v1.4) e XAdES (v2.5) na skill e alerta para a necessidade de atualizacao do XMLPoliciesOID, evitando incidentes futuros.",
          "is_bot": false,
          "headline": "docs(cli): atualiza skill de cadeias com licoes aprendidas",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T19:10:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d40b1736b1726564d779caee8e116410f78f1672",
          "body": "…atualizado",
          "is_bot": false,
          "headline": "chore: adiciona os artefatos fisicos das novas politicas PAdES e BKS …",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T18:50:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4be7ff9d92330a059c7f5255c8871302d626ac4e",
          "body": "Baseado no levantamento oficial das raizes, mapeia e adiciona suporte nativo as politicas PAdES v1.3 e v1.4, alem de atualizar o default do PAdESSigner para a versao v1.3 garantindo compatibilidade da RB com Raiz v12.",
          "is_bot": false,
          "headline": "fix(policy): complementa suporte a PAdES com raizes v12",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T18:50:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "341d52b61cacdab36857700da436e9fc5752b3d0",
          "body": "Mapeia as politicas XML v2.5 e PAdES v1.3/v1.4, alinhando os construtores padroes para XAdES (v2.5) de acordo com os ultimos lancamentos da ICP-Brasil. OIDs atualizados em XMLPoliciesOID.",
          "is_bot": false,
          "headline": "fix(policy): corrige limites de versoes para XAdES e PAdES com raiz v12",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T18:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d86811d224636e50f387a6b3104ff40af324e34",
          "body": "Atendendo a recomendacao do lider tecnico (Ronald), a validacao estrita que barrava assinaturas incompatíveis com a Raiz v12 foi comentada para não causar breaking changes ou bloqueios em produtos satelites antes do esperado. A prioridade emergencial eh focar na migracao suave dos defaults para v2.4 (ja realizados). Uma arquitetura definitiva para cruzar as raizes homologadas dentro do arquivo .der da politica sera pensada em releases futuras.",
          "is_bot": false,
          "headline": "fix(policy): suspende trava de seguranca de raiz provisoriamente",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T12:10:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d49f976e03c30fc736fee81f85eeebdc214a71e",
          "body": "…v2.4\n\nSubstitui a política AD_RB_CADES_2_3 pela AD_RB_CADES_2_4 no TokenSignatureIT para atestar a interoperabilidade do hardware fisico com a nova Raiz v12 e com as travas do RootCompatValidator.",
          "is_bot": false,
          "headline": "test: atualiza teste do token para validar fluxo com a nova politica …",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T11:14:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8448e510ebfc2c1781eb20acce26ad762d315fb",
          "body": "…rtefatos\n\nEssa skill instrui o agente de IA a seguir um fluxo seguro e validado sempre que solicitado a atualizar cadeias ou politicas, passando pelo descobrimento da LPA, download e testes de compilacao.",
          "is_bot": false,
          "headline": "feat(cli): adiciona skill para o Gemini automatizar atualizacoes de a…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T10:15:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9afa20852c186df08b7719cb6a7ea56d7828450d",
          "body": "O relatorio explica a causa raiz da rejeicao de assinaturas no ITI, esclarece que a automacao de politicas nao falhou, e documenta as modificacoes (Hotfix, Defaults, RootCompatValidator) realizadas no motor Java, alem de orientacoes para os produtos finais.",
          "is_bot": false,
          "headline": "docs: adiciona relatorio de incidente sobre Raiz v12 e politicas",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T10:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3ba71c057e6e0c7618bba99d72420253daf1bd1",
          "body": "Mapeia as novas politicas v2.4 e v2.5 do ITI no enum PolicyFactory. Implementa trava de seguranca (RootCompatValidator) que barra assinaturas caso o certificado pertença a uma hierarquia de Raiz v12 mas a politica solicitada seja antiga (< v2.4), impedindo assinaturas invalidas. Atualiza os defaults de CAdES, PAdES e XAdES para as ultimas versoes confiaveis das politicas.",
          "is_bot": false,
          "headline": "feat(policy): Suporte a Raiz v12 e politicas v2.4/v2.5",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-18T10:07:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "126312b05664ee2d0d8919aa48cf6ac7370f6082",
          "body": "Atualiza as dependências do Bouncy Castle nos POMs e nos scripts de automação Go para a versão lts8on-2.73.11, alinhando com as atualizações do Java. Remove referências ao DatatypeConverter deprecado em ICPBrasilOnLineSerproProviderCA.java e atualiza os binários gerados.",
          "is_bot": false,
          "headline": "chore: atualiza Bouncy Castle para LTS 2.73.11 e ajusta código Java",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T18:52:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cfdcec4ec8d9d9d6800bfdeb407232c63f290fb",
          "body": "…tomation\n\nAtualiza dependências do projeto para usar pacotes Bouncy Castle LTS (bc*-lts8on) na versão 2.73.11, garantindo melhor suporte a ECDSA/SHA512. Substitui DatatypeConverter por Base64 para compatibilidade com Java 25. Adiciona script unificado de atualização de artefatos de homologação.",
          "is_bot": false,
          "headline": "feat: upgrade Bouncy Castle to 2.73.11 and add homologation update au…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T18:50:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4ccc7a2ce2d96b1717b27fc891cda79762a38c3",
          "body": "O importador agora suporta a flag '-update-lpa', que baixa o LPA.xml da ICP-Brasil, faz o parse das URLs (incluindo inferência da extensão .der) e as adiciona automaticamente ao politicas.txt, mantendo a lista oficial sempre em dia com o ITI.",
          "is_bot": false,
          "headline": "feat: adiciona flag -update-lpa para autodescoberta de políticas",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T18:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f646f6cdf831b16ee45247f67fc33e3d69d5880b",
          "body": "Consolida as rotinas de download de cadeias e políticas de prod/hom em um único projeto modular em automacao-importador/. Resolve erro de parsing de certificados ECC (Raiz v13) adicionando rotina de limpeza PEM com OpenSSL antes da importação do keytool. Remove scripts bash/go esparsos.",
          "is_bot": false,
          "headline": "refactor: cria importador unificado em Go e remove scripts antigos",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T18:07:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c90790bd19dd1b3011ee6d7350e79392853b7097",
          "body": "Atualiza scripts de download de políticas e cadeias para incluir headers de navegador, resolvendo falhas de conexão com os servidores da ICP-Brasil e ITI.",
          "is_bot": false,
          "headline": "fix: adicionar User-Agent para evitar bloqueios no download de artefatos",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T14:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3efffe3d5ff2a92e6fcc3495afa779fb826c492",
          "body": "Adiciona script mestre 'atualizar-artefatos-producao.sh' e script auxiliar para download de cadeias. Inclui documentação detalhada sobre o processo de atualização de produção.",
          "is_bot": false,
          "headline": "feat: automação completa para atualização de cadeias e políticas",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T13:56:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "088ce2649d6be7beca447f5f93f0efc7cee8d856",
          "body": "…il 'it'\n\nRenomeia arquivos de teste de integração para *IT.java para serem ignorados pelo surefire. Configura failsafe no parent pom com skipITs=true por padrão. Adiciona perfil 'it' para ativar os testes de integração quando desejado.",
          "is_bot": false,
          "headline": "feat: isolar testes de integração usando maven-failsafe-plugin e perf…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T13:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dad84386a6f34ac46e5cbaf48ae9951bd2b4dc6",
          "body": "- Adiciona 'synchronized' ao CAManager.getCertificateChain para evitar condições de corrida.\n- Implementa try-with-resources nos provedores de cadeias para garantir o fechamento de streams.\n- Resolve erro 'O arquivo já está sendo usado por outro processo' no Windows.",
          "is_bot": false,
          "headline": "fix: corrige lock de arquivo e concorrência no carregamento de cadeias",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-17T13:38:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3719ed1d45fcc6396a99015e256ae844e9da099b",
          "body": "…FX real\n\n- Ajusta getCertificateLevel para usar startsWith ao invés de equals, permitindo identificar corretamente os certificados que possuem sub-políticas anexadas ao OID base (ex: 2.16.76.1.2.201.1 para SE-S).\n- Adiciona PfxIntegrationTest que valida empiricamente a extração do CNPJ (Y1V5MYJT000195) a partir do serialNumber do DN utilizando o certificado de homologação do novo perfil.",
          "is_bot": false,
          "headline": "fix: Correspondência flexível de OID para sub-políticas e teste com P…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-16T17:31:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b07a9457e5352786db9f6c9f5101979a9c8bf24",
          "body": "- Adiciona suporte aos novos perfis de certificados: Selo Eletrônico (SE-S, SE-H) e Aplicações Específicas (AE-S, AE-H).\n- Extração de CNPJ e CPF a partir do OID 2.5.4.5 (serialNumber) no DN para os novos perfis.\n- Extração do CNPJ da AR a partir do OID 2.16.76.1.4.5.1 no SubjectAlternativeName.\n- R\n[…]\nficados mockados.\n- Adiciona TokenIntegrationTest para validação empírica de certificados em hardware token, incluindo verificação de retrocompatibilidade com OIDs extintos (Título Eleitor, RIC, etc).",
          "is_bot": false,
          "headline": "feat: Suporte à Resolução 211 da ICP-Brasil",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-16T17:20:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af4067fdd1ece526f7c2eb0cf5f7a9d1acbf52ba",
          "body": "…ateLevel()\n\n- Corrige getCertificateLevel() que usava startsWith() em OIDs,\n  causando colisão entre A2 (2.16.76.1.2.2) e SE-S (2.16.76.1.2.201)\n  e entre A1 (2.16.76.1.2.1) e S1-S4 (2.16.76.1.2.101-104)\n- Troca cast de DLSequence para ASN1Sequence (compatível com DER)\n- Remove varASN1InputStream f\n[…]\nE para retornar corporateName de Equipment\n- Adiciona bloco SE ao toString() e mensagens i18n\n- Adiciona ICPBRCertificateSE (nova classe)\n- Adiciona teste de SE com policy OID, renomeia teste enganoso",
          "is_bot": false,
          "headline": "fix: corrige detecção de Selo Eletrônico e bugs de OID em getCertific…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-15T19:32:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "373b74304aa699a52b5183d178a032737cbfcb93",
          "body": null,
          "is_bot": false,
          "headline": "arquivo removido",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-11T11:24:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61ce32ac29ea249c27d4fcad16f9c87bc5226694",
          "body": null,
          "is_bot": false,
          "headline": "Executa os testes em todas as versoes java LTS",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-11T11:21:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "990fcf054bec24b95297a1d8c6a73677b1b0bd61",
          "body": "Roda os testes do signer-core no Java 8, 11, 17 e 25 para validar a retrocompatibilidade da refatoração.",
          "is_bot": false,
          "headline": "chore: adiciona script go para automação de testes multi-versão",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-11T11:16:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f30ae7dc93f4bdec1a2d4efcaf610e2188678f3",
          "body": "O Java 9+ utiliza o método Provider.configure() que quebrava o build em Java 8. Adicionado método de inicialização via reflection que suporta o Java 9+ e possui fallback compatível com os antigos construtores SunPKCS11 do Java 8.",
          "is_bot": false,
          "headline": "fix: refatora PKCS11 Provider para suportar Java 8 via Reflection",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-11T11:07:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c414a49e043a916bcf20601df91ea1c72ce826a",
          "body": "…1 ICP-Brasil)\n\nMapeia novos OIDs para Selo Eletrônico (SE-S, SE-H) e CNPJ da AR.\n\nPrioriza extração de CPF e CNPJ pelo campo serialNumber no DN do certificado.\n\nGarante retrocompatibilidade mantendo extração via SubjectAlternativeNames (SAN) para perfis legados.\n\nRemove fallback depreciado que extraía dados fatiando o Common Name (CN).\n\nAdiciona BasicCertificateTest validando extrações de CPF e CNPJ nos novos padrões.",
          "is_bot": false,
          "headline": "feat: adiciona suporte aos novos perfis de certificados (Resolução 21…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-11T11:00:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2231c334383cce5c9e1e9ce439f67a94e0e4e21c",
          "body": "…iciona testes",
          "is_bot": false,
          "headline": "fix: corrige parsing de PolicyInfo para lidar com revocationDate e ad…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-06-01T14:44:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10a8dccc6c477620f3e136b1c47bbfdd6b00b9f2",
          "body": "A partir do xmlsec 2.3.x, Canonicalizer.canonicalizeSubtree(Node) que\nretornava byte[] foi removida. A nova assinatura é\ncanonicalizeSubtree(Node, OutputStream) que retorna void.\n\nArquivos corrigidos (8 chamadas no total):\n- XMLSigner.java (2 chamadas)\n- XMLChecker.java (3 chamadas)\n- XMLSignedAttri\n[…]\nByteArrayOutputStream();\n                c14n.canonicalizeSubtree(node, baos);\n                byte[] result = baos.toByteArray();\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: adapta canonicalizeSubtree para API do xmlsec 2.3.x",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-29T18:21:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c5eb6e2917f22ac1b4485a5dd8ae4d17b72d47a",
          "body": "- ASN1Object: substitui System.out.println por logger (SLF4J)\n- PolicyIssuerName: substitui System.out.println por logger (SLF4J)\n- PolicyInfo: corrige condição que usava 'secondObject' (índice 1)\n  em vez de 'revocationObject' (índice 3) para detectar revocationDate\n- policy-impl-xades: atualiza xmlsec 2.0.10 → 2.3.5 (fix de segurança,\n  resolve Dependabot PR #397 do upstream demoiselle/signer)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: corrige bugs e atualiza xmlsec para 2.3.5",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-29T17:59:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f7016af5000d3be05b15f231d70d8598f5068bb0",
          "body": "Em Java 25+, entradas OtherName no SAN podem ter mais de 2 elementos,\nfazendo list.size() != 2 lançar exceção e abortar todo o loop.\nResultado: mapa 'extras' vazio, getCNPJ() retorna null (NPE nos chamadores).\n\nCorreção:\n- Muda condição para < 2 (tolera listas com 2+ elementos)\n- Remove throw, usa continue para pular entrada inválida\n- Muda logger.error para logger.info (não é erro crítico)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: corrige parsing de SubjectAlternativeNames com mais de 2 elementos",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-28T12:19:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b43814e217c6263d6a9d8cd4a9182de57086e044",
          "body": "…externos\n\n- Versão 3.0.1 → 3.10.1 (build, reporting, perfil aggregated)\n- Substitui failOnError=false por <doclint>none</doclint> (causa raiz dos erros)\n- Adiciona detectJavaApiLink=false e detectOfflineLinks=false para evitar\n  falhas de redirecionamento HTTP nos links externos (Oracle, BouncyCastle)\n- Remove links externos que causavam 'Unexpected redirection' errors\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(javadoc): atualiza plugin 3.10.1, doclint=none, desabilita links …",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-26T16:13:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "751c3b6a40bb9172b322afe17c0421acee15e65c",
          "body": "… failOnError\\n\\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: maven-javadoc-plugin — add BouncyCastle javadoc link and disable…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-26T13:33:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2882ff9b746131472efd1e695c8dfc0f1b09e623",
          "body": "BouncyCastle 1.80 passou a retornar DLTaggedObject e DLSequence\nao invés de DERTaggedObject e DERSequence ao parsear arquivos DER.\n\nAs verificações 'instanceof DERTaggedObject' e 'instanceof DERSequence'\nfalhavam silenciosamente, fazendo com que signerAndVeriferRules ficasse\nnull em CommonRules.pars\n[…]\nence por ASN1Sequence\n- Atualizados casts e imports correspondentes\n- ASN1Object.getDERSequence() e getDEREnumerated() atualizados\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: corrige parsing de política ASN.1 com BouncyCastle 1.80",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-25T20:50:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f9639a6b5da2d82bd2500b2fb392a50f9c567a6b",
          "body": "4.5.1",
          "is_bot": false,
          "headline": "Merge pull request #442 from demoiselle/4.5.1",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-05-21T18:08:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "001bc864fecbb46e84eabac218cf56825681ee94",
          "body": "4.5.1",
          "is_bot": false,
          "headline": "Merge pull request #441 from evandrojr/4.5.1",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-05-21T18:06:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "332d152220012373c69bbc796fc9092cc8d1c82d",
          "body": null,
          "is_bot": false,
          "headline": "Atualiza a versão para 4.6.0-SNAPSHOT em arquivos de documentação",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-20T14:13:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cee764b6150481343e999fb77ede912364e08971",
          "body": null,
          "is_bot": false,
          "headline": "4.6.0-SNAPSHOT",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-20T13:59:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ec76b3a21aed44075fada7681e6a80fe8a84d03",
          "body": null,
          "is_bot": false,
          "headline": "Remove versão SNAPSHOT e define versão estável 4.5.1 no pom.xml",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-20T13:50:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24b0cbb2137562eeba20298fc89540f56b4a5f80",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch '4.5.1' into 4.6.0-com-4.5.1",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-20T13:49:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb381c8fd6802bdd4947444050fb4ddf88420717",
          "body": "…erar-versao.sh",
          "is_bot": false,
          "headline": "Atualiza versão para 4.5.1 em todos os arquivos pom.xml e no script g…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-18T14:26:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6637283ae54c08384d0d08aa95c6c578f0a33b0",
          "body": null,
          "is_bot": false,
          "headline": "Atualiza versão para 4.5.1 em arquivos de documentação e pom.xml",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-18T14:17:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63956df148a0ea65d2903a781e249c9f46ee4515",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Adiciona release notes 4.5.1 e atualiza README",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-15T13:55:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e5e2d661457a5b0b9c3808a6b8fe8850621234c",
          "body": "…o HTTPS\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Cache SSLContext ICP-Brasil para evitar reconstrução a cada requisiçã…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-15T13:48:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "919105653d96039eea7632145bf755141a2c0b00",
          "body": "Ao fazer fallback de HTTP para HTTPS, a JVM rejeitava certificados\ndos servidores do governo (ex: politicas.icpbrasil.gov.br) por não\nter os CAs da ICP-Brasil no truststore padrão.\n\nA solução carrega os CAs disponíveis via ProviderCAFactory (ServiceLoader)\ne constrói um SSLContext confiável para a conexão HTTPS. Um ThreadLocal\nprevine recursão infinita quando providers online também usam Downloads.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Corrige erro PKIX em conexões HTTPS usando cadeia ICP-Brasil",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-15T13:45:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0ce0ead8fe30b4226181a3522bbe48d5468c88b7",
          "body": "…o de versão",
          "is_bot": false,
          "headline": "Adiciona script gerar-versao.sh para automatizar o processo de criaçã…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-15T13:32:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03697916b2f90bceb4ec9b224b9ecb89e3343a2e",
          "body": "…HOT em todos os arquivos pom.xml",
          "is_bot": false,
          "headline": "Aumento timeout download cadeias e Atualiza a versão para 4.5.1-SNAPS…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-15T13:31:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93e49913eb033933cd2e40d0bd4e48c3c64dfa8c",
          "body": "Tika 2.9.3 chama UnsynchronizedByteArrayInputStream.builder() que foi\nintroduzido no commons-io 2.12.0. Atualiza todas as declaracoes:\n- bom/pom.xml: 2.11.0 -> 2.15.1\n- policy-impl-pades/pom.xml: 2.8.0 -> 2.15.1\n- policy-impl-xades/pom.xml: 2.6 -> 2.15.1\n- signer-xmldsig/pom.xml: 2.6 -> 2.15.1\n- signer-examples/pom.xml: 2.8.0 -> 2.15.1\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: atualiza commons-io de versoes antigas para 2.15.1",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T20:48:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "21ec1faa922b9062fa9fb26568487d2cdd6502a8",
          "body": "…ado não é encontrada",
          "is_bot": false,
          "headline": "Loga informação do fornecedor e da cadeia quando a cadeia do certific…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T20:27:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "515ca3265edccd1318f30fd4e08901c37a54cfae",
          "body": "…1.80\n\nBouncyCastle 1.80 retorna DLTaggedObject em vez de DERTaggedObject ao\nler sequencias via ASN1InputStream. Os casts para DERTaggedObject lancavam\nClassCastException silenciosa no CertificateExtra, deixando o mapa extras\nvazio. Como resultado, isCertificatePF()/isCertificatePJ() retornavam fals\n[…]\nt (superclasse), ASN1OctetString e ASN1String\nem vez das classes DER* concretas, tornando o parsing robusto para\nDL*, DER* e BER*.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: corrige parsing de OtherName do SAN compativel com BouncyCastle …",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T19:49:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1bee215294bfb789bc3bc0cd8660a3fc98a6c09",
          "body": null,
          "is_bot": false,
          "headline": "sMerge branch 'master' of github.com:evandrojr/signer",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T12:09:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7d757dc483801128ba7ee483229fe1a95433411",
          "body": "…ado não é encontrada",
          "is_bot": false,
          "headline": "Loga informação do fornecedor e da cadeia quando a cadeia do certific…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T12:09:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8dda5e127c6120d862ac62e3faa5b99c81c1a85",
          "body": "…SignaturePolicy (campo OPTIONAL ETSI)",
          "is_bot": false,
          "headline": "fix: trata NPE quando signerAndVeriferRules é null em CAdESChecker e …",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-14T11:25:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce9112fb32f9fa24f0807ac2a92849da0ceab837",
          "body": "…ampo OPTIONAL ETSI)",
          "is_bot": false,
          "headline": "fix: trata NPE quando signingCertTrustCondition é null na política (c…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-13T14:18:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfe581c53d5a26aa455713185d22990643688400",
          "body": "… envelopSignature",
          "is_bot": false,
          "headline": "fix: restaura declarações de attributeFactory e unsignedAttributes em…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-13T14:09:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79ac0972baf7827d60c85ca6c4eaaa60e52528df",
          "body": "… OPTIONAL ETSI)",
          "is_bot": false,
          "headline": "fix: trata NPE quando signerAndVeriferRules é null na política (campo…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-13T13:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0d048fee4b84ff3043ef79c86cf5f0cf869d215",
          "body": "…o OPTIONAL ETSI)",
          "is_bot": false,
          "headline": "fix: trata NPE quando algorithmConstraintSet é null na política (camp…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-13T13:51:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6eb9cf2e87662478a7ae24380a6be6582212fc4d",
          "body": "PDFs do Gov.br com assinatura ML-DSA-44 mas certificado com chave RSA\ncausavam InvalidKeyException nao capturada que propagava como\nSignerException sem adicionar o SignatureInformations ao resultado.\n\nSolucao:\n- Adiciona catch(CMSSignerDigestMismatchException) e catch(CMSException)\n  no bloco intern\n[…]\ne ficou inalcancavel\n- Mismatch de algoritmo/chave agora marca a assinatura como invalida\n  com mensagem clara, sem lancar excecao\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: trata CMSException no verify para mismatch algoritmo/chave (ML-DSA)",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-12T20:12:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fce36bf3b5d73ec5f8c3a436277d61b416403ce6",
          "body": "Evita que Maven resolva 1.80.0.redhat-00001 (fork Red Hat) via\nrange [1.80,1.81) declarada pelo bcmail-jdk18on:1.80. A versão redhat\nnão tem o fix de verificação ML-DSA presente no 1.80 padrão.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: pina bcpkix/bcprov/bcutil 1.80 explicitamente no BOM",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-12T19:56:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4679ffbe5d4ce84dbfadb76714986116942febce",
          "body": "BC 1.79 tinha bug na camada JCA que causava:\n  InvalidKeyException: unknown public key passed to ML-DSA\nao verificar assinaturas pós-quânticas ML-DSA de documentos externos\n(ex: PDFs assinados pelo Gov.br). Corrigido na 1.80.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: atualiza BouncyCastle 1.79 → 1.80 para corrigir verificação ML-DSA",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-12T19:49:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4ccc6e55c549f025b52a5d057976649e2f4e9f92",
          "body": "feat: suporte ML-DSA-44/65/87 (FIPS 204) - algoritmos pos-quanticos",
          "is_bot": false,
          "headline": "Merge pull request #2 from iasegura/copilot-suporte-ML-DSA-44",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-05-12T19:22:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5eef48e377b50022cf3f09f15c07a40ac8f8ab51",
          "body": "…-ML-DSA-44",
          "is_bot": false,
          "headline": "Merge branch '4.5.1-Novo-algoritmo-pos-quantico' into copilot-suporte…",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-05-12T19:15:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d96f9c493539c4291a50c13001596006c4d92ec",
          "body": "- Registra OIDs ML-DSA-44/65/87 em AlgorithmNames, SignerAlgorithmEnum e AsymmetricAlgorithmEnum\n- Corrige cast RSAKey em CAdESSigner para suportar chaves EC e pos-quanticas\n- Corrige NPE em CAdESChecker para algoritmos desconhecidos\n- Atualiza Bouncy Castle de 1.62 (jdk15on) para 1.79 (jdk18on)\n- A\n[…]\ntarget de 1.7 para 1.8\n- Corrige API BC: getObject() -> getBaseObject() (5 arquivos)\n- Corrige SunPKCS11 para Java 9+ (9 arquivos)\n- Adiciona testes unitarios e de integracao (sign/verify) para ML-DSA",
          "is_bot": false,
          "headline": "feat: suporte ML-DSA-44/65/87 (FIPS 204) - algoritmos pos-quanticos",
          "author_name": "Gabriel Almeida Gonçalves",
          "author_login": "gabriel4567",
          "committed_at": "2026-05-11T16:39:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba649c645b8582ae22923cc3b71cc9a7581015f2",
          "body": "O método fixAliases() acessava o campo privado KeyStore.keyStoreSpi\nvia reflexão para corrigir o bug 6672015 (aliases duplicados no SunMSCAPI).\nEsse bug foi resolvido desde a build 101 do Java 1.8 (bug 6483657).\n\nNo Java 9+, field.setAccessible(true) em campos de módulos fechados lança\nInaccessibleObjectException sem add-opens. Como o workaround é desnecessário\npara qualquer Java >= 1.8.0_101, o corpo do método foi removido.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: remove reflexão em MSKeyStoreLoader incompatível com Java 9+",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-08T16:59:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ea02108222f856a77ad8b74de9677a08d95ebeb1",
          "body": "Os construtores SunPKCS11(InputStream) e SunPKCS11(String) foram\nremovidos no Java 9. Substitui por Provider.configure() que é a\nAPI pública oficial desde o Java 9.\n\nProblemas corrigidos:\n- NoSuchMethodException ao tentar instanciar SunPKCS11 via reflexão\n  causava NullPointerException em ex.getCaus\n[…]\no removida: login feito via AuthProvider.login() (API pública)\n- Verificação null-safe para ex.getCause() em todos os catch blocks\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: compatibilidade SunPKCS11 com Java 9+",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-05-07T19:51:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae88c273f2aeba4a9050979ab3e0f7a4f664d066",
          "body": "…nível\n\n- Adiciona método CRLValidator.validate(X509Certificate, Date) que verifica se o certificado estava revogado ANTES de uma data específica\n- Modifica CAdESChecker para extrair timestamp antes da validação CRL\n- Usa data do timestamp (quando disponível) ao invés da data atual para validação de\n[…]\nrtificado era válido no momento da assinatura)\n- Atualiza BOM para versão 4.5.1-SNAPSHOT\n\nIssue: Assinaturas com timestamp válido mas certificado revogado posteriormente devem ser consideradas válidas",
          "is_bot": false,
          "headline": "Valida revogação de certificado usando data do timestamp quando dispo…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-02-11T13:16:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cff39e87371de38253873f71aa8f9f6bd0f67fd",
          "body": "- Teste CAdESSigningCertificateV2Test.java\n- Verifica presença do atributo signing-certificate-v2 (OID 1.2.840.113549.1.9.16.2.47)\n- Valida estrutura do atributo em assinaturas SHA-256\n- Documenta validação completa feita por CAdESChecker\n- Inclui keystore de teste para execução\n\nTestes: 2 passed, 0 failed, 0 skipped\nBuild: SUCCESS",
          "is_bot": false,
          "headline": "Adiciona teste unitário para validação RFC 5035",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-02-11T11:47:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c8d8cb0d7f67665dd560bd3598a32d47b18ed14",
          "body": "- Adiciona validação de hash do certificado nos atributos assinados\n- Previne substituição de certificado (ataque man-in-the-middle)\n- Integrado à arquitetura de políticas ICP-Brasil\n- Suporte a SHA-256/384/512 (v2) e SHA-1 (v1 legado)\n- Estabelece padrão para validação semântica de outros atributos\n[…]\ncas\n- Métodos: validateMandatedAttributeContent, validateSigningCertificateV2/V1\n- Mensagens: error.rfc5035.* e warn.rfc2634.* (pt_BR e en_US)\n- Conformidade: ETSI EN 319 102-1 v1.4.1 clausula 5.2.8.1",
          "is_bot": false,
          "headline": "Implementa validação RFC 5035 (signing-certificate-v2)",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-02-10T19:34:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bded984f87f1c2aa7099ce8b3fbcb396a17c4463",
          "body": "Atualizar versao para 4.5.1-SNAPSHOT em todos os arquivos pom.xml",
          "is_bot": false,
          "headline": "Tenta HTTP primeiro, depois HTTPS sem verificacao de certificado",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2026-01-29T14:10:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0fbac1c1ce4cf4e3181cb186f9a4e82062e22eb",
          "body": null,
          "is_bot": false,
          "headline": "Delete gerar-versao.sh",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-01-23T14:18:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82d2faff2ce662efa07ba5c6a455330111c02dfd",
          "body": null,
          "is_bot": false,
          "headline": "Delete Todo-4.5.0.txt",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-01-23T14:17:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a48898879ead5ac8f8db5947ca7d64c6c34f37ba",
          "body": "Incorporação versão 4.5.0 ao master",
          "is_bot": false,
          "headline": "Merge pull request #438 from demoiselle/4.5.0-SNAPSHOT",
          "author_name": "Evandro Magalhães Leite Júnior",
          "author_login": "evandrojr",
          "committed_at": "2026-01-23T14:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e79734ae965b52c8523c689cd0e29b1b3788bc92",
          "body": null,
          "is_bot": false,
          "headline": "Update documentation to version 4.5.0",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T17:15:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0514bd639afa6a88366ec1bae81199f640874ef1",
          "body": "…o pom.xml",
          "is_bot": false,
          "headline": "Adicionar Evandro Magalhães Leite Júnior à lista de desenvolvedores n…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T15:46:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77967dba26c13ce2b5a169b9b43eb652a6238ecb",
          "body": "… for 4.5.0 release",
          "is_bot": false,
          "headline": "Add GPG signing plugin and fix Maven Central deployment configuration…",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T14:54:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38871eeb239d46087bc817103c0a78f684c28433",
          "body": null,
          "is_bot": false,
          "headline": "Fix Maven Central repository configuration for release deployment",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T14:47:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a2b38d7838e7077b3d8a697e2a968595a623037",
          "body": null,
          "is_bot": false,
          "headline": "Fix merge conflict in pom.xml",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T14:04:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ca9e099e11f7374cdc5c1e7f4e15239a3681335",
          "body": null,
          "is_bot": false,
          "headline": "Merge: resolve conflict and set version to 4.5.0",
          "author_name": "Evandro Jr",
          "author_login": "evandrojr",
          "committed_at": "2025-11-21T14:02:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 3,
      "commits_last_year": 113,
      "latest_release_at": "2025-11-21T14:01:49Z",
      "latest_release_tag": "4.5.0",
      "releases_from_tags": true,
      "days_since_last_push": 1,
      "active_weeks_last_year": 20,
      "days_since_latest_release": 245,
      "mean_days_between_releases": 1569.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "org.demoiselle.signer:signer-core",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-core",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:55:52Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:chain-iti",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/chain-iti",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:55:43Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:signer-timestamp",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-timestamp",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:59:32Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:signer-cryptography",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-cryptography",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:55:51Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:policy-engine",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/policy-engine",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 45,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T18:30:31Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:signer-xmldsig",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-xmldsig",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:59:33Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil",
          "exists": true,
          "license": "GNU Lesser General Public License, Version 3",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/chain-icp-brasil",
          "is_deprecated": false,
          "latest_version": "4.6.1",
          "repository_url": "https://github.com/demoiselle/signer",
          "versions_count": 45,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T14:55:48Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        }
      ]
    },
    "popularity": {
      "forks": 80,
      "stars": 172,
      "watchers": 30,
      "fork_history": {
        "days": [
          {
            "date": "2017-01-27",
            "count": 1
          },
          {
            "date": "2017-10-03",
            "count": 1
          },
          {
            "date": "2017-10-11",
            "count": 1
          },
          {
            "date": "2017-10-23",
            "count": 1
          },
          {
            "date": "2017-11-10",
            "count": 1
          },
          {
            "date": "2018-01-09",
            "count": 1
          },
          {
            "date": "2018-02-05",
            "count": 1
          },
          {
            "date": "2018-04-27",
            "count": 1
          },
          {
            "date": "2018-08-08",
            "count": 2
          },
          {
            "date": "2018-09-04",
            "count": 1
          },
          {
            "date": "2018-10-09",
            "count": 1
          },
          {
            "date": "2018-11-01",
            "count": 1
          },
          {
            "date": "2018-11-02",
            "count": 1
          },
          {
            "date": "2019-02-14",
            "count": 1
          },
          {
            "date": "2019-03-26",
            "count": 1
          },
          {
            "date": "2019-03-29",
            "count": 2
          },
          {
            "date": "2019-06-05",
            "count": 1
          },
          {
            "date": "2019-06-06",
            "count": 1
          },
          {
            "date": "2019-07-11",
            "count": 1
          },
          {
            "date": "2019-08-03",
            "count": 1
          },
          {
            "date": "2019-08-08",
            "count": 1
          },
          {
            "date": "2019-11-11",
            "count": 1
          },
          {
            "date": "2020-03-29",
            "count": 1
          },
          {
            "date": "2020-05-12",
            "count": 1
          },
          {
            "date": "2020-05-26",
            "count": 1
          },
          {
            "date": "2020-06-22",
            "count": 1
          },
          {
            "date": "2020-06-25",
            "count": 1
          },
          {
            "date": "2020-08-25",
            "count": 1
          },
          {
            "date": "2020-08-26",
            "count": 1
          },
          {
            "date": "2020-09-11",
            "count": 1
          },
          {
            "date": "2020-11-10",
            "count": 1
          },
          {
            "date": "2020-12-31",
            "count": 1
          },
          {
            "date": "2021-01-18",
            "count": 1
          },
          {
            "date": "2021-03-06",
            "count": 1
          },
          {
            "date": "2021-05-27",
            "count": 1
          },
          {
            "date": "2021-06-02",
            "count": 1
          },
          {
            "date": "2021-07-07",
            "count": 1
          },
          {
            "date": "2021-08-16",
            "count": 1
          },
          {
            "date": "2021-08-19",
            "count": 1
          },
          {
            "date": "2021-08-24",
            "count": 1
          },
          {
            "date": "2021-08-30",
            "count": 1
          },
          {
            "date": "2021-10-04",
            "count": 1
          },
          {
            "date": "2021-10-09",
            "count": 1
          },
          {
            "date": "2021-11-16",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-02-17",
            "count": 1
          },
          {
            "date": "2022-03-15",
            "count": 1
          },
          {
            "date": "2022-03-16",
            "count": 2
          },
          {
            "date": "2022-03-29",
            "count": 1
          },
          {
            "date": "2022-05-30",
            "count": 1
          },
          {
            "date": "2022-09-30",
            "count": 1
          },
          {
            "date": "2022-11-16",
            "count": 1
          },
          {
            "date": "2023-04-26",
            "count": 1
          },
          {
            "date": "2023-06-16",
            "count": 1
          },
          {
            "date": "2023-08-29",
            "count": 1
          },
          {
            "date": "2023-10-17",
            "count": 1
          },
          {
            "date": "2023-10-20",
            "count": 1
          },
          {
            "date": "2023-11-03",
            "count": 1
          },
          {
            "date": "2024-02-08",
            "count": 1
          },
          {
            "date": "2024-02-26",
            "count": 1
          },
          {
            "date": "2024-06-11",
            "count": 1
          },
          {
            "date": "2024-07-30",
            "count": 1
          },
          {
            "date": "2024-08-15",
            "count": 1
          },
          {
            "date": "2024-11-07",
            "count": 1
          },
          {
            "date": "2024-11-18",
            "count": 1
          },
          {
            "date": "2025-04-04",
            "count": 1
          },
          {
            "date": "2025-04-06",
            "count": 1
          },
          {
            "date": "2025-06-03",
            "count": 1
          },
          {
            "date": "2025-06-10",
            "count": 1
          },
          {
            "date": "2025-06-20",
            "count": 1
          },
          {
            "date": "2025-07-15",
            "count": 1
          },
          {
            "date": "2025-07-30",
            "count": 1
          },
          {
            "date": "2025-08-12",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 77,
        "total_forks": 80
      },
      "star_history": null,
      "open_issues_and_prs": 46
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "automacao-importador/go.mod",
        "bom/pom.xml",
        "chain-icp-brasil-homolog/go.mod",
        "chain-icp-brasil-homolog/pom.xml",
        "chain-icp-brasil/pom.xml",
        "chain-iti-homolog/pom.xml",
        "chain-iti/pom.xml",
        "chain-serpro-neosigner/pom.xml",
        "core/pom.xml",
        "cryptography/pom.xml",
        "documentation/reference/pom.xml",
        "parent/pom.xml",
        "policy-engine/pom.xml",
        "policy-impl-cades/pom.xml",
        "policy-impl-pades/pom.xml",
        "policy-impl-xades/pom.xml",
        "pom.xml",
        "signer-examples/pom.xml",
        "signer-xmldsig/pom.xml",
        "timestamp/pom.xml"
      ],
      "largest_source_bytes": 208648,
      "source_files_sampled": 370,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "automacao-importador/go.mod",
        "bom/pom.xml",
        "chain-icp-brasil-homolog/go.mod",
        "chain-icp-brasil-homolog/pom.xml",
        "chain-icp-brasil/pom.xml",
        "chain-iti-homolog/pom.xml",
        "chain-iti/pom.xml",
        "chain-serpro-neosigner/pom.xml",
        "core/pom.xml",
        "cryptography/pom.xml",
        "parent/pom.xml",
        "policy-engine/pom.xml",
        "policy-impl-cades/pom.xml",
        "policy-impl-pades/pom.xml",
        "policy-impl-xades/pom.xml",
        "pom.xml",
        "signer-examples/pom.xml",
        "signer-xmldsig/pom.xml",
        "timestamp/pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 9,
        "malicious_count": 0,
        "assessed_package": "maven:org.demoiselle.signer:signer-core@4.6.1",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "maven"
      ],
      "dependencies": [
        {
          "name": "golang.org/x/net",
          "manifest": "automacao-importador/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.17.0"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil-homolog",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:signer-cryptography",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:policy-engine",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-cades",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-xades",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-pades",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:signer-timestamp",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:chain-serpro-neosigner",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.demoiselle.signer:chain-iti",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${demoiselle.signer.version}"
        },
        {
          "name": "org.apache.logging.log4j:log4j-api",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.apache.logging.log4j:log4j-core",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.apache.logging.log4j:log4j-1.2-api",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.slf4j:slf4j-log4j12",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.32"
        },
        {
          "name": "org.bouncycastle:bcmail-lts8on",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.73.11"
        },
        {
          "name": "org.bouncycastle:bcpkix-lts8on",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.73.11"
        },
        {
          "name": "org.bouncycastle:bcprov-lts8on",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.73.11"
        },
        {
          "name": "org.bouncycastle:bcutil-lts8on",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.73.11"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.15.1"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "chain-icp-brasil-homolog/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.42.0"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "chain-icp-brasil-homolog/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "chain-icp-brasil/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "chain-iti-homolog/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil-homolog",
          "manifest": "chain-iti-homolog/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "chain-iti/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil",
          "manifest": "chain-iti/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:chain-serpro-neosigner",
          "manifest": "chain-iti/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "chain-serpro-neosigner/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil",
          "manifest": "chain-serpro-neosigner/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.apache.logging.log4j:log4j-api",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.apache.logging.log4j:log4j-core",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.apache.logging.log4j:log4j-1.2-api",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.slf4j:slf4j-log4j12",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.32"
        },
        {
          "name": "com.sun.xml.bind:jaxb-core",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.0.1"
        },
        {
          "name": "javax.xml.bind:jaxb-api",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.1"
        },
        {
          "name": "com.sun.xml.bind:jaxb-impl",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "cryptography/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:bom",
          "manifest": "parent/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.apache.logging.log4j:log4j-1.2-api",
          "manifest": "parent/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.25.4"
        },
        {
          "name": "org.slf4j:slf4j-log4j12",
          "manifest": "parent/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.32"
        },
        {
          "name": "org.bouncycastle:bcmail-lts8on",
          "manifest": "parent/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.73.11"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "policy-engine/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "policy-engine/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.15.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "policy-impl-cades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-cryptography",
          "manifest": "policy-impl-cades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:policy-engine",
          "manifest": "policy-impl-cades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-timestamp",
          "manifest": "policy-impl-cades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "policy-impl-pades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-cryptography",
          "manifest": "policy-impl-pades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:policy-engine",
          "manifest": "policy-impl-pades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-cades",
          "manifest": "policy-impl-pades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.apache.santuario:xmlsec",
          "manifest": "policy-impl-xades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.5"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-cades",
          "manifest": "policy-impl-xades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "policy-impl-xades/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.15.1"
        },
        {
          "name": "org.demoiselle.signer:core",
          "manifest": "signer-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.7.1"
        },
        {
          "name": "org.demoiselle.signer:chain-icp-brasil",
          "manifest": "signer-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.7.1"
        },
        {
          "name": "org.demoiselle.signer:policy-impl-cades",
          "manifest": "signer-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.7.1"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "signer-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.15.1"
        },
        {
          "name": "org.apache.santuario:xmlsec",
          "manifest": "signer-xmldsig/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.2.6"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "signer-xmldsig/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "signer-xmldsig/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.15.1"
        },
        {
          "name": "org.demoiselle.signer:signer-cryptography",
          "manifest": "timestamp/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "org.demoiselle.signer:signer-core",
          "manifest": "timestamp/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.6.1"
        },
        {
          "name": "com.mashape.unirest:unirest-java",
          "manifest": "timestamp/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.4.9"
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "timestamp/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.22.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "golang.org/x/net",
            "direct": true,
            "version": "v0.17.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": true,
            "version": "v0.42.0",
            "ecosystem": "go"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": true,
            "version": "2.22.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.mashape.unirest:unirest-java",
            "direct": true,
            "version": "1.4.9",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-core",
            "direct": true,
            "version": "2.3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-impl",
            "direct": true,
            "version": "2.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": "2.15.1",
            "ecosystem": "maven"
          },
          {
            "name": "javax.xml.bind:jaxb-api",
            "direct": true,
            "version": "2.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.logging.log4j:log4j-1.2-api",
            "direct": true,
            "version": "2.25.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.logging.log4j:log4j-api",
            "direct": true,
            "version": "2.25.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.logging.log4j:log4j-core",
            "direct": true,
            "version": "2.25.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.santuario:xmlsec",
            "direct": true,
            "version": "2.2.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.santuario:xmlsec",
            "direct": true,
            "version": "2.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcmail-lts8on",
            "direct": true,
            "version": "2.73.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcpkix-lts8on",
            "direct": true,
            "version": "2.73.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcprov-lts8on",
            "direct": true,
            "version": "2.73.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcutil-lts8on",
            "direct": true,
            "version": "2.73.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:bom",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:chain-icp-brasil",
            "direct": true,
            "version": "3.7.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:chain-icp-brasil",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:chain-icp-brasil-homolog",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:chain-iti",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:chain-serpro-neosigner",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:core",
            "direct": true,
            "version": "3.7.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:policy-engine",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:policy-impl-cades",
            "direct": true,
            "version": "3.7.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:policy-impl-cades",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:policy-impl-pades",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:policy-impl-xades",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:signer-core",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:signer-cryptography",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.demoiselle.signer:signer-timestamp",
            "direct": true,
            "version": "4.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-log4j12",
            "direct": true,
            "version": "1.7.32",
            "ecosystem": "maven"
          },
          {
            "name": "br.gov.frameworkdemoiselle.documentation:demoiselle-docbook-xslt",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "br.gov.frameworkdemoiselle.documentation:demoiselle-jdocbook-style",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "commons-codec:commons-codec",
            "direct": false,
            "version": "1.10",
            "ecosystem": "maven"
          },
          {
            "name": "commons-codec:commons-codec",
            "direct": false,
            "version": "1.14",
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": "4.13.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-assembly-plugin",
            "direct": false,
            "version": "2.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-deploy-plugin",
            "direct": false,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-failsafe-plugin",
            "direct": false,
            "version": "2.22.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "3.10.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-scm-plugin",
            "direct": false,
            "version": "1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.wagon:wagon-ssh",
            "direct": false,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.pdfbox:pdfbox",
            "direct": false,
            "version": "2.0.24",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.maven.plugins:maven-jdocbook-plugin",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.seam:seam-docbook-xslt",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.seam:seam-jdocbook-style",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.weld:weld-docbook-xslt",
            "direct": false,
            "version": "1.1.1-Beta5",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss:jbossorg-jdocbook-style",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter",
            "direct": false,
            "version": "5.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.sonatype.central:central-publishing-maven-plugin",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "maven"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 57,
        "direct_count": 33,
        "indirect_count": 24
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 33,
        "open_issues": 40,
        "closed_ratio": 0.9,
        "closed_issues": 362,
        "closed_unmerged_prs": 11
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "esaito",
          "commits": 591,
          "avatar_url": "https://avatars.githubusercontent.com/u/1101956?v=4"
        },
        {
          "type": "User",
          "login": "juliancesar",
          "commits": 127,
          "avatar_url": "https://avatars.githubusercontent.com/u/4247825?v=4"
        },
        {
          "type": "User",
          "login": "evandrojr",
          "commits": 123,
          "avatar_url": "https://avatars.githubusercontent.com/u/939608?v=4"
        },
        {
          "type": "User",
          "login": "FabianoK",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/4664271?v=4"
        },
        {
          "type": "User",
          "login": "kyriosdata",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/1735792?v=4"
        },
        {
          "type": "User",
          "login": "eduardomg",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/1227746?v=4"
        },
        {
          "type": "User",
          "login": "FabianoSerpro",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/197613080?v=4"
        },
        {
          "type": "User",
          "login": "fabiomdj",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/69532695?v=4"
        },
        {
          "type": "User",
          "login": "laubstein",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/457100?v=4"
        },
        {
          "type": "User",
          "login": "botelhojp",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/1793654?v=4"
        }
      ],
      "contributors_sampled": 20,
      "top_contributor_share": 0.649
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 7,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/2 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 6 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "16 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "89c54a31fd05b8a7a410bb9c5c5e9c0ebe4a9d7c",
        "ran_at": "2026-07-25T10:35:29Z",
        "aggregate_score": 3.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T07:22:03Z",
      "oldest_open_prs": [
        {
          "number": 444,
          "created_at": "2026-07-03T04:07:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 445,
          "created_at": "2026-07-04T05:20:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 446,
          "created_at": "2026-07-04T05:20:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 447,
          "created_at": "2026-07-04T05:20:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 452,
          "created_at": "2026-07-15T20:44:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 453,
          "created_at": "2026-07-24T07:22:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-15T20:42:29Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 86,
          "created_at": "2017-07-02T23:50:51Z",
          "last_comment_at": "2019-11-24T13:23:46Z",
          "last_comment_author": "joserenecampa"
        },
        {
          "number": 89,
          "created_at": "2017-07-20T14:20:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2017-11-09T17:01:24Z",
          "last_comment_at": "2018-03-20T11:46:37Z",
          "last_comment_author": "alissonns"
        },
        {
          "number": 113,
          "created_at": "2017-11-23T12:56:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 114,
          "created_at": "2017-11-23T12:57:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 138,
          "created_at": "2018-03-13T12:34:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 223,
          "created_at": "2019-08-14T21:46:17Z",
          "last_comment_at": "2024-01-11T13:50:29Z",
          "last_comment_author": "alexandre-mbm"
        },
        {
          "number": 230,
          "created_at": "2019-11-25T18:05:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 255,
          "created_at": "2020-06-29T14:30:02Z",
          "last_comment_at": "2020-06-29T20:28:59Z",
          "last_comment_author": "esaito"
        },
        {
          "number": 266,
          "created_at": "2020-09-04T19:39:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 304,
          "created_at": "2021-07-25T09:07:50Z",
          "last_comment_at": "2024-12-28T19:07:29Z",
          "last_comment_author": "denydias"
        },
        {
          "number": 322,
          "created_at": "2021-11-04T13:34:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 336,
          "created_at": "2022-03-29T21:29:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 343,
          "created_at": "2022-05-08T21:09:23Z",
          "last_comment_at": "2022-05-13T15:01:18Z",
          "last_comment_author": "HelloWar75"
        },
        {
          "number": 345,
          "created_at": "2022-05-30T13:09:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 360,
          "created_at": "2022-12-30T17:04:32Z",
          "last_comment_at": "2023-02-15T10:01:29Z",
          "last_comment_author": "leanmaster"
        },
        {
          "number": 369,
          "created_at": "2023-04-19T14:07:55Z",
          "last_comment_at": "2024-10-18T12:46:33Z",
          "last_comment_author": "williamargenton"
        },
        {
          "number": 377,
          "created_at": "2023-06-21T12:49:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 382,
          "created_at": "2023-08-07T13:48:47Z",
          "last_comment_at": "2023-08-11T20:56:28Z",
          "last_comment_author": "esaito"
        },
        {
          "number": 383,
          "created_at": "2023-08-18T11:13:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/demoiselle/signer",
    "host": "github.com",
    "name": "signer",
    "owner": "demoiselle"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 49,
        "vitality": 64,
        "community": 55,
        "governance": 66,
        "engineering": 58
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 64,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 113,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 20
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "20/52 weeks with commits",
                "points": 13.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 20
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "113 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 113
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "releases_count": 3,
              "latest_release_tag": "4.5.0",
              "releases_from_tags": true,
              "days_since_latest_release": 245,
              "mean_days_between_releases": 1569.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "3 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 245 days ago",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 245
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1569.5 days",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1569.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 9,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 9 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "forks": 80,
              "stars": 172,
              "watchers": 30,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "172 stars",
                "points": 36.2,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 172
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "80 forks",
                "points": 15.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 80
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "30 watchers",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (LGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "LGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 66,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 20,
              "top_contributor_share": 0.649
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 65% of commits",
                "points": 7.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 65
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "20 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "merged_prs": 33,
              "open_issues": 40,
              "closed_issues": 362,
              "issue_closed_ratio": 0.9,
              "closed_unmerged_prs": 11
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "90% of issues closed",
                "points": 42.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 90
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "33/44 decided PRs merged",
                "points": 28.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 33,
                      "decided": 44
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/2 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "followers": 28,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "demoiselle",
              "public_repos": 29,
              "account_age_days": 5685
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "28 followers of demoiselle",
                "points": 10.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 28,
                      "login": "demoiselle"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "29 public repos, account ~15 yr old",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 29
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "org.demoiselle.signer:signer-core",
                "org.demoiselle.signer:chain-iti",
                "org.demoiselle.signer:signer-timestamp",
                "org.demoiselle.signer:signer-cryptography",
                "org.demoiselle.signer:policy-engine",
                "org.demoiselle.signer:signer-xmldsig",
                "org.demoiselle.signer:chain-icp-brasil"
              ],
              "ecosystems": "maven",
              "any_deprecated": false,
              "min_days_since_publish": 9
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "7 package(s) on maven",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 7,
                      "ecosystems": "maven"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 9 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "45 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 45
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 58,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "icp-brasil",
                "digital-signature",
                "cryptography",
                "timestamp",
                "pki",
                "certificates",
                "x509certificates",
                "x509"
              ],
              "has_wiki": true,
              "homepage": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 3.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/2 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "16 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the maven:org.demoiselle.signer:signer-core@4.6.1 runtime dependency closure — what installing the published package pulls in — 9 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:org.demoiselle.signer:signer-core@4.6.1",
                  "assessed": 9
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 9,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 9,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 62,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.74,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "74 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 39.5,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 74,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 73,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.16,
              "toolchain_manifests": [
                "automacao-importador/go.mod",
                "bom/pom.xml",
                "chain-icp-brasil-homolog/go.mod",
                "chain-icp-brasil-homolog/pom.xml",
                "chain-icp-brasil/pom.xml",
                "chain-iti-homolog/pom.xml",
                "chain-iti/pom.xml",
                "chain-serpro-neosigner/pom.xml",
                "core/pom.xml",
                "cryptography/pom.xml",
                "documentation/reference/pom.xml",
                "parent/pom.xml",
                "policy-engine/pom.xml",
                "policy-impl-cades/pom.xml",
                "policy-impl-pades/pom.xml",
                "policy-impl-xades/pom.xml",
                "pom.xml",
                "signer-examples/pom.xml",
                "signer-xmldsig/pom.xml",
                "timestamp/pom.xml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "automacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "automacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Java (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "16 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 16,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 208648,
              "source_files_sampled": 370,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/370 source files over 60KB",
                "points": 54.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 370,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch maven package 'org.demoiselle.signer:signer-examples' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T10:35:51.571881Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/demoiselle/signer.svg",
  "full_name": "demoiselle/signer",
  "license_state": "standard",
  "license_spdx": "LGPL-3.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenMaven.