JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"defcon",
"android",
"blackhat",
"blackbox",
"malware-analysis",
"malware-detection"
],
"is_fork": false,
"size_kb": 11154,
"has_wiki": true,
"homepage": "https://doc.quark-engine.com",
"languages": {
"CSS": 3871,
"HTML": 48575,
"Shell": 42854,
"Python": 556102,
"Dockerfile": 316,
"JavaScript": 5017
},
"pushed_at": "2026-07-15T02:58:13Z",
"created_at": "2019-10-22T01:19:27Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T18:40:37Z",
"description": null,
"is_archived": false,
"is_disabled": false,
"license_spdx": "GPL-3.0",
"default_branch": "master",
"license_spdx_raw": "GPL-3.0",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": "Even Flow Foundation",
"type": "Organization",
"login": "ev-flow",
"company": null,
"location": null,
"followers": 40,
"avatar_url": "https://avatars.githubusercontent.com/u/57204411?v=4",
"created_at": "2019-10-31T02:23:39Z",
"is_verified": null,
"public_repos": 24,
"account_age_days": 2456
},
"license": {
"state": "standard",
"spdx_id": "GPL-3.0",
"raw_spdx": "GPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v26.7.1",
"kind": "patch",
"published_at": "2026-07-02T03:01:42Z"
},
{
"tag": "v26.6.1",
"kind": "patch",
"published_at": "2026-06-03T13:54:00Z"
},
{
"tag": "v26.5.1",
"kind": "patch",
"published_at": "2026-05-06T11:22:55Z"
},
{
"tag": "v26.4.1",
"kind": "patch",
"published_at": "2026-04-29T11:11:45Z"
},
{
"tag": "v26.3.1",
"kind": "patch",
"published_at": "2026-03-07T02:44:16Z"
},
{
"tag": "v26.2.1",
"kind": "patch",
"published_at": "2026-02-06T10:16:31Z"
},
{
"tag": "v26.1.1",
"kind": "patch",
"published_at": "2026-01-07T02:48:32Z"
},
{
"tag": "v25.12.1",
"kind": "patch",
"published_at": "2025-12-05T14:25:52Z"
},
{
"tag": "v25.11.1",
"kind": "patch",
"published_at": "2025-11-06T04:12:28Z"
},
{
"tag": "v25.9.1",
"kind": "patch",
"published_at": "2025-09-03T11:22:57Z"
},
{
"tag": "v25.8.1",
"kind": "patch",
"published_at": "2025-08-06T13:07:15Z"
},
{
"tag": "v25.7.1",
"kind": "patch",
"published_at": "2025-07-03T05:54:25Z"
},
{
"tag": "v25.6.1",
"kind": "patch",
"published_at": "2025-06-04T09:07:12Z"
},
{
"tag": "v25.5.1",
"kind": "patch",
"published_at": "2025-05-08T02:40:49Z"
},
{
"tag": "v25.4.1",
"kind": "patch",
"published_at": "2025-04-03T12:35:40Z"
},
{
"tag": "v25.3.1",
"kind": "patch",
"published_at": "2025-03-05T11:21:07Z"
},
{
"tag": "v25.2.1",
"kind": "patch",
"published_at": "2025-02-06T06:22:18Z"
},
{
"tag": "v25.1.1",
"kind": "patch",
"published_at": "2025-01-01T05:18:37Z"
},
{
"tag": "v24.12.1",
"kind": "patch",
"published_at": "2024-12-03T05:22:03Z"
},
{
"tag": "v24.11.2",
"kind": "patch",
"published_at": "2024-11-15T07:53:45Z"
},
{
"tag": "v24.11.1",
"kind": "patch",
"published_at": "2024-11-06T23:35:03Z"
},
{
"tag": "v24.10.1",
"kind": "patch",
"published_at": "2024-10-02T15:24:37Z"
},
{
"tag": "v24.9.1",
"kind": "patch",
"published_at": "2024-09-04T13:36:59Z"
},
{
"tag": "v24.8.1",
"kind": "patch",
"published_at": "2024-08-07T03:13:20Z"
},
{
"tag": "v24.7.1",
"kind": "patch",
"published_at": "2024-07-03T04:57:26Z"
},
{
"tag": "v24.6.1",
"kind": "patch",
"published_at": "2024-06-05T09:18:31Z"
},
{
"tag": "v24.5.1",
"kind": "patch",
"published_at": "2024-05-02T09:26:48Z"
},
{
"tag": "v24.4.1",
"kind": "patch",
"published_at": "2024-04-03T06:23:23Z"
},
{
"tag": "v24.2.1",
"kind": "patch",
"published_at": "2024-02-07T05:42:18Z"
},
{
"tag": "v23.12.1",
"kind": "patch",
"published_at": "2023-12-27T01:15:00Z"
},
{
"tag": "v23.11.1",
"kind": "patch",
"published_at": "2023-11-29T02:07:55Z"
},
{
"tag": "v23.10.1",
"kind": "patch",
"published_at": "2023-10-25T03:48:32Z"
},
{
"tag": "v23.9.1",
"kind": "patch",
"published_at": "2023-09-27T06:21:31Z"
},
{
"tag": "v23.8.1",
"kind": "patch",
"published_at": "2023-08-30T14:53:16Z"
},
{
"tag": "v23.7.1",
"kind": "patch",
"published_at": "2023-07-25T05:47:09Z"
},
{
"tag": "v23.6.1",
"kind": "patch",
"published_at": "2023-06-28T08:24:57Z"
},
{
"tag": "v23.5.1",
"kind": "patch",
"published_at": "2023-05-31T09:01:26Z"
},
{
"tag": "v23.4.1",
"kind": "patch",
"published_at": "2023-04-26T07:27:41Z"
},
{
"tag": "v23.3.1",
"kind": "patch",
"published_at": "2023-03-28T07:09:15Z"
},
{
"tag": "v23.2.1",
"kind": "patch",
"published_at": "2023-02-22T02:12:47Z"
},
{
"tag": "v22.12.1",
"kind": "patch",
"published_at": "2022-12-28T02:39:50Z"
},
{
"tag": "v22.11.1",
"kind": "patch",
"published_at": "2022-11-30T02:43:29Z"
},
{
"tag": "v22.10.1",
"kind": "patch",
"published_at": "2022-10-26T12:13:17Z"
},
{
"tag": "v22.9.1",
"kind": "patch",
"published_at": "2022-09-29T02:24:11Z"
},
{
"tag": "v22.7.1",
"kind": "patch",
"published_at": "2022-07-27T13:28:56Z"
},
{
"tag": "v22.6.1",
"kind": "patch",
"published_at": "2022-06-29T03:16:27Z"
},
{
"tag": "v22.5.1",
"kind": "patch",
"published_at": "2022-05-25T05:20:00Z"
},
{
"tag": "v22.4.1",
"kind": "patch",
"published_at": "2022-04-27T01:44:43Z"
},
{
"tag": "v22.3.1",
"kind": "patch",
"published_at": "2022-03-28T14:50:28Z"
},
{
"tag": "v22.2.1",
"kind": "patch",
"published_at": "2022-02-15T07:44:19Z"
},
{
"tag": "v22.1.1",
"kind": "patch",
"published_at": "2022-01-04T08:02:41Z"
},
{
"tag": "v21.11.2",
"kind": "patch",
"published_at": "2021-11-25T14:25:59Z"
},
{
"tag": "v21.11.1",
"kind": "patch",
"published_at": "2021-11-02T10:17:24Z"
},
{
"tag": "v21.10.2",
"kind": "patch",
"published_at": "2021-10-06T03:18:41Z"
},
{
"tag": "v21.10.1",
"kind": "patch",
"published_at": "2021-10-06T02:41:48Z"
},
{
"tag": "v21.8.1",
"kind": "patch",
"published_at": "2021-08-24T06:47:58Z"
},
{
"tag": "v21.7.2",
"kind": "patch",
"published_at": "2021-07-20T05:42:27Z"
},
{
"tag": "v21.7.1",
"kind": "patch",
"published_at": "2021-07-15T10:34:22Z"
},
{
"tag": "v21.6.3",
"kind": "patch",
"published_at": "2021-06-24T10:53:34Z"
},
{
"tag": "v21.6.2",
"kind": "patch",
"published_at": "2021-06-09T09:46:26Z"
},
{
"tag": "v21.6.1",
"kind": "patch",
"published_at": "2021-06-07T09:16:12Z"
},
{
"tag": "v21.5.1",
"kind": "patch",
"published_at": "2021-05-28T02:24:18Z"
},
{
"tag": "v21.4.3",
"kind": "patch",
"published_at": "2021-04-07T09:55:43Z"
},
{
"tag": "v21.4.2",
"kind": "patch",
"published_at": "2021-04-07T08:36:55Z"
},
{
"tag": "v21.4.1",
"kind": "patch",
"published_at": "2021-04-07T06:31:04Z"
},
{
"tag": "v21.3.4",
"kind": "patch",
"published_at": "2021-03-30T08:45:17Z"
},
{
"tag": "v21.3.3",
"kind": "patch",
"published_at": "2021-03-13T04:52:36Z"
},
{
"tag": "v21.3.2",
"kind": "patch",
"published_at": "2021-03-09T11:37:55Z"
},
{
"tag": "21.3.1",
"kind": "patch",
"published_at": "2021-03-08T09:20:12Z"
},
{
"tag": "v21.02.2",
"kind": "patch",
"published_at": "2021-02-26T02:47:17Z"
},
{
"tag": "v21.02.1",
"kind": "patch",
"published_at": "2021-02-04T07:27:28Z"
},
{
"tag": "v21.01.6",
"kind": "patch",
"published_at": "2021-01-28T07:12:04Z"
},
{
"tag": "v21.01.5",
"kind": "patch",
"published_at": "2021-01-25T12:45:45Z"
},
{
"tag": "v21.01.4",
"kind": "patch",
"published_at": "2021-01-21T08:11:18Z"
},
{
"tag": "v21.01.3",
"kind": "patch",
"published_at": "2021-01-20T03:55:15Z"
},
{
"tag": "v21.01.2",
"kind": "patch",
"published_at": "2021-01-18T09:23:17Z"
},
{
"tag": "v21.01.1",
"kind": "patch",
"published_at": "2021-01-05T08:07:49Z"
},
{
"tag": "v20.12",
"kind": "other",
"published_at": "2020-12-07T02:43:37Z"
},
{
"tag": "v20.11",
"kind": "other",
"published_at": "2020-11-25T03:19:01Z"
},
{
"tag": "v20.10",
"kind": "other",
"published_at": "2020-10-28T07:17:12Z"
},
{
"tag": "v20.08",
"kind": "other",
"published_at": "2020-08-18T10:21:24Z"
},
{
"tag": "v20.04",
"kind": "other",
"published_at": "2020-04-17T08:09:01Z"
},
{
"tag": "v20.01",
"kind": "other",
"published_at": "2020-01-09T01:51:32Z"
},
{
"tag": "v19.10",
"kind": "other",
"published_at": "2019-11-01T03:06:08Z"
}
],
"recent_commits": [
{
"oid": "cb80e96d36a5220505acb820a8b19e9dcbef4644",
"body": "* feat(skills): add dependency-update PR validator skill\n\nDependabot PRs on ev-flow/quark-engine look green but often aren't —\nCI hardcodes some package versions (pytest.yml:53) independent of\nsetup.py, and unrelated flakes/baseline drift get blamed on the bump.\nThis skill checks actual installed ve\n[…]\n use, so any GitHub write requires\nan explicit human permission prompt.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: add dependency-update PR validator skill (#932)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-07-15T02:58:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "03e1a7f9e13f69fc60e41961a58b814f1f49a263",
"body": null,
"is_bot": false,
"headline": "fix: include interfaces in superclass relationships (#953)",
"author_name": "Xiaojie Wen",
"author_login": "wenxiaojie1",
"committed_at": "2026-07-14T19:07:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0a39d961ca444aafc7f283715a25de406e847cac",
"body": "Bumps [pip](https://github.com/pypa/pip) from 26.1 to 26.1.2.\n- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)\n- [Commits](https://github.com/pypa/pip/compare/26.1...26.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: pip\n dependency-version: 26.1.2\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pip from 26.1 to 26.1.2 (#951)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-11T07:28:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "108394f67daf1b336d5398a3e73cee031a76f84c",
"body": "* docs: add AhRat malware family analysis report\n\nAhRat is the MITRE S1095 AhMyth-derived Android RAT documented by ESET\nin May 2023 inside the trojanized \"iRecorder — Screen Recorder\" app on\nGoogle Play. We tested 15 publicly available samples and flagged all\n15 as high-risk via existing Quark rul\n[…]\nPresent tense throughout the coverage-gap clause.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add Quark malware analysis report for AhRat (#934)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-07-08T14:45:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8a480f86a423128977194482b3e142105349ca7e",
"body": "* fix: validate rule path only when used\n\n* Address review: simplify rule option validation and dedupe test setup\n\n- Set exists=False directly on the --rule option instead of patching the\n parameter after the command is defined.\n- Use the plain path in the missing-rule error so the assertion is portable\n on Windows (repr escapes backslashes).\n- Extract the duplicated Quark mock into a mock_quark fixture.",
"is_bot": false,
"headline": "fix: validate default rule path only when used (#937)",
"author_name": "Vincent Gao",
"author_login": "gaoflow",
"committed_at": "2026-07-08T13:37:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "850bad6c28cc163925b20b2b428d092a622ce010",
"body": null,
"is_bot": false,
"headline": "Fix malware report README links (#942)",
"author_name": "Xiaojie Wen",
"author_login": "wenxiaojie1",
"committed_at": "2026-07-07T11:49:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf35a66292a185dc0585675c7fff3e5126d5ebf0",
"body": "* Update version information for v26.7.1\n\n* Update changelog by removing old entries\n\nRemoved dependency updates and CI enhancements from changelog.\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.7.1 (#939)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-01T14:10:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1df1d49ff096f871a13b3d7fa8931522f5c72100",
"body": "* docs: add new Quark rule for NGate malware detection\n\n* docs: trim NGate sample list to detected subset\n\n* Add NGate malware description to README\n\nAdded new malware entry for NGate with detailed behaviors.",
"is_bot": false,
"headline": "Add new Quark rule for NGate malware detection (#931)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-06-24T13:46:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "86b84cf6db00fb17718cb88ca845258ded9c94ba",
"body": "The CI env-prep step installed Shuriken-Analyzer via\n`pip install git+https://github.com/Fare9/Shuriken-Analyzer.git@main#subdirectory=shuriken/bindings/Python/`,\nwhich compiles C++/pybind11 bindings at install time. That upstream is\nunmaintained and the build has started failing during CI setup.\n\nS\n[…]\ns/core/test_apkinfo.py to pytest.skip when\nthe `shuriken` module is absent (ShurikenImp.__init__ otherwise raises),\nkeeping the test job green.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: drop Shuriken-Analyzer build from CI (#933)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-06-24T13:21:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fbaceb10a49a34c127de2bb7710d59c56553019a",
"body": "Bumps [pytest](https://github.com/pytest-dev/pytest) from 9.0.2 to 9.0.3.\n- [Release notes](https://github.com/pytest-dev/pytest/releases)\n- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)\n- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3)\n\n---\nupdated-\n[…]\nndency-version: 9.0.3\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pytest from 9.0.2 to 9.0.3 in Pipfile.lock (#906)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T04:21:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f90ae20f484d37c942e44d59a3e440bc220cc634",
"body": "Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0.\n- [Release notes](https://github.com/psf/requests/releases)\n- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)\n- [Commits](https://github.com/psf/requests/compare/v2.32.5...v2.33.0)\n\n---\nupdated-dependencies:\n-\n[…]\nndency-version: 2.33.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump requests from 2.32.5 to 2.33.0 (#893)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T03:40:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d96d41f22c6fec16002de2bb08115753fe8a0cd",
"body": "Bumps [idna](https://github.com/kjd/idna) from 3.11 to 3.15.\n- [Release notes](https://github.com/kjd/idna/releases)\n- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)\n- [Commits](https://github.com/kjd/idna/compare/v3.11...v3.15)\n\n---\nupdated-dependencies:\n- dependency-name: idna\n dependency-version: '3.15'\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump idna from 3.11 to 3.15 (#923)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T03:31:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06eccfeadb38a91b7b629b4de50dab052ffa3461",
"body": "* docs: fix Cerberus report rule number (#00277 -> #00276)\n\n* docs: add SuperCardX analysis report (report-only, no new rule)\n\n* Add SuperCardX malware entry to README\n\n* docs: drop SuperCardX T1437 section (IP-level evidence does not justify Application Layer Protocol)\n\n* docs: drop SuperCardX samples that did not reach high-risk threshold",
"is_bot": false,
"headline": "Add Quark malware analysis report for SuperCardX (#927)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-06-19T13:27:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4acae9278ec95290b8c2a70f1ea2834138ef44aa",
"body": null,
"is_bot": false,
"headline": "feat: Phase 5 dynamic string resolution via DexTrace (#919)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-06-11T11:30:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "025e32c147238e2524f3d56aa9e4a83abfab69b9",
"body": "* docs: add new Quark rules for Cerberus malware detection\n\nAdd a malware report section for the Cerberus Android banking\ntrojan (MITRE ATT&CK Mobile S0480) covering rule #00277. The\nreport walks through 3 techniques the family employs — Base64\nobfuscation, accessibility-driven input injection, and\n[…]\nbution problem.\n\n* Update README with new image and Cerberus details\n\nAdded an image to the table and included details about the Cerberus banking trojan.\n\n* Change expected Ahmyth_RESULT from 41 to 42",
"is_bot": false,
"headline": "Add new Quark rules for Cerberus malware detection (#926)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-06-09T11:41:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4faa02cc1bb521a0257754a7885ad3a3b91baabc",
"body": "* Update version information for v26.6.1\n\n* Remove dependency update from debian changelog\n\nRemoved dependency update section from changelog.\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.6.1 (#925)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-06-03T12:59:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a71a8275c9b21fb1f80bad80c8c975f13a36b3b8",
"body": "* docs: add new Quark rules for BRATA malware detection\n\nAdd a malware report section for the BRATA Android banking trojan\n(MITRE ATT&CK Mobile S1094) covering rule #00276. The report walks\nthrough 4 techniques the family employs — security software discovery,\nscreen capture, input injection, and d\n[…]\nrules (#00265, #00210, #00187/#00212/#00215).\n\n* docs: rename BRATA section heading to \"Brata Malware Family Analysis Report\"\n\nAlign the section title with the wording used in the X post\nannouncement.",
"is_bot": false,
"headline": "Add new Quark rules for BRATA malware detection (#917)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-05-27T15:44:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5337c501eeabbd8aad6b1e75b5306ce96267e867",
"body": "* docs: add new Quark rules for TangleBot malware detection\n\nAdd a malware report section for the TangleBot Android trojan\n(MITRE ATT&CK Mobile S1069) covering rule #00275. The report walks\nthrough 6 techniques the family employs — location tracking, software\ndiscovery, screen capture, data from lo\n[…]\nits\n file size for efficient network exfiltration.\n\n* Add TangleBot details to malware list in README\n\nAdded TangleBot entry to the malware table with details on its functionality and attack methods.",
"is_bot": false,
"headline": "Add new Quark rules for TangleBot malware detection (#916)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-05-20T00:49:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f0c035af30eb78f41170bc4babe00489cba0833",
"body": "Bumps [lxml](https://github.com/lxml/lxml) from 6.0.2 to 6.1.0.\n- [Release notes](https://github.com/lxml/lxml/releases)\n- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)\n- [Commits](https://github.com/lxml/lxml/compare/lxml-6.0.2...lxml-6.1.0)\n\n---\nupdated-dependencies:\n- dependen\n[…]\nxml\n dependency-version: 6.1.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump lxml from 6.0.2 to 6.1.0 (#910)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-17T08:33:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32d735541fbcff912f6fb83b319a8d1aec777ead",
"body": "Bumps [pip](https://github.com/pypa/pip) from 26.0 to 26.1.\n- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)\n- [Commits](https://github.com/pypa/pip/compare/26.0...26.1)\n\n---\nupdated-dependencies:\n- dependency-name: pip\n dependency-version: '26.1'\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pip from 26.0 to 26.1 (#914)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-17T08:33:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca7c1fd0682286034538092c33aad974bcd58e55",
"body": "Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0.\n- [Release notes](https://github.com/urllib3/urllib3/releases)\n- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)\n- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0)\n\n---\nupdated-dependenc\n[…]\nib3\n dependency-version: 2.7.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump urllib3 from 2.6.3 to 2.7.0 (#918)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-17T08:33:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a81a5528ad16614e5f10863f008eda02e7bf47b",
"body": "* docs: add new Quark rules for GodFather malware detection\n\nAdd a malware report section for the GodFather Android banking trojan\n(MITRE ATT&CK Mobile S1231) covering rule #00274. The report walks\nthrough 6 techniques the family employs — software discovery, input\ncapture, SMS control, call contro\n[…]\nll listed techniques statically from APK bytecode.\n\n* Update README with new images and banking trojan details\n\nAdded new images and updated the list of banking trojans with their behaviors and links.",
"is_bot": false,
"headline": "Add new Quark rules for Godfather malware detection (#915)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-05-13T16:23:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dbe6d54cb0bafbb946a02c49c8bed0b3b3a3a4e8",
"body": "* Update version information for v26.5.1\n\n* Clean up debian changelog by removing sections\n\nRemoved test improvement and dependency update sections from changelog.\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.5.1 (#913)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-05-06T11:18:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04dad520ff289c61d004727801f41710d0cc6e18",
"body": "* Document new Quark rules for Anubis malware\n\nAdded new Quark rules for Anubis malware detection, detailing behaviors and testing results. Included behavior maps and identified well-known threats associated with Anubis.\n\n* Revise Anubis malware report with new findings\n\nUpdated the Anubis malware r\n[…]\nviors and capabilities. Adjusted formatting and added a summary report for a TrickMo sample.\n\n* Change Ahmyth_RESULT check from 40 to 41\n\nUpdate the condition for checking Ahmyth_RESULT in smoke test.",
"is_bot": false,
"headline": "Add new Quark rules for Anubis malware detection (#911)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-05-02T13:44:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "87b278ccb238e741e167f6c2cc352d0fd6e5bafc",
"body": "* Add new Quark rules for TrickMo malware detection\n\n* Revise TrickMo malware report wording per review feedback\n\n- Split intro paragraph into rules announcement and family description\n- Rewrite each section's narrative to explain the combined behavior\n\n* Update TrickMo description and image links i\n[…]\nrove clarity in malware report\n\n* Replace images in malware report with new links\n\nUpdated images in the TrickMo malware report to new URLs.\n\n---------\n\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": false,
"headline": "Add new Quark rules for TrickMo malware detection (#909)",
"author_name": "James Chiang",
"author_login": "e619003",
"committed_at": "2026-04-25T15:10:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "189a8413a9e067c4325b028fe070ec826e1c4138",
"body": "* Separate filled-new-array-kind instruction parsing logic from invoke-kind ones\n\n* Fix getting empty string as the parameter type if there are no parameters\n\n* Reuse newly-added functions in invoke-kind instruction parsing logic\n\n* Update unit tests to reflect changes and covert type-inferring scen\n[…]\n synchronized with its\n value on the stack; remove the now-redundant ret_type attribute\n- Update tests to unpack the new tuple structure\n\n* fix: add ValueNode import and type annotation for ret_stack",
"is_bot": false,
"headline": "Fix #867: Separate filled-new-array parsing from invoke-kind (#886)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-04-21T15:34:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c292273e8fbb2d9e0676aaa8692b157bbe4279b4",
"body": "* Add new Quark rules for Antidot malware detection\n\nAdded new Quark rules for Antidot malware detection, detailing behaviors and identified threats. Included summary report and tested APKs.\n\n* Revise Antidot malware report with updated images\n\nUpdated images and descriptions in the malware report t\n[…]\nion and its interaction with getDataColumn for accessing sensitive information.\n\n* Fix reference to getDataColumn function in report\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add new Quark rules for Arsink malware detection (#907)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-18T09:30:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "43cb778e7a5b698366167385fcf21fbae7d1e685",
"body": "Update the expected Ahmyth_RESULT from 39 to 40 in smoke test.",
"is_bot": false,
"headline": "Change expected Ahmyth_RESULT value in smoke test (#908)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-16T23:13:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0011718dfb7d54e098420d079c830efeef753da",
"body": "Bumps [pygments](https://github.com/pygments/pygments) from 2.19.2 to 2.20.0.\n- [Release notes](https://github.com/pygments/pygments/releases)\n- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)\n- [Commits](https://github.com/pygments/pygments/compare/2.19.2...2.20.0)\n\n---\nupdate\n[…]\nts\n dependency-version: 2.20.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pygments from 2.19.2 to 2.20.0 (#897)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-12T06:20:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "70a3203b19ba74a76f2651b5c230993c765f503f",
"body": "Bumps [black](https://github.com/psf/black) from 26.1a1 to 26.3.1.\n- [Release notes](https://github.com/psf/black/releases)\n- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)\n- [Commits](https://github.com/psf/black/commits/26.3.1)\n\n---\nupdated-dependencies:\n- dependency-name: black\n \n[…]\ndency-version: 26.3.1\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump black from 26.1a1 to 26.3.1 (#884)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-12T06:20:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40838cb5aa0b6dd3b5da97e795cf4a36f4211499",
"body": "* Add new Quark rules for Antidot malware detection\n\nAdded new Quark rules for Antidot malware detection, detailing behaviors and identified threats. Included summary report and tested APKs.\n\n* Revise Antidot malware report with updated images\n\nUpdated images and descriptions in the malware report to reflect new findings and behaviors detected by Quark.",
"is_bot": false,
"headline": "Add new Quark rules for Antidot malware detection (#903)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-11T13:47:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b6d5cd786a86d18f3db16a0dde10c0144d8e2f2",
"body": null,
"is_bot": false,
"headline": "Update expected behavior count in smoke test (#905)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-11T08:22:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dce8cba30114856b96a6ac65e39a89334812876a",
"body": "* Update version information for v26.4.1\n\n* Refactor changelog entries for clarity and consistency\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.4.1 (#896)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-04T01:54:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4361bbd209013c8c57ad0e4b9522502bbfd53352",
"body": "* Add Quark rules for SharkBot malware detection\n\nAdded new Quark rules for identifying SharkBot malware, detailing its capabilities and behaviors. Included summary report and tested APKs.\n\n* Revise SharkBot rules description for clarity\n\nImproved clarity and structure of SharkBot rules description.\n[…]\nle\n\n* Replace outdated images in malware_report.rst\n\nUpdated images in the malware report to new sources.\n\n* Update SharkBot description in README\n\nRemoved the fourth action from SharkBot description.",
"is_bot": false,
"headline": "Update README for Sharkbot (#901)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-04T01:53:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0f29053a9abee3336c2e7f0ceca68f10e2121d38",
"body": "* Fix: PyEval Fails to Track Byte Array Registers\n\nCloses #889\n\n* fix: restore Ahmyth expected count to 39 (byte array tracking fixed)\n\n* test: add object array and multi-dim array cases to test_bears_object\n\nCover [Ljava/lang/String; and [[B type descriptors, which both start\nwith \"[\" and should return True from bears_object().\n\n---------\n\nCo-authored-by: SWE-agent <noemail@swe-agent.com>\nCo-authored-by: haeter525 <cindejze412@gmail.com>",
"is_bot": true,
"headline": "Fix #889: bears_object() now recognizes array types as objects (#890)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-03T14:56:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e73b36e062df1a66d41d353dba40cd4cfd94bc71",
"body": "* Add Quark rules for SharkBot malware detection\n\nAdded new Quark rules for identifying SharkBot malware, detailing its capabilities and behaviors. Included summary report and tested APKs.\n\n* Revise SharkBot rules description for clarity\n\nImproved clarity and structure of SharkBot rules description.\n\n* Revise malware report for clarity and updated images\n\nUpdated images and clarified descriptions regarding SMS interception and additional payload downloading.",
"is_bot": false,
"headline": "Add Sharkbot malware family analysis report (#900)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-03T14:53:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e6ce8a70a5b6d49d2dd560e4f4bb79d32d2b0451",
"body": "Added additional malware families and their behaviors to the analysis report.",
"is_bot": false,
"headline": "Update malware family analysis report table (#898)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-04-01T06:46:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9fb4362ef32c98b7b3c806bb79c11cf06951ef36",
"body": "* Introduce Quark rule for detecting Hydra malware\n\nAdded new Quark rule for Hydra malware detection with detailed analysis and behavior maps.\n\n* Fix image URLs in malware_report.rst\n\nUpdated image URLs in the malware report to new links.\n\n* update Hydra report\n\n* Remove HTML entity references from malware report",
"is_bot": false,
"headline": "Add Hydra malware family analysis report (#892)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-03-27T06:19:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94c0d0ef88d538e7d1ce5ae4b611facfa1f54f34",
"body": null,
"is_bot": false,
"headline": "Fix annotation of quark.utils.tools.contains (#885)",
"author_name": "Sergey Sayamov",
"author_login": "dolamroth",
"committed_at": "2026-03-22T09:08:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e54214adfa8bc3f4c946779d3ff98e1e3077b92f",
"body": "* Fix instruction names for PyEval.CAST_TYPE\n\n* Fix cast-type operation names in tests.evaluator\n\n* ci: adjust Ahmyth smoke test result due to issue #889\n\n---------\n\nCo-authored-by: haeter525 <cindejze412@gmail.com>",
"is_bot": false,
"headline": "Fix #871: Fix instruction names for PyEval.CAST_TYPE (#872)",
"author_name": "Sergey Sayamov",
"author_login": "dolamroth",
"committed_at": "2026-03-22T09:04:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bbf4c730e94645f87ba96791e93111d14a9416c",
"body": null,
"is_bot": false,
"headline": "Update smoke test CI with new behavior counts (#888)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-03-19T13:10:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73291af35febc0d278b9562e3af8e39f411568fd",
"body": "* Add empty workflow\n\n* Implement workflow\n\n* Add run name\n\n* Update AI agent files\n\n* Fix hard-coded PR URL pattern\n\n* rename fix-incorrect-opcode-naming to tool-usage-example for better clarity",
"is_bot": false,
"headline": "Add an AI issue solver workflow to help solving issues (#875)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-03-13T08:43:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e5f7cbeabc6e17565da2406f57f5da84ca470be",
"body": "Bumps [pip](https://github.com/pypa/pip) from 25.3 to 26.0.\n- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)\n- [Commits](https://github.com/pypa/pip/compare/25.3...26.0)\n\n---\nupdated-dependencies:\n- dependency-name: pip\n dependency-version: '26.0'\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pip from 25.3 to 26.0 (#862)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-09T13:53:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64c46d364b1fad1cb7e5dcbd4cd3dffb954539f2",
"body": "Bumps [flask](https://github.com/pallets/flask) from 2.2.5 to 3.1.3.\n- [Release notes](https://github.com/pallets/flask/releases)\n- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)\n- [Commits](https://github.com/pallets/flask/compare/2.2.5...3.1.3)\n\n---\nupdated-dependencies:\n- dep\n[…]\nndency-version: 3.1.3\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump flask from 2.2.5 to 3.1.3 (#865)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-09T13:53:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f73185122dbdd4ddb9395b520860b0c6c821d87",
"body": "Bumps [werkzeug](https://github.com/pallets/werkzeug) from 3.1.5 to 3.1.6.\n- [Release notes](https://github.com/pallets/werkzeug/releases)\n- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)\n- [Commits](https://github.com/pallets/werkzeug/compare/3.1.5...3.1.6)\n\n---\nupdated-depe\n[…]\neug\n dependency-version: 3.1.6\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump werkzeug from 3.1.5 to 3.1.6 (#883)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-09T13:51:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8aa0aa35d3c410f10fa4c49091ab9edc19e16104",
"body": "…ytecode (#874)\n\n* Process invoke-polymorphic instructions in AndroguardImp.get_method_bytecode\n\n* Update apkinfo.py",
"is_bot": false,
"headline": "Process invoke-polymorphic instructions in AndroguardImp.get_method_b…",
"author_name": "Sergey Sayamov",
"author_login": "dolamroth",
"committed_at": "2026-03-07T07:15:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "227a89f33595b87bf6a89337dfd08951034a1812",
"body": "* Update version information for v26.3.1\n\n* Update changelog\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.3.1 (#882)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-03-06T11:28:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7bf677312c201883e3c34cf2035e9b7d62b4e298",
"body": null,
"is_bot": false,
"headline": "Update codex cli and use new flags (#877)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-03-06T10:52:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "837de0f36119ad4bdb14e210dad999ec74f65129",
"body": "… (#879)",
"is_bot": false,
"headline": "Fix AttributeError in BaseApkinfo: add auto_fix_checksum to __slots__…",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-03-06T10:21:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef0cdfe16fc0ae8e0ffc5aa78634ce232c6f5e48",
"body": null,
"is_bot": false,
"headline": "Fixes #868: Fix removing items from list, which is being iterated (#869)",
"author_name": "Sergey Sayamov",
"author_login": "dolamroth",
"committed_at": "2026-03-01T09:51:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4d256f89ad182ac16e9b7e7a713091403d24d6b",
"body": "… (#870)\n\n* Add LRUCache to AndroguardImp.lowerfunc\n\n* Move call to lowerfunc outside of loop",
"is_bot": false,
"headline": "Fixes #864: Cache lowerfunc in apkinfo to match other implementations…",
"author_name": "Sergey Sayamov",
"author_login": "dolamroth",
"committed_at": "2026-03-01T09:25:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b821a634c551c654ef271b91080fd5d73b2a9446",
"body": "Add safe DEX checksum repair flow (for androguard)",
"is_bot": false,
"headline": "Merge pull request #866 from e619003/add-auto-repair-bad-dex-checksums",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-02-27T08:23:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b541db32141e295992a127222ce61a0f160029e",
"body": "…less --auto-fix-checksum is provided",
"is_bot": false,
"headline": "Add interactive confirmation before repairing damaged DEX checksum un…",
"author_name": "James Chiang",
"author_login": "e619003",
"committed_at": "2026-02-25T09:11:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aaa5bf2fd935308cb88bbc650f0650443f5e2af0",
"body": "…droguard only)\n\nAllow users to configure whether bad checksum should be automatically fixed instead of raising an error.\n\nThis option is currently supported for androguard only.",
"is_bot": false,
"headline": "Add auto_fix_checksum option to control automatic checksum fixing (an…",
"author_name": "James Chiang",
"author_login": "e619003",
"committed_at": "2026-02-24T08:21:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a69b0e7e3b9b3fe837c91218c87792d3bec837bf",
"body": null,
"is_bot": false,
"headline": "Add auto-repair bad DEX checksums.",
"author_name": "James Chiang",
"author_login": "e619003",
"committed_at": "2026-02-24T03:30:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05e7ffa1d601cef8608db1a94642cb94999206ba",
"body": "Add ToxicPanda malware family analysis report",
"is_bot": false,
"headline": "Merge pull request #863 from haeter525/add_toxicpanda_report",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-02-12T01:53:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aff724b5c893fbddde814356947bc72d74108b40",
"body": null,
"is_bot": false,
"headline": "Add ToxicPanda analysis reports",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-02-08T14:22:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa6b80cad15293885f2a19e4a05ac97c8f54db43",
"body": "Record register usage instead of full state to reduce memory usage",
"is_bot": false,
"headline": "Merge pull request #845 from haeter525/lazy_invoked_state",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-02-06T09:15:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0add3c5c0c29445354620de19054071822a6bf6d",
"body": "* Update version information for v26.2.1\n\n* Update changelog for version 26.2.1-0kali1\n\nUpdated changelog to reflect dependency updates, new features, and documentation enhancements.\n\n---------\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Shaun Dang <pulorsok@gmail.com>",
"is_bot": true,
"headline": "Update version information to v26.2.1 (#861)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-06T09:13:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "55f8d104eda120c26049881f536f2b3d4c431d56",
"body": null,
"is_bot": false,
"headline": "Merge branch 'master' into lazy_invoked_state",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-02-01T07:06:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7a2eac8d90ae36801b461827a06c5393e58eab7",
"body": null,
"is_bot": false,
"headline": "Fix incorrect precondition checks for implementation lookup",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-02-01T06:55:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "55da7f7cf6ede4cbeac962279424cea81f6e87c6",
"body": "…Manifest header (#859)\n\n* Detect and patch invalid compression method in APK\n\n* Detect and patch invalid AndroidManifest signature\n\n* Add unit tests for ApkPatcher\n\n* Avoid accessing the data and file attributes if they do not exist\n\n* Fix codacy issues\n\n* Add general log handler\n\n* Handle malformed filenames\n\n* Prevent OOM crashes\n\n* Fix error due to AndroidManifest not in APK",
"is_bot": false,
"headline": "Fix Quark crashes due to invalid values in APK ZIP header and Android…",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2026-01-30T14:24:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d29a9e2f4a92ca33bf223df6c119329b9845eb53",
"body": "… source RegObject is not found",
"is_bot": false,
"headline": "Initialize a RegObject with Primitive instead of BytecodeOps when the…",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-26T13:22:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b684c4969d98ccc2dea1cfa89835f57344fd691",
"body": null,
"is_bot": false,
"headline": "Reconstruct documentation (#857)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-01-23T14:31:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "66ddfe9b9105d518251e8d0acf042489d9bfcb30",
"body": null,
"is_bot": false,
"headline": "Update outdated dependencies (#856)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2026-01-21T13:54:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65f3db1dbf0f7ec1cf64d90695e771191672d1c4",
"body": "Update README to Match QuarkEngine’s New 2026 Direction",
"is_bot": false,
"headline": "Merge pull request #854 from pulorsok/master",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-01-17T03:58:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "177cfad0310c878bf96a562774f923d001d25ab4",
"body": null,
"is_bot": false,
"headline": "Update title for Android Malware section",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-01-16T03:39:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "469e34c7cd7dbcdae995497275b6150050c8612e",
"body": "Updated README to reflect new project focus and features.",
"is_bot": false,
"headline": "Revise README for Android Malware Ontology and features",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2026-01-16T03:17:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5bf7c6339d8380f0d80e29c824d4d050dad508c6",
"body": null,
"is_bot": false,
"headline": "Add loop detection in iterativeResolve",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-06T14:15:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e5f3097df70723810daea2b65f130f7478ba511",
"body": null,
"is_bot": false,
"headline": "Update outdated dependencies (#850)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2026-01-06T13:54:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b1b176825b5b3b66b4d063a03b97522a35b4ba2",
"body": null,
"is_bot": true,
"headline": "Update version information to v26.1.1 (#849)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-01-06T11:57:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b52607428afe65a7f3910029f905965ef00b8e71",
"body": null,
"is_bot": false,
"headline": "Fix smoke tests error",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-04T13:10:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e245f4fe4f45847e0c6107e9e788da337c7ac8f9",
"body": null,
"is_bot": false,
"headline": "Merge branch 'master' into lazy_invoked_state",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-04T12:43:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d195adc9e28ea99302ec17a7f73e7ef8c2dd8cd",
"body": null,
"is_bot": false,
"headline": "Fix unit tests",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-04T12:28:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "307ff46a4798facec8dfd94604598043d1e133c8",
"body": null,
"is_bot": false,
"headline": "Avoid recursion depth risk and use cache",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2026-01-04T12:28:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e100a509550459b1f6c61564438de1ac5fa573f",
"body": "Update the expected result for Quark analysis in the smoke test",
"is_bot": false,
"headline": "Merge pull request #846 from zinwang/fix_smoketest_1223",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-12-24T02:05:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a89d05a5c022333ddcaf9e68f3fe7160a7dcf77a",
"body": null,
"is_bot": false,
"headline": "Update the expected result for Quark analysis in the smoke test",
"author_name": "zinwang",
"author_login": "zinwang",
"committed_at": "2025-12-23T03:12:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c9f76e9b991c825cc66dbd32200b7951db6db49",
"body": "* Add docs for PhantomCard\n\n* Add docs for PhantomCard\n\n* Update description for phantomcard\n\n* Update description for phantomcard",
"is_bot": false,
"headline": "Add docs for PhantomCard (#843)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2025-12-22T10:36:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "666c344507b443c08ac1ceb67ba8840681c00257",
"body": null,
"is_bot": false,
"headline": "Update smoke_test",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T06:20:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e26d1850bab6dbf330e9f1ae74e217c8223cc90",
"body": null,
"is_bot": false,
"headline": "Update smoke tests",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T05:54:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83919d9a7759e27c3e87d841bd784d048b0a9a93",
"body": null,
"is_bot": false,
"headline": "Handle unknown-type registers as object-bearing to improve tracking",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "452fac836ddc55da83cdadb63c261ba92d20b81e",
"body": null,
"is_bot": false,
"headline": "Cache fixed and frequently accessed property to improve performance",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf935993f3650d83f52f863fb6de0894a9a8348f",
"body": null,
"is_bot": false,
"headline": "Update unit tests",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5f946ce827e4a871ef1a0adbe623fdfb555d1ac",
"body": null,
"is_bot": false,
"headline": "Eliminate register count limits to handle large-method APKs",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b430ebcaf2c7498e1a6c643840d9c206fdd5623",
"body": null,
"is_bot": false,
"headline": "Record register usage instead of full state snapshots to reduce memory",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6cb6be0d7365199f41f45ed05cab99bc43b7691",
"body": null,
"is_bot": false,
"headline": "Remove unused RegisterObject attribute",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d90dac0199e9827e9427a9db72ad612ac94e56a4",
"body": null,
"is_bot": false,
"headline": "Refine TableObject function names for clarity",
"author_name": "haeter525",
"author_login": "haeter525",
"committed_at": "2025-12-21T01:24:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1305bee4975e80d7944ebd6ae0b200982c2ee3c4",
"body": "* Add image to startActivityWithIntent.json section",
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-927 (#844)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-12-20T03:55:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b950d6a806c71e03cc524907ac4d9f6de9be16a1",
"body": "* Revise CWE-749 detection process documentation\n\nUpdated section titles and added images for CWE-749 detection process.\n\n* Update Quark Script CWE-749 documentation",
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-749 (#842)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-12-12T15:47:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9531676c5a1f923a702e49dffc026a84db5892be",
"body": null,
"is_bot": true,
"headline": "Update version information to v25.12.1 (#837)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-12-04T13:22:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "835c9ca98d2c85ddc3d6298b3a307ae90a53780c",
"body": "For newcomers it might not be obvious how to get the rules. Previously,\nif they followed the install guide and tried to analyze an APK, they\nwere presented with the following error:\n`Path '/<path>/.quark-engine/quark-rules/rules' does not exist.`",
"is_bot": false,
"headline": "Add freshquark command to installation instructions (#835)",
"author_name": "Andras Gemes",
"author_login": "gemesa",
"committed_at": "2025-11-28T08:55:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5c988567c87ffd31d5a1ad3e50294f54e6a1b03",
"body": null,
"is_bot": false,
"headline": "Add docs for SLocker (#832)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2025-11-27T18:08:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83349e63ff9d550574c61f84d566fba470469b65",
"body": null,
"is_bot": false,
"headline": "Update macOS runner in smoke test (#834)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2025-11-26T12:13:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d28c34afd8ad59cdc4af0a3edccb799b76c8880",
"body": null,
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-940 (#831)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-11-21T13:58:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c57fa1dceca6fb0281b207ec864e77e097995db9",
"body": "* Support invoke-kind/range\n\n* Allow multiple register referencing to same data\n\n* Track internal state change of object\n\n* Fix pytest error\n\n* Update expected results in smoke test\n\n* Avoid nested loops and if statements.",
"is_bot": false,
"headline": "Fix behavior not detected in Slocker malware family (#828)",
"author_name": "Haeter",
"author_login": "haeter525",
"committed_at": "2025-11-14T15:40:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7814e7cf0bdf5ee7176c7975b29a63b423cb25d6",
"body": null,
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-780 (#829)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-11-14T13:48:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fcb65f990c8e4ee5d4d1fc6f94d1ce95237dc8c1",
"body": null,
"is_bot": true,
"headline": "Update version information to v25.11.1 (#825)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-11-05T04:44:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a191880effe8228d9d9fa877ec19005f8ba545f1",
"body": null,
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-926 (#823)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-10-31T02:09:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca9611043dd121c6ab2e7ba7d7da638a751a029c",
"body": null,
"is_bot": false,
"headline": "Add docs for DawDropper (#822)",
"author_name": "Khin Wong",
"author_login": "zinwang",
"committed_at": "2025-10-24T10:15:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ffd44c877573679eb1999815f942433565878af4",
"body": null,
"is_bot": false,
"headline": "Optimize the document of Quark Script CWE-601 (#821)",
"author_name": "Shaun Dang",
"author_login": "pulorsok",
"committed_at": "2025-10-09T05:37:04Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 84,
"commits_last_year": 119,
"latest_release_at": "2026-07-02T03:01:42Z",
"latest_release_tag": "v26.7.1",
"releases_from_tags": false,
"days_since_last_push": 7,
"active_weeks_last_year": 50,
"days_since_latest_release": 20,
"mean_days_between_releases": 33.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": false,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "quark-engine",
"exists": true,
"license": null,
"keywords": [
"License :: OSI Approved :: GNU General Public License v3 (GPLv3)",
"Operating System :: OS Independent",
"Programming Language :: Python :: 3",
"Topic :: Security"
],
"ecosystem": "pypi",
"matches_repo": false,
"registry_url": "https://pypi.org/project/quark-engine/",
"is_deprecated": false,
"latest_version": "26.7.1",
"repository_url": "https://github.com/quark-engine/quark-engine",
"versions_count": 79,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 17361,
"first_published_at": "2020-04-10T05:33:27.313703Z",
"latest_published_at": "2026-07-02T03:01:57.741401Z",
"latest_version_yanked": null,
"days_since_latest_publish": 20
}
]
},
"popularity": {
"forks": 214,
"stars": 1697,
"watchers": 39,
"fork_history": {
"days": [
{
"date": "2019-11-02",
"count": 1
},
{
"date": "2019-12-23",
"count": 2
},
{
"date": "2019-12-26",
"count": 1
},
{
"date": "2019-12-28",
"count": 1
},
{
"date": "2019-12-30",
"count": 2
},
{
"date": "2019-12-31",
"count": 1
},
{
"date": "2020-01-28",
"count": 1
},
{
"date": "2020-01-30",
"count": 1
},
{
"date": "2020-02-08",
"count": 1
},
{
"date": "2020-04-25",
"count": 2
},
{
"date": "2020-06-06",
"count": 2
},
{
"date": "2020-06-08",
"count": 1
},
{
"date": "2020-06-10",
"count": 1
},
{
"date": "2020-06-11",
"count": 2
},
{
"date": "2020-06-30",
"count": 2
},
{
"date": "2020-07-26",
"count": 1
},
{
"date": "2020-08-01",
"count": 1
},
{
"date": "2020-08-09",
"count": 1
},
{
"date": "2020-08-18",
"count": 1
},
{
"date": "2020-08-24",
"count": 1
},
{
"date": "2020-08-30",
"count": 2
},
{
"date": "2020-09-02",
"count": 2
},
{
"date": "2020-09-03",
"count": 1
},
{
"date": "2020-09-19",
"count": 1
},
{
"date": "2020-09-22",
"count": 1
},
{
"date": "2020-10-26",
"count": 1
},
{
"date": "2020-10-28",
"count": 1
},
{
"date": "2020-11-01",
"count": 1
},
{
"date": "2020-11-02",
"count": 1
},
{
"date": "2020-11-06",
"count": 1
},
{
"date": "2020-12-05",
"count": 1
},
{
"date": "2020-12-10",
"count": 1
},
{
"date": "2020-12-18",
"count": 1
},
{
"date": "2020-12-25",
"count": 1
},
{
"date": "2020-12-28",
"count": 1
},
{
"date": "2021-02-05",
"count": 1
},
{
"date": "2021-02-06",
"count": 1
},
{
"date": "2021-02-11",
"count": 1
},
{
"date": "2021-02-14",
"count": 1
},
{
"date": "2021-02-27",
"count": 1
},
{
"date": "2021-03-13",
"count": 1
},
{
"date": "2021-03-16",
"count": 3
},
{
"date": "2021-03-22",
"count": 1
},
{
"date": "2021-03-29",
"count": 3
},
{
"date": "2021-03-31",
"count": 1
},
{
"date": "2021-04-08",
"count": 2
},
{
"date": "2021-04-13",
"count": 1
},
{
"date": "2021-04-20",
"count": 1
},
{
"date": "2021-04-26",
"count": 1
},
{
"date": "2021-05-03",
"count": 1
},
{
"date": "2021-05-27",
"count": 1
},
{
"date": "2021-06-01",
"count": 1
},
{
"date": "2021-06-05",
"count": 1
},
{
"date": "2021-06-07",
"count": 1
},
{
"date": "2021-06-18",
"count": 1
},
{
"date": "2021-06-25",
"count": 1
},
{
"date": "2021-07-05",
"count": 2
},
{
"date": "2021-07-13",
"count": 1
},
{
"date": "2021-07-16",
"count": 1
},
{
"date": "2021-07-18",
"count": 1
},
{
"date": "2021-07-19",
"count": 2
},
{
"date": "2021-07-31",
"count": 1
},
{
"date": "2021-08-07",
"count": 1
},
{
"date": "2021-08-10",
"count": 1
},
{
"date": "2021-08-18",
"count": 1
},
{
"date": "2021-08-20",
"count": 1
},
{
"date": "2021-08-26",
"count": 2
},
{
"date": "2021-08-28",
"count": 1
},
{
"date": "2021-08-31",
"count": 1
},
{
"date": "2021-09-02",
"count": 1
},
{
"date": "2021-09-03",
"count": 1
},
{
"date": "2021-09-04",
"count": 1
},
{
"date": "2021-09-27",
"count": 1
},
{
"date": "2021-10-04",
"count": 1
},
{
"date": "2021-10-15",
"count": 1
},
{
"date": "2021-10-19",
"count": 1
},
{
"date": "2021-10-22",
"count": 1
},
{
"date": "2021-11-24",
"count": 1
},
{
"date": "2021-11-26",
"count": 2
},
{
"date": "2021-12-08",
"count": 1
},
{
"date": "2021-12-10",
"count": 2
},
{
"date": "2022-01-15",
"count": 1
},
{
"date": "2022-01-21",
"count": 1
},
{
"date": "2022-01-26",
"count": 1
},
{
"date": "2022-02-25",
"count": 1
},
{
"date": "2022-03-08",
"count": 1
},
{
"date": "2022-03-15",
"count": 1
},
{
"date": "2022-03-18",
"count": 1
},
{
"date": "2022-03-20",
"count": 1
},
{
"date": "2022-03-22",
"count": 1
},
{
"date": "2022-03-28",
"count": 1
},
{
"date": "2022-03-30",
"count": 1
},
{
"date": "2022-04-01",
"count": 1
},
{
"date": "2022-05-13",
"count": 1
},
{
"date": "2022-05-16",
"count": 1
},
{
"date": "2022-06-09",
"count": 1
},
{
"date": "2022-06-28",
"count": 1
},
{
"date": "2022-07-09",
"count": 1
},
{
"date": "2022-07-15",
"count": 1
},
{
"date": "2022-07-26",
"count": 1
},
{
"date": "2022-08-04",
"count": 1
},
{
"date": "2022-08-10",
"count": 1
},
{
"date": "2022-08-19",
"count": 1
},
{
"date": "2022-08-26",
"count": 1
},
{
"date": "2022-09-01",
"count": 1
},
{
"date": "2022-09-08",
"count": 1
},
{
"date": "2022-09-23",
"count": 1
},
{
"date": "2022-09-28",
"count": 2
},
{
"date": "2022-10-13",
"count": 1
},
{
"date": "2022-11-04",
"count": 2
},
{
"date": "2022-11-18",
"count": 1
},
{
"date": "2022-11-19",
"count": 1
},
{
"date": "2022-12-02",
"count": 1
},
{
"date": "2022-12-15",
"count": 1
},
{
"date": "2022-12-19",
"count": 1
},
{
"date": "2023-01-10",
"count": 1
},
{
"date": "2023-01-16",
"count": 1
},
{
"date": "2023-02-20",
"count": 1
},
{
"date": "2023-02-23",
"count": 1
},
{
"date": "2023-03-06",
"count": 1
},
{
"date": "2023-03-22",
"count": 1
},
{
"date": "2023-03-30",
"count": 1
},
{
"date": "2023-04-21",
"count": 1
},
{
"date": "2023-05-26",
"count": 1
},
{
"date": "2023-06-30",
"count": 1
},
{
"date": "2023-08-01",
"count": 1
},
{
"date": "2023-08-04",
"count": 1
},
{
"date": "2023-08-24",
"count": 1
},
{
"date": "2023-11-05",
"count": 1
},
{
"date": "2023-12-26",
"count": 1
},
{
"date": "2023-12-29",
"count": 1
},
{
"date": "2024-03-12",
"count": 1
},
{
"date": "2024-06-13",
"count": 1
},
{
"date": "2024-07-15",
"count": 1
},
{
"date": "2024-08-02",
"count": 1
},
{
"date": "2024-08-15",
"count": 1
},
{
"date": "2024-09-06",
"count": 1
},
{
"date": "2024-09-16",
"count": 1
},
{
"date": "2024-09-25",
"count": 1
},
{
"date": "2024-10-09",
"count": 1
},
{
"date": "2024-10-11",
"count": 1
},
{
"date": "2024-10-25",
"count": 1
},
{
"date": "2024-12-16",
"count": 1
},
{
"date": "2025-02-01",
"count": 1
},
{
"date": "2025-02-16",
"count": 1
},
{
"date": "2025-02-24",
"count": 1
},
{
"date": "2025-03-05",
"count": 1
},
{
"date": "2025-03-10",
"count": 1
},
{
"date": "2025-03-23",
"count": 1
},
{
"date": "2025-03-30",
"count": 1
},
{
"date": "2025-05-24",
"count": 1
},
{
"date": "2025-07-06",
"count": 1
},
{
"date": "2025-07-21",
"count": 1
},
{
"date": "2025-07-29",
"count": 1
},
{
"date": "2025-07-31",
"count": 1
},
{
"date": "2025-08-04",
"count": 1
},
{
"date": "2025-08-06",
"count": 1
},
{
"date": "2025-08-12",
"count": 1
},
{
"date": "2025-08-16",
"count": 1
},
{
"date": "2025-08-31",
"count": 1
},
{
"date": "2025-09-30",
"count": 1
},
{
"date": "2025-10-19",
"count": 1
},
{
"date": "2025-11-08",
"count": 1
},
{
"date": "2025-11-13",
"count": 1
},
{
"date": "2025-11-14",
"count": 1
},
{
"date": "2025-11-22",
"count": 1
},
{
"date": "2025-11-26",
"count": 1
},
{
"date": "2025-11-28",
"count": 1
},
{
"date": "2025-12-22",
"count": 1
},
{
"date": "2026-01-23",
"count": 1
},
{
"date": "2026-01-24",
"count": 1
},
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-23",
"count": 1
},
{
"date": "2026-02-26",
"count": 2
},
{
"date": "2026-03-01",
"count": 1
},
{
"date": "2026-04-06",
"count": 1
},
{
"date": "2026-04-09",
"count": 1
},
{
"date": "2026-04-12",
"count": 1
},
{
"date": "2026-05-23",
"count": 1
},
{
"date": "2026-06-03",
"count": 2
},
{
"date": "2026-06-14",
"count": 1
},
{
"date": "2026-06-17",
"count": 1
},
{
"date": "2026-06-19",
"count": 2
},
{
"date": "2026-06-21",
"count": 1
},
{
"date": "2026-06-27",
"count": 1
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-06-30",
"count": 1
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-04",
"count": 1
}
],
"complete": true,
"collected": 212,
"total_forks": 214
},
"star_history": null,
"open_issues_and_prs": 80
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"demos",
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"docs/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 38670,
"source_files_sampled": 95,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 6692
},
"dependencies": {
"manifests": [
"Pipfile",
"docs/requirements.txt",
"setup.py"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 44,
"malicious_count": 0,
"assessed_package": "pypi:quark-engine@26.7.1",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "alabaster",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "alabaster",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "androguard",
"direct": false,
"version": "3.4.0a1",
"ecosystem": "pypi"
},
{
"name": "annotated-types",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "anyio",
"direct": false,
"version": "4.12.1",
"ecosystem": "pypi"
},
{
"name": "asn1crypto",
"direct": false,
"version": "1.5.1",
"ecosystem": "pypi"
},
{
"name": "asttokens",
"direct": false,
"version": "3.0.1",
"ecosystem": "pypi"
},
{
"name": "babel",
"direct": false,
"version": "2.17.0",
"ecosystem": "pypi"
},
{
"name": "black",
"direct": false,
"version": "26.3.1",
"ecosystem": "pypi"
},
{
"name": "certifi",
"direct": false,
"version": "2026.1.4",
"ecosystem": "pypi"
},
{
"name": "charset-normalizer",
"direct": false,
"version": "3.4.4",
"ecosystem": "pypi"
},
{
"name": "cli-helpers",
"direct": false,
"version": "2.7.0",
"ecosystem": "pypi"
},
{
"name": "click",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "click",
"direct": false,
"version": "8.0.4",
"ecosystem": "pypi"
},
{
"name": "click-default-group",
"direct": false,
"version": "1.2.4",
"ecosystem": "pypi"
},
{
"name": "colorama",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "colorama",
"direct": false,
"version": "0.4.4",
"ecosystem": "pypi"
},
{
"name": "commonmark",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "condense-json",
"direct": false,
"version": "0.1.3",
"ecosystem": "pypi"
},
{
"name": "configobj",
"direct": false,
"version": "5.0.9",
"ecosystem": "pypi"
},
{
"name": "contourpy",
"direct": false,
"version": "1.3.2",
"ecosystem": "pypi"
},
{
"name": "cycler",
"direct": false,
"version": "0.12.1",
"ecosystem": "pypi"
},
{
"name": "decorator",
"direct": false,
"version": "5.2.1",
"ecosystem": "pypi"
},
{
"name": "delegator-py",
"direct": false,
"version": "0.1.1",
"ecosystem": "pypi"
},
{
"name": "dextrace",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "distro",
"direct": false,
"version": "1.9.0",
"ecosystem": "pypi"
},
{
"name": "docutils",
"direct": false,
"version": "0.21.2",
"ecosystem": "pypi"
},
{
"name": "exceptiongroup",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "executing",
"direct": false,
"version": "2.2.1",
"ecosystem": "pypi"
},
{
"name": "flask",
"direct": false,
"version": "3.1.3",
"ecosystem": "pypi"
},
{
"name": "fonttools",
"direct": false,
"version": "4.61.1",
"ecosystem": "pypi"
},
{
"name": "frida",
"direct": false,
"version": "15.2.2",
"ecosystem": "pypi"
},
{
"name": "frida-tools",
"direct": false,
"version": "11.0.0",
"ecosystem": "pypi"
},
{
"name": "graphviz",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "graphviz",
"direct": false,
"version": "0.18.2",
"ecosystem": "pypi"
},
{
"name": "h11",
"direct": false,
"version": "0.16.0",
"ecosystem": "pypi"
},
{
"name": "httpcore",
"direct": false,
"version": "1.0.9",
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": false,
"version": "0.28.1",
"ecosystem": "pypi"
},
{
"name": "idna",
"direct": false,
"version": "3.11",
"ecosystem": "pypi"
},
{
"name": "imagesize",
"direct": false,
"version": "1.4.1",
"ecosystem": "pypi"
},
{
"name": "iniconfig",
"direct": false,
"version": "2.3.0",
"ecosystem": "pypi"
},
{
"name": "ipython",
"direct": false,
"version": "8.18.0",
"ecosystem": "pypi"
},
{
"name": "itsdangerous",
"direct": false,
"version": "2.2.0",
"ecosystem": "pypi"
},
{
"name": "jedi",
"direct": false,
"version": "0.19.2",
"ecosystem": "pypi"
},
{
"name": "jinja2",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jinja2",
"direct": false,
"version": "3.1.6",
"ecosystem": "pypi"
},
{
"name": "jiter",
"direct": false,
"version": "0.12.0",
"ecosystem": "pypi"
},
{
"name": "kiwisolver",
"direct": false,
"version": "1.4.10rc0",
"ecosystem": "pypi"
},
{
"name": "langchain",
"direct": false,
"version": "0.2.11",
"ecosystem": "pypi"
},
{
"name": "langchain-core",
"direct": false,
"version": "0.2.23",
"ecosystem": "pypi"
},
{
"name": "langchain-openai",
"direct": false,
"version": "0.1.17",
"ecosystem": "pypi"
},
{
"name": "librt",
"direct": false,
"version": "0.7.7",
"ecosystem": "pypi"
},
{
"name": "litecli",
"direct": false,
"version": "1.17.0",
"ecosystem": "pypi"
},
{
"name": "llm",
"direct": false,
"version": "0.28",
"ecosystem": "pypi"
},
{
"name": "lxml",
"direct": false,
"version": "6.1.0",
"ecosystem": "pypi"
},
{
"name": "markupsafe",
"direct": false,
"version": "3.0.3",
"ecosystem": "pypi"
},
{
"name": "matplotlib",
"direct": false,
"version": "3.10.8",
"ecosystem": "pypi"
},
{
"name": "matplotlib-inline",
"direct": false,
"version": "0.2.1",
"ecosystem": "pypi"
},
{
"name": "mock",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": "1.19.1",
"ecosystem": "pypi"
},
{
"name": "mypy-extensions",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "networkx",
"direct": false,
"version": "3.4.2",
"ecosystem": "pypi"
},
{
"name": "numpy",
"direct": false,
"version": "2.2.6",
"ecosystem": "pypi"
},
{
"name": "objection",
"direct": false,
"version": "1.11.0",
"ecosystem": "pypi"
},
{
"name": "openai",
"direct": false,
"version": "2.15.0",
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": false,
"version": "26.0rc2",
"ecosystem": "pypi"
},
{
"name": "parso",
"direct": false,
"version": "0.8.5",
"ecosystem": "pypi"
},
{
"name": "pathspec",
"direct": false,
"version": "1.0.3",
"ecosystem": "pypi"
},
{
"name": "pathvalidate",
"direct": false,
"version": "3.2.3",
"ecosystem": "pypi"
},
{
"name": "pexpect",
"direct": false,
"version": "4.9.0",
"ecosystem": "pypi"
},
{
"name": "pillow",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pillow",
"direct": false,
"version": "12.1.0",
"ecosystem": "pypi"
},
{
"name": "pip",
"direct": false,
"version": "26.1.2",
"ecosystem": "pypi"
},
{
"name": "platformdirs",
"direct": false,
"version": "4.9.4",
"ecosystem": "pypi"
},
{
"name": "plotly",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "plotly",
"direct": false,
"version": "5.4.0",
"ecosystem": "pypi"
},
{
"name": "pluggy",
"direct": false,
"version": "1.6.0",
"ecosystem": "pypi"
},
{
"name": "prettytable",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "prettytable",
"direct": false,
"version": "2.4.0",
"ecosystem": "pypi"
},
{
"name": "prompt-toolkit",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "prompt-toolkit",
"direct": false,
"version": "3.0.36",
"ecosystem": "pypi"
},
{
"name": "ptyprocess",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "pure-eval",
"direct": false,
"version": "0.2.3",
"ecosystem": "pypi"
},
{
"name": "puremagic",
"direct": false,
"version": "1.30",
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": false,
"version": "2.12.5",
"ecosystem": "pypi"
},
{
"name": "pydantic-core",
"direct": false,
"version": "2.41.5",
"ecosystem": "pypi"
},
{
"name": "pydot",
"direct": false,
"version": "4.0.1",
"ecosystem": "pypi"
},
{
"name": "pygments",
"direct": false,
"version": "2.20.0",
"ecosystem": "pypi"
},
{
"name": "pyparsing",
"direct": false,
"version": "3.3.1",
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": "9.0.3",
"ecosystem": "pypi"
},
{
"name": "python-dateutil",
"direct": false,
"version": "2.9.0.post0",
"ecosystem": "pypi"
},
{
"name": "python-ulid",
"direct": false,
"version": "3.1.0",
"ecosystem": "pypi"
},
{
"name": "pytokens",
"direct": false,
"version": "0.4.1",
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": false,
"version": "6.0.3",
"ecosystem": "pypi"
},
{
"name": "r2pipe",
"direct": false,
"version": "1.8.0",
"ecosystem": "pypi"
},
{
"name": "readthedocs-sphinx-ext",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "recommonmark",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": "2.33.0",
"ecosystem": "pypi"
},
{
"name": "rzpipe",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "rzpipe",
"direct": false,
"version": "0.1.2",
"ecosystem": "pypi"
},
{
"name": "semver",
"direct": false,
"version": "2.13.0",
"ecosystem": "pypi"
},
{
"name": "setuptools",
"direct": false,
"version": "80.9.0",
"ecosystem": "pypi"
},
{
"name": "six",
"direct": false,
"version": "1.17.0",
"ecosystem": "pypi"
},
{
"name": "sniffio",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "snowballstemmer",
"direct": false,
"version": "3.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinx",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "sphinx",
"direct": false,
"version": "8.1.3",
"ecosystem": "pypi"
},
{
"name": "sphinx-rtd-theme",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "sphinx-rtd-theme",
"direct": false,
"version": "3.1.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-applehelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-devhelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-htmlhelp",
"direct": false,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-jquery",
"direct": false,
"version": "4.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-jsmath",
"direct": false,
"version": "1.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-qthelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-serializinghtml",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sqlite-fts4",
"direct": false,
"version": "1.0.3",
"ecosystem": "pypi"
},
{
"name": "sqlite-migrate",
"direct": false,
"version": "0.1b0",
"ecosystem": "pypi"
},
{
"name": "sqlite-utils",
"direct": false,
"version": "4.0a1",
"ecosystem": "pypi"
},
{
"name": "sqlparse",
"direct": false,
"version": "0.5.5",
"ecosystem": "pypi"
},
{
"name": "stack-data",
"direct": false,
"version": "0.6.3",
"ecosystem": "pypi"
},
{
"name": "tabulate",
"direct": false,
"version": "0.9.0",
"ecosystem": "pypi"
},
{
"name": "tenacity",
"direct": false,
"version": "9.1.2",
"ecosystem": "pypi"
},
{
"name": "tomli",
"direct": false,
"version": "2.4.0",
"ecosystem": "pypi"
},
{
"name": "tqdm",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "tqdm",
"direct": false,
"version": "4.66.5",
"ecosystem": "pypi"
},
{
"name": "traitlets",
"direct": false,
"version": "5.14.3",
"ecosystem": "pypi"
},
{
"name": "typing-extensions",
"direct": false,
"version": "4.15.0",
"ecosystem": "pypi"
},
{
"name": "typing-inspection",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "urllib3",
"direct": false,
"version": "2.6.3",
"ecosystem": "pypi"
},
{
"name": "wcwidth",
"direct": false,
"version": "0.2.14",
"ecosystem": "pypi"
},
{
"name": "werkzeug",
"direct": false,
"version": "3.1.6",
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 132,
"direct_count": 0,
"indirect_count": 132
}
},
"maintainership": {
"issues": {
"open_prs": 23,
"merged_prs": 518,
"open_issues": 57,
"closed_ratio": 0.818,
"closed_issues": 257,
"closed_unmerged_prs": 90
},
"bus_factor": 3,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "krnick",
"commits": 354,
"avatar_url": "https://avatars.githubusercontent.com/u/16042160?v=4"
},
{
"type": "User",
"login": "haeter525",
"commits": 161,
"avatar_url": "https://avatars.githubusercontent.com/u/3461569?v=4"
},
{
"type": "User",
"login": "pulorsok",
"commits": 148,
"avatar_url": "https://avatars.githubusercontent.com/u/16009212?v=4"
},
{
"type": "User",
"login": "18z",
"commits": 85,
"avatar_url": "https://avatars.githubusercontent.com/u/593954?v=4"
},
{
"type": "User",
"login": "zinwang",
"commits": 78,
"avatar_url": "https://avatars.githubusercontent.com/u/32264884?v=4"
},
{
"type": "User",
"login": "JerryTasi",
"commits": 60,
"avatar_url": "https://avatars.githubusercontent.com/u/127014343?v=4"
},
{
"type": "User",
"login": "sidra-asa",
"commits": 57,
"avatar_url": "https://avatars.githubusercontent.com/u/7848936?v=4"
},
{
"type": "User",
"login": "LiangPPP",
"commits": 30,
"avatar_url": "https://avatars.githubusercontent.com/u/61388755?v=4"
},
{
"type": "User",
"login": "sharteeya",
"commits": 17,
"avatar_url": "https://avatars.githubusercontent.com/u/38580996?v=4"
},
{
"type": "User",
"login": "PoJenC",
"commits": 8,
"avatar_url": "https://avatars.githubusercontent.com/u/120995761?v=4"
}
],
"contributors_sampled": 31,
"top_contributor_share": 0.34
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ai-issue-solver.yml",
"codeql-analysis.yml",
"config.yaml",
"config.yaml",
"docker-image.yml",
"docker-publish.yml",
"github-release-draft.yml",
"github-release-issue-pr.yml",
"kali-package.yml",
"pytest.yml",
"pythonpublish.yml",
"smoke_test.yml",
"sweagent.yaml",
"tool-usage-example.yaml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [
"Pipfile.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 6 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 0,
"reason": "dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "25 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "26 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "cb80e96d36a5220505acb820a8b19e9dcbef4644",
"ran_at": "2026-07-22T11:44:18Z",
"aggregate_score": 5.3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T19:52:44Z",
"oldest_open_prs": [
{
"number": 336,
"created_at": "2022-04-23T11:43:16Z",
"last_comment_at": "2022-04-24T10:38:16Z",
"last_comment_author": "haeter525"
},
{
"number": 337,
"created_at": "2022-04-25T08:59:00Z",
"last_comment_at": "2022-09-08T08:51:41Z",
"last_comment_author": "lgtm-com"
},
{
"number": 378,
"created_at": "2022-08-19T15:53:30Z",
"last_comment_at": "2022-08-19T20:21:34Z",
"last_comment_author": "codecov-commenter"
},
{
"number": 394,
"created_at": "2022-10-07T11:20:36Z",
"last_comment_at": "2023-02-22T04:27:54Z",
"last_comment_author": "zinwang"
},
{
"number": 404,
"created_at": "2022-10-20T18:29:08Z",
"last_comment_at": "2022-11-03T16:35:21Z",
"last_comment_author": "zinwang"
},
{
"number": 421,
"created_at": "2022-11-08T07:10:40Z",
"last_comment_at": "2022-11-13T16:55:25Z",
"last_comment_author": "haeter525"
},
{
"number": 492,
"created_at": "2023-03-21T13:18:49Z",
"last_comment_at": "2023-03-30T22:02:42Z",
"last_comment_author": "sidra-asa"
},
{
"number": 583,
"created_at": "2023-11-23T15:58:55Z",
"last_comment_at": "2023-11-23T16:10:11Z",
"last_comment_author": "codecov-commenter"
},
{
"number": 692,
"created_at": "2024-09-25T06:28:46Z",
"last_comment_at": "2024-09-25T06:37:59Z",
"last_comment_author": "codecov"
},
{
"number": 729,
"created_at": "2025-01-20T09:04:18Z",
"last_comment_at": "2025-04-16T02:23:25Z",
"last_comment_author": "zinwang"
},
{
"number": 797,
"created_at": "2025-08-16T19:20:28Z",
"last_comment_at": "2025-08-19T10:42:21Z",
"last_comment_author": "codecov"
},
{
"number": 855,
"created_at": "2026-01-18T18:52:22Z",
"last_comment_at": "2026-01-18T19:10:14Z",
"last_comment_author": "codecov"
},
{
"number": 894,
"created_at": "2026-03-29T09:13:11Z",
"last_comment_at": "2026-03-29T09:32:32Z",
"last_comment_author": "codecov"
},
{
"number": 920,
"created_at": "2026-05-17T08:36:52Z",
"last_comment_at": "2026-05-17T08:56:02Z",
"last_comment_author": "codecov"
},
{
"number": 922,
"created_at": "2026-05-17T08:41:15Z",
"last_comment_at": "2026-06-21T04:20:03Z",
"last_comment_author": "haeter525"
},
{
"number": 928,
"created_at": "2026-06-19T21:44:49Z",
"last_comment_at": "2026-06-19T22:03:07Z",
"last_comment_author": "codecov"
},
{
"number": 929,
"created_at": "2026-06-21T03:34:36Z",
"last_comment_at": "2026-06-21T03:52:48Z",
"last_comment_author": "codecov"
},
{
"number": 930,
"created_at": "2026-06-21T03:56:33Z",
"last_comment_at": "2026-06-21T04:14:48Z",
"last_comment_author": "codecov"
},
{
"number": 935,
"created_at": "2026-06-26T07:09:16Z",
"last_comment_at": "2026-06-26T07:25:42Z",
"last_comment_author": "codecov"
},
{
"number": 947,
"created_at": "2026-07-05T08:08:35Z",
"last_comment_at": "2026-07-05T08:24:59Z",
"last_comment_author": "codecov"
}
],
"last_merged_pr_at": "2026-07-15T02:58:13Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 44,
"created_at": "2020-02-19T07:18:30Z",
"last_comment_at": "2020-03-25T01:14:03Z",
"last_comment_author": "18z"
},
{
"number": 75,
"created_at": "2020-09-29T13:55:46Z",
"last_comment_at": "2021-09-08T08:34:28Z",
"last_comment_author": "sharteeya"
},
{
"number": 94,
"created_at": "2020-11-20T07:46:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 130,
"created_at": "2021-02-17T06:17:14Z",
"last_comment_at": "2022-03-05T16:13:04Z",
"last_comment_author": "VivekChoudhary128"
},
{
"number": 131,
"created_at": "2021-02-17T06:23:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 132,
"created_at": "2021-02-17T06:25:54Z",
"last_comment_at": "2021-03-22T11:57:05Z",
"last_comment_author": "codewithvicky"
},
{
"number": 135,
"created_at": "2021-02-17T08:46:46Z",
"last_comment_at": "2021-02-22T17:10:10Z",
"last_comment_author": "pulorsok"
},
{
"number": 153,
"created_at": "2021-03-29T18:14:29Z",
"last_comment_at": "2021-10-20T00:55:44Z",
"last_comment_author": "leeweiche20"
},
{
"number": 157,
"created_at": "2021-04-09T07:58:33Z",
"last_comment_at": "2021-06-03T10:49:29Z",
"last_comment_author": "3aglew0"
},
{
"number": 159,
"created_at": "2021-04-17T10:54:37Z",
"last_comment_at": "2021-05-29T10:43:08Z",
"last_comment_author": "3aglew0"
},
{
"number": 226,
"created_at": "2021-08-05T21:21:11Z",
"last_comment_at": "2021-10-20T05:30:28Z",
"last_comment_author": "sharteeya"
},
{
"number": 227,
"created_at": "2021-08-09T04:37:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 228,
"created_at": "2021-08-09T05:21:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 229,
"created_at": "2021-08-09T05:28:33Z",
"last_comment_at": "2021-10-03T09:43:22Z",
"last_comment_author": "haeter525"
},
{
"number": 263,
"created_at": "2021-10-06T21:34:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 299,
"created_at": "2022-01-09T18:34:17Z",
"last_comment_at": "2025-12-14T08:10:10Z",
"last_comment_author": "haeter525"
},
{
"number": 305,
"created_at": "2022-01-29T21:12:28Z",
"last_comment_at": "2022-03-09T11:36:25Z",
"last_comment_author": "chinggg"
},
{
"number": 313,
"created_at": "2022-03-08T08:03:19Z",
"last_comment_at": "2022-03-08T10:01:18Z",
"last_comment_author": "VivekChoudhary128"
},
{
"number": 324,
"created_at": "2022-03-30T13:48:34Z",
"last_comment_at": "2022-04-19T05:04:21Z",
"last_comment_author": "haeter525"
},
{
"number": 330,
"created_at": "2022-04-21T23:11:58Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/ev-flow/quark-engine",
"host": "github.com",
"name": "quark-engine",
"owner": "ev-flow"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"security": 62,
"vitality": 99,
"community": 67,
"governance": 75,
"engineering": 92
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 99,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"commits_last_year": 119,
"human_commit_share": 0.78,
"days_since_last_push": 7,
"active_weeks_last_year": 50
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 7 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 7
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "50/52 weeks with commits",
"points": 34.6,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 50
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "119 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 119
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "25 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 84,
"latest_release_tag": "v26.7.1",
"releases_from_tags": false,
"days_since_latest_release": 20,
"mean_days_between_releases": 33.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "84 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 84
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 20 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 20
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~33.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 33.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 7,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 7 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 7
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 67,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "good",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"forks": 214,
"stars": 1697,
"watchers": 39,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "1,697 stars",
"points": 52.4,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 1697
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "214 forks",
"points": 19.4,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 214
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "39 watchers",
"points": 8.8,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 39
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (GPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "GPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 75,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "good",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"bus_factor": 3,
"contributors_sampled": 31,
"top_contributor_share": 0.34
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "3 contributor(s) cover half of all commits",
"points": 36,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 3
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 34% of commits",
"points": 14.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 34
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "31 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 31
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 6 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 86,
"inputs": {
"merged_prs": 518,
"open_issues": 57,
"closed_issues": 257,
"issue_closed_ratio": 0.818,
"closed_unmerged_prs": 90
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "82% of issues closed",
"points": 38.2,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 82
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "518/608 decided PRs merged",
"points": 32.6,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 518,
"decided": 608
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"followers": 40,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "ev-flow",
"public_repos": 24,
"account_age_days": 2456
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "40 followers of ev-flow",
"points": 11.6,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 40,
"login": "ev-flow"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "24 public repos, account ~6 yr old",
"points": 22.2,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 24
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 92,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 94,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "14 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 14
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 16,
"status": "met",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"defcon",
"android",
"blackhat",
"blackbox",
"malware-analysis",
"malware-detection"
],
"has_wiki": true,
"homepage": "https://doc.quark-engine.com",
"has_readme": true,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://doc.quark-engine.com",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "6 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 6
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 62,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 53,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 6 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "dangerous workflow patterns detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "25 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "26 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the pypi:quark-engine@26.7.1 runtime dependency closure — what installing the published package pulls in — 44 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "pypi:quark-engine@26.7.1",
"assessed": 44
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 44,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 44,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 6
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 70,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "good",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.692,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 6692
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "54 of 78 human commits state their intent (structured subject or explanatory body)",
"points": 36.9,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 54,
"sampled": 78
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Pipfile.lock"
],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [
"docs/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.04,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.12
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "docs/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 11,
"status": "met",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "4 of the last 100 commits agent-authored or agent-credited",
"points": 8,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 4,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "12 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 12,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 38670,
"source_files_sampled": 95,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/95 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 95,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"demos",
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "demos, examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "demos, examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"pypi package 'quark-engine' points at a different repository (https://github.com/quark-engine/quark-engine); excluded from ecosystem scoring"
],
"report_type": "repository",
"generated_at": "2026-07-22T11:44:49.522001Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/ev-flow/quark-engine.svg",
"full_name": "ev-flow/quark-engine",
"license_state": "standard",
"license_spdx": "GPL-3.0"
}