JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"oci",
"containers",
"airgap",
"kubernetes",
"airgapped",
"cli",
"disconnected"
],
"is_fork": false,
"size_kb": 82937,
"has_wiki": false,
"homepage": "https://hauler.dev",
"languages": {
"Go": 538595,
"HTML": 631,
"Shell": 7560,
"Makefile": 1496,
"Dockerfile": 1410
},
"pushed_at": "2026-08-03T03:41:23Z",
"created_at": "2020-08-14T10:00:56Z",
"owner_type": "Organization",
"updated_at": "2026-08-03T03:41:54Z",
"description": "Airgap Swiss Army Knife",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": null,
"type": "Organization",
"login": "hauler-dev",
"company": null,
"location": null,
"followers": 10,
"avatar_url": "https://avatars.githubusercontent.com/u/165307012?v=4",
"created_at": "2024-03-28T16:21:44Z",
"is_verified": null,
"public_repos": 6,
"account_age_days": 857
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v2.0.2",
"kind": "patch",
"published_at": "2026-07-21T19:22:16Z"
},
{
"tag": "v2.0.1",
"kind": "patch",
"published_at": "2026-06-23T16:22:18Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2026-06-23T01:44:15Z"
},
{
"tag": "v2.0.0-rc.2",
"kind": "prerelease",
"published_at": "2026-06-22T20:09:13Z"
},
{
"tag": "v2.0.0-rc.1",
"kind": "prerelease",
"published_at": "2026-06-22T15:31:50Z"
},
{
"tag": "v1.4.3",
"kind": "patch",
"published_at": "2026-05-05T05:26:28Z"
},
{
"tag": "v1.4.3-rc.1",
"kind": "prerelease",
"published_at": "2026-04-28T00:46:41Z"
},
{
"tag": "v2.0.0-dev.2",
"kind": "prerelease",
"published_at": "2026-04-08T16:10:38Z"
},
{
"tag": "v2.0.0-dev.1",
"kind": "prerelease",
"published_at": "2026-03-12T05:20:40Z"
},
{
"tag": "v1.4.2",
"kind": "patch",
"published_at": "2026-03-06T15:57:03Z"
},
{
"tag": "v1.4.2-rc.1",
"kind": "prerelease",
"published_at": "2026-03-03T16:26:35Z"
},
{
"tag": "v1.4.2-dev.1",
"kind": "prerelease",
"published_at": "2026-01-22T15:32:15Z"
},
{
"tag": "v1.4.1",
"kind": "patch",
"published_at": "2026-01-16T12:56:15Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-01-12T22:41:04Z"
},
{
"tag": "v1.4.0-rc.1",
"kind": "prerelease",
"published_at": "2026-01-09T21:06:05Z"
},
{
"tag": "v1.3.2",
"kind": "patch",
"published_at": "2025-12-17T13:50:19Z"
},
{
"tag": "v1.3.1",
"kind": "patch",
"published_at": "2025-11-07T00:52:59Z"
},
{
"tag": "v1.3.1-rc.1",
"kind": "prerelease",
"published_at": "2025-11-03T19:24:51Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2025-10-15T03:49:30Z"
},
{
"tag": "v1.3.0-dev.1",
"kind": "prerelease",
"published_at": "2025-10-01T16:00:10Z"
},
{
"tag": "v1.2.5",
"kind": "patch",
"published_at": "2025-07-14T20:20:09Z"
},
{
"tag": "v1.2.4",
"kind": "patch",
"published_at": "2025-05-01T15:50:05Z"
},
{
"tag": "v1.2.3",
"kind": "patch",
"published_at": "2025-04-22T17:15:27Z"
},
{
"tag": "v1.2.3-dev.1",
"kind": "prerelease",
"published_at": "2025-04-08T13:54:02Z"
},
{
"tag": "v1.2.2",
"kind": "patch",
"published_at": "2025-03-28T17:49:50Z"
},
{
"tag": "v1.2.2-rc.1",
"kind": "prerelease",
"published_at": "2025-03-27T13:26:50Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2025-02-07T18:47:42Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2025-02-07T00:02:45Z"
},
{
"tag": "v1.2.0-dev.2",
"kind": "prerelease",
"published_at": "2025-01-25T05:04:19Z"
},
{
"tag": "v1.2.0-dev.1",
"kind": "prerelease",
"published_at": "2025-01-11T02:55:51Z"
},
{
"tag": "v1.1.1",
"kind": "patch",
"published_at": "2024-12-09T13:35:45Z"
},
{
"tag": "v1.1.1-rc.1",
"kind": "prerelease",
"published_at": "2024-12-04T21:11:48Z"
},
{
"tag": "v1.1.1-dev.1",
"kind": "prerelease",
"published_at": "2024-11-15T04:32:45Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2024-10-04T22:32:48Z"
},
{
"tag": "v1.1.0-rc.10",
"kind": "prerelease",
"published_at": "2024-10-02T18:41:08Z"
},
{
"tag": "v1.1.0-rc.9",
"kind": "prerelease",
"published_at": "2024-10-02T01:21:33Z"
},
{
"tag": "v1.1.0-rc.8",
"kind": "prerelease",
"published_at": "2024-10-01T20:17:40Z"
},
{
"tag": "v1.1.0-rc.7",
"kind": "prerelease",
"published_at": "2024-10-01T17:21:52Z"
},
{
"tag": "v1.1.0-rc.6",
"kind": "prerelease",
"published_at": "2024-10-01T16:31:15Z"
},
{
"tag": "v1.1.0-rc.5",
"kind": "prerelease",
"published_at": "2024-10-01T13:45:43Z"
},
{
"tag": "v1.1.0-rc.4",
"kind": "prerelease",
"published_at": "2024-09-27T22:19:42Z"
},
{
"tag": "v1.1.0-rc.3",
"kind": "prerelease",
"published_at": "2024-09-24T20:58:53Z"
},
{
"tag": "v1.0.8",
"kind": "patch",
"published_at": "2024-09-04T18:14:58Z"
},
{
"tag": "v1.1.0-rc.2",
"kind": "prerelease",
"published_at": "2024-08-30T11:34:04Z"
},
{
"tag": "v1.1.0-rc.1",
"kind": "prerelease",
"published_at": "2024-08-26T21:37:14Z"
},
{
"tag": "v1.0.7",
"kind": "patch",
"published_at": "2024-08-13T19:23:25Z"
},
{
"tag": "v1.0.6",
"kind": "patch",
"published_at": "2024-08-05T17:12:31Z"
},
{
"tag": "v1.0.5",
"kind": "patch",
"published_at": "2024-08-02T02:09:16Z"
},
{
"tag": "v1.0.5-rc.1",
"kind": "prerelease",
"published_at": "2024-07-31T03:56:45Z"
},
{
"tag": "v1.0.4",
"kind": "patch",
"published_at": "2024-06-26T03:28:42Z"
},
{
"tag": "v1.0.4-rc.3",
"kind": "prerelease",
"published_at": "2024-06-26T02:56:49Z"
},
{
"tag": "v1.0.4-rc.2",
"kind": "prerelease",
"published_at": "2024-06-25T03:23:48Z"
},
{
"tag": "v1.0.4-rc.1",
"kind": "prerelease",
"published_at": "2024-06-14T20:49:11Z"
},
{
"tag": "v1.0.3",
"kind": "patch",
"published_at": "2024-04-24T16:58:16Z"
},
{
"tag": "v1.0.2",
"kind": "patch",
"published_at": "2024-04-15T16:45:14Z"
},
{
"tag": "v1.0.2-rc.4",
"kind": "prerelease",
"published_at": "2024-04-06T01:46:08Z"
},
{
"tag": "v1.0.2-rc.3",
"kind": "prerelease",
"published_at": "2024-04-06T00:54:58Z"
},
{
"tag": "v1.0.2-rc.2",
"kind": "prerelease",
"published_at": "2024-04-06T00:14:33Z"
},
{
"tag": "v1.0.2-rc.1",
"kind": "prerelease",
"published_at": "2024-04-05T23:14:33Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2024-02-27T16:37:48Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2024-02-20T13:10:30Z"
},
{
"tag": "v1.0.0-rc.1",
"kind": "prerelease",
"published_at": "2024-02-16T13:30:04Z"
},
{
"tag": "v0.4.4",
"kind": "patch",
"published_at": "2024-02-13T00:46:59Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2024-01-31T21:08:57Z"
},
{
"tag": "v0.4.3-rc.1",
"kind": "prerelease",
"published_at": "2024-01-29T19:59:07Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2023-12-19T18:15:57Z"
},
{
"tag": "v0.4.2-rc.1",
"kind": "prerelease",
"published_at": "2023-12-19T17:02:07Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2023-12-14T20:48:00Z"
},
{
"tag": "v0.4.1-rc.2",
"kind": "prerelease",
"published_at": "2023-12-05T17:27:57Z"
},
{
"tag": "v0.4.1-rc.1",
"kind": "prerelease",
"published_at": "2023-11-30T19:15:01Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2023-11-07T15:34:16Z"
},
{
"tag": "v0.4.0-rc.2",
"kind": "prerelease",
"published_at": "2023-11-06T14:19:47Z"
},
{
"tag": "v0.4.0-rc.1",
"kind": "prerelease",
"published_at": "2023-11-04T15:38:25Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2022-01-25T19:10:44Z"
},
{
"tag": "v0.3.0-rc.4",
"kind": "prerelease",
"published_at": "2022-01-25T18:32:01Z"
},
{
"tag": "v0.3.0-rc.3",
"kind": "prerelease",
"published_at": "2022-01-24T23:53:35Z"
},
{
"tag": "v0.3.0-rc.2",
"kind": "prerelease",
"published_at": "2022-01-20T15:43:22Z"
},
{
"tag": "v0.3.0-rc.1",
"kind": "prerelease",
"published_at": "2022-01-12T18:48:44Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2021-11-16T19:14:46Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2021-11-12T17:18:19Z"
},
{
"tag": "v0.2.0-rc.4",
"kind": "prerelease",
"published_at": "2021-11-12T17:01:04Z"
},
{
"tag": "v0.2.0-rc.3",
"kind": "prerelease",
"published_at": "2021-11-11T21:05:40Z"
},
{
"tag": "v0.2.0-rc.2",
"kind": "prerelease",
"published_at": "2021-11-11T20:06:41Z"
},
{
"tag": "v0.2.0-rc.1",
"kind": "prerelease",
"published_at": "2021-11-11T19:24:26Z"
},
{
"tag": "v0.1.0-alpha3",
"kind": "prerelease",
"published_at": "2021-06-18T14:35:34Z"
}
],
"recent_commits": [
{
"oid": "2e280f27172277c004fad5a54f029356eba0fd7f",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "address helm chart verification, auth, and tls options (#601)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-08-03T03:41:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3764e8378595bd7c64e391074e03345671b8f3f",
"body": "…ring (#705)",
"is_bot": false,
"headline": "update hauler store remove to handle registry reference as part of st…",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-07-31T23:58:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "744f1b1b8d07743e0b6fe70299cfeb66817e3376",
"body": null,
"is_bot": false,
"headline": "fix: process helm deps before --add-images discovery (#703)",
"author_name": "aeltai",
"author_login": "aeltai",
"committed_at": "2026-07-31T15:17:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8dc864ca77c0729bf3f9036881958e3c6324b3e3",
"body": "Signed-off-by: Eric Klatzer <eric@klatzer.at>\nCo-authored-by: Zack Brady <zackbrady123@gmail.com>",
"is_bot": false,
"headline": "feat: extend charts resource by platform (#657)",
"author_name": "Eric Klatzer",
"author_login": "eklatzer",
"committed_at": "2026-07-30T18:59:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06ab061e102a619812f5965a73a0b9b5313c26ad",
"body": "…roup across 1 directory (#700)\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump google.golang.org/grpc from 1.82.0 to 1.82.1 in the go_modules g…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-30T18:46:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee55c5ba87f8961adfd1bbbdb060355ab152d94a",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix for homebrew macOS binary quarantine (#690)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-27T14:55:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c760462f406e95dc5e35b696b52bc99e9db600c",
"body": "… across 1 directory (#691)\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in the go_modules group…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T15:29:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76ca37fb4f1ff0ed7a3c897f365b2952ba70d95d",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (#688)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T15:23:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8677f3cc6c9b3287a911179747e9c8b925bd1a59",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix: bump golang to 1.26.5 (#685)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-21T18:30:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f5d767cd8813d61a00f52d82007003e05501fe3",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "registry auth fallback bugfix (#672)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-21T16:51:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f4a8baec62b0f2918986ef0a94563c6d46281b0",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix for copying digest artifacts (#673)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-21T15:55:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7e5c7a7c507a7aec6b6cd73d36b20023fff438e",
"body": "Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix: plain-http enforces use of http on bearer token fetch (#677) (#678)",
"author_name": "Jeroen van Erp",
"author_login": "hierynomus",
"committed_at": "2026-07-20T14:39:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59251c628d5fe48f782dd2a2ab9ef46215bcb92b",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/sigstore/cosign/v3 from 3.1.1 to 3.1.2 (#674)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T13:52:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2680e57f2e7f51c9be2afdd3463a5bfb016c95f8",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "bump containerd to v2 (#663)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-16T14:51:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb5e324f3a72816859009c9cb65f7cd6a882528e",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix the broken behavior for --insecure on copy (#668)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-16T14:19:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4195c4695ea7fc91543fa4afbf8feb87db6654e8",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "utilize vex for trivy scan (#662)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-10T17:53:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b9069d57c64858f16ab6c19fe3f1ed94dd397532",
"body": "Signed-off-by: Zack Brady <zackbrady123@gmail.com>",
"is_bot": false,
"headline": "added audit log functionality (#632)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-07-10T17:52:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d04bbdd6457ac992440b86b725d346fe2aa9363",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump helm.sh/helm/v4 from 4.2.2 to 4.2.3 (#661)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T12:41:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c38ba852b35384a58e681fbdad0e408af18af8df",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#659)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T12:40:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1dad651db6cedd73d8a6c836d222034fbcc77dc",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump golang.org/x/sync from 0.21.0 to 0.22.0 (#650)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T05:49:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d93167185f460fc64279805cba05477ac3267aeb",
"body": "Signed-off-by: Eric Klatzer <eric@klatzer.at>\nCo-authored-by: Zack Brady <zackbrady123@gmail.com>",
"is_bot": false,
"headline": "feat: extend charts resource with helm values (#644)",
"author_name": "Eric Klatzer",
"author_login": "eklatzer",
"committed_at": "2026-07-08T17:24:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cbf07f07d9cd2661f249b27ef1f71934a515455e",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "updates for helm v4 (#648)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-07-04T18:11:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32c30ac28a586d963d9e69b7340cf7b125319fbb",
"body": null,
"is_bot": false,
"headline": "unpinned distribution/distribution dependency (#647)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-07-04T13:31:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d912cfa85f2d398b26648f45bf145febea7a5de9",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "digest only regression fix (#643)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-06-26T13:55:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d00a53c9469298dad651282af0ae2a87e6514c2",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "add trivy to make and add new vuln GHA (#641)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-06-24T13:53:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f47155d6f8ccec22ba6f609f2f1f4919b02fce1",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "bump go to 1.26.4 to squash CVE noise (#640)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-06-23T15:58:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2bcc74450fccc3a1b16a745f4e3dab5b7371d93d",
"body": null,
"is_bot": false,
"headline": "removed experimental warnings from a few flags (#638)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-06-22T21:11:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec5082df181c03d409beea587b1d92d6ec9fb211",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "add v2 to module path to correct version (#637)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-06-22T20:40:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "905b3e4932a08c3cf814b03ffc4afeede10862ba",
"body": "Signed-off-by: Eric Klatzer <eric@klatzer.at>\nCo-authored-by: Zack Brady <zackbrady123@gmail.com>",
"is_bot": false,
"headline": "fix: image detection regex to allow hyphen in image property (#604)",
"author_name": "Eric Klatzer",
"author_login": "eklatzer",
"committed_at": "2026-06-22T15:10:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f68969de5cd60a23a85c84d883a9cf628a680b2e",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (#635)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T12:59:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "538a43f8ec04c0b501b6cd70bd7097f77510fcca",
"body": null,
"is_bot": false,
"headline": "updated git ignore (#631)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-06-19T16:17:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1baff64cc0af3eb0732e5033e0f5dd3dd02a0082",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#633)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-19T15:00:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e3fda28ce5b74bf554eeff3f8ad500134a05013",
"body": null,
"is_bot": false,
"headline": "bumped versions and dependencies (#630)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-06-18T19:14:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5abb42e7fc3bfedbd3105f71b7040a4c029120e2",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (#623)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-18T15:21:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c03e58024817928a0b4735b7788e5478f4845ad",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#625)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-18T14:30:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c5f8252b88a29e91344e0e97db4c0e3d96317d0",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 (#628)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-18T14:29:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65c665ce81dace2c21afc20f2c6489b0ed2f7b0a",
"body": "…#621)",
"is_bot": false,
"headline": "remove experimental notes from rewrite and remove for 2.0.0 release (…",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-06-09T22:53:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b31ba465e1fa657451c265790471b10d5d962ad",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump golang.org/x/sync from 0.20.0 to 0.21.0 (#620)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T18:34:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0431058430320aeadca85a0a4935ca00a083e0d",
"body": null,
"is_bot": false,
"headline": "411 special characters fix (#618)",
"author_name": "Adam Toy",
"author_login": "atoy3731",
"committed_at": "2026-06-03T13:36:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c6c10222981d3f450cfb59bddce502e06c371b9c",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/containerd/containerd from 1.7.31 to 1.7.32 (#616)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T07:19:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69d6b6e6959b1da6cfcd8a3f04f8a193b24eb6b1",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/google/go-containerregistry from 0.21.5 to 0.21.6 (#613)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T07:15:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "953211d308bb50e2c514c6e7ebcf3d28378cd9ec",
"body": "…o_modules group across 1 directory (#612)\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 in the g…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-14T13:59:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e782019c31946fe9e19f88543670ef3acd9ec53",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "bump go to 1.26.0",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-05-14T13:13:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7ab99b2a49f601a26f916a5095601ff01049414",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump helm.sh/helm/v3 from 3.20.2 to 3.21.0 (#610)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-14T12:44:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cfa7ea3484b5b57fa982a3df2445ffc1f6640d85",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "bump github.com/sigstore/cosign/v3 from 3.0.5 to 3.0.6",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-05-13T16:14:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "99406d6cf81b86db1823a6b46895e152add54b2b",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/containerd/containerd from 1.7.30 to 1.7.31 (#596)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T04:09:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "820baf0ba76567a8002bd35786659b7423cf83ea",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/google/go-containerregistry from 0.20.7 to 0.21.5 (#600)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T04:09:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d379ffa6601c51b161d8e3f31b31e0cf616f386d",
"body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/rs/zerolog from 1.34.0 to 1.35.1 (#593)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T04:08:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8b777abc8af3b09665bb1f37ac66cc06b72b6138",
"body": "…… (#585)",
"is_bot": false,
"headline": "add dependabot configuration file to track multiple release minor rel…",
"author_name": "Adam Toy",
"author_login": "atoy3731",
"committed_at": "2026-05-05T18:52:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fbcbb282c3a6556d409c95369fec071b2c7446c0",
"body": "Signed-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>",
"is_bot": false,
"headline": "remove cherrypick bot and add mergify details (#581)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-05-03T19:27:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf6e7bcc4012b6d6fa14ef3a93391031b3a94431",
"body": null,
"is_bot": false,
"headline": "added makefile command for vulnerability checks (#577)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-05-01T13:45:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6677f10d7b1770a66f55dfda1d682a0524e40650",
"body": null,
"is_bot": false,
"headline": "fixed github workflows (tests and cherrypicker) (#574)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-04-22T21:01:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eca35ecb921660c6f0ed163f0141d171c2a467ff",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "adjust logging for extracting oci artifacts with cosign bits (#575)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-04-22T16:57:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2bf284e183dfc698068de7d6c7fff8d1eeada24d",
"body": null,
"is_bot": false,
"headline": "removed unnecessary rewrite flag from sync (#572)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-04-21T20:53:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3cd3c037979a17bc19a0b4e394117694639a660",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/sigstore/timestamp-authority/v2](https://github.com/sigstore/timestamp-authority).\n\n\nupdates `github.com/sigstore/timestamp-authority/v2` from 2.0.4 to 2.0.6\n- [Release notes](https://github.com/sigstore/timestamp-authority/rel\n[…]\n\n dependency-type: indirect\n dependency-group: go_modules\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/sigstore/timestamp-authority/v2 (#557)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-19T23:24:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40c4fdded4559223002e4ddb9e408aae4af47a9a",
"body": "signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "add ability to add images from local docker daemon (#551)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-04-19T22:51:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b2d0f9f01eb629d22d5452bd95353f97aa989635",
"body": "signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "add dry-run flag for sync --products (#547)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-04-14T20:27:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "57d45f136ee5064fc86713acca21cb6534b19dbe",
"body": null,
"is_bot": false,
"headline": "handle large diff passed to gh api (#553)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-04-12T00:26:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8560d02a6d05647a866b20b691e7fb3f5c206d01",
"body": "bumps the go_modules group with 1 update in the / directory: [helm.sh/helm/v3](https://github.com/helm/helm).\n\nupdates `helm.sh/helm/v3` from 3.19.0 to 3.20.2\n- [Release notes](https://github.com/helm/helm/releases)\n- [Commits](https://github.com/helm/helm/compare/v3.19.0...v3.20.2)\n\n---\nupdated-dep\n[…]\nency-type: direct:production\n dependency-group: go_modules\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump helm.sh/helm/v3 in the go_modules group across 1 directory (#552)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-11T14:39:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a8d6e2e527304346ba7c2754d3fe16db3ddc9fb5",
"body": null,
"is_bot": false,
"headline": "verified commits and better messges (#550)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-04-09T00:23:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7319874ea86e5a93a9448feb6cf9f7293f29f1fa",
"body": "bumps the go_modules group with 1 update in the / directory: [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go).\n\nupdates `go.opentelemetry.io/otel/sdk` from 1.40.0 to 1.43.0\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](\n[…]\n\n dependency-type: indirect\n dependency-group: go_modules\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump go.opentelemetry.io/otel/sdk (#548)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-08T21:30:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f059a135da3df60ab96ac9bd86dc60b157185a7d",
"body": "…egistry (#541)\n\n* add optional flag for excluding extra artifacts when pulling from a registry\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* add optional flag to charts for excluding extra artifacts when pulling from a registry\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "add optional flag for excluding extra artifacts when pulling from a r…",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-04-07T16:48:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b3e21806feaad915c0cfa0b665abc71aeb3d17ba",
"body": "* allow multiple prefix references\n* fixed some duplications",
"is_bot": false,
"headline": "allow multiple prefix references (#532)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-04-07T11:51:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93938d1acbdc108850471b2cf243f627b0c5f199",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose).\n\n\nupdates `github.com/go-jose/go-jose/v4` from 4.1.3 to 4.1.4\n\n- [Release notes](https://github.com/go-jose/go-jose/releases)\n- [Commits](https://github.com/go-jose/go-jo\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/go-jose/go-jose/v4 (#542)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-03T12:41:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "641b9db8fda161e84144ca7c662c83f29260e7d4",
"body": "* chunk the haul\n* validate numeric suffix on join\n* enforce valid chunk size\n* containerd warning\n* updated test.go files",
"is_bot": false,
"headline": "chunk the haul (#519)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-25T14:59:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c68e72df1c96a4c9d375c0485c30add659d225a4",
"body": "* sync images.txt files\n* test worklflow sync w image list\n* images.txt",
"is_bot": false,
"headline": "option to sync images.txt files natively (#538)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-25T14:53:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e8046a1e306eff545f3f157867a93996df43b6de",
"body": "* fixed keep registry logic\n* trim library/\n* updated test\n* test updates",
"is_bot": false,
"headline": "fix keep registry logic (#537)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-25T14:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7fd03ea52e79e1e230f6d795e0b87417c87aba9f",
"body": null,
"is_bot": false,
"headline": "images.txt testdata file (#539)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-24T17:27:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa9b883d4cd3d314de2ce837fb1bbf84626afbc5",
"body": "this workflow automates cherry-picking changes from merged pull requests to specified release branches based on comments... it handles permission checks, version parsing, and conflict resolution during the cherry-pick process.\n\nSigned-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>",
"is_bot": false,
"headline": "add cherry-pick workflow for release branches (#533)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-19T03:26:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "565b27d54bb02ab54f331889b7243698d332cc6a",
"body": "…y (#536)\n\nbumps the go_modules group with 1 update in the / directory: [google.golang.org/grpc](https://github.com/grpc/grpc-go).\n\nupdates `google.golang.org/grpc` from 1.78.0 to 1.79.3\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump google.golang.org/grpc in the go_modules group across 1 director…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-19T03:25:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3adb9257b7ca6cc5e7722a94b359f4cc5ce370da",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "adjust hauler's kind annotation to not reflect cosign (#535)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-19T03:24:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "268485f6d67e1e4efbadae29c7166b73a08eb4ac",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix dockerhub default host bug (#534)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-19T03:24:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47479b1fa275551670bca72b76a118f6f65853a0",
"body": "* adjust extract to handle images and image indices appropriately\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* updates for review feedback\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "adjust extract to handle an image index appropriately (#531)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-12T03:49:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbde34690f65d5f2cab636af5d18de968f62829e",
"body": "* improved test coverage\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* adjusted mapper_test for oddball oci files\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "improved test coverage (#530)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-10T21:46:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0dd1896191834a6a8e12dcc0a85fc1641c1ee8f3",
"body": "* fix extract for oci files\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* have extract guard against path traversal\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "fix extract for oci files (#529)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-10T16:54:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc6123918fa007f317edde54a366d41784109222",
"body": "* removed deprecated code\n* removed all supported for v1alpha1",
"is_bot": false,
"headline": "removed deprecated code (#528)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-03-10T16:51:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "995e5384120b5cf3c8b1ea372b268162beb08fb4",
"body": "… (#526)\n\nbumps the go_modules group with 1 update in the / directory: [github.com/docker/cli](https://github.com/docker/cli).\n\n\nupdates `github.com/docker/cli` from 29.0.3+incompatible to 29.2.0+incompatible\n- [Commits](https://github.com/docker/cli/compare/v29.0.3...v29.2.0)\n\n---\n\nupdated-dependen\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/docker/cli in the go_modules group across 1 directory…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-06T17:27:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e2a59508afefe3671482447ea649c7b934a07d98",
"body": "…ased implementation (#515)\n\n* remove oras from hauler\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* remove cosign fork and use upstream cosign for verification\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* added support for oci referrers\n\nSigned-off-by: Ada\n[…]\non doesnt include anything other than actual container images\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "over-\"haul\": replace oras v1 and cosign fork with native containerd-b…",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-03-06T16:45:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26b11d5abc54c84502751c6c81549fb50c76cbb4",
"body": "* smaller changes and updates for v1.4.2 release\n* removed unused env variable",
"is_bot": false,
"headline": "smaller changes and updates for v1.4.2 release (#524)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-03-06T01:50:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4b16c723d14c3d10c12c0d85448ba2ad43ad812",
"body": null,
"is_bot": false,
"headline": "dev.md file (#521)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-03-02T21:13:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "666d220d6c9be61d0094b55edd97afcf3f449dc7",
"body": "bumps the go_modules group with 1 update in the / directory: [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go).\n\nupdates `go.opentelemetry.io/otel/sdk` from 1.39.0 to 1.40.0\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump go.opentelemetry.io/otel/sdk (#520)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-02T05:40:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ed7504264371dd4fdfc64911e64665cd10914b0",
"body": "…d (#514)\n\nco-authored-by: devleitner <devleitner@protonmail.com>",
"is_bot": false,
"headline": "fix: handling of file referenced dependencies without repository fiel…",
"author_name": "devLeitner",
"author_login": "devLeitner",
"committed_at": "2026-03-02T05:40:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e255eda0074d9a2123085441cf009c22177205e7",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/theupdateframework/go-tuf/v2](https://github.com/theupdateframework/go-tuf).\n\nupdates `github.com/theupdateframework/go-tuf/v2` from 2.3.1 to 2.4.1\n- [Release notes](https://github.com/theupdateframework/go-tuf/releases)\n- [Com\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/theupdateframework/go-tuf/v2 (#517)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-23T22:19:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16f47999b1357531c00fb320e5bdab061ab63c1a",
"body": "* keep registry on rewrite if not specified\n* better logic\n* add test\n* accurate info output for rewrite references\n* apply suggestions from code review\n\ncomment format and improved test\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nSigned-off-by: Camryn Carter <camryn.carter\n[…]\n\n\n---------\n\nSigned-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>\nCo-authored-by: Zack Brady <zackbrady123@gmail.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "keep registry on image rewrite if not specified (#501)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-02-23T22:18:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c6865442436cf34fbf471607a2b141c9083b6c1",
"body": "Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "update tablewriter to v1.1.2 (#512)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-02-14T16:55:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ecd87d944447d6d59afe6b9984df0e2d3ccac36",
"body": "Signed-off-by: Eric Klatzer <eric@klatzer.at>",
"is_bot": false,
"headline": "fix for file:// dependency chart path resolutions (#510)",
"author_name": "Eric Klatzer",
"author_login": "eklatzer",
"committed_at": "2026-02-14T16:43:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a35589817139e7a625940ffe6f274eb8f1b52cd1",
"body": "* update cosign fork to 3.0.4 plus dep tidy\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n* update to cosign fork tag v3.0.4+hauler.2\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>\n\n---------\n\nSigned-off-by: Adam Martin <adam.martin@ranchergovernment.com>",
"is_bot": false,
"headline": "update cosign fork to 3.0.4 plus dep tidy (#509)",
"author_name": "Adam Martin",
"author_login": "amartin120",
"committed_at": "2026-02-13T03:07:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3440b1a641b3a7f27979b1feabff9bab1208d200",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/theupdateframework/go-tuf/v2](https://github.com/theupdateframework/go-tuf).\n\nupdates `github.com/theupdateframework/go-tuf/v2` from 2.3.1 to 2.4.1\n- [Release notes](https://github.com/theupdateframework/go-tuf/releases)\n- [Com\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/theupdateframework/go-tuf/v2 (#502)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-27T14:55:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9081ac257b5f5a22f04fd2a8613a81ebc14e1d10",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore).\n\nupdates `github.com/sigstore/sigstore` from 1.10.3 to 1.10.4\n- [Release notes](https://github.com/sigstore/sigstore/releases)\n- [Commits](https://github.com/sigstore/si\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/sigstore/sigstore (#498)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-22T21:18:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a01895bfff3a79889426ded17ed00f43a711bfb6",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/sigstore/rekor](https://github.com/sigstore/rekor).\n\nupdates `github.com/sigstore/rekor` from 1.4.3 to 1.5.0\n- [Release notes](https://github.com/sigstore/rekor/releases)\n- [Changelog](https://github.com/sigstore/rekor/blob/mai\n[…]\n dependency-type: indirect\n dependency-group: go_modules\n\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/sigstore/rekor (#497)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-22T19:25:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e8a5f82b7d5178a5bc3c4ffcbeab52a3928232fe",
"body": null,
"is_bot": false,
"headline": "new fix for new helm chart features (#496)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-22T15:30:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dffcb8254c9e0cad80b4ea3395d5f30a66f68895",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/theupdateframework/go-tuf/v2](https://github.com/theupdateframework/go-tuf).\n\nupdates `github.com/theupdateframework/go-tuf/v2` from 2.3.0 to 2.3.1\n- [Release notes](https://github.com/theupdateframework/go-tuf/releases)\n- [Com\n[…]\n\n dependency-type: indirect\n dependency-group: go_modules\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/theupdateframework/go-tuf/v2 (#495)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-21T18:24:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4a2b7b13a7a3e3dab926893c0be1a67dea6d8457",
"body": null,
"is_bot": false,
"headline": "fixed typos for containerd imports (#493)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-16T01:45:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf22fa8551751d82c9b55f154e97d5712306ee44",
"body": "* fixed hauler save for containerd\n* added flag for containerd compatibility",
"is_bot": false,
"headline": "fix and support containerd imports of `hauls` (#492)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-15T14:09:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28432fc05776d20eebb66bf34e92213bff07d6f9",
"body": "bumps the go_modules group with 1 update in the / directory: [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio).\n\nupdates `github.com/sigstore/fulcio` from 1.8.3 to 1.8.5\n- [Release notes](https://github.com/sigstore/fulcio/releases)\n- [Changelog](https://github.com/sigstore/fulcio/blo\n[…]\n\n dependency-type: indirect\n dependency-group: go_modules\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "bump github.com/sigstore/fulcio (#489)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-14T04:57:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ac7d82b55fb2d2e22e8f76b06312d68815ffa109",
"body": "* added error logging for hauler store serve\n* updated logging for hauler store remove to match others\n* added more error logging for user responses",
"is_bot": false,
"headline": "added/updated logging for `serve` and `remove` (#487)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-12T21:36:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ded947d609e52788da79e0da6557925be49a0aaa",
"body": "* added/fixed helm chart images/dependencies features\n* added helm chart images/dependencies features to sync/manifests\n* more fixes for helm chart images/dependencies features\n* fixed tests for incorrect referenced images\n* fixed sync for helm chart images/dependencies\n* added helm chart image anno\n[…]\nfeatures\n* updated ordering of experimental\n* added more parsing types for helm images/dependencies\n* a few more remove artifacts updates\n\n---------\n\nSigned-off-by: Zack Brady <zackbrady123@gmail.com>",
"is_bot": false,
"headline": "added/fixed helm chart images/dependencies features (#485)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-09T18:39:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff3cece87fe2905c3c3378306a64b69124b64307",
"body": "* updates for experimental features and renamed delete to remove\n* added examples back for experimental features\n* update stability warning message\n\nCo-authored-by: Camryn Carter <camryn.carter@ranchergovernment.com>\nSigned-off-by: Zack Brady <zackbrady123@gmail.com>\n\n* fixed more tests to use ghcr for hauler\n* updated test data workflow\n\n---------\n\nSigned-off-by: Zack Brady <zackbrady123@gmail.com>\nCo-authored-by: Camryn Carter <camryn.carter@ranchergovernment.com>",
"is_bot": false,
"headline": "more experimental feature updates (#486)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-08T19:57:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c54065f3160f443b5344d6c7189cfd91c2813230",
"body": null,
"is_bot": false,
"headline": "add experimental notes (#483)",
"author_name": "Camryn Carter",
"author_login": "CamrynCarter",
"committed_at": "2026-01-08T05:59:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "382dea42a5a06da23fd5871872ac37806dabe3c6",
"body": null,
"is_bot": false,
"headline": "updated tempdir flag to store persistent flags (#484)",
"author_name": "Zack Brady",
"author_login": "zackbradys",
"committed_at": "2026-01-07T13:31:40Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 85,
"commits_last_year": 120,
"latest_release_at": "2026-07-21T19:22:16Z",
"latest_release_tag": "v2.0.2",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 34,
"days_since_latest_release": 12,
"mean_days_between_releases": 15.2
},
"artifacts": {
"collected": true,
"structure": [
"tree.dockerfile",
"tree.go_main",
"tree.goreleaser"
],
"declarations": []
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [],
"total": 0,
"header": 0,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": false,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 49,
"stars": 226,
"watchers": 10,
"fork_history": {
"days": [
{
"date": "2021-11-12",
"count": 1
},
{
"date": "2021-12-06",
"count": 1
},
{
"date": "2022-04-25",
"count": 1
},
{
"date": "2022-07-27",
"count": 1
},
{
"date": "2022-08-19",
"count": 1
},
{
"date": "2023-04-07",
"count": 1
},
{
"date": "2023-07-19",
"count": 1
},
{
"date": "2023-11-27",
"count": 1
},
{
"date": "2024-01-17",
"count": 1
},
{
"date": "2024-02-23",
"count": 1
},
{
"date": "2024-02-26",
"count": 1
},
{
"date": "2024-03-24",
"count": 1
},
{
"date": "2024-03-27",
"count": 1
},
{
"date": "2024-04-22",
"count": 1
},
{
"date": "2024-04-30",
"count": 1
},
{
"date": "2024-05-06",
"count": 1
},
{
"date": "2024-05-24",
"count": 1
},
{
"date": "2024-05-26",
"count": 1
},
{
"date": "2024-07-29",
"count": 1
},
{
"date": "2024-09-04",
"count": 1
},
{
"date": "2024-10-06",
"count": 1
},
{
"date": "2024-10-16",
"count": 1
},
{
"date": "2024-11-15",
"count": 1
},
{
"date": "2024-12-13",
"count": 1
},
{
"date": "2025-01-25",
"count": 1
},
{
"date": "2025-01-27",
"count": 1
},
{
"date": "2025-02-21",
"count": 1
},
{
"date": "2025-04-09",
"count": 1
},
{
"date": "2025-04-18",
"count": 1
},
{
"date": "2025-05-13",
"count": 1
},
{
"date": "2025-05-16",
"count": 1
},
{
"date": "2025-06-09",
"count": 1
},
{
"date": "2025-07-03",
"count": 1
},
{
"date": "2025-07-17",
"count": 1
},
{
"date": "2025-10-17",
"count": 1
},
{
"date": "2025-10-27",
"count": 1
},
{
"date": "2026-01-12",
"count": 1
},
{
"date": "2026-01-19",
"count": 1
},
{
"date": "2026-01-31",
"count": 1
},
{
"date": "2026-02-10",
"count": 1
},
{
"date": "2026-02-19",
"count": 1
},
{
"date": "2026-04-16",
"count": 2
},
{
"date": "2026-04-27",
"count": 1
},
{
"date": "2026-04-29",
"count": 1
},
{
"date": "2026-05-10",
"count": 1
},
{
"date": "2026-07-02",
"count": 1
},
{
"date": "2026-07-20",
"count": 2
}
],
"complete": true,
"collected": 49,
"total_forks": 49
},
"star_history": null,
"open_issues_and_prs": 29
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 31819,
"source_files_sampled": 99,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.18.6",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5841"
],
"fixed_version": "1.18.7",
"advisory_count": 1,
"oldest_advisory_days": 6
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 26
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 2
},
"advisory_count": 2,
"affected_count": 2,
"assessed_count": 362,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/common-nighthawk/go-figure",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210622060536-734e95fb86be"
},
{
"name": "github.com/containerd/containerd/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.3.3"
},
{
"name": "github.com/containerd/errdefs",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/distribution/distribution/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.1.1"
},
{
"name": "github.com/distribution/reference",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.0"
},
{
"name": "github.com/google/go-containerregistry",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.7"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/gorilla/handlers",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.2"
},
{
"name": "github.com/gorilla/mux",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.1"
},
{
"name": "github.com/mholt/archives",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.5"
},
{
"name": "github.com/mitchellh/go-homedir",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/olekukonko/tablewriter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.4"
},
{
"name": "github.com/opencontainers/go-digest",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/opencontainers/image-spec",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1"
},
{
"name": "github.com/pkg/errors",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.1"
},
{
"name": "github.com/rs/zerolog",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.35.1"
},
{
"name": "github.com/sigstore/cosign/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.1.2"
},
{
"name": "github.com/sirupsen/logrus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.4"
},
{
"name": "github.com/spf13/afero",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.15.0"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.22.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "helm.sh/helm/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.2.3"
},
{
"name": "k8s.io/apimachinery",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.3"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/common-nighthawk/go-figure",
"direct": true,
"version": "v0.0.0-20210622060536-734e95fb86be",
"ecosystem": "go"
},
{
"name": "github.com/containerd/containerd/v2",
"direct": true,
"version": "v2.3.3",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/distribution/distribution/v3",
"direct": true,
"version": "v3.1.1",
"ecosystem": "go"
},
{
"name": "github.com/distribution/reference",
"direct": true,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-containerregistry",
"direct": true,
"version": "v0.21.7",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/handlers",
"direct": true,
"version": "v1.5.2",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/mux",
"direct": true,
"version": "v1.8.1",
"ecosystem": "go"
},
{
"name": "github.com/mholt/archives",
"direct": true,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/go-homedir",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/tablewriter",
"direct": true,
"version": "v1.1.4",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/go-digest",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/image-spec",
"direct": true,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": true,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/rs/zerolog",
"direct": true,
"version": "v1.35.1",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/cosign/v3",
"direct": true,
"version": "v3.1.2",
"ecosystem": "go"
},
{
"name": "github.com/sirupsen/logrus",
"direct": true,
"version": "v1.9.4",
"ecosystem": "go"
},
{
"name": "github.com/spf13/afero",
"direct": true,
"version": "v1.15.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": true,
"version": "v0.22.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "helm.sh/helm/v4",
"direct": true,
"version": "v4.2.3",
"ecosystem": "go"
},
{
"name": "k8s.io/apimachinery",
"direct": true,
"version": "v0.36.3",
"ecosystem": "go"
},
{
"name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
"direct": false,
"version": "v1.36.11-20260415201107-50325440f8f2.1",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/auth",
"direct": false,
"version": "v0.20.0",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/auth/oauth2adapt",
"direct": false,
"version": "v0.2.8",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/compute/metadata",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/connect",
"direct": false,
"version": "v1.20.0",
"ecosystem": "go"
},
{
"name": "cuelabs.dev/go/oci/ociregistry",
"direct": false,
"version": "v0.0.0-20251212221603-3adeb8663819",
"ecosystem": "go"
},
{
"name": "cuelang.org/go",
"direct": false,
"version": "v0.16.1",
"ecosystem": "go"
},
{
"name": "dario.cat/mergo",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/agnivade/levenshtein",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/alibabacloud-gateway-spi",
"direct": false,
"version": "v0.0.4",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/cr-20160607",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/cr-20181201",
"direct": false,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/darabonba-openapi",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/debug",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/endpoint-util",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/openapi-util",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/tea",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/tea-utils",
"direct": false,
"version": "v1.4.5",
"ecosystem": "go"
},
{
"name": "github.com/alibabacloud-go/tea-xml",
"direct": false,
"version": "v1.1.3",
"ecosystem": "go"
},
{
"name": "github.com/aliyun/credentials-go",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/aliyuncontainerservice/ack-ram-tool/pkg/credentials/provider",
"direct": false,
"version": "v0.14.0",
"ecosystem": "go"
},
{
"name": "github.com/andybalholm/brotli",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/asaskevich/govalidator",
"direct": false,
"version": "v0.0.0-20230301143203-a9d515a09cc2",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2",
"direct": false,
"version": "v1.42.0",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/config",
"direct": false,
"version": "v1.32.25",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/credentials",
"direct": false,
"version": "v1.19.24",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
"direct": false,
"version": "v1.18.29",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
"direct": false,
"version": "v1.4.29",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
"direct": false,
"version": "v2.7.29",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
"direct": false,
"version": "v1.4.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ecr",
"direct": false,
"version": "v1.55.3",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ecrpublic",
"direct": false,
"version": "v1.38.10",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
"direct": false,
"version": "v1.13.12",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
"direct": false,
"version": "v1.13.29",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/signin",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sso",
"direct": false,
"version": "v1.31.3",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
"direct": false,
"version": "v1.36.6",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sts",
"direct": false,
"version": "v1.43.3",
"ecosystem": "go"
},
{
"name": "github.com/aws/smithy-go",
"direct": false,
"version": "v1.27.2",
"ecosystem": "go"
},
{
"name": "github.com/awslabs/amazon-ecr-credential-helper/ecr-login",
"direct": false,
"version": "v0.12.0",
"ecosystem": "go"
},
{
"name": "github.com/azure/azure-sdk-for-go",
"direct": false,
"version": "v68.0.0+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-ansiterm",
"direct": false,
"version": "v0.0.0-20250102033503-faa5f7b0171c",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest",
"direct": false,
"version": "v14.2.0+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/autorest",
"direct": false,
"version": "v0.11.29",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/autorest/adal",
"direct": false,
"version": "v0.9.23",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/autorest/azure/auth",
"direct": false,
"version": "v0.5.12",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/autorest/azure/cli",
"direct": false,
"version": "v0.4.6",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/autorest/date",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/logger",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-autorest/tracing",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/blang/semver",
"direct": false,
"version": "v3.5.1+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/blang/semver/v4",
"direct": false,
"version": "v4.0.0",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/plumbing",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/sevenzip",
"direct": false,
"version": "v1.6.1",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/windows",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bshuster-repo/logrus-logstash-hook",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/buildkite/agent/v3",
"direct": false,
"version": "v3.130.0",
"ecosystem": "go"
},
{
"name": "github.com/buildkite/go-pipeline",
"direct": false,
"version": "v0.17.1",
"ecosystem": "go"
},
{
"name": "github.com/buildkite/interpolate",
"direct": false,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/buildkite/roko",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/burntsushi/toml",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/cenkalti/backoff/v5",
"direct": false,
"version": "v5.0.3",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/chai2010/gettext-go",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/chrismellard/docker-credential-acr-env",
"direct": false,
"version": "v0.0.0-20230304212654-82a0ddb27589",
"ecosystem": "go"
},
{
"name": "github.com/clbanning/mxj/v2",
"direct": false,
"version": "v2.7.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/displaywidth",
"direct": false,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/uax29/v2",
"direct": false,
"version": "v2.6.0",
"ecosystem": "go"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.6.3",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/apd/v3",
"direct": false,
"version": "v3.2.1",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs/pkg",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/log",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/platforms",
"direct": false,
"version": "v1.0.0-rc.4",
"ecosystem": "go"
},
{
"name": "github.com/containerd/ttrpc",
"direct": false,
"version": "v1.2.8",
"ecosystem": "go"
},
{
"name": "github.com/containerd/typeurl/v2",
"direct": false,
"version": "v2.2.3",
"ecosystem": "go"
},
{
"name": "github.com/coreos/go-oidc/v3",
"direct": false,
"version": "v3.18.0",
"ecosystem": "go"
},
{
"name": "github.com/coreos/go-systemd/v22",
"direct": false,
"version": "v22.7.0",
"ecosystem": "go"
},
{
"name": "github.com/cyberphone/json-canonicalization",
"direct": false,
"version": "v0.0.0-20241213102144-19d51d7fe467",
"ecosystem": "go"
},
{
"name": "github.com/cyphar/filepath-securejoin",
"direct": false,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.2-0.20180830191138-d8f796af33cc",
"ecosystem": "go"
},
{
"name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
"direct": false,
"version": "v4.4.1",
"ecosystem": "go"
},
{
"name": "github.com/digitorus/pkcs7",
"direct": false,
"version": "v0.0.0-20230818184609-3a137a874352",
"ecosystem": "go"
},
{
"name": "github.com/digitorus/timestamp",
"direct": false,
"version": "v0.0.0-20231217203849-220c5c2851b7",
"ecosystem": "go"
},
{
"name": "github.com/dimchansky/utfbom",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/docker/cli",
"direct": false,
"version": "v29.5.3+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/docker/docker-credential-helpers",
"direct": false,
"version": "v0.9.5",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-connections",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-events",
"direct": false,
"version": "v0.0.0-20250808211157-605354379745",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-metrics",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-units",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/dsnet/compress",
"direct": false,
"version": "v0.0.2-0.20230904184137-39efe44ab707",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/dylibso/observe-sdk/go",
"direct": false,
"version": "v0.0.0-20240819160327-2d926c5d788a",
"ecosystem": "go"
},
{
"name": "github.com/emicklei/go-restful/v3",
"direct": false,
"version": "v3.13.0",
"ecosystem": "go"
},
{
"name": "github.com/emicklei/proto",
"direct": false,
"version": "v1.14.3",
"ecosystem": "go"
},
{
"name": "github.com/evanphx/json-patch/v5",
"direct": false,
"version": "v5.9.11",
"ecosystem": "go"
},
{
"name": "github.com/exponent-io/jsonpath",
"direct": false,
"version": "v0.0.0-20210407135951-1de76d718b3f",
"ecosystem": "go"
},
{
"name": "github.com/extism/go-sdk",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "github.com/fatih/color",
"direct": false,
"version": "v1.19.0",
"ecosystem": "go"
},
{
"name": "github.com/felixge/httpsnoop",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/fluxcd/cli-utils",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": false,
"version": "v1.10.1",
"ecosystem": "go"
},
{
"name": "github.com/fxamacker/cbor/v2",
"direct": false,
"version": "v2.9.0",
"ecosystem": "go"
},
{
"name": "github.com/go-chi/chi/v5",
"direct": false,
"version": "v5.3.0",
"ecosystem": "go"
},
{
"name": "github.com/go-errors/errors",
"direct": false,
"version": "v1.5.1",
"ecosystem": "go"
},
{
"name": "github.com/go-gorp/gorp/v3",
"direct": false,
"version": "v3.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v4",
"direct": false,
"version": "v4.1.4",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/analysis",
"direct": false,
"version": "v0.25.2",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/errors",
"direct": false,
"version": "v0.22.8",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/jsonpointer",
"direct": false,
"version": "v0.23.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/jsonreference",
"direct": false,
"version": "v0.21.6",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/loads",
"direct": false,
"version": "v0.24.0",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/runtime",
"direct": false,
"version": "v0.32.4",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/runtime/server-middleware",
"direct": false,
"version": "v0.30.0",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/spec",
"direct": false,
"version": "v0.22.6",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/strfmt",
"direct": false,
"version": "v0.26.4",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/cmdutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/conv",
"direct": false,
"version": "v0.27.0",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/fileutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/jsonname",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/jsonutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/loading",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/mangling",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/netutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/stringutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/typeutils",
"direct": false,
"version": "v0.27.0",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/yamlutils",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/validate",
"direct": false,
"version": "v0.26.0",
"ecosystem": "go"
},
{
"name": "github.com/go-piv/piv-go/v2",
"direct": false,
"version": "v2.6.0",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/gobwas/glob",
"direct": false,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/goccy/go-json",
"direct": false,
"version": "v0.10.6",
"ecosystem": "go"
},
{
"name": "github.com/gofrs/flock",
"direct": false,
"version": "v0.13.0",
"ecosystem": "go"
},
{
"name": "github.com/gogo/protobuf",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v4",
"direct": false,
"version": "v4.5.2",
"ecosystem": "go"
},
{
"name": "github.com/golang/snappy",
"direct": false,
"version": "v0.0.4",
"ecosystem": "go"
},
{
"name": "github.com/google/btree",
"direct": false,
"version": "v1.1.3",
"ecosystem": "go"
},
{
"name": "github.com/google/certificate-transparency-go",
"direct": false,
"version": "v1.3.3",
"ecosystem": "go"
},
{
"name": "github.com/google/gnostic-models",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-github/v88",
"direct": false,
"version": "v88.0.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-querystring",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/google/s2a-go",
"direct": false,
"version": "v0.1.9",
"ecosystem": "go"
},
{
"name": "github.com/googleapis/enterprise-certificate-proxy",
"direct": false,
"version": "v0.3.16",
"ecosystem": "go"
},
{
"name": "github.com/googleapis/gax-go/v2",
"direct": false,
"version": "v2.22.0",
"ecosystem": "go"
},
{
"name": "github.com/gosuri/uitable",
"direct": false,
"version": "v0.0.4",
"ecosystem": "go"
},
{
"name": "github.com/grpc-ecosystem/grpc-gateway/v2",
"direct": false,
"version": "v2.29.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-cleanhttp",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-retryablehttp",
"direct": false,
"version": "v0.7.8",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru/arc/v2",
"direct": false,
"version": "v2.0.5",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru/v2",
"direct": false,
"version": "v2.0.7",
"ecosystem": "go"
},
{
"name": "github.com/huandu/xstrings",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/ianlancetaylor/demangle",
"direct": false,
"version": "v0.0.0-20240805132620-81f5be970eca",
"ecosystem": "go"
},
{
"name": "github.com/in-toto/attestation",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/in-toto/in-toto-golang",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/jedisct1/go-minisign",
"direct": false,
"version": "v0.0.0-20230811132847-661be99b8267",
"ecosystem": "go"
},
{
"name": "github.com/jmoiron/sqlx",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/json-iterator/go",
"direct": false,
"version": "v1.1.12",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.18.6",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/pgzip",
"direct": false,
"version": "v1.2.6",
"ecosystem": "go"
},
{
"name": "github.com/lann/builder",
"direct": false,
"version": "v0.0.0-20180802200727-47ae307949d0",
"ecosystem": "go"
},
{
"name": "github.com/lann/ps",
"direct": false,
"version": "v0.0.0-20150810152359-62de8c46ede0",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/blackmagic",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/dsig",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/dsig-secp256k1",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/httpcc",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/httprc/v3",
"direct": false,
"version": "v3.0.5",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/jwx/v3",
"direct": false,
"version": "v3.1.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/option/v2",
"direct": false,
"version": "v2.0.0",
"ecosystem": "go"
},
{
"name": "github.com/letsencrypt/boulder",
"direct": false,
"version": "v0.20260309.0",
"ecosystem": "go"
},
{
"name": "github.com/lib/pq",
"direct": false,
"version": "v1.12.3",
"ecosystem": "go"
},
{
"name": "github.com/liggitt/tabwriter",
"direct": false,
"version": "v0.0.0-20181228230101-89fcab3d43de",
"ecosystem": "go"
},
{
"name": "github.com/makenowjust/heredoc",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/goutils",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/semver/v3",
"direct": false,
"version": "v3.5.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/sprig/v3",
"direct": false,
"version": "v3.3.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/squirrel",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-colorable",
"direct": false,
"version": "v0.1.14",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.19",
"ecosystem": "go"
},
{
"name": "github.com/microsoft/go-winio",
"direct": false,
"version": "v0.6.3-0.20251027160822-ad3df93bed29",
"ecosystem": "go"
},
{
"name": "github.com/miekg/pkcs11",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/mikelolasagasti/xz",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/minio/minlz",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/copystructure",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/go-wordwrap",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/reflectwalk",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/moby/docker-image-spec",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/locker",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/api",
"direct": false,
"version": "v1.54.2",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/client",
"direct": false,
"version": "v0.4.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/term",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/concurrent",
"direct": false,
"version": "v0.0.0-20180306012644-bacd9c7ef1dd",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/reflect2",
"direct": false,
"version": "v1.0.3-0.20250322232337-35a7c28c31ee",
"ecosystem": "go"
},
{
"name": "github.com/monochromegane/go-gitignore",
"direct": false,
"version": "v0.0.0-20200626010858-205db1a8cc00",
"ecosystem": "go"
},
{
"name": "github.com/mozillazg/docker-credential-acr-helper",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/munnerz/goautoneg",
"direct": false,
"version": "v0.0.0-20191010083416-a7dc8b61c822",
"ecosystem": "go"
},
{
"name": "github.com/nozzle/throttler",
"direct": false,
"version": "v0.0.0-20180817012639-2ea982251481",
"ecosystem": "go"
},
{
"name": "github.com/nwaples/rardecode/v2",
"direct": false,
"version": "v2.2.1",
"ecosystem": "go"
},
{
"name": "github.com/oklog/ulid/v2",
"direct": false,
"version": "v2.1.1",
"ecosystem": "go"
},
{
"name": "github.com/oleiade/reflections",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/cat",
"direct": false,
"version": "v0.0.0-20250911104152-50322a0618f6",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/errors",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/ll",
"direct": false,
"version": "v0.1.6",
"ecosystem": "go"
},
{
"name": "github.com/open-policy-agent/opa",
"direct": false,
"version": "v1.17.1",
"ecosystem": "go"
},
{
"name": "github.com/pborman/uuid",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/peterbourgon/diskv",
"direct": false,
"version": "v2.0.1+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/pierrec/lz4/v4",
"direct": false,
"version": "v4.1.22",
"ecosystem": "go"
},
{
"name": "github.com/pkg/browser",
"direct": false,
"version": "v0.0.0-20240102092130-5ac0b6a4141c",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.23.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.67.5",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/otlptranslator",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.20.1",
"ecosystem": "go"
},
{
"name": "github.com/protocolbuffers/txtpbfmt",
"direct": false,
"version": "v0.0.0-20260217160748-a481f6a22f94",
"ecosystem": "go"
},
{
"name": "github.com/protonmail/go-crypto",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/rcrowley/go-metrics",
"direct": false,
"version": "v0.0.0-20250401214520-65e299d6c5c9",
"ecosystem": "go"
},
{
"name": "github.com/redis/go-redis/extra/rediscmd/v9",
"direct": false,
"version": "v9.5.3",
"ecosystem": "go"
},
{
"name": "github.com/redis/go-redis/extra/redisotel/v9",
"direct": false,
"version": "v9.5.3",
"ecosystem": "go"
},
{
"name": "github.com/redis/go-redis/v9",
"direct": false,
"version": "v9.20.1",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.14.1",
"ecosystem": "go"
},
{
"name": "github.com/rubenv/sql-migrate",
"direct": false,
"version": "v1.8.1",
"ecosystem": "go"
},
{
"name": "github.com/russross/blackfriday/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/sagikazarmark/locafero",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"direct": false,
"version": "v6.0.2",
"ecosystem": "go"
},
{
"name": "github.com/sassoftware/relic",
"direct": false,
"version": "v7.2.1+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/secure-systems-lab/go-securesystemslib",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/segmentio/asm",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/shibumi/go-pathspec",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/shopspring/decimal",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/protobuf-specs",
"direct": false,
"version": "v0.5.1",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/rekor",
"direct": false,
"version": "v1.5.3",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/rekor-tiles/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/sigstore",
"direct": false,
"version": "v1.10.8",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/sigstore-go",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/timestamp-authority/v2",
"direct": false,
"version": "v2.1.2",
"ecosystem": "go"
},
{
"name": "github.com/sorairolake/lzip-go",
"direct": false,
"version": "v0.3.8",
"ecosystem": "go"
},
{
"name": "github.com/sourcegraph/conc",
"direct": false,
"version": "v0.3.1-0.20240121214520-5f936abd7ae8",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": false,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/spf13/viper",
"direct": false,
"version": "v1.21.0",
"ecosystem": "go"
},
{
"name": "github.com/spiffe/go-spiffe/v2",
"direct": false,
"version": "v2.7.0",
"ecosystem": "go"
},
{
"name": "github.com/starry-s/zip",
"direct": false,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/subosito/gotenv",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/syndtr/goleveldb",
"direct": false,
"version": "v1.0.1-0.20220721030215-126854af5e6d",
"ecosystem": "go"
},
{
"name": "github.com/tchap/go-patricia/v2",
"direct": false,
"version": "v2.3.3",
"ecosystem": "go"
},
{
"name": "github.com/tetratelabs/wabin",
"direct": false,
"version": "v0.0.0-20230304001439-f6f874872834",
"ecosystem": "go"
},
{
"name": "github.com/tetratelabs/wazero",
"direct": false,
"version": "v1.12.0",
"ecosystem": "go"
},
{
"name": "github.com/thales-e-security/pool",
"direct": false,
"version": "v0.0.2",
"ecosystem": "go"
},
{
"name": "github.com/thalesignite/crypto11",
"direct": false,
"version": "v1.2.5",
"ecosystem": "go"
},
{
"name": "github.com/theupdateframework/go-tuf",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/theupdateframework/go-tuf/v2",
"direct": false,
"version": "v2.4.2",
"ecosystem": "go"
},
{
"name": "github.com/titanous/rocacheck",
"direct": false,
"version": "v0.0.0-20171023193734-afe73141d399",
"ecosystem": "go"
},
{
"name": "github.com/tjfoc/gmsm",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/transparency-dev/formats",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/transparency-dev/merkle",
"direct": false,
"version": "v0.0.2",
"ecosystem": "go"
},
{
"name": "github.com/ulikunitz/xz",
"direct": false,
"version": "v0.5.15",
"ecosystem": "go"
},
{
"name": "github.com/valyala/fastjson",
"direct": false,
"version": "v1.6.10",
"ecosystem": "go"
},
{
"name": "github.com/vektah/gqlparser/v2",
"direct": false,
"version": "v2.5.33",
"ecosystem": "go"
},
{
"name": "github.com/x448/float16",
"direct": false,
"version": "v0.8.4",
"ecosystem": "go"
},
{
"name": "github.com/xeipuuv/gojsonpointer",
"direct": false,
"version": "v0.0.0-20190905194746-02993c407bfb",
"ecosystem": "go"
},
{
"name": "github.com/xeipuuv/gojsonreference",
"direct": false,
"version": "v0.0.0-20180127040603-bd5ef7bd5415",
"ecosystem": "go"
},
{
"name": "github.com/xlab/treeprint",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/yashtewari/glob-intersection",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/youmark/pkcs8",
"direct": false,
"version": "v0.0.0-20240726163527-a2c0da244d78",
"ecosystem": "go"
},
{
"name": "gitlab.com/gitlab-org/api/client-go",
"direct": false,
"version": "v1.46.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/bridges/prometheus",
"direct": false,
"version": "v0.68.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/exporters/autoexport",
"direct": false,
"version": "v0.67.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.68.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
"direct": false,
"version": "v0.19.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp",
"direct": false,
"version": "v0.19.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/prometheus",
"direct": false,
"version": "v0.66.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdoutlog",
"direct": false,
"version": "v0.19.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdoutmetric",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/log",
"direct": false,
"version": "v0.19.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/log",
"direct": false,
"version": "v0.19.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/proto/otlp",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/atomic",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/multierr",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/zap",
"direct": false,
"version": "v1.28.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v2",
"direct": false,
"version": "v2.4.4",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "go4.org",
"direct": false,
"version": "v0.0.0-20230225012048-214862532bf5",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": false,
"version": "v0.37.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.56.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": false,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": false,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": false,
"version": "v0.15.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/api",
"direct": false,
"version": "v0.284.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": false,
"version": "v0.0.0-20260526163538-3dc84a4a5aaa",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260526163538-3dc84a4a5aaa",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": false,
"version": "v1.82.1",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": false,
"version": "v1.36.12-0.20260120151049-f2248ac996af",
"ecosystem": "go"
},
{
"name": "gopkg.in/evanphx/json-patch.v4",
"direct": false,
"version": "v4.13.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/inf.v0",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "gopkg.in/ini.v1",
"direct": false,
"version": "v1.67.3",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v2",
"direct": false,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "k8s.io/api",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/apiextensions-apiserver",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/apiserver",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/cli-runtime",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/client-go",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/component-base",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/klog/v2",
"direct": false,
"version": "v2.140.0",
"ecosystem": "go"
},
{
"name": "k8s.io/kube-openapi",
"direct": false,
"version": "v0.0.0-20260319004828-5883c5ee87b9",
"ecosystem": "go"
},
{
"name": "k8s.io/kubectl",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/utils",
"direct": false,
"version": "v0.0.0-20260319190234-28399d86e0b5",
"ecosystem": "go"
},
{
"name": "oras.land/oras-go/v2",
"direct": false,
"version": "v2.6.2",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/controller-runtime",
"direct": false,
"version": "v0.24.1",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/json",
"direct": false,
"version": "v0.0.0-20250730193827-2d320260d730",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/kustomize/api",
"direct": false,
"version": "v0.21.1",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/kustomize/kyaml",
"direct": false,
"version": "v0.21.1",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/randfill",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/release-utils",
"direct": false,
"version": "v0.12.4",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/structured-merge-diff/v6",
"direct": false,
"version": "v6.3.3",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/yaml",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 362,
"direct_count": 24,
"indirect_count": 338
}
},
"maintainership": {
"issues": {
"open_prs": 7,
"merged_prs": 376,
"open_issues": 22,
"closed_ratio": 0.908,
"closed_issues": 216,
"closed_unmerged_prs": 72
},
"bus_factor": 2,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "amartin120",
"commits": 149,
"avatar_url": "https://avatars.githubusercontent.com/u/42001113?v=4"
},
{
"type": "User",
"login": "zackbradys",
"commits": 147,
"avatar_url": "https://avatars.githubusercontent.com/u/7769650?v=4"
},
{
"type": "User",
"login": "joshrwolf",
"commits": 75,
"avatar_url": "https://avatars.githubusercontent.com/u/30101244?v=4"
},
{
"type": "User",
"login": "CamrynCarter",
"commits": 16,
"avatar_url": "https://avatars.githubusercontent.com/u/98115139?v=4"
},
{
"type": "User",
"login": "nikkelma",
"commits": 14,
"avatar_url": "https://avatars.githubusercontent.com/u/16194510?v=4"
},
{
"type": "User",
"login": "dweomer",
"commits": 12,
"avatar_url": "https://avatars.githubusercontent.com/u/1033444?v=4"
},
{
"type": "User",
"login": "bgulla",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/2697267?v=4"
},
{
"type": "User",
"login": "clanktron",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/52805671?v=4"
},
{
"type": "User",
"login": "eklatzer",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/47006675?v=4"
},
{
"type": "User",
"login": "atoy3731",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/5939985?v=4"
}
],
"contributors_sampled": 26,
"top_contributor_share": 0.331
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"pages.yaml",
"release.yaml",
"testdata.yaml",
"tests.yaml",
"vulnerabilities.yaml",
"vulnerability-scan.yaml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 6,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 9,
"reason": "Found 21/22 approved changesets -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 11 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 4,
"reason": "SAST tool is not run on all commits -- score normalized to 4",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 8,
"reason": "2 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "2e280f27172277c004fad5a54f029356eba0fd7f",
"ran_at": "2026-08-03T04:11:11Z",
"aggregate_score": 6.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 5,
"decided_7d": 7,
"merged_30d": 16,
"authors_30d": 7,
"decided_30d": 20,
"sample_size": 60,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 7,
"newcomer_merged_30d": 2,
"bot_prs_excluded_30d": 33,
"newcomer_authors_30d": 3,
"newcomer_decided_30d": 4
},
"ci_last_run_at": "2026-08-03T03:43:51Z",
"oldest_open_prs": [
{
"number": 508,
"created_at": "2026-02-10T05:14:33Z",
"last_comment_at": "2026-02-10T05:17:03Z",
"last_comment_author": "derhornspieler"
},
{
"number": 682,
"created_at": "2026-07-20T21:21:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 694,
"created_at": "2026-07-25T22:39:01Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 695,
"created_at": "2026-07-25T22:53:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 699,
"created_at": "2026-07-29T12:57:10Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 702,
"created_at": "2026-07-31T04:48:33Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 706,
"created_at": "2026-07-31T23:59:06Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-08-03T03:41:23Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 169,
"created_at": "2024-02-02T00:33:48Z",
"last_comment_at": "2026-07-25T23:13:07Z",
"last_comment_author": "CamrynCarter"
},
{
"number": 183,
"created_at": "2024-02-17T01:46:51Z",
"last_comment_at": "2026-04-07T17:09:04Z",
"last_comment_author": "clemenko"
},
{
"number": 236,
"created_at": "2024-04-27T15:17:52Z",
"last_comment_at": "2025-10-01T23:16:53Z",
"last_comment_author": "clemenko"
},
{
"number": 300,
"created_at": "2024-08-20T15:01:03Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 347,
"created_at": "2024-10-22T17:24:00Z",
"last_comment_at": "2024-12-17T17:59:23Z",
"last_comment_author": "CamrynCarter"
},
{
"number": 387,
"created_at": "2025-01-14T14:17:52Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 389,
"created_at": "2025-01-17T06:09:30Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 392,
"created_at": "2025-01-24T11:38:40Z",
"last_comment_at": "2025-03-20T03:30:41Z",
"last_comment_author": "zackbradys"
},
{
"number": 395,
"created_at": "2025-01-29T23:17:24Z",
"last_comment_at": "2025-01-30T00:16:00Z",
"last_comment_author": "zackbradys"
},
{
"number": 410,
"created_at": "2025-02-05T20:53:05Z",
"last_comment_at": "2025-03-20T03:27:42Z",
"last_comment_author": "zackbradys"
},
{
"number": 416,
"created_at": "2025-02-27T14:03:46Z",
"last_comment_at": "2026-04-17T13:33:33Z",
"last_comment_author": "ebyjacob"
},
{
"number": 445,
"created_at": "2025-07-25T17:05:59Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 451,
"created_at": "2025-09-24T07:54:29Z",
"last_comment_at": "2026-07-09T16:05:56Z",
"last_comment_author": "eklatzer"
},
{
"number": 477,
"created_at": "2025-12-05T16:02:02Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 479,
"created_at": "2025-12-12T05:04:07Z",
"last_comment_at": "2026-03-10T19:57:39Z",
"last_comment_author": "CamrynCarter"
},
{
"number": 544,
"created_at": "2026-04-07T09:45:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 556,
"created_at": "2026-04-17T19:57:15Z",
"last_comment_at": "2026-04-23T19:41:16Z",
"last_comment_author": "amartin120"
},
{
"number": 576,
"created_at": "2026-04-23T12:58:19Z",
"last_comment_at": "2026-04-27T22:07:21Z",
"last_comment_author": "zackbradys"
},
{
"number": 622,
"created_at": "2026-06-12T04:30:50Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 645,
"created_at": "2026-06-29T17:49:40Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/hauler-dev/hauler",
"host": "github.com",
"name": "hauler",
"owner": "hauler-dev"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 71 is calibrated to 84 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 71,
"calibrated": 84,
"calibration": "2026-08-02"
}
}
],
"value": 84,
"inputs": {
"security": 73,
"vitality": 89,
"community": 58,
"governance": 65,
"calibration": "2026-08-02",
"engineering": 67,
"ai_readiness": 65,
"weighted_overall_raw": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 89,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 88,
"inputs": {
"commits_last_year": 120,
"human_commit_share": 0.67,
"days_since_last_push": 0,
"active_weeks_last_year": 34
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "34/52 weeks with commits",
"points": 23.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 34
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "120 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 120
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 85,
"latest_release_tag": "v2.0.2",
"releases_from_tags": false,
"days_since_latest_release": 12,
"mean_days_between_releases": 15.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "85 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 85
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 12 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 12
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~15.2 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 15.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 58,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"forks": 49,
"stars": 226,
"watchers": 10,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "226 stars",
"points": 38.2,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 226
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "49 forks",
"points": 14,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 49
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "10 watchers",
"points": 5.3,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 10
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 57,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 0,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [],
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 65,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 26,
"top_contributor_share": 0.331
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 33% of commits",
"points": 15.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 33
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "26 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 26
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 11 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"merged_prs": 376,
"open_issues": 22,
"closed_issues": 216,
"prs_merged_7d": 5,
"prs_decided_7d": 7,
"prs_merged_30d": 16,
"prs_decided_30d": 20,
"issue_closed_ratio": 0.908,
"closed_unmerged_prs": 72,
"first_time_authors_30d": 3,
"first_time_prs_merged_30d": 2,
"first_time_prs_decided_30d": 4
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "91% of issues closed",
"points": 38.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 91
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "376/448 decided PRs merged",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 376,
"decided": 448
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "2/4 first-time contributors' PRs merged in 30d",
"points": 6.5,
"status": "partial",
"details": [
{
"code": "newcomer_prs_merged",
"params": {
"days": 30,
"merged": 2,
"decided": 4
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 21/22 approved changesets -- score normalized to 9",
"points": 13.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"followers": 10,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "hauler-dev",
"public_repos": 6,
"account_age_days": 857
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "10 followers of hauler-dev",
"points": 7.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 10,
"login": "hauler-dev"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "6 public repos, account ~2 yr old",
"points": 10.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 6
}
},
{
"code": "account_age_years",
"params": {
"years": 2
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 67,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"topics": [
"oci",
"containers",
"airgap",
"kubernetes",
"airgapped",
"cli",
"disconnected"
],
"has_wiki": false,
"homepage": "https://hauler.dev",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://hauler.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 73,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 21/22 approved changesets -- score normalized to 9",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 11 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 4",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "2 existing vulnerabilities detected",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 362 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 362
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 2,
"affected_packages": 2,
"assessed_packages": 362,
"unassessed_packages": 0,
"affected_by_severity": "unknown 2",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 362,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 14
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 65,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.925,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "62 of 67 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 62,
"sampled": 67
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.01,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.33
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "1 of the last 100 commits agent-authored or agent-credited",
"points": 2,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "33 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 33,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 31819,
"source_files_sampled": 99,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/99 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 99,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"cli"
],
"scores": {
"cli": 13
},
"primary": "cli",
"evidence": [
{
"tier": "dependencies",
"label": "cli",
"source": "dep:github.com/spf13/cobra",
"weight": 4
},
{
"tier": "structure",
"label": "cli",
"source": "tree.goreleaser",
"weight": 4
},
{
"tier": "structure",
"label": "cli",
"source": "tree.go_main",
"weight": 3
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": false
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch go package 'hauler.dev/go/hauler/v2' from its registry"
],
"report_type": "repository",
"generated_at": "2026-08-03T04:11:40.592847Z",
"schema_version": "0.30.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/h/hauler-dev/hauler.svg",
"full_name": "hauler-dev/hauler",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}