Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 09:59 UTC

linuxfoundation / lfx-v1-sync-helper

LFX v1<>v2 data sync helper

GoMIT★ 0 Sterne⑂ 1 Forkseit Okt. 2025Auf GitHub ansehen ↗

linuxfoundation/lfx-v1-sync-helper erreicht einen Gesundheitsindex von 69 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (93/100) ab, am schwächsten bei Community & Adoption (24/100). Zuletzt heute aktualisiert. 2 Mitwirkende tragen den Großteil der jüngsten Arbeit.

69
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

69
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

1.394 Follower61 öffentliche Reposseit Sept. 2011

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/linuxfoundation/lfx-v1-sync-helperv0.13.4-70vor 10 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

93Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
24.2/36Commit-Rhythmus — 35/52 Wochen mit Commits
18/18Commit-Volumen — 629 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year629
human_commit_share1
days_since_last_push0
active_weeks_last_year35

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 69 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 10 Tagen
27/27Release-Rhythmus — ein Release etwa alle 4,9 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count69
latest_release_tagv0.13.4
releases_from_tagsnein
days_since_latest_release10
mean_days_between_releases4,9
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

24Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 1 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks1
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

83Gut · 24 % des Gesamtindex
Wie die Bewertung erfolgt
25.2/54Bus-Faktor — 2 Beitragende decken die Hälfte aller Commits ab
13.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 40 % der Commits
13.5/13.5Breite der Beitragenden — 14 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 6 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor2
contributors_sampled14
top_contributor_share0,396
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
37.1/38.3PR-Annahme — 128/132 entschiedene PRs gemergt
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Verwendete Eingangsdaten
merged_prs128
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
22.6/25Reichweite des Inhabers — 1.394 Follower von linuxfoundation
25/25Kontohistorie — 61 öffentliche Repos, Kontoalter ca. 14 Jahre
Verwendete Eingangsdaten
followers1.394
owner_typeOrganization
is_verified
owner_loginlinuxfoundation
public_repos61
account_age_days5.435

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 10 Tagen
20/20Versionshistorie — 70 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/linuxfoundation/lfx-v1-sync-helper
ecosystemsgo
any_deprecatednein
min_days_since_publish10

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

57Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 5 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

40Gefährdet
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepage
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

78Gut · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
6/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 6 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
2.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
3.8/7.5Vulnerabilities — 5 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate7,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
26.6/35Direkte Abhängigkeiten ohne bekannte Advisories — 1 betroffen: golang.org/x/text v0.37.0 (unknown)
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
40/40Keine offenen Advisories — kein Advisory ist länger als 90 Tage öffentlich
Verwendete Eingangsdaten
sourceosv
advisories6
affected_packages5
assessed_packages121
unassessed_packages0
affected_by_severityhigh 1, moderate 1, unknown 3
direct_affected_packages1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories. Die verbleibenden Gewichte wurden renormalisiert. 121 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

83Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 88 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,88
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes19.554
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 22 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
5/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum, uv.lock
has_dockerfileja
typed_languageja
bootstrap_filesMakefile
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,22
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/55 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes50.871
source_files_sampled55
oversized_source_files0

Eckdaten

0GitHub-Sterne
14Mitwirkende
629Commits, letzte 12 Monate
0Tage seit letztem Push
69Releases
2Bus-Faktor
0offene Issues
Go, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Could not fetch pypi package 'lfx-v1-sync-helper' from its registry

Weitere Details

OpenSSF Scorecard 7.5 / 10
7.5Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 09:58 UTC

10Binary-Artifactsno binaries found in the repo
8Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 6 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
5Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 5
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
5Vulnerabilities5 existing vulnerabilities detected
Direkte Abhängigkeiten 21
RegistryPaketVersionsvorgabeManifest
Gogithub.com/akamensky/base58v0.0.0-20210829145138-ce8bf8802e8fgo.mod
Gogithub.com/auth0/go-auth0v1.40.0go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.41.7go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.17go.mod
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.16go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/dynamodbv1.57.3go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/dynamodbstreamsv1.32.16go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.42.1go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/linuxfoundation/lfx-v2-committee-servicev0.4.12go.mod
Gogithub.com/linuxfoundation/lfx-v2-project-servicev0.6.11go.mod
Gogithub.com/nats-io/nats.gov1.52.0go.mod
Gogithub.com/patrickmn/go-cachev2.1.0+incompatiblego.mod
Gogithub.com/vmihailenco/msgpack/v5v5.4.1go.mod
Gogoa.design/goa/v3v3.26.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/textv0.37.0go.mod
Gogolang.org/x/timev0.15.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
PyPImeltano==4.2.0pyproject.toml
Alle Abhängigkeiten 121

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 21 direkte und 100 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Gogithub.com/akamensky/base58v0.0.0-20210829145138-ce8bf8802e8fdirekt
Gogithub.com/auth0/go-auth0v1.40.0direkt
Gogithub.com/aws/aws-sdk-go-v2v1.41.7direkt
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.17direkt
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.16direkt
Gogithub.com/aws/aws-sdk-go-v2/service/dynamodbv1.57.3direkt
Gogithub.com/aws/aws-sdk-go-v2/service/dynamodbstreamsv1.32.16direkt
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.42.1direkt
Gogithub.com/golang-jwt/jwt/v5v5.3.1direkt
Gogithub.com/google/uuidv1.6.0direkt
Gogithub.com/linuxfoundation/lfx-v2-committee-servicev0.4.12direkt
Gogithub.com/linuxfoundation/lfx-v2-project-servicev0.6.11direkt
Gogithub.com/nats-io/nats.gov1.52.0direkt
Gogithub.com/patrickmn/go-cachev2.1.0+incompatibledirekt
Gogithub.com/vmihailenco/msgpack/v5v5.4.1direkt
Gogoa.design/goa/v3v3.26.0direkt
Gogolang.org/x/oauth2v0.36.0direkt
Gogolang.org/x/textv0.37.0direkt
Gogolang.org/x/timev0.15.0direkt
Gogopkg.in/yaml.v3v3.0.1direkt
PyPImeltano4.2.0direkt
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.23indirekt
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.23indirekt
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.23indirekt
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.24indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.9indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/internal/endpoint-discoveryv1.11.23indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.23indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.0.11indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.30.17indirekt
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.35.21indirekt
Gogithub.com/aws/smithy-gov1.25.1indirekt
Gogithub.com/decred/dcrd/dcrec/secp256k1/v4v4.4.1indirekt
Gogithub.com/go-chi/chi/v5v5.3.0indirekt
Gogithub.com/goccy/go-jsonv0.10.6indirekt
Gogithub.com/gorilla/websocketv1.5.3indirekt
Gogithub.com/klauspost/compressv1.18.6indirekt
Gogithub.com/lestrrat-go/blackmagicv1.0.4indirekt
Gogithub.com/lestrrat-go/httpccv1.0.1indirekt
Gogithub.com/lestrrat-go/httprcv1.0.6indirekt
Gogithub.com/lestrrat-go/iterv1.0.2indirekt
Gogithub.com/lestrrat-go/jwx/v2v2.1.6indirekt
Gogithub.com/lestrrat-go/optionv1.0.1indirekt
Gogithub.com/nats-io/nkeysv0.4.16indirekt
Gogithub.com/nats-io/nuidv1.0.1indirekt
Gogithub.com/puerkitobio/rehttpv1.4.0indirekt
Gogithub.com/segmentio/asmv1.2.1indirekt
Gogithub.com/vmihailenco/tagparser/v2v2.0.0indirekt
Gogo.devnw.com/structsv1.0.0indirekt
Gogolang.org/x/cryptov0.52.0indirekt
Gogolang.org/x/sysv0.45.0indirekt
PyPIadjust-precision-for-schema0.3.4indirekt
PyPIalembic1.18.4indirekt
PyPIanyio4.13.0indirekt
PyPIattrs25.4.0indirekt
PyPIattrs26.1.0indirekt
PyPIbackoff2.2.1indirekt
PyPIboto31.43.6indirekt
PyPIbotocore1.43.6indirekt
PyPIcertifi2026.4.22indirekt
PyPIcharset-normalizer3.4.7indirekt
PyPIciso86012.3.3indirekt
PyPIclick8.3.3indirekt
PyPIclick-default-group1.2.4indirekt
PyPIcolorama0.4.6indirekt
PyPIdateparser1.4.0indirekt
PyPIdistlib0.4.0indirekt
PyPIfasteners0.20indirekt
PyPIfilelock3.29.0indirekt
PyPIgreenlet3.5.0indirekt
PyPIidna3.15indirekt
PyPIjinja23.1.6indirekt
PyPIjmespath1.1.0indirekt
PyPIjsonschema2.6.0indirekt
PyPIjsonschema4.26.0indirekt
PyPIjsonschema-specifications2025.9.1indirekt
PyPIlfx-v1-sync-helper0.1.1indirekt
PyPIlibrt0.7.8indirekt
PyPImako1.3.12indirekt
PyPImarkdown-it-py4.2.0indirekt
PyPImarkupsafe3.0.3indirekt
PyPImdurl0.1.2indirekt
PyPImsgspec0.20.0indirekt
PyPImypy1.19.1indirekt
PyPImypy-extensions1.1.0indirekt
PyPInats-py2.12.0indirekt
PyPIpackaging26.2indirekt
PyPIpathspec1.0.3indirekt
PyPIpip26.1.1indirekt
PyPIplatformdirs4.9.6indirekt
PyPIpsutil7.2.2indirekt
PyPIpygments2.20.0indirekt
PyPIpython-dateutil2.9.0.post0indirekt
PyPIpython-discovery1.3.1indirekt
PyPIpython-dotenv1.2.2indirekt
PyPIpytz2025.2indirekt
PyPIpytz2026.2indirekt
PyPIpyyaml6.0.3indirekt
PyPIreferencing0.37.0indirekt
PyPIregex2026.5.9indirekt
PyPIrequests2.34.0indirekt
PyPIrich14.3.4indirekt
PyPIrpds-py0.30.0indirekt
PyPIruamel-yaml0.19.1indirekt
PyPIs3transfer0.17.0indirekt
PyPIsimplejson3.20.2indirekt
PyPIsinger-python6.3.0indirekt
PyPIsix1.17.0indirekt
PyPIsmart-open7.6.1indirekt
PyPIsnowplow-tracker1.1.0indirekt
PyPIsqlalchemy2.0.49indirekt
PyPIstructlog25.5.0indirekt
PyPItypes-jsonschema4.26.0.20260109indirekt
PyPItypes-simplejson3.20.0.20250822indirekt
PyPItyping-extensions4.15.0indirekt
PyPItzdata2026.2indirekt
PyPItzlocal5.3.1indirekt
PyPIurllib32.7.0indirekt
PyPIuv0.11.14indirekt
PyPIvirtualenv21.3.2indirekt
PyPIwrapt2.1.2indirekt
Abhängigkeits-Advisories 5

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 121 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 5 tragen bekannte Advisories, davon 1 direkte.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
pip26.1.1indirekthoch226.1.2
uv0.11.14indirektmittel10.11.15
golang.org/x/textv0.37.0direktunbekannt10.39.0
github.com/klauspost/compressv1.18.6indirektunbekannt11.18.7
golang.org/x/cryptov0.52.0indirektunbekannt1

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 16428,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 627772,
        "Shell": 5120,
        "Python": 20529,
        "Makefile": 5670
      },
      "pushed_at": "2026-07-27T23:45:25Z",
      "created_at": "2025-10-30T20:44:41Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T16:08:41Z",
      "description": "LFX v1<>v2 data sync helper",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://www.linuxfoundation.org/",
      "name": "The Linux Foundation",
      "type": "Organization",
      "login": "linuxfoundation",
      "company": null,
      "location": null,
      "followers": 1394,
      "avatar_url": "https://avatars.githubusercontent.com/u/1040002?v=4",
      "created_at": "2011-09-10T02:25:10Z",
      "is_verified": null,
      "public_repos": 61,
      "account_age_days": 5435
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.13.4",
          "kind": "patch",
          "published_at": "2026-07-17T16:08:52Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2026-07-16T19:43:20Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-07-08T22:00:24Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-08T15:46:03Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-02T10:38:52Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-06-22T19:41:36Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-06-16T08:01:12Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-06-11T20:25:38Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-06-03T20:24:53Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-03T17:22:52Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-02T15:28:40Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-01T16:00:06Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-05-21T13:59:50Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-05-18T21:13:19Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-04-24T19:51:32Z"
        },
        {
          "tag": "v0.8.8",
          "kind": "patch",
          "published_at": "2026-04-23T13:02:40Z"
        },
        {
          "tag": "v0.8.7",
          "kind": "patch",
          "published_at": "2026-04-20T20:53:23Z"
        },
        {
          "tag": "v0.8.6",
          "kind": "patch",
          "published_at": "2026-04-20T20:01:58Z"
        },
        {
          "tag": "v0.8.5",
          "kind": "patch",
          "published_at": "2026-04-20T16:14:56Z"
        },
        {
          "tag": "v0.8.4",
          "kind": "patch",
          "published_at": "2026-04-20T15:57:03Z"
        },
        {
          "tag": "v0.8.3",
          "kind": "patch",
          "published_at": "2026-04-20T00:22:21Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-04-17T15:44:16Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-04-09T21:32:53Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-04-08T20:51:29Z"
        },
        {
          "tag": "v0.7.8",
          "kind": "patch",
          "published_at": "2026-04-08T00:11:45Z"
        },
        {
          "tag": "v0.7.7",
          "kind": "patch",
          "published_at": "2026-04-02T22:44:32Z"
        },
        {
          "tag": "v0.7.6",
          "kind": "patch",
          "published_at": "2026-04-02T22:36:16Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-04-01T21:37:30Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2026-03-31T14:39:30Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-31T12:05:07Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-26T18:40:01Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-17T19:38:41Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-17T18:46:27Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-11T15:50:38Z"
        },
        {
          "tag": "v0.5.19",
          "kind": "patch",
          "published_at": "2026-03-10T00:19:44Z"
        },
        {
          "tag": "v0.5.18",
          "kind": "patch",
          "published_at": "2026-03-09T21:31:49Z"
        },
        {
          "tag": "v0.5.17",
          "kind": "patch",
          "published_at": "2026-03-09T16:20:21Z"
        },
        {
          "tag": "v0.5.16",
          "kind": "patch",
          "published_at": "2026-03-04T23:16:45Z"
        },
        {
          "tag": "v0.5.15",
          "kind": "patch",
          "published_at": "2026-03-03T11:42:13Z"
        },
        {
          "tag": "v0.5.14",
          "kind": "patch",
          "published_at": "2026-03-02T23:51:27Z"
        },
        {
          "tag": "v0.5.13",
          "kind": "patch",
          "published_at": "2026-02-21T15:43:54Z"
        },
        {
          "tag": "v0.5.12",
          "kind": "patch",
          "published_at": "2026-02-20T22:11:24Z"
        },
        {
          "tag": "v0.5.11",
          "kind": "patch",
          "published_at": "2026-02-20T18:36:32Z"
        },
        {
          "tag": "v0.5.10",
          "kind": "patch",
          "published_at": "2026-02-20T01:33:18Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-02-19T18:44:06Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-02-19T18:20:55Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-02-19T17:56:03Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-02-18T22:33:37Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-02-17T23:54:54Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-02-07T00:21:30Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-01-28T00:17:20Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-01-22T00:49:43Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-01-20T20:08:19Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-01-06T19:34:34Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2025-12-24T02:17:47Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2025-12-19T00:06:36Z"
        },
        {
          "tag": "v0.3.8",
          "kind": "patch",
          "published_at": "2025-12-16T23:30:32Z"
        },
        {
          "tag": "v0.3.7",
          "kind": "patch",
          "published_at": "2025-12-15T19:52:15Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2025-12-09T20:10:28Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2025-12-05T00:25:29Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2025-12-04T18:39:23Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2025-12-03T19:11:45Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2025-12-03T16:29:00Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2025-12-03T07:17:54Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2025-12-03T02:38:25Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2025-12-02T16:52:19Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2025-12-02T00:17:05Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2025-12-01T17:26:36Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2025-11-26T23:37:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "da4ab4b00327f2a74dd5bcc777ef4e3c54abaca7",
          "body": "fix(committee-members): sync contact SFID (MemberID) to v1 on delete",
          "is_bot": false,
          "headline": "Merge pull request #131 from linuxfoundation/jme/LFXV2-2673",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-17T16:08:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "099e6b69ba9ff1a223923c70a5c27a1c4f1c0f6c",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into jme/LFXV2-2673",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-16T20:35:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa47d384e5f9d82ba1bcc1327c317686bb34850b",
          "body": "feat: populate podAnnotations in deployment chart and update codeowners",
          "is_bot": false,
          "headline": "Merge pull request #134 from linuxfoundation/agaete/add-podAnnotations",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-16T19:35:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cf2c11152a8e02e05bad713b56b583cfc41352f",
          "body": "Signed-off-by: Antonia Gaete <agaete@linuxfoundation.org>",
          "is_bot": false,
          "headline": "feat: populate podAnnotations in deployment chart and update codeowners",
          "author_name": "Antonia Gaete",
          "author_login": "agaetep",
          "committed_at": "2026-07-16T19:28:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "708a19bb4f52fab80fcb5bf5d112d46c73624141",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into jme/LFXV2-2673",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-15T22:00:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89e9ca8832bed94d1574f539c8908f54cf185b87",
          "body": "The v1 project-service DELETE/PATCH .../committees/{c}/members/{MemberID}\nendpoints match on contact_name__c (the contact SFID), not the\nplatform-community__c record sfid. The reverse mapping's member field now\ncarries the contact SFID instead, so the delete/update path can use the\ncorrect value for\n[…]\nclassification logic\n\nAddresses Copilot review feedback on PR #131.\n\nIssue: LFXV2-2673\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nSigned-off-by: Jordan Evans <jevans@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(committee-members): sync contact SFID (MemberID) to v1 on delete",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-15T21:39:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "32df2be90fc2f9cda461803fa494eddb3e79742f",
          "body": "…ge-cases",
          "is_bot": false,
          "headline": "Merge pull request #132 from linuxfoundation/lfxv2-2662-email-sync-ed…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-15T00:31:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62950961aaba9b7ae5fc7fbab4ddc4ae4ba3b9e3",
          "body": "…y semantics\n\n- lfx_v1_client.go: fix stale doc comment on isSoleQualifyingAlternateEmail\n  (the caller no longer falls back to normal link logic on error).\n- handlers_users.go: updateContactEmailMappingIndex previously returned a\n  bool that conflated 'did the write apply' with 'should this be\n  re\n[…]\ny/redelivery.\n\n  Updated the one existing test that stubs this function to match the\n  new signature.\n\nAssisted-by: github-copilot:claude-sonnet-5\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Address fourth round of PR #132 review feedback on mapping-write retr…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-14T20:07:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16a303b97510879bf0096f2a2459b6b701b63104",
          "body": "- isSoleQualifyingAlternateEmail: wrap the ambiguous\n  multiple-qualifying-rows-no-primary case in a sentinel error\n  (errAmbiguousDefactoPrimaryEmail) so callers can distinguish it from\n  other (potentially transient) errors.\n- handleAlternateEmailUpdate: request redelivery on a transient\n  sole-de\n[…]\neturn's own decision,\n  rather than a shared shouldRetry variable threaded through unrelated\n  logic.\n\nAssisted-by: github-copilot:claude-sonnet-5\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Address third round of PR #132 review feedback and clean up retry flow",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-14T18:17:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d36cdfc5f9b748944f2059b4cf12560cd9cd0e75",
          "body": "- lookupMergedUser: fix revive unused-parameter lint by dropping the\n  now-unused candidateEmailSfid parameter from\n  isSoleQualifyingAlternateEmail (the loop never referenced it).\n- backfillEmailsForUser / syncSingleUser: revert the earlier\n  qualifyingComplete flag back to an immediate abort on a \n[…]\na single unflagged\n  qualifying row), so this is now treated as an error/abort instead of\n  guessing.\n\nAssisted-by: github-copilot:claude-sonnet-5\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Address second round of PR #132 review feedback on email sync heuristics",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-14T16:25:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47714c133baba4875af405b5df56355281c5b842",
          "body": "- lookupMergedUser: check username presence/validity together and\n  return an accurate error distinguishing a missing username from a\n  bogus one (space or @). Moving the check earlier also avoids the\n  primary-email lookup for users we're going to reject anyway.\n- isSoleQualifyingAlternateEmail: pr\n[…]\nad failure now aborts processing\n  for that user instead of silently undercounting qualifying emails.\n\nAssisted-by: github-copilot:claude-sonnet-5\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Address PR #132 review comments on error handling and messages",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-14T15:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "038cbffb2a00db94fb102f28249440120c3c02d7",
          "body": "- Treat alternate emails whose domain ends in \".old\" as inactive,\n  even if active__c is still true (v1 soft-deactivation convention).\n- Treat a user's sole qualifying alternate email (active, and\n  verified or primary) as a de-facto primary email, matching\n  auth0-db-sync.js's heuristic, instead of\n[…]\nue into v2 as a literal identifier (committee\n  members, project executive director/program manager).\n\nAssisted-by: github-copilot:claude-sonnet-5\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Fix alternate email sync edge cases and bogus username handling",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-13T21:54:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "148b159a42504f06964fa2798ff77f7f10320c6e",
          "body": "…p-org-uuid\n\nfix: ignore CDP org UUIDs on v2→v1 committee member sync (LFXV2-2647)",
          "is_bot": false,
          "headline": "Merge pull request #130 from linuxfoundation/fix/LFXV2-2647-ignore-cd…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T21:50:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34eefe0791518697e1525257eac4922f51e4bb7c",
          "body": "Post b2b/b2c Salesforce split produces org IDs with an \"lf\" key prefix\ninstead of the traditional \"001\". Since IsValid is a format-only check\n(15/18 alphanumeric chars, no prefix or checksum validation), these IDs\nshould pass. Add explicit 15- and 18-char lf-prefix cases to confirm.\n\nLFXV2-2647\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "test(sfid): add lf-prefix SFID test cases for post b2b/b2c split IDs",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T21:45:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bf43a06dca704b67c853c00fd60cd4bea59afcae",
          "body": "Reword comments on sfid.IsValid and resolveOrgIDFromEventData so they\nmatch the implementation: 15/18-char alphanumeric check without\nAccount prefix or checksum validation.\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(review): clarify sfid.IsValid is format-only, not Account-specific",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T20:58:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6dc4fe5e60c493ab2382d2c99d31ada65ebfdb98",
          "body": "Add TestResolveOrgIDFromEventData_ignoresNonSFID covering the new core\nbehavior introduced by this PR: CDP UUIDs, hex digests, and other\nnon-SFID organization.id values are dropped and the function returns \"\"\n(no network call since name+website are empty).\n\nThe existing TestResolveOrgIDFromEventData\n[…]\nrcises the new branch\nadded in resolveOrgIDFromEventData (per copilot-pull-request-reviewer).\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(review): add test coverage for non-SFID ignore path LFXV2-2647",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T20:37:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3af71d1401ca71d975d94861f20891280a8d6a84",
          "body": "Reuse internal/sfid instead of a local shape check so SFID validation\nstays consistent with Normalize18 and other callers in this repo.\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "refactor: validate committee member org ids with sfid.IsValid",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T19:50:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c517b1a8ca65761fe1a46476091a70b5332947aa",
          "body": "Replace CDP UUID-specific filtering with general SFID shape validation\nso UUIDs, placeholders, and other non-SFID values fall back to name/website\nresolution instead of failing project-service sync.\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "refactor: only pass organization.id to v1 when it looks like an SFID",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T19:46:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "27023c86325788db727611390cfd776a34dd651a",
          "body": "Self-serve stored CDP organization UUIDs in organization.id caused v1\nproject-service to reject member create/update. Treat UUIDs as unset and\nresolve from name/website instead so v2→v1 sync can proceed.\n\nRelated: LFXV2-2647\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: ignore CDP org UUIDs when syncing committee members to v1",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-08T19:44:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b9aba3e66a0ef4f0144ed2fca88248cabb2dc495",
          "body": "fix: require exact domain match in org website search",
          "is_bot": false,
          "headline": "Merge pull request #129 from linuxfoundation/jme/LFXV2-2627",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-08T15:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ca4b84a00cb7e585965d3cd85c44e3d826bb0ef",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into jme/LFXV2-2627",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-08T15:23:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83952a32c3739868cda64467646b0393984292c8",
          "body": "…lse-unlink\n\nfix(auth): unlink Auth0 identity when active__c=false; profile-sync refactor",
          "is_bot": false,
          "headline": "Merge pull request #128 from linuxfoundation/fix/LFXV2-1507-active-fa…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-07T22:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7b06011c89951c20082d553beeb337126240674",
          "body": "…g org assignment\n\nThe org-service search uses a substring LIKE query, so searching for\n'linuxfoundation.org' could match unrelated orgs such as\n'myprofile.lfx.linuxfoundation.org'. The first result was returned\nblindly, causing committee member records to be assigned the wrong org.\n\nAdd normalizeDo\n[…]\nh to the org creation path rather than accepting a\nfalse positive.\n\nIssue: LFXV2-2627\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Jordan Evans <jevans@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix: require exact domain match in org website search to prevent wron…",
          "author_name": "Jordan Evans",
          "author_login": "jordane",
          "committed_at": "2026-07-07T22:43:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbcc698c29e664a44d8c4bd07b1e7be88b579736",
          "body": "- Remove errors field from backfillEmailsResult and backfillProfilesResult:\n  abort-on-error means the field was always zero; remove from structs,\n  page-complete log lines, and final summary log lines in main.go.\n- handleMergedUserDelete: use deleteIndexKeyFn instead of calling\n  mappingsKV.Delete \n[…]\ns updated_at, so the failing\n  user will be retried on the next run via the inclusive cursor query.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address automated review feedback on deletion refactor",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-06T22:32:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "efc37d924fc9add8285801a013f0b38b06954cb4",
          "body": "… semantics\n\nSeveral related changes to make deletion handling consistent and correct:\n\ngetV1ObjectData (lfx_v1_client.go):\n- Check _sdc_deleted_at before isdeleted; a WAL soft-delete means the row\n  was physically removed from the source DB, so there is no need to also\n  inspect the SFDC-semantic i\n[…]\nFn in delete handler test.\n- Add isActive: true to all active test cases (zero value is now false).\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor(handlers): centralise soft-delete routing; clean up deletion…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-06T21:23:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b3a78191c12e9e1c40d865b683fbc4e958814e7e",
          "body": "Address review comment from copilot-pull-request-reviewer[bot]:\n\n- auth0_mgmt.go: add context.DeadlineExceeded and context.Canceled as\n  retryable errors in isRetryableAuth0Error; a per-call timeout expiry\n  on the handler's auth0CallTimeout wrapper should NACK for redelivery,\n  not silently drop th\n[…]\nadlineExceeded,\n  wrapped context.DeadlineExceeded, and context.Canceled\n\nResolves 1 review thread.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #128 review feedback",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-06T17:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdb9c59ef1388056e3f0715739602a542a4ede21",
          "body": "Conflict in auth0_mgmt.go: main renamed WithRetries() to WithRetryStrategy{}\n(API rename) in the same region our branch deleted the backfill-bool conditional\nentirely. Resolution: keep our WithNoRetries() always — no backfill parameter.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Merge branch 'main' into fix/LFXV2-1507-active-false-unlink",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-06T16:27:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b299bc520fa62e3d1ee79ef41a53de28a523da9",
          "body": "…tion\n\nfix(backfill): replace ephemeral consumers with ScanSubjectData for all KV stream scans",
          "is_bot": false,
          "headline": "Merge pull request #122 from linuxfoundation/fix/next-by-subj-enumera…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-06T16:14:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e649be51e44ecdbbd19a8229a63952f48993dbd4",
          "body": "Return an empty map instead of a separate boolean to signal no changes.\nCallers check len(patch) == 0 which is more idiomatic Go.\nUpdate tests to match the new signature and fix a test case that\nincorrectly expected absent keys via wantFieldChecks (now uses\nwantAbsent instead).\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor(auth0): simplify buildAuth0Metadata to return single map",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T23:08:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee73635c856e8607d5703d5c0a647581d2d8d01d",
          "body": "Auth0 merges top-level user_metadata keys on PATCH, so there is no need\nto read all existing fields and re-send the full object. buildAuth0Metadata\nnow returns a patch map containing only keys whose values differ from the\nexisting metadata, making the PATCH body minimal and more race-safe.\n\nWhile he\n[…]\n preserved in the return value\n(Auth0 PATCH semantics guarantee that without help from the caller).\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor: send only changed fields in Auth0 user_metadata PATCH",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T22:13:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "151d8004cb51d19453eb846a38516ddab2fe22da",
          "body": "- Remove duplicate opening line in v1ToAuth0Fields comment block.\n- Replace handleMergedUserUpdate doc comment, which still described the\n  old fire-and-forget goroutine, profileSyncDelay, immediate ACK, and\n  SDK-level retries; update to reflect the current synchronous path that\n  NACKs on retryable Auth0 errors with WithNoRetries on the client.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "docs: fix stale and duplicate comments after profile-sync refactor",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T21:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60cf0637920a0348921f5dd1453ef2fdf5b5b9ec",
          "body": "… rate limit\n\n- Remove backfill bool from initAuth0MgmtClient; always use WithNoRetries.\n  Live path NACKs on retryable errors (JetStream redelivery handles backoff);\n  backfill aborts on error and saves cursor.\n- Make profile sync synchronous (remove fire-and-forget goroutine and\n  profileSyncDelay\n[…]\n unlink cases), TestBuildAuth0Metadata\n  (removes name field expectations, adds wantAbsent checks).\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor(auth0): synchronous profile sync, no SDK retries, outer-loop…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T21:37:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d2cf978f13f3781c743a465129fe861ddd25092",
          "body": "v1 user-service has two soft-delete paths for alternate emails:\n  - Delete the database row → Meltano WAL sets _sdc_deleted_at → routed\n    to handleAlternateEmailDelete which calls unlinkEmailIdentityFn.\n  - Set active__c=false without deleting the row → WAL replicates as a\n    plain PUT with no _s\n[…]\nuth0\nuser's own email field (not a linked identity) and is therefore out of\nscope for this handler.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(auth): unlink Auth0 identity when active__c=false on a KV PUT",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T16:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1befbb7fa7d067abd191c37bc22a2bd0e106d6b7",
          "body": "Resolve single conflict in AGENTS.md: keep ScanSubjectData heading from\nfeature branch (supersedes the EnumerateLiveSubjects heading that main\nstill carried from an older iteration).\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Merge branch 'main' into fix/next-by-subj-enumeration",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-02T16:12:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ec7868b5b3d7924579effc12222a2d4636b97b8",
          "body": "fix: resolve workspace project IDs by slug",
          "is_bot": false,
          "headline": "Merge pull request #125 from linuxfoundation/LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-02T05:17:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "554c9dd46919b8c0a3be217673cb3124bdee5dd1",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-02T04:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ae8beb97ba2676fefd02317acf42d1efff5fd1c",
          "body": "Address review comments from copilot-pull-request-reviewer:\n\n- nats_scan.go: broaden opTimeout doc comment to mention both\n  cfg.NATSFetchMaxWait and cfg.ReindexNATSOpTimeout as valid\n  caller-supplied values (per copilot-pull-request-reviewer)\n- AGENTS.md: update per-call deadline bullet to reflect\n[…]\n's law per QF1001 suggestion\n\nResolves 2 review threads (doc fixes); responds to 3 false positives.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #122 review feedback and lint",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-07-01T20:50:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6851ff26a349eb67ef4a3c4d5ec144c76d631e4",
          "body": "…e-skip-notifications\n\n[LFXV2-1836] feat: suppress committee member notifications for V1/PCC-synced adds",
          "is_bot": false,
          "headline": "Merge pull request #127 from linuxfoundation/feat/LFXV2-1836-committe…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T18:47:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d53763568b1d9465b1f03872c97df5fb8a15c83",
          "body": "…(LFXV2-2567)\n\nRun gofmt -w to re-align the payload block after SkipNotification widened\nthe longest key.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(review): gofmt-align DeleteCommitteeMemberPayload struct literal …",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T18:37:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "892a241dbbad2c55fc9ab4dd5e75c67fc1bbd3d1",
          "body": "…teCommitteeMember (LFXV2-2567)\n\nAvoid inline condition expression as a function argument — assign the\nresult to a named variable first for clarity.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(review): extract skipNotification variable before passing to dele…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T18:34:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f28edc6257181d0ebf509d56cadfcbfa751a7049",
          "body": "…eMember\n\nPass skipNotification as a parameter to deleteCommitteeMember (consistent\nwith the create path) so the caller in handlers_committees.go controls it\nvia the CommitteeSkipMemberNotifications env var instead of hardcoding true.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(LFXV2-2567): thread skip_notification flag through deleteCommitte…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T18:32:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3149ead431f45b714449a05ad8ee3af0f4479544",
          "body": "…ip_notification\n\nBumps lfx-v2-committee-service from v0.4.8 to v0.4.12 which adds\nSkipNotification to DeleteCommitteeMemberPayload. Uncomments the\npreviously TODO'd SkipNotification: true so V1/PCC-synced member\nremoves no longer trigger removal emails.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "feat(LFXV2-2567): bump committee-service to v0.4.12, enable delete sk…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T18:24:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bfbe6b6ea6cf9f02631eccfb3b894b537e281a32",
          "body": "Run gofmt -w to re-align the LoadConfig struct-literal block after\nCommitteeSkipMemberNotifications widened the longest key, bringing the\nwhole field group to a consistent column.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(review): align config.go struct literal with gofmt (LFXV2-2567)",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T17:49:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f48f1f531fb607d1f4a7b14b9e1d6db761d02220",
          "body": "…tial-success test\n\nreconcileProjects sent a duplicate bulk-add entry when two non-deleted\nworkspace-project associations shared the same project_id. Also corrects\na target-nats-kv comment left stale after the Go backfill stopped\nsplitting composite project_id values, adds test coverage for a\nbulk-a\n[…]\nmd notes\nfrom doc comments (not visible to reviewers).\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(workspaces): dedupe bulk-add slugs, fix stale KV comment, add par…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-01T17:43:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bec97b21629a544a3cf60a3f5507c7f3e2c75ac",
          "body": "…endency bump\n\nAdds a commented-out SkipNotification: true to deleteCommitteeMember so the\nintent is clear: once the committee service is bumped to v0.4.9+ (which adds\nX-Skip-Notification to the DELETE member endpoint), remove the comment.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "feat(LFXV2-2567): note skip_notification on member delete pending dep…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T17:41:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6238d21354e9de053be757c418ad6804ec0ed0fc",
          "body": "…#67 contract\n\nSend project_id verbatim as project_slug (no split/lookup/skip), switch\nthe idempotency cache to a slug-keyed format that stores generated\nproject_uid per association, and match generated UIDs from the\nresponse's nested workspace.projects[] instead of the succeeded list.\nAlso count a \n[…]\n UID in the response, instead of silently dropping it.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(workspaces): align workspace-project sync with member-service PR …",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-01T17:35:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f73726c78025f791a07866b09bfea57e4e9490bb",
          "body": "Treat transient slug resolution failures as workspace errors so backfill does not reconcile project removals from an incomplete desired set.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(workspaces): guard project reconciliation on slug lookup errors",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-01T17:35:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a42d2e54b26f0b693e5522e203f925ad29a44fda",
          "body": "Use the slug portion of uuid:slug workspace-project references and cache canonical v2 project UIDs under project.slug.<hash>. This keeps workspace backfill reconciliation UID-keyed and avoids using v1-internal UUID prefixes.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: resolve workspace project IDs by slug",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-07-01T17:35:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4538465c6f994550132c8694e284a2217ad167d1",
          "body": "…chart\n\nAdds the env var to values.yaml so it is configurable per environment\nwithout a code change. Defaults to \"true\" (suppress V1/PCC-sync emails).\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "feat(LFXV2-1836): expose COMMITTEE_SKIP_MEMBER_NOTIFICATIONS in Helm …",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T17:28:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8594ac95b0b90841f3dbecbf8566e794b952c5fb",
          "body": "… test\n\nAdd parseBooleanEnvWithDefault(name, def) reusing the existing truthy-token\nset (true/yes/t/y/1) so that COMMITTEE_SKIP_MEMBER_NOTIFICATIONS respects\nthe same convention as the other boolean env vars. With the new helper, values\nlike \"0\", \"no\", or \"off\" now correctly re-enable notifications \n[…]\n cover the newly consistent\nbehaviour. Drop the unused strings import.\n\nAddresses: LFXV2-1836\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "fix(review): align boolean-env convention and fix tautological config…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T14:10:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45de44e59426278a12ca235a1a4a43a23a732fa7",
          "body": "…synced adds\n\nBumps the committee-service client dependency from v0.2.34 to v0.4.8 and\nwires five new generated endpoints (GetOrgCommitteeSeats, ReassignOrgCommitteeSeat,\nGetCurrentWeeklyBrief, GenerateWeeklyBrief, UpdateCurrentWeeklyBrief).\n\nAdds COMMITTEE_SKIP_MEMBER_NOTIFICATIONS env var (default\n[…]\nug scoping is\nhandled on the committee-service side via EMAIL_NOTIFICATION_PROJECT_ALLOWLIST.\n\nGenerated with [Claude Code](https://claude.ai/code)\n\nSigned-off-by: Andres Tobon <andrest2455@gmail.com>",
          "is_bot": false,
          "headline": "feat(LFXV2-1836): suppress committee member notifications for V1/PCC-…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-07-01T13:42:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8afe836cf4fb5bd59ae68ae46ba181c7f1fa6bc6",
          "body": "…used-ctx\n\nfix(lint): rename unused ctx parameter in dispatchProfileSync",
          "is_bot": false,
          "headline": "Merge pull request #126 from linuxfoundation/fix/megalinter-revive-un…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-30T21:38:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e471a1fbe3ed222ade679bcc89086ae88b9c5d6f",
          "body": "revive flagged dispatchProfileSync's ctx parameter as unused because\nthe function immediately discards it — the goroutine it spawns creates\nits own context.Background() timeout. Rename to _ to make the\nintentional discard explicit and clear the MegaLinter GO_REVIVE error.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(lint): rename unused ctx parameter in dispatchProfileSync",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-30T21:34:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "716af88d19853ce1556d72cd3ce5c17e0d3a2686",
          "body": "…l-sync-fixes\n\nfix(auth): fix alternate email sync and add backfill commands",
          "is_bot": false,
          "headline": "Merge pull request #120 from linuxfoundation/emsearcy/LFXV2-1507-emai…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-30T21:09:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbeaa0d2e4e4c317bf8ab41b96abc999f80916bf",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- backfill_email_profile.go: fix variable PerPage antipattern in\n  listAuth0UserPage — remove the limit parameter and always use\n  backfillPageSize for PerPage; when PerPage shrank to match remaining\n  on the final page of a run, Auth\n[…]\nackfill commands and none are being added per\nproject conventions.\n\nResolves 8 of 9 review threads.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #120 review feedback (round 4)",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-30T19:06:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec0b2c7eb6e5747f286ffd464962c099ac99e9cd",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into emsearcy/LFXV2-1507-email-sync-fixes",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-30T16:32:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "026b959e3acffdcdedd2c449681f6c867b4f55db",
          "body": "fix(target-nats-kv): normalize \":\" in KV key for uuid:slug project IDs (LFXV2-2215)",
          "is_bot": false,
          "headline": "Merge pull request #124 from linuxfoundation/LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-30T13:19:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "108f86a726d4b326b2def721142fb6921fc02e39",
          "body": "`platform.organization_workspace_project.project_id` stores values in\n`uuid:slug` form (e.g. `bdf801de-...:vllm`). Raw `:` in a JetStream KV\nsubject token is rejected at runtime with `InvalidKeyError`, causing every\nworkspace-project record to be skipped silently.\n\nFix: replace `:` with `_` when bui\n[…]\nyload.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(target-nats-kv): normalize `:` in KV key for uuid:slug project IDs",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-30T12:51:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6dfa07934abc2152d550bfbef7e10cce6e8f92f3",
          "body": "feat(LFXV2-2215): workspace migration follow-up — composite key support and org-not-found skip",
          "is_bot": false,
          "headline": "Merge pull request #123 from linuxfoundation/LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-30T08:58:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "501b9c1829c22f257a948a82a9bd8f07a3ce0d7b",
          "body": "UUIDs do contain \"-\" — the join is unambiguous because parts are\nfixed-width, not because the separator is absent from values. Reword\nthe comment in build_primary_key_value to reflect this and include a\nconcrete collision example for variable-length parts.\n\nAddresses Copilot review on PR #123.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(target-nats-kv): correct composite-key join comment",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-29T13:18:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f3c001fd6d650654053c087e849bdf55a0564eaa",
          "body": "…andling\n\nAdd composite primary key support to target-nats-kv (build_primary_key_value),\nwire skipped counter for 404 org-not-found in the Go backfill path, and\nupdate tap-postgres-catalog ConfigMap regeneration docs in AGENTS.md.\n\n- target-nats-kv: extract build_primary_key_value to handle >=1 Sing\n[…]\nxist).\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat: workspace data migration — composite key support and org-skip h…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-29T13:00:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cce94cfbbcbd1b949036b05dad2a443eda05a527",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into fix/next-by-subj-enumeration",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-29T05:35:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95349aef1e320abca5a2ae84b3b88133c3194ebf",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- backfill_email_profile.go: fix pagination bug in backfillAlternateEmails\n  and backfillProfiles — cursor was being updated mid-run, changing the\n  Search() query lower-bound between pages and causing offset pagination to\n  skip user\n[…]\n.\n- manifests/backfill-workspaces-job.yaml: same secret name alignment.\n\nResolves 8 review threads.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #120 review feedback (round 3)",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-26T18:43:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f903dbb7052ba698a9361ad6b19a53219dba9eb9",
          "body": "…est convention\n\nThe workspaces job was pulling HEIMDALL_CLIENT_ID from a secretKeyRef\n(heimdall_client_id in v1-sync-helper-secrets) which does not exist in\ncluster. All other one-shot job manifests use a plain value placeholder\nwith a comment directing the operator to fill it in from the running\ndeployment before applying. Align to that same pattern.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(manifests): align backfill-workspaces HEIMDALL_CLIENT_ID to manif…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-26T16:23:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56d97ac8fe2beb5e0f680389953d5c1670bd7cbc",
          "body": "Resolve conflict in main.go by combining --backfill-alternate-emails,\n--backfill-profiles, and --sync-user flags from this branch with the\n--backfill-workspaces flag introduced in main. Collapse the redundant\ntwo-stage mutual-exclusion check into a single oneShotCount guard\ncovering all one-shot flags.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Merge branch 'main' into emsearcy/LFXV2-1507-email-sync-fixes",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-26T16:17:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee1317748c6c61abb3619bfad02533efaad519e0",
          "body": "feat(LFXV2-2215): add --backfill-workspaces one-shot migration command",
          "is_bot": false,
          "headline": "Merge pull request #121 from linuxfoundation/LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-26T15:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b8f020f7fa743f553df595c9be05b440ee9cc0c",
          "body": "…ecords\n\nA one-shot migration that exits 0 with missing workspace records is\nharder to detect than a run that exits 1. Return an error (preserving\nthe partial result for the caller to discard) so the Job exits non-zero\nand can be cleanly retried.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(workspaces): make fetchKVSubjectRecords fail fast on skipped KV r…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-25T06:22:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5764994c85d91e047ca48a09df75c9fe97017fdc",
          "body": "- Fix blocking: createWorkspace decoded wrong response shape (wrapped envelope\n  vs flat); updated test mock to match real member-service 201 body\n- Fix: cache-write failure after 201 now returns error + increments errors\n  so the workspace is not silently unrecoverable on re-run\n- Fix: createAndCac\n[…]\nIMDALL_CLIENT_ID in Job manifest now uses secretKeyRef\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(workspaces): address human reviewer findings on backfill-workspaces",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-25T05:37:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0898bc5606106e41c3d2cba5b6cd152550e11aa",
          "body": "…ll KV stream scans\n\nBoth KV_v1-objects (54M sequences, 35.6M tombstones) and KV_v1-mappings\n(34M sequences) in production are too large for consumer-based enumeration.\nA DeliverAllPolicy consumer streams all sequences through a single connection,\nsaturating NATS server CPU (~357%), preventing heart\n[…]\ne.go to nats_scan.go. Remove the now-unused kvObjectsSubjectPrefix\nconstant from handlers_users.go.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(backfill): replace ephemeral consumers with ScanSubjectData for a…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-24T23:15:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ac98b5b980160f72b6d69b1e45d0c34efe21871",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- backfill_email_profile.go: replace backfillCursor struct with plain\n  string cursor; use ms-precision RFC3339Nano (Truncate(ms)) to preserve\n  Auth0's actual updated_at precision; add runPage for correct within-run\n  pagination so p\n[…]\n\n- manifests/rebuild-user-secondary-indexes-job.yaml: same secret fixes\n\nResolves 7 review threads.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #120 review feedback",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-24T22:58:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8b49f71017eadac598b3284536169ca7e5f7ef9c",
          "body": "…erateLiveSubjects\n\nPR #117 (merged today) introduced the shared EnumerateLiveSubjects\nhelper with built-in NumPending end-of-stream guard, tombstone\nfiltering, and configurable NATSFetchMaxWait. Replace the bespoke\nconsumer setup/Fetch loop with EnumerateLiveSubjects + v1KV.Get\npoint reads, matchin\n[…]\nSize, workspaceFetchMaxWait constants and\ntime import.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor(workspaces): replace bespoke fetchKVSubjectRecords with Enum…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T19:16:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11be4c7a590d5bba72dfd4176e64eb3c3e480e6e",
          "body": "…oject\n\nCovers the 404-tolerant delete paths added in the previous commit —\ndeleteWorkspace (204/404 success, 500 error) and removeWorkspaceProject\n(200/204/404 success, 500 error).\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "test(workspaces): add tests for deleteWorkspace and removeWorkspacePr…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T18:58:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf10525ee2f9b68ab96c52a76074b2c0087b059a",
          "body": "- fetchKVSubjectRecords: replace empty-batch break with cons.Info()\n  NumPending==0 guard to handle sparse streams correctly\n- reconcileProjects: capture errorsBefore before add/remove; gate\n  putWorkspaceCacheEntry on *errors==errorsBefore so partial applies\n  are not cached as complete\n- bulkAddPr\n[…]\n misleading comment/log in workspace pass-through case\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(workspaces): address Copilot review findings on backfill-workspaces",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T18:53:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37f46dd1419e080d5111d379fa544fcc5fb54622",
          "body": "One-shot Kubernetes Job that runs --backfill-workspaces against the\nv1-objects NATS KV bucket and syncs legacy workspace records into the\nv2 member-service. Additive-only, supports --dry-run. Apply manually\nafter WAL publication is active per environment; HEIMDALL_CLIENT_ID\nmust be filled in before applying.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "chore: add backfill-workspaces Job manifest",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T18:45:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb96ea45c7ccbe2a6a376e468236f02cbd540221",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into LFXV2-2215",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T18:38:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29ea65a212568fbdfe01f1ee8325bcaf229efc60",
          "body": "Adds a new --backfill-workspaces flag that reads legacy\nplatform.organization_workspace and organization_workspace_project\nrecords from the v1-objects KV bucket and syncs them into the v2\nmember-service via the b2b_org workspaces API. Supports --dry-run,\nloop-prevention, and idempotent re-runs via a\n[…]\nMeltano replication config,\nand updates documentation.\n\nJira: LFXV2-2215\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2215\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "feat: add --backfill-workspaces one-shot migration command",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-24T18:30:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6a6632369c43f540f1577122feba9e514484d26",
          "body": "- Add Auth0 Management API enumeration pattern note alongside the\n  EnumerateLiveSubjects section, explaining when to use each approach\n  (NATS KV outer loop vs Auth0 user outer loop)\n- Move --backfill-acs-project and --backfill-acs-org before the\n  email/profile backfills so section order matches m\n[…]\ncs-project entry that was\n  left over below --sync-user (full detail now at the top of the section)\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "docs(agents): align backfill section with Auth0-enumeration pattern",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-24T17:56:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5258bd3facdc5195741db35164910cbe0ec7da44",
          "body": "…mail-sync-fixes\n\nConflicts resolved:\n- AGENTS.md: retain intro sentence from branch; take EnumerateLiveSubjects\n  section and --backfill-acs-project detail from main; drop duplicate\n  --backfill-acs-org stub at conflict boundary (fully documented below)\n- cmd/lfx-v1-sync-helper/config.go: take NATS\n[…]\nmain;\n  drop ProfileSyncBackfill (removed on this branch, replaced by --backfill-profiles CLI flag)\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into emsearcy/LFXV2-1507-e…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-24T16:59:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e1723ad5d0dcef7da83bbbd568f13afa3cf9b60",
          "body": "…h-max-wait\n\nfix(nats): consolidate ephemeral consumers into EnumerateLiveSubjects abstraction",
          "is_bot": false,
          "headline": "Merge pull request #117 from linuxfoundation/fix/LFXV2-1750-nats-fetc…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-24T16:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e44759e59052c77779d1c45bf41c018706085f55",
          "body": "- Use Auth0 user.GetUsername() instead of stripping auth0| prefix;\n  treat a missing username as a fatal error that stops the backfill\n  rather than silently skipping users.\n\n- Switch cursor range query from exclusive {cursor TO *} to inclusive\n  [cursor TO *]; Auth0 updated_at has second precision \n[…]\n\n\n- Update AGENTS.md to reflect inclusive cursor behavior and mutual\n  exclusion of one-shot flags.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(backfill): address PR review feedback",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T23:06:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34a8be6b0c1bfb9f9e18f2a871e9f7d163e7fa6e",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- nats_enumerate.go: use a short-lived background context for the\n  deferred DeleteConsumer call so a cancelled or deadline-exceeded\n  enumeration context does not prevent best-effort cleanup; the ephemeral\n  consumer falls back to se\n[…]\nw threads; thread PRRT_kwDOQMZPQ86LubXs\n(EnumerateLiveSubjects unit tests) addressed by reply only.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #117 review feedback (third batch)",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T22:14:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "911003c98410f1f8558bba35e36031fdb37fec81",
          "body": "- Fix verified__c → email_verified__c in getAlternateEmailDetails: the\n  deprecated verified__c column is almost never set, causing ~95% of\n  verified alternate emails to be silently skipped by the live sync.\n\n- Add --backfill-alternate-emails [--limit N] [--dry-run]: iterates\n  Auth0 users (Usernam\n[…]\nials) instead of the ad-hoc variants.\n\n- Update AGENTS.md with documentation for all new CLI flags.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(auth): fix alternate email sync and add backfill commands",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T21:33:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "520c6f7fe97236b4901764c1f220bb4543a73d98",
          "body": "…tests\n\nAddress review comments from copilot-pull-request-reviewer[bot]:\n\n- ingest_acs_org.go: wrap each v1KV.Get in the collectOrgAccountSFIDs\n  point-read loop with context.WithTimeout(ctx, cfg.NATSFetchMaxWait) for\n  parity with the reindex pass 2 pattern (ReindexNATSOpTimeout)\n- ingest_acs_proje\n[…]\neads; thread PRRT_kwDOQMZPQ86LuORL\n(cons.Info() broker load acceptability) addressed by reply only.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): add per-op KV timeout to backfill passes; extend config …",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T21:19:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e981e770f4ef7c92401786974d37fd675242e41",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- nats_enumerate.go: replace tombstoned map with a counter; the map\n  was only used for the completion log and doubled peak memory on large\n  enumerations with no correctness benefit\n- nats_enumerate.go: use errKey constant instead of\n[…]\nthe\n  actual cons.Info() / NumPending end-of-stream detection behaviour\n\nResolves 6 review threads.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #117 review feedback",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T18:46:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9aa5cf992d8a8990ac1adbca22d8827ad2c62a78",
          "body": "Add cons.Info() with a generous timeout (default 120s, configurable via\nWithInfoTimeout) after each batch to check NumPending==0. This is a\ncorrectness requirement: on sparse streams the server may exhaust\nFetchMaxWait without filling a batch, and a subsequent empty Fetch\nwould silently terminate the loop with incomplete results. Relying on\nempty-batch termination alone is not safe.\n\nAssisted-by: github-copilot:claude-opus-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(nats): add cons.Info() NumPending check to EnumerateLiveSubjects",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T18:17:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bffb9ca8c2e20bea789efe0ee24e0af0e4b34eb",
          "body": "…etch-max-wait",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into fix/LFXV2-1750-nats-f…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T18:07:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "257427a771588c565b8a40316b2cc2e275f29308",
          "body": "…al consumers\n\nConverge three separate ephemeral consumer implementations (user\nreindex, project SFID collection, org SFID collection) into a single\nshared EnumerateLiveSubjects function in nats_enumerate.go.\n\nAll three callers previously duplicated the same core logic: ephemeral\npull consumer creat\n[…]\neshold 5m,\n  explicit defer delete\n\nNet reduction of ~146 lines across the three consumer call sites.\n\nAssisted-by: github-copilot:claude-opus-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "refactor(nats): extract EnumerateLiveSubjects abstraction for ephemer…",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T18:03:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "896c927b26bfb9b9595761dabbdc665b9c75c0f8",
          "body": "Address review comments from copilot-pull-request-reviewer[bot]:\n\n- handlers_users.go: guard cfg.NATSFetchMaxWait <= 0 before use;\n  fall back to defaultNATSFetchMaxWait, consistent with the backfill\n  consumers (per copilot-pull-request-reviewer[bot])\n- ingest_acs_project.go: remove local fetchMaxW\n[…]\nr[bot])\n\nAlso tightens the zero-check from == 0 to <= 0 for robustness.\n\nResolves 3 review threads.\n\nAssisted-by: github-copilot:claude-sonnet-4.6\nSigned-off-by: Eric Searcy <eric@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(review): address PR #117 review feedback",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-23T16:47:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6046b86bf091234f793971c7c6b91bfa12f601c0",
          "body": "annotate cronjobs for datadog alert routing",
          "is_bot": false,
          "headline": "Merge pull request #119 from linuxfoundation/agaete/annotate-cronjobs",
          "author_name": "Antonia Gaete",
          "author_login": "agaetep",
          "committed_at": "2026-06-22T17:52:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97684138c6705485ecbab8f9b380fe9f7f55148d",
          "body": "Signed-off-by: Antonia Gaete <agaete@linuxfoundation.org>",
          "is_bot": false,
          "headline": "copilot suggestions",
          "author_name": "Antonia Gaete",
          "author_login": "agaetep",
          "committed_at": "2026-06-22T17:32:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e257eeb6a704c757226620f64db99885a9b1ec2",
          "body": "Signed-off-by: Antonia Gaete <agaete@linuxfoundation.org>",
          "is_bot": false,
          "headline": "annotate cronjobs for datadog alert routing",
          "author_name": "Antonia Gaete",
          "author_login": "agaetep",
          "committed_at": "2026-06-22T17:16:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10b6bbffcf74d796494673da9e434de7a3323a71",
          "body": "…helper\n\ndocs: add cross-repo routing callout (LFXV2-2015)",
          "is_bot": false,
          "headline": "Merge pull request #108 from linuxfoundation/feat/LFXV2-2015-v1-sync-…",
          "author_name": "Pepe Garcia-Reyero Sais",
          "author_login": "josep-reyero",
          "committed_at": "2026-06-17T09:18:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9faaf4e9ef4210f0af9395e6ec603eaacdea3d09",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into feat/LFXV2-2015-v1-sync-helper",
          "author_name": "Pepe Garcia-Reyero Sais",
          "author_login": "josep-reyero",
          "committed_at": "2026-06-17T09:14:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6619d63a1e4d2867487a9115ae1939466ae5a34b",
          "body": "feat(backfill): backfill pending ACS org invites into b2b_org settings (LFXV2-2204)",
          "is_bot": false,
          "headline": "Merge pull request #118 from linuxfoundation/LFXV2-2204",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-15T16:22:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e2e34ce7379cb958b17108f20ce5d45799e5c1f",
          "body": "…tions\n\nWiden ±1s boundary to ±10s in TestFetchACSOrgInvitesByRole_TimeFilter to\nprevent flake when wall clock ticks between the test and production cutoff.\nAdd explicit scopeid/rolenames/status/showuniqueusers assertions to the\nTimeFilter and Pagination test handlers so a wrong param name is caught\nrather than silently accepted by ACS.\n\nJira: LFXV2-2204\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2204\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "test(backfill): fix flaky time boundary and add ACS query param asser…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-12T16:47:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a5047773f81dc74aeb5d8490b9760b4674eb64b",
          "body": "… review fixes\n\n- ingest_acs_org.go: mergeOrgUsersWithACS now builds an email-keyed index\n  of existing pending (Username==nil) rows. When an accepted grant arrives\n  for the same email on run 2+, the stale pending row is replaced in-place\n  rather than appended -- preventing alice from appearing tw\n[…]\nio test.\n\nAddresses dealako review comment on PR #118.\n\nJira: LFXV2-2204\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2204\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(backfill): fix stale pending-invite duplicate on subsequent runs;…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-12T16:34:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d5f306d5cd610412675752c4b609ca351629d1d",
          "body": "…tored email\n\n- ingest_acs_org.go: on fetchACSOrgInvitesByRole error, fall back to empty\n  invites instead of skipping the org entirely -- accepted grants are still\n  backfilled when the /invites endpoint is temporarily unavailable.\n- ingest_acs_org_invites.go: replace inv.Email == \"\" blank check wi\n[…]\nup key.\n\nAddresses Copilot review comments on PR #118.\n\nJira: LFXV2-2204\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2204\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "fix(backfill): proceed with grants if invite fetch fails; normalize s…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-12T15:29:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f2e8d6865c884ea06678b4a05713a4ef7838488",
          "body": "…s (LFXV2-2204)\n\nFold pending-invite backfill into the existing --backfill-acs-org path.\nAccepted grants (username-keyed) and pending invites (email-keyed, last\n1 year) are now migrated in a single run.\n\nKey changes:\n- New ingest_acs_org_invites.go: fetchACSOrgInvitesByRole uses confirmed\n  ACS para\n[…]\n\"invited_as\":\"writer\",\"invite_status\":\"pending\"}],...}\n\nJira: LFXV2-2204\nLink: https://linuxfoundation.atlassian.net/browse/LFXV2-2204\nSigned-off-by: Prabodh Chaudhari <pchaudhari@linuxfoundation.org>",
          "is_bot": false,
          "headline": "feat(backfill): backfill pending ACS org invites into b2b_org setting…",
          "author_name": "Prabodh Chaudhari",
          "author_login": "prabodhcs",
          "committed_at": "2026-06-12T14:36:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c0c59c0ddbe388f75d7769ba3fdd5ab11472dff",
          "body": "…me-instead-of-sub\n\nfix(v1-sync-helper): use LFX username for v2 impersonation and writes (LFXV2-2169)",
          "is_bot": false,
          "headline": "Merge pull request #114 from linuxfoundation/atobon/LFXV2-2169-userna…",
          "author_name": "Andres Tobon",
          "author_login": "andrest50",
          "committed_at": "2026-06-10T21:29:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de1d4cae095c4cc385c292d8a64e6a13746af63f",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into atobon/LFXV2-2169-username-instead-of-sub",
          "author_name": "Eric Searcy",
          "author_login": "emsearcy",
          "committed_at": "2026-06-10T21:04:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 69,
      "commits_last_year": 629,
      "latest_release_at": "2026-07-17T16:08:52Z",
      "latest_release_tag": "v0.13.4",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 35,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 4.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/linuxfoundation/lfx-v1-sync-helper",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/linuxfoundation/lfx-v1-sync-helper",
          "is_deprecated": false,
          "latest_version": "v0.13.4",
          "repository_url": "https://github.com/linuxfoundation/lfx-v1-sync-helper",
          "versions_count": 70,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-17T16:08:31Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-19",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 5
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 50871,
      "source_files_sampled": 55,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 19554
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "pip",
            "direct": false,
            "version": "26.1.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8,
            "advisory_ids": [
              "GHSA-wf93-45jw-7689",
              "PYSEC-2026-196"
            ],
            "fixed_version": "26.1.2",
            "advisory_count": 2,
            "oldest_advisory_days": 56
          },
          {
            "name": "uv",
            "direct": false,
            "version": "0.11.14",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-4gg8-gxpx-9rph"
            ],
            "fixed_version": "0.11.15",
            "advisory_count": 1,
            "oldest_advisory_days": 59
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.37.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 13
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.6",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5841"
            ],
            "fixed_version": "1.18.7",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 20
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1,
          "unknown": 3,
          "moderate": 1
        },
        "advisory_count": 6,
        "affected_count": 5,
        "assessed_count": 121,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "github.com/akamensky/base58",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20210829145138-ce8bf8802e8f"
        },
        {
          "name": "github.com/auth0/go-auth0",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.40.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.41.7"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.17"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/credentials",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.16"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/dynamodb",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.57.3"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/dynamodbstreams",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.16"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/linuxfoundation/lfx-v2-committee-service",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.12"
        },
        {
          "name": "github.com/linuxfoundation/lfx-v2-project-service",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.11"
        },
        {
          "name": "github.com/nats-io/nats.go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.52.0"
        },
        {
          "name": "github.com/patrickmn/go-cache",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.0+incompatible"
        },
        {
          "name": "github.com/vmihailenco/msgpack/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.4.1"
        },
        {
          "name": "goa.design/goa/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.26.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.37.0"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "meltano",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==4.2.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/akamensky/base58",
            "direct": true,
            "version": "v0.0.0-20210829145138-ce8bf8802e8f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/auth0/go-auth0",
            "direct": true,
            "version": "v1.40.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": true,
            "version": "v1.41.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": true,
            "version": "v1.19.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/dynamodb",
            "direct": true,
            "version": "v1.57.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/dynamodbstreams",
            "direct": true,
            "version": "v1.32.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": true,
            "version": "v1.42.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/linuxfoundation/lfx-v2-committee-service",
            "direct": true,
            "version": "v0.4.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/linuxfoundation/lfx-v2-project-service",
            "direct": true,
            "version": "v0.6.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nats.go",
            "direct": true,
            "version": "v1.52.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/patrickmn/go-cache",
            "direct": true,
            "version": "v2.1.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/msgpack/v5",
            "direct": true,
            "version": "v5.4.1",
            "ecosystem": "go"
          },
          {
            "name": "goa.design/goa/v3",
            "direct": true,
            "version": "v3.26.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": true,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "meltano",
            "direct": true,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.24",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery",
            "direct": false,
            "version": "v1.11.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.0.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.30.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.35.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.25.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
            "direct": false,
            "version": "v4.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-chi/chi/v5",
            "direct": false,
            "version": "v5.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/goccy/go-json",
            "direct": false,
            "version": "v0.10.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/websocket",
            "direct": false,
            "version": "v1.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/blackmagic",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/httpcc",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/httprc",
            "direct": false,
            "version": "v1.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/iter",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/jwx/v2",
            "direct": false,
            "version": "v2.1.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/option",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nkeys",
            "direct": false,
            "version": "v0.4.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nuid",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/puerkitobio/rehttp",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/asm",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/tagparser/v2",
            "direct": false,
            "version": "v2.0.0",
            "ecosystem": "go"
          },
          {
            "name": "go.devnw.com/structs",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "adjust-precision-for-schema",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "pypi"
          },
          {
            "name": "alembic",
            "direct": false,
            "version": "1.18.4",
            "ecosystem": "pypi"
          },
          {
            "name": "anyio",
            "direct": false,
            "version": "4.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "25.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "backoff",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.43.6",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.43.6",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.4.22",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.7",
            "ecosystem": "pypi"
          },
          {
            "name": "ciso8601",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "click-default-group",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "dateparser",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "distlib",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fasteners",
            "direct": false,
            "version": "0.20",
            "ecosystem": "pypi"
          },
          {
            "name": "filelock",
            "direct": false,
            "version": "3.29.0",
            "ecosystem": "pypi"
          },
          {
            "name": "greenlet",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.15",
            "ecosystem": "pypi"
          },
          {
            "name": "jinja2",
            "direct": false,
            "version": "3.1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "jmespath",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "2.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "4.26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-specifications",
            "direct": false,
            "version": "2025.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "lfx-v1-sync-helper",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "librt",
            "direct": false,
            "version": "0.7.8",
            "ecosystem": "pypi"
          },
          {
            "name": "mako",
            "direct": false,
            "version": "1.3.12",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-it-py",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markupsafe",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "mdurl",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "msgspec",
            "direct": false,
            "version": "0.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mypy",
            "direct": false,
            "version": "1.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "mypy-extensions",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nats-py",
            "direct": false,
            "version": "2.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pathspec",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pip",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "platformdirs",
            "direct": false,
            "version": "4.9.6",
            "ecosystem": "pypi"
          },
          {
            "name": "psutil",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dateutil",
            "direct": false,
            "version": "2.9.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-discovery",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytz",
            "direct": false,
            "version": "2025.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytz",
            "direct": false,
            "version": "2026.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "referencing",
            "direct": false,
            "version": "0.37.0",
            "ecosystem": "pypi"
          },
          {
            "name": "regex",
            "direct": false,
            "version": "2026.5.9",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": false,
            "version": "14.3.4",
            "ecosystem": "pypi"
          },
          {
            "name": "rpds-py",
            "direct": false,
            "version": "0.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ruamel-yaml",
            "direct": false,
            "version": "0.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "s3transfer",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "simplejson",
            "direct": false,
            "version": "3.20.2",
            "ecosystem": "pypi"
          },
          {
            "name": "singer-python",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "smart-open",
            "direct": false,
            "version": "7.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "snowplow-tracker",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sqlalchemy",
            "direct": false,
            "version": "2.0.49",
            "ecosystem": "pypi"
          },
          {
            "name": "structlog",
            "direct": false,
            "version": "25.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "types-jsonschema",
            "direct": false,
            "version": "4.26.0.20260109",
            "ecosystem": "pypi"
          },
          {
            "name": "types-simplejson",
            "direct": false,
            "version": "3.20.0.20250822",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tzdata",
            "direct": false,
            "version": "2026.2",
            "ecosystem": "pypi"
          },
          {
            "name": "tzlocal",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uv",
            "direct": false,
            "version": "0.11.14",
            "ecosystem": "pypi"
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": "21.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "wrapt",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 121,
        "direct_count": 21,
        "indirect_count": 100
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 5,
        "merged_prs": 128,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 4
      },
      "bus_factor": 2,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "emsearcy",
          "commits": 249,
          "avatar_url": "https://avatars.githubusercontent.com/u/1682693?v=4"
        },
        {
          "type": "User",
          "login": "andrest50",
          "commits": 147,
          "avatar_url": "https://avatars.githubusercontent.com/u/56457791?v=4"
        },
        {
          "type": "User",
          "login": "prabodhcs",
          "commits": 66,
          "avatar_url": "https://avatars.githubusercontent.com/u/52558975?v=4"
        },
        {
          "type": "User",
          "login": "mauriciozanettisalomao",
          "commits": 63,
          "avatar_url": "https://avatars.githubusercontent.com/u/25565880?v=4"
        },
        {
          "type": "User",
          "login": "joanreyero",
          "commits": 38,
          "avatar_url": "https://avatars.githubusercontent.com/u/37874460?v=4"
        },
        {
          "type": "User",
          "login": "jordane",
          "commits": 36,
          "avatar_url": "https://avatars.githubusercontent.com/u/342364?v=4"
        },
        {
          "type": "User",
          "login": "bramwelt",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/324567?v=4"
        },
        {
          "type": "User",
          "login": "agaetep",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/82597086?v=4"
        },
        {
          "type": "User",
          "login": "josep-reyero",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/106924814?v=4"
        },
        {
          "type": "User",
          "login": "AlanSherman",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/1022557?v=4"
        }
      ],
      "contributors_sampled": 14,
      "top_contributor_share": 0.396
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "license-header-check.yml",
        "mega-linter.yml",
        "publish-branch.yaml",
        "publish-main.yaml",
        "publish-release.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 8,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 6 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 5,
            "reason": "dependency not pinned by hash detected -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 5,
            "reason": "5 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "da4ab4b00327f2a74dd5bcc777ef4e3c54abaca7",
        "ran_at": "2026-07-28T09:58:58Z",
        "aggregate_score": 7.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T23:55:38Z",
      "oldest_open_prs": [
        {
          "number": 78,
          "created_at": "2026-04-01T22:38:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 82,
          "created_at": "2026-04-07T19:05:33Z",
          "last_comment_at": "2026-04-08T17:39:33Z",
          "last_comment_author": "emsearcy"
        },
        {
          "number": 133,
          "created_at": "2026-07-14T18:34:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 135,
          "created_at": "2026-07-17T16:22:37Z",
          "last_comment_at": "2026-07-27T22:13:29Z",
          "last_comment_author": "emsearcy"
        },
        {
          "number": 136,
          "created_at": "2026-07-17T23:13:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-17T16:08:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/linuxfoundation/lfx-v1-sync-helper",
    "host": "github.com",
    "name": "lfx-v1-sync-helper",
    "owner": "linuxfoundation"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 69,
      "inputs": {
        "security": 78,
        "vitality": 93,
        "community": 24,
        "governance": 83,
        "engineering": 57
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 93,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 629,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 35
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "35/52 weeks with commits",
                "points": 24.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 35
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "629 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 629
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 69,
              "latest_release_tag": "v0.13.4",
              "releases_from_tags": false,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 4.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "69 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 69
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 10,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 10 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 83,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 14,
              "top_contributor_share": 0.396
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 40% of commits",
                "points": 13.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "14 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 98,
            "inputs": {
              "merged_prs": 128,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 4
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "128/132 decided PRs merged",
                "points": 37.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 128,
                      "decided": 132
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "followers": 1394,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "linuxfoundation",
              "public_repos": 61,
              "account_age_days": 5435
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,394 followers of linuxfoundation",
                "points": 22.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1394,
                      "login": "linuxfoundation"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "61 public repos, account ~14 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 61
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/linuxfoundation/lfx-v1-sync-helper"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "70 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 70
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 57,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 78,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 75,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 7.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 2.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "5 existing vulnerabilities detected",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 121 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 121
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 89,
            "inputs": {
              "source": "osv",
              "advisories": 6,
              "affected_packages": 5,
              "assessed_packages": 121,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1, moderate 1, unknown 3",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: golang.org/x/text v0.37.0 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "golang.org/x/text v0.37.0 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 121,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 9
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 83,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.88,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 19554
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "88 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 88,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.22,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "22 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 22,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 50871,
              "source_files_sampled": 55,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/55 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 55,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'lfx-v1-sync-helper' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T09:59:20.301848Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/linuxfoundation/lfx-v1-sync-helper.svg",
  "full_name": "linuxfoundation/lfx-v1-sync-helper",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.