Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-25 19:56 UTC

manifest-cyber / cli

Public repository containing Manifest CLI Documentation and Releases

ShellMIT★ 3 Sterne⑂ 0 Forksseit Feb. 2023Auf GitHub ansehen ↗

manifest-cyber/cli erreicht einen Gesundheitsindex von 55 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (75/100) ab, am schwächsten bei AI Readiness (20/100). Zuletzt vor 1 Tag aktualisiert. 3 Mitwirkende tragen den Großteil der jüngsten Arbeit.

55
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

55
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Manifest CyberOrganisation
21 Follower38 öffentliche Reposseit Juni 2022

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

75Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
6.2/36Commit-Rhythmus — 9/52 Wochen mit Commits
12.9/18Commit-Volumen — 26 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year26
human_commit_share1
days_since_last_push1
active_weeks_last_year9
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 100 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 3 Tagen
27/27Release-Rhythmus — ein Release etwa alle 6,2 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count100
latest_release_tagv0.36.3-beta.0
releases_from_tagsnein
days_since_latest_release3
mean_days_between_releases6,2

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

27Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
4.9/60Stars — 3 Stars
0/25Forks — 0 Forks
1.7/15Watcher — 3 Watcher
Verwendete Eingangsdaten
forks0
stars3
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

62Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
36/54Bus-Faktor — 3 Beitragende decken die Hälfte aller Commits ab
18.2/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 19 % der Commits
13.5/13.5Breite der Beitragenden — 11 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Verwendete Eingangsdaten
bus_factor3
contributors_sampled11
top_contributor_share0,189
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — 0 % der Issues geschlossen
35.5/38.3PR-Annahme — 26/28 entschiedene PRs gemergt
10.5/15OpenSSF Scorecard: Code-Review — Found 8/11 approved changesets -- score normalized to 7
Verwendete Eingangsdaten
merged_prs26
open_issues2
closed_issues0
issue_closed_ratio0
closed_unmerged_prs2
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
9.7/25Reichweite des Inhabers — 21 Follower von manifest-cyber
19.9/25Kontohistorie — 38 öffentliche Repos, Kontoalter ca. 4 Jahre
Verwendete Eingangsdaten
followers21
owner_typeOrganization
is_verified
owner_loginmanifest-cyber
public_repos38
account_age_days1.510

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

54Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 2 Workflow(s)
0/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
16/20OpenSSF Scorecard: CI-Tests — 9 out of 11 merged PRs checked by a CI test -- score normalized to 8
Verwendete Eingangsdaten
has_cija
has_testsnein
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

52Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2/2.5CI-Tests — 9 out of 11 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
5.2/7.5Code-Review — Found 8/11 approved changesets -- score normalized to 7
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
4/5SAST — SAST tool is not run on all commits -- score normalized to 8
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,2
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

20Kritisch · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
35/40Lesbare Commit-Historie — 59 von 90 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,656
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
0/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
0/10Reproduzierbare Umgebung
8.9/10Belegte Agentenpraxis — 4 der letzten 90 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsnein
lockfiles
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,044
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — Shell ohne Typprüfungs-Konfiguration
0/55Handhabbare Dateigrößen — keine Quelldateien erkannt
Verwendete Eingangsdaten
primary_languageShell
largest_source_bytes
source_files_sampled0
oversized_source_files0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Handhabbare Dateigrößen. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

3GitHub-Sterne
11Mitwirkende
26Commits, letzte 12 Monate
1Tage seit letztem Push
100Releases
3Bus-Faktor
2offene Issues
Paket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

OpenSSF Scorecard 5.2 / 10
5.2Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-25 19:55 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
8CI-Tests9 out of 11 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
7Code-ReviewFound 8/11 approved changesets -- score normalized to 7
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
8SASTSAST tool is not run on all commits -- score normalized to 8
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Alle Abhängigkeiten 0

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 0 direkte und 0 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Abhängigkeits-Advisories nicht bewertet

Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies to assess

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 475,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 11903
      },
      "pushed_at": "2026-07-24T14:49:07Z",
      "created_at": "2023-02-01T11:02:46Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T14:49:24Z",
      "description": "Public repository containing Manifest CLI Documentation and Releases",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Shell",
      "significant_languages": [
        "Shell"
      ]
    },
    "owner": {
      "blog": "https://manifestcyber.com",
      "name": "Manifest Cyber",
      "type": "Organization",
      "login": "manifest-cyber",
      "company": null,
      "location": "United States of America",
      "followers": 21,
      "avatar_url": "https://avatars.githubusercontent.com/u/106975015?v=4",
      "created_at": "2022-06-06T13:06:14Z",
      "is_verified": null,
      "public_repos": 38,
      "account_age_days": 1510
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.36.3-beta.0",
          "kind": "prerelease",
          "published_at": "2026-07-21T21:55:38Z"
        },
        {
          "tag": "v0.36.2",
          "kind": "patch",
          "published_at": "2026-07-17T17:07:47Z"
        },
        {
          "tag": "v0.36.1",
          "kind": "patch",
          "published_at": "2026-07-06T23:35:38Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-07-06T22:16:23Z"
        },
        {
          "tag": "v0.35.1-beta.0",
          "kind": "prerelease",
          "published_at": "2026-07-01T19:32:06Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2026-06-17T14:58:13Z"
        },
        {
          "tag": "v0.34.2",
          "kind": "patch",
          "published_at": "2026-06-10T21:50:18Z"
        },
        {
          "tag": "v0.34.1",
          "kind": "patch",
          "published_at": "2026-06-04T17:31:30Z"
        },
        {
          "tag": "v0.35.0-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-28T18:42:58Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2026-05-26T21:12:44Z"
        },
        {
          "tag": "v0.33.1-beta.2",
          "kind": "prerelease",
          "published_at": "2026-05-26T19:01:34Z"
        },
        {
          "tag": "v0.33.1-beta.1",
          "kind": "prerelease",
          "published_at": "2026-05-18T20:30:10Z"
        },
        {
          "tag": "v0.33.1-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-18T17:05:45Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2026-05-14T14:39:39Z"
        },
        {
          "tag": "v0.32.3-beta.1",
          "kind": "prerelease",
          "published_at": "2026-05-13T21:45:07Z"
        },
        {
          "tag": "v0.32.3-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-13T11:41:07Z"
        },
        {
          "tag": "v0.32.2",
          "kind": "patch",
          "published_at": "2026-05-08T20:41:40Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-05-05T19:24:07Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-04-28T20:29:27Z"
        },
        {
          "tag": "v0.31.2",
          "kind": "patch",
          "published_at": "2026-04-23T19:03:55Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-04-20T18:09:22Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-03-03T19:55:33Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-01-27T20:19:18Z"
        },
        {
          "tag": "v0.30.0-beta.3",
          "kind": "prerelease",
          "published_at": "2026-01-27T00:32:16Z"
        },
        {
          "tag": "v0.30.0-beta.2",
          "kind": "prerelease",
          "published_at": "2025-12-18T14:18:12Z"
        },
        {
          "tag": "v0.30.0-beta.1",
          "kind": "prerelease",
          "published_at": "2025-12-15T21:45:25Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2025-12-12T22:41:29Z"
        },
        {
          "tag": "v0.30.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-12-08T18:25:34Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2025-12-02T15:40:52Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2025-11-25T20:05:20Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2025-11-24T17:04:29Z"
        },
        {
          "tag": "v0.26.2",
          "kind": "patch",
          "published_at": "2025-10-03T17:37:49Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2025-08-29T15:21:12Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2025-08-28T20:25:01Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2025-08-20T16:09:40Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2025-08-15T19:22:47Z"
        },
        {
          "tag": "v0.23.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-08-15T01:33:50Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2025-07-01T12:12:43Z"
        },
        {
          "tag": "v0.21.4-beta.0",
          "kind": "prerelease",
          "published_at": "2025-06-27T15:48:22Z"
        },
        {
          "tag": "v0.22.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-06-25T19:16:26Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2025-06-13T14:11:20Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2025-06-12T18:10:23Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2025-05-19T12:57:57Z"
        },
        {
          "tag": "v0.21.1-beta.0",
          "kind": "prerelease",
          "published_at": "2025-05-18T14:24:46Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2025-05-05T17:04:08Z"
        },
        {
          "tag": "v0.21.0-rc.1",
          "kind": "prerelease",
          "published_at": "2025-05-05T15:15:20Z"
        },
        {
          "tag": "v0.20.2-beta.0",
          "kind": "prerelease",
          "published_at": "2025-05-02T16:23:52Z"
        },
        {
          "tag": "v0.21.0-rc.0",
          "kind": "prerelease",
          "published_at": "2025-04-30T15:14:30Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2025-04-23T20:29:20Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2025-04-23T16:31:01Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2025-04-21T15:38:25Z"
        },
        {
          "tag": "v0.18.8",
          "kind": "patch",
          "published_at": "2025-04-02T11:30:00Z"
        },
        {
          "tag": "v0.18.7",
          "kind": "patch",
          "published_at": "2025-03-05T19:46:03Z"
        },
        {
          "tag": "v0.18.6",
          "kind": "patch",
          "published_at": "2025-03-04T18:21:52Z"
        },
        {
          "tag": "v0.18.5",
          "kind": "patch",
          "published_at": "2025-03-03T16:59:56Z"
        },
        {
          "tag": "v0.18.4",
          "kind": "patch",
          "published_at": "2025-02-18T17:04:28Z"
        },
        {
          "tag": "v0.18.3",
          "kind": "patch",
          "published_at": "2025-01-16T15:58:40Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2025-01-15T18:06:24Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2024-12-11T11:02:08Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2024-11-26T13:42:18Z"
        },
        {
          "tag": "v0.17.4",
          "kind": "patch",
          "published_at": "2024-11-06T15:15:33Z"
        },
        {
          "tag": "v0.17.3",
          "kind": "patch",
          "published_at": "2024-10-25T21:48:25Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2024-10-01T16:43:20Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2024-09-30T21:03:55Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2024-09-23T16:30:24Z"
        },
        {
          "tag": "v0.17.0-beta.0",
          "kind": "prerelease",
          "published_at": "2024-09-20T19:04:27Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2024-08-27T18:56:47Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2024-08-14T08:35:18Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2024-08-05T16:11:04Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2024-07-21T18:51:59Z"
        },
        {
          "tag": "v0.14.9",
          "kind": "patch",
          "published_at": "2024-06-25T14:59:04Z"
        },
        {
          "tag": "v0.14.8",
          "kind": "patch",
          "published_at": "2024-05-23T12:59:27Z"
        },
        {
          "tag": "v0.14.7",
          "kind": "patch",
          "published_at": "2024-05-16T17:52:57Z"
        },
        {
          "tag": "v0.14.6",
          "kind": "patch",
          "published_at": "2024-05-10T14:50:20Z"
        },
        {
          "tag": "v0.14.5",
          "kind": "patch",
          "published_at": "2024-05-09T17:56:05Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2024-05-07T06:49:07Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2024-05-05T13:45:46Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2024-04-30T15:18:42Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2024-04-18T17:23:13Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2024-03-11T17:08:34Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2024-03-06T13:38:07Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2024-02-29T00:07:14Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2024-02-28T15:52:19Z"
        },
        {
          "tag": "v0.12.6",
          "kind": "patch",
          "published_at": "2023-12-31T15:56:49Z"
        },
        {
          "tag": "v0.12.5",
          "kind": "patch",
          "published_at": "2023-12-31T12:32:48Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2023-12-22T19:28:00Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2023-12-06T17:54:54Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2023-12-01T17:41:40Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2023-11-22T14:51:34Z"
        },
        {
          "tag": "v0.12.1-beta.1",
          "kind": "prerelease",
          "published_at": "2023-11-20T12:58:19Z"
        },
        {
          "tag": "v0.12.1-beta.0",
          "kind": "prerelease",
          "published_at": "2023-11-19T15:16:49Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2023-11-16T11:21:53Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2023-11-04T05:29:33Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2023-09-26T12:05:56Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2023-08-09T22:08:43Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2023-08-01T16:10:07Z"
        },
        {
          "tag": "v0.9.4",
          "kind": "patch",
          "published_at": "2023-07-28T04:48:06Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2023-07-27T13:30:06Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2023-07-25T21:07:39Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2023-07-20T20:49:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4e1525749499ec355e61eabe23cfc96396a9e67d",
          "body": "… (#32)\n\n## Summary\n\nDocuments which Manifest API token scope each CLI flag requires, and how\nto find a product ID, in the public CLI docs. Derived by tracing every\nmanifest-api call the CLI makes and mapping each endpoint to its\npermission guard.\n\n### README.md\n- New **Scope permissions by flag** t\n[…]\nre attached.\n* Included `crat`-specific authentication scope guidance and clarified\nthat `--llm-api-key` is not a Manifest token.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document API token scopes per flag and how to find a product ID…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-24T14:49:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3de8a1ef8f43c67aad37bb59df04ce7144e10fc4",
          "body": "Map the granular permission labels to the composite scope names shown on\nthe token creation screen: Manage SBOMs and VEX (--publish), Manage\nproducts + Manage assets (product flags), and View all pages and data\n(the read scope that covers scan-status polling and --download-vdr).",
          "is_bot": false,
          "headline": "docs: use the UI's composite scope names for token permissions",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-24T14:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ba4bd3a6158261d4f834fdc115afd25f2964da0",
          "body": "--product-id and --product-label only take effect together with --publish\n(the product association runs in the publish flow), so the example without\n--publish would not actually assign the SBOM to a product.",
          "is_bot": false,
          "headline": "docs: add --publish to the product-assignment sbom example",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-23T20:42:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abec2e2b394d66fa2cecae0ce9ae78d4eb6ae049",
          "body": "Adds a scope-permission reference so users know which token permissions\neach publish/product/VDR flag requires:\n\n- README.md: \"Scope permissions by flag\" table in the API Tokens section,\n  and expands the --product-id description with how to find a product ID\n  from its page URL.\n- ARGUMENTS.md: \"To\n[…]\nitionally require \"View all SBOMs and VEX documents\".\ncrat publishes, polls, and downloads a VDR, so its --api-key needs all\nthree publish/VDR scopes; --llm-api-key is unrelated to the Manifest token.",
          "is_bot": false,
          "headline": "docs: document API token scopes per flag and how to find a product ID",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-21T21:38:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27bcffce56345059e556fafd15abb558bed38c56",
          "body": "…ciliation (#29)\n\nAdds --update-product to the publish Snapshots flag reference in\nARGUMENTS.md and a \"Reconciling a Product's Inventory to a Snapshot\"\nsection in README.md. The flag reconciles a product's inventory to a\nsnapshot (removing snapshot-labeled assets that predate the timestamp)\nthen adds the published asset. Requires --product-id and both snapshot\nflags; mutually exclusive with --replace-in-product.",
          "is_bot": false,
          "headline": "docs: document the --update-product flag for snapshot inventory recon…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-07T12:58:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f91d01ec7e23cdc4d473ec3fb03a9a796d2c7e81",
          "body": "…ciliation\n\nAdds --update-product to the publish Snapshots flag reference in\nARGUMENTS.md and a \"Reconciling a Product's Inventory to a Snapshot\"\nsection in README.md. The flag reconciles a product's inventory to a\nsnapshot (removing snapshot-labeled assets that predate the timestamp)\nthen adds the published asset. Requires --product-id and both snapshot\nflags; mutually exclusive with --replace-in-product.",
          "is_bot": false,
          "headline": "docs: document the --update-product flag for snapshot inventory recon…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-07T12:54:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a29e33a02edc0fd21ffce184a99cbb0d15a52476",
          "body": "Documents the new `--supplier` flag on `generate` and `merge`, added to\nthe CLI in manifest-cli.\n\n## Changes\n\n- `ARGUMENTS.md`: `--supplier` row in the Generate and Merge flag\ntables, plus a \"Generate with a Supplier\" example.\n- `README.md`: `--supplier` entry in the generate flag list.\n\nThe flag se\n[…]\non is applied to generated and merged\nSBOM output.\n* Included an example showing how to generate an SBOM with a supplier\nvalue.\n\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document the --supplier flag (#28)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-06T23:18:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80bc6f0142b3782806930b6ce835758f67b3731c",
          "body": "Adds --supplier to the generate and merge flag references in ARGUMENTS.md\nand README.md, plus a generate example. The flag sets the supplier on the\nCycloneDX root component and BOM metadata; for SPDX it sets the package\nsupplier, falling back to --group.",
          "is_bot": false,
          "headline": "docs: document the --supplier flag for generate and merge",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-06T23:15:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8d140bcf614234f3bbb5ee971ab6797f0d2e732",
          "body": "## Summary\n\n- Add `csbom` as a supported generator in all relevant references\n(`--generator` flag descriptions and the Generators section)\n- Add `## Generating a C/C++ SBOM with csbom` section to README with\ninstall and usage example, linking to the new dedicated page\n- Add `## Workflow` section to \n[…]\nsh pipeline\n* Updated README and CLI argument docs to list `csbom` in generator\noptions for install/generate and related commands\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom and workflow documentation (#27)",
          "author_name": "Leidson Campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T17:32:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9bcd05c651fb5e9c8f24bb37cdf30b91db7b83d",
          "body": "- Fix \"analyses\" -> \"analyzes\" in csbom.md\n- Remove spdx-json from csbom output formats (cyclonedx-json only)\n- Add workflow command section to ARGUMENTS.md with --workflow-file, --preset, --file flags\n- Add workflow command to ARGUMENTS.md table of contents\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] address review feedback on csbom and workflow docs",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T17:01:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "10506c6595f32835bb6ac0b215e176785c45132c",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom to generator lists in ARGUMENTS.md",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T14:27:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9f763a825980b211a57849d48c4ee8641b5691aa",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom releases link to csbom.md",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-19T00:04:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ea52ba407ca213c1f36d634bc70f987ff61553cf",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom and workflow documentation",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-18T23:09:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f1521f4f9f0f4410dbf2537dabcc633094b9c25d",
          "body": "The `--version` flag for SBOM generation has no `-v` shorthand — `-v` is\nbound to `--verbose`. This removes the inaccurate `v,` prefix from the\nflag documentation so users don't try to use a shorthand that doesn't\nexist.",
          "is_bot": false,
          "headline": "docs: correct version flag, no -v shorthand (#25)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-12T21:31:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e061f473745c4102a17277843e2c5115f312e06",
          "body": "The --version flag for SBOM generation has no -v shorthand (-v is bound\nto --verbose). Remove the inaccurate 'v,' prefix from the docs.",
          "is_bot": false,
          "headline": "docs: correct version flag, no -v shorthand",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-12T21:20:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd356d3db5ed6b6a3fb12c6589d69574d761858e",
          "body": "…h flags (#24)\n\n## Summary\n\nDocuments previously-undocumented CLI publish functionality.\n\n**Snapshots**\n- README.md: a *Publishing Snapshots* section covering snapshot mode,\nthe paired `--snapshot-label` / `--snapshot-timestamp` flags, the\ndeactivation sweep, timestamp validation rules, and examples\n[…]\n with snapshot-mode semantics,\nuse cases, required flags, validation constraints, example commands, and\nCI integration guidance.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document snapshot publishing and previously-undocumented publis…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T16:02:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c09fd186516f67c0ac5b85cd4bf64a67e5854d93",
          "body": "…lace-in-product",
          "is_bot": false,
          "headline": "docs: add usage guide for deactivate-older, deactivate-label, and rep…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4150a7feeca4eb9010f92955edbee9fffc9369d1",
          "body": "…t publish flags",
          "is_bot": false,
          "headline": "docs: document name, version, deactivate-label, and replace-in-produc…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:29:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "857ae9ca6f302e5eb31342354f1a1db6c89af164",
          "body": "Add a Publishing Snapshots section to the README and the --snapshot-label\nand --snapshot-timestamp flags to the publish command reference, covering\nsnapshot mode, timestamp validation rules, and usage examples.",
          "is_bot": false,
          "headline": "docs: document snapshot publishing in README and ARGUMENTS",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:19:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50ebc94906fd6f07d50a461c788f960e67ed1bd0",
          "body": "…RLs (PLAT-1692) (#23)\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Documentation**\n* Added comprehensive CLI reference guide documenting all available\ncommands, flags, environment variables, and usage examples\n  * Updated repository URLs for apt and yum package installations\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: update README, add updated exhausted arguments list, fix fury U…",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-24T17:10:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "884408ed3f3b4ab6ce821e0a9c3528a6a31e44f1",
          "body": null,
          "is_bot": false,
          "headline": "PLAT-1692: Add exhaustive arguments list",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-20T18:16:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "143c518e1c80353bd069a0ed5196defa59787f95",
          "body": null,
          "is_bot": false,
          "headline": "Update fury URLs (added from legacy PR from Ori)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-20T18:03:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7f25353e68b26375d15464a80bc2e49d01831ac",
          "body": "…n (#22)",
          "is_bot": false,
          "headline": "docs: update readme to include info on how to update to latest versio…",
          "author_name": "Marina",
          "author_login": "marinacabrerarosa",
          "committed_at": "2026-02-03T17:40:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfd374156209d1338da334e0fedfd74f13b5acff",
          "body": null,
          "is_bot": false,
          "headline": "docs: update readme to include info on how to update to latest version",
          "author_name": "Marina Rosa",
          "author_login": "marinacabrerarosa",
          "committed_at": "2026-02-03T16:23:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9872a9e69921984abb7a9237efaa15080320a925",
          "body": null,
          "is_bot": false,
          "headline": "docs: update api token creation screenshots (#21)",
          "author_name": "Marina",
          "author_login": "marinacabrerarosa",
          "committed_at": "2025-12-08T21:36:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1be10f2c0accf7f8f2ccbe81a3c9fcfbda8b1695",
          "body": null,
          "is_bot": false,
          "headline": "docs: update api token creation screenshots",
          "author_name": "Marina Rosa",
          "author_login": "marinacabrerarosa",
          "committed_at": "2025-12-08T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13756bd2a19b595fc1685ec103d0f5af79b4c6ec",
          "body": null,
          "is_bot": false,
          "headline": "feat: update docs for enrichment arg (#20)",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2025-04-30T16:45:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "540f17abcb522ac6855acc56ab599dcac48c1867",
          "body": null,
          "is_bot": false,
          "headline": "feat: update docs for enrichment arg",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2025-04-30T16:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46d4ee7880519bb788f2f2b4cfcf787bdba6c2d3",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): fix install methods [PLAT-459] (#19)",
          "author_name": "meghmanifest",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-22T13:32:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6ce8d47f153682fbe2d77ce433a2490c4c015a0",
          "body": null,
          "is_bot": false,
          "headline": "schedule for cron and pr workflow",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:54:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "233a822140ce396d8a7ae5008fa8df0390eb9af2",
          "body": null,
          "is_bot": false,
          "headline": "attempt for apt",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:32:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae078872c693aca198d2b4179d5779e70352c5cf",
          "body": null,
          "is_bot": false,
          "headline": "ci - attempt fix for scoop and apt",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05ea8b7d46805b5d84bc769ccb9e65bc1b848a20",
          "body": null,
          "is_bot": false,
          "headline": "update GH action test harness",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T17:59:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d20402535efb701c8d707136b97d1321cc3e91f4",
          "body": null,
          "is_bot": false,
          "headline": "Updates readme and adds test harness (attempt 1)",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T17:52:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7f7bbf04d6859f945cf56aaffec41cd4ce013ba",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md (#18)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2025-04-21T14:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a863bd5e6ebbefd6e8a28bc77af076b843c5bb57",
          "body": "Signed-off-by: lsell-manifest <lexi@manifestcyber.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2025-04-18T17:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3c8a5d18f72f54374aea148974c499b65117a86",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix readme description for active flag (#17)",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2024-09-23T12:39:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f837f997603fd454dcf9172a6a25ecd389452ac",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix readme description for active flag",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2024-09-23T01:49:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a86c64b0f28bc8c8bf64e75229ee6d8161a3d6f",
          "body": null,
          "is_bot": false,
          "headline": "Add generator installation example (#15)",
          "author_name": "Devon",
          "author_login": "devon-manifest",
          "committed_at": "2024-08-15T17:33:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb26ddcfe143e23b8f07f6aa19bccb61eb28a205",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2024-08-15T17:31:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2aaca154ae5652d6c2eee239fba3d3b2faf8ab7f",
          "body": "- Add active flag\r\n- Remove old sbom default filename reference",
          "is_bot": false,
          "headline": "docs(generate): Active flag documentation [MFST-3107] (#14)",
          "author_name": "Devon",
          "author_login": "devon-manifest",
          "committed_at": "2024-07-26T16:17:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf3cb44fed0ce6c16a59208caa3580e71cad64b8",
          "body": null,
          "is_bot": false,
          "headline": "Add active flag; remove old sbom name default filename",
          "author_name": "Devon Mackay",
          "author_login": "devon-manifest",
          "committed_at": "2024-07-26T16:07:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2677ec5364046efd0ea2c9c1877a6ca60280b221",
          "body": "…h (#13)",
          "is_bot": false,
          "headline": "docs: add info about generator installationshould be in execution pat…",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-06-25T13:16:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfd1c7be0fc28d12fcc43a2723eec8c9ceaff020",
          "body": null,
          "is_bot": false,
          "headline": "fix(docs): update yum repo setup",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-06-08T12:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94b2f52361700e416d966b83c997e28052297397",
          "body": null,
          "is_bot": false,
          "headline": "docs: add generator preset and config",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-23T16:37:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c86fb3e6837e51f74687a21816d1e269cabdeb9d",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): add  install command (#12)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2024-05-08T16:54:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "493a1830ff0cd00c582ef41c090a0f1058279705",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): add  install command",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-08T16:51:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebfabaab41aba940deb505606721691ce0894bac",
          "body": null,
          "is_bot": false,
          "headline": "docs: cleanup deprecation notices",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:17:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3e6039fbc9683e7e111f4eac565fd8af28580b1",
          "body": null,
          "is_bot": false,
          "headline": "docs: update manifest to manifest-cli",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:13:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fe3c871566ec7ad16e4be88b6bdfc40450b018f",
          "body": null,
          "is_bot": false,
          "headline": "docs: update manifest to manifest-cli",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:12:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7793290c276650a5d6872218b64b134f0826707e",
          "body": null,
          "is_bot": false,
          "headline": "docs(publish): product and labels support",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d6e06e70aeaad8a9d5e7b137f5e145e750f2bfa",
          "body": null,
          "is_bot": false,
          "headline": "fix(install): use native cd and not pushd/popd",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-02-28T22:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46279e354a0e9a6beeef7659ecc1695af64b0be",
          "body": null,
          "is_bot": false,
          "headline": "chore(install): script updated to support rename",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-02-28T17:04:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa214789427d819baca5743031936ecdee53b73b",
          "body": null,
          "is_bot": false,
          "headline": "chore(docs): add manifest-cli change notice",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-01-18T09:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136cd327aec55f6d965767536e8d8cdd785a1560",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md (#10)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-09-27T17:31:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcf9774cb0007ffeae67df56b259bbc71b42cfcd",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-09-27T17:30:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bed2db235f7421d9aad348553282cfb36b27f62",
          "body": " Use v2 GitHub action to generate and publish SBOMs\r\n\r\nGITHUBERINO NO RATE LIMIT PL0X",
          "is_bot": false,
          "headline": "MFST-44: Eating our dogfood and drinking our champagne! (#9)",
          "author_name": "Alper Demirci",
          "author_login": "alperdemirci",
          "committed_at": "2023-08-17T19:47:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f1f00ead4196cb15d4180d6f50e43c5ab37270",
          "body": "… action to generate and publish SBOMs",
          "is_bot": false,
          "headline": "MFST-44: Eating our dogfood and drinking our champagne! Use v2 GitHub…",
          "author_name": "wey-chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-08-15T21:25:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae3d3e7b939619754d52640eb88d89f903ef03c2",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix formatting issues",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T16:21:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ee51829bdb5a44ef03d48115c7d1dc783fde164",
          "body": null,
          "is_bot": false,
          "headline": "docs: update README.md for CDX versions [MFST-792] (#8)",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-08-01T16:20:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69ec0e548c53157fb3e2cad6b9fc2b18c61503bc",
          "body": null,
          "is_bot": false,
          "headline": "docs: update install script",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T16:06:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67dcc2886cb4fc8b6b35ad6346c4c0635d84a1de",
          "body": null,
          "is_bot": false,
          "headline": "chore: add install scripts",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T15:18:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9eafd0d27c16f9aeea7430b55fb64bc4006e8293",
          "body": null,
          "is_bot": false,
          "headline": "docs: add labels and deprecate --path (#6)",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-07-26T09:21:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d38cb01191cc84d6b7e3f1324f35ffc85ab8a153",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #7 from manifest-cyber/bardenstein-patch-1",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-07-25T16:35:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fcacd09dda03e2875ce14dce8e72e4b6d929a69",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-07-25T16:33:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa7072b6a24b5dea030ff1155d973fa249cffb98",
          "body": "* Update README.md\r\n\r\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>\r\n\r\n---------\r\n\r\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>\r\nCo-authored-by: manifestori <ori@manifestcyber.com>",
          "is_bot": false,
          "headline": "chore: update Docs for attestation (#5)",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-13T06:25:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cccca871cc9d7b563c7c4bb64f2b2745c2c57c2",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #4 from manifest-cyber/update-docs",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-07-05T14:34:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a19441214153f4a5ebfbb6652663f1019f29a8b7",
          "body": "Explicit callout for package manifests and updated example for pointing to two files\n\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-05T14:12:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6433f272254ae3102e6e41a4b19e5ccd6b21a377",
          "body": "Added best practices, annotations, and fixed some nits\n\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-03T21:17:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ea19ebcb96c3c2f8df936b3cfd80d9a457ac70",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-22T17:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1399ac4db528f22836618d2cf5ab457211089612",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-16T17:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8984dc4b8b39103a3106ab8d8e49748c6496f780",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-16T17:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6205b7429f879a75b9f298e2c55e5af3318f8db1",
          "body": "Readme cleanup",
          "is_bot": false,
          "headline": "Merge pull request #2 from manifest-cyber/readme-cleanup",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-03-11T16:44:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7b60e7efa29d70643942ecd7bae8a3a6df950ae",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into readme-cleanup",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17afabf887765e5b429115a84e019c8c6289cfb8",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #1 from manifest-cyber/wey-chiang-patch-1",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:43:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a8a6e906a172fa0406105e9cf3e0f6092ca46a0",
          "body": null,
          "is_bot": false,
          "headline": "Delete img2.png",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc210e5e9e101b4681133673a3105e5a46da395e",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:41:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a87f82165093fac71c9fa937897997824c4b086f",
          "body": "Cleaned up parts of the Installation section",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-03-11T14:25:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "610922c434d26412a84d47642c358c619540f268",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:14:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e89fd96f9e548df013dd4041fbc379320eaa458",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:13:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "195126c54213278bc9eb7b97218006febee5e936",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:06:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1006b038363ff148dd6eb73a2ceb83d024eccdd6",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:01:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "572390f76add1c854d3995ab5d861a391878db5a",
          "body": null,
          "is_bot": false,
          "headline": "Images for README",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:00:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "916b2ec43f8ed70b8dfd306573bcfcdff427d538",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c971e25282fd23c2e06e6f8486db167a8ed518d",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:55:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc47bd0dd4f8bf4be1b0180a59b47cfa758e93d",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f5bbd2ca60f18b9d337edd4d27a6bf7175b9a65",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0e64345ab57a393f6bc55f22734a9d2129d7d35",
          "body": null,
          "is_bot": false,
          "headline": "chore: add license",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-02-21T16:23:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69c528e7200db7d37e754d6e6748beae61a4561c",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-02-10T18:08:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "170c563a22726c1eaf8bff7a3297217b37d2f2a6",
          "body": null,
          "is_bot": false,
          "headline": "Initial commit",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-02-01T11:02:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 26,
      "latest_release_at": "2026-07-21T21:55:38Z",
      "latest_release_tag": "v0.36.3-beta.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 6.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 0,
      "stars": 3,
      "watchers": 3,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": null,
      "source_files_sampled": 0,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 26,
        "open_issues": 2,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 3,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "manifestori",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/116580393?v=4"
        },
        {
          "type": "User",
          "login": "lsell-manifest",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/174354346?v=4"
        },
        {
          "type": "User",
          "login": "adefee",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/4471948?v=4"
        },
        {
          "type": "User",
          "login": "bardenstein",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/862262?v=4"
        },
        {
          "type": "User",
          "login": "wey-chiang",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/71197790?v=4"
        },
        {
          "type": "User",
          "login": "meghmanifest",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/207568321?v=4"
        },
        {
          "type": "User",
          "login": "leidson-campos",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/252052331?v=4"
        },
        {
          "type": "User",
          "login": "dotCipher",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/3977074?v=4"
        },
        {
          "type": "User",
          "login": "marinacabrerarosa",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/218649872?v=4"
        },
        {
          "type": "User",
          "login": "devon-manifest",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/146471916?v=4"
        }
      ],
      "contributors_sampled": 11,
      "top_contributor_share": 0.189
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "install.test.yml",
        "production.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 7,
            "reason": "Found 8/11 approved changesets -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 8,
            "reason": "SAST tool is not run on all commits -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4e1525749499ec355e61eabe23cfc96396a9e67d",
        "ran_at": "2026-07-25T19:55:54Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T00:42:33Z",
      "oldest_open_prs": [
        {
          "number": 30,
          "created_at": "2026-07-15T11:08:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 31,
          "created_at": "2026-07-15T11:08:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T14:49:08Z",
      "ci_last_conclusion": "STARTUP_FAILURE",
      "oldest_open_issues": [
        {
          "number": 11,
          "created_at": "2024-03-29T17:25:12Z",
          "last_comment_at": "2024-04-30T16:53:10Z",
          "last_comment_author": "manifestori"
        },
        {
          "number": 26,
          "created_at": "2026-06-17T23:46:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/manifest-cyber/cli",
    "host": "github.com",
    "name": "cli",
    "owner": "manifest-cyber"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 52,
        "vitality": 75,
        "community": 27,
        "governance": 62,
        "engineering": 54
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "commits_last_year": 26,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "26 commits in the last year",
                "points": 12.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.36.3-beta.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 6.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 27,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 7,
            "inputs": {
              "forks": 0,
              "stars": 3,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "3 stars",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 62,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 11,
              "top_contributor_share": 0.189
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 19% of commits",
                "points": 18.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 19
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "11 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "merged_prs": 26,
              "open_issues": 2,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "26/28 decided PRs merged",
                "points": 35.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 26,
                      "decided": 28
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 8/11 approved changesets -- score normalized to 7",
                "points": 10.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "followers": 21,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "manifest-cyber",
              "public_repos": 38,
              "account_age_days": 1510
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "21 followers of manifest-cyber",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 21,
                      "login": "manifest-cyber"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "38 public repos, account ~4 yr old",
                "points": 19.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 38
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 54,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 8/11 approved changesets -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "critical",
        "name": "AI Readiness",
        "value": 20,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.656,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "59 of 90 human commits state their intent (structured subject or explanatory body)",
                "points": 35,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 59,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 9,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.044,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 90 commits agent-authored or agent-credited",
                "points": 8.9,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "critical",
            "name": "Code legibility for models",
            "note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "manageable_file_sizes"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "primary_language": "Shell",
              "largest_source_bytes": null,
              "source_files_sampled": 0,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Shell without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Shell"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "no source files detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_source_files",
                    "params": {}
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T19:56:12.861623Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/manifest-cyber/cli.svg",
  "full_name": "manifest-cyber/cli",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistiken.