Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 2.5.0 · 2026-07-28 15:33 UTC

microsoft / security-devops-action

Microsoft Security DevOps for GitHub Actions.

JavaScript · TypeScriptMIT★ 160 Sterne⑂ 61 Forksseit Aug. 2019Auf GitHub ansehen ↗

microsoft/security-devops-action erreicht einen Gesundheitsindex von 73 von 100 und liegt damit im Bereich Gut. Am stärksten schneidet es bei Engineering Quality (75/100) ab, am schwächsten bei Community & Adoption (55/100). Zuletzt vor 1 Tag aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

73
gesamt / 100
Gut

Software-Gesundheitsindex

Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.

73
Außergewöhnlich93-100Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent80-92Durchgehend stark; geringfügige Lücken
Gut65-79Gesund; Lücken sind begrenzt und beherrschbar
Mittel50-64Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach35-49Wesentliche Schwächen in mehreren Bereichen
Gefährdet20-34Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-19Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Der gewichtete Gesamtwert 64 wird auf der veröffentlichten Indexskala auf 73 kalibriert (Register-Kalibrierung 2026-08-02).

Eigentümerschaft

MicrosoftOrganisation
126.051 Follower8.225 öffentliche Reposseit Dez. 2013

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
npmmicrosoft-security-devops-action1.12.22621vor 87 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

62Mittel · 21 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
8.3/36Commit-Rhythmus — 12/52 Wochen mit Commits
17/18Commit-Volumen — 77 Commits im letzten Jahr
3/10OpenSSF Scorecard: Maintained — 3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3
Verwendete Eingangsdaten
commits_last_year77
human_commit_share0,88
days_since_last_push1
active_weeks_last_year12
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 13 Releases veröffentlicht
7.2/36Release-Aktualität — letztes Release vor 627 Tagen
19.8/27Release-Rhythmus — ein Release etwa alle 107,2 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count13
latest_release_tagv1.12.0
releases_from_tagsnein
days_since_latest_release627
mean_days_between_releases107,2
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

55Mittel · 17 % des Gesamtindex
Wie die Bewertung erfolgt
35.7/60Stars — 160 Stars
14.8/25Forks — 61 Forks
5/15Watcher — 9 Watcher
Verwendete Eingangsdaten
forks61
stars160
watchers9
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
readme_badges
has_contributingnein
has_issue_templatenein
has_code_of_conductja
readme_badge_services
has_pull_request_templatenein
Wie die Bewertung erfolgt
32.3/80Downloads pro Monat — 262 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesmicrosoft-security-devops-action
dependents
ecosystemsnpm
total_downloads
monthly_downloads262
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

67Gut · 23 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
9.7/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 57 % der Commits
13.5/13.5Breite der Beitragenden — 19 Beitragende
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Verwendete Eingangsdaten
bus_factor1
contributors_sampled19
top_contributor_share0,567
Wie die Bewertung erfolgt
34.6/42Issue-Lösungsquote — 82 % der Issues geschlossen
20.3/30PR-Annahme — 105/155 entschiedene PRs gemergt
0/13Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Verwendete Eingangsdaten
merged_prs105
open_issues18
closed_issues85
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0,825
closed_unmerged_prs50
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
25/25Reichweite des Inhabers — 126.051 Follower von microsoft
25/25Kontohistorie — 8.225 öffentliche Repos, Kontoalter ca. 12 Jahre
Verwendete Eingangsdaten
followers126.051
owner_typeOrganization
is_verified
owner_loginmicrosoft
public_repos8.225
account_age_days4.612

Paketpflege

84Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 87 Tagen
4/20Versionshistorie — 1 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesmicrosoft-security-devops-action
ecosystemsnpm
any_deprecatednein
min_days_since_publish87

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

75Gut · 19 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 9 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

85Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
10/10Topics — 3 Topics
10/10Wiki
Verwendete Eingangsdaten
topicssecurity, devops, microsoft
has_wikija
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

61Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
2.2/7.5Maintained — 3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3
0/5Packaging — keine Daten
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
4/5SAST — SAST tool is not run on all commits -- score normalized to 8
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 16 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5,1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

Abhängigkeits-Advisories

100Außergewöhnlich
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories16
affected_packages6
assessed_packages318
unassessed_packages0
affected_by_severityhigh 5, moderate 1
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories, Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. 318 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.

58Mittel · 4 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 68 von 88 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,773
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — test/tsconfig.json, tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 17 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 11 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
7/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfileja
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configstest/tsconfig.json, tsconfig.json
agent_commit_share0,17
toolchain_manifests
dependency_bot_commit_share0,11
Wie die Bewertung erfolgt
27/45Typprüfbarer Code — JavaScript mit Typprüfungs-Konfiguration (test/tsconfig.json, tsconfig.json)
55/55Handhabbare Dateigrößen — 0/20 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageJavaScript
largest_source_bytes12.125
source_files_sampled20
oversized_source_files0
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — samples
Verwendete Eingangsdaten
example_dirssamples
has_mcp_signalnein
api_schema_files

Eckdaten

160GitHub-Sterne
19Mitwirkende
77Commits, letzte 12 Monate
1Tage seit letztem Push
13Releases
1Bus-Faktor
18offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 61 ⇿
0Sterne
61Forks
12Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

01020304050606032022-022024-042026-07
Major 0Minor 7Patch 5

Jeder Punkt umfasst 5 Tage.

OpenSSF Scorecard 5.1 / 10
5.1Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 15:33 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
3Maintained3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3
k. A.Packagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
8SASTSAST tool is not run on all commits -- score normalized to 8
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities16 existing vulnerabilities detected
Direkte Abhängigkeiten 3
RegistryPaketVersionsvorgabeManifest
npm@actions/core2.0.3package.json
npm@actions/exec2.0.0package.json
npm@microsoft/security-devops-actions-toolkit1.11.0package.json
Alle Abhängigkeiten 318

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 5 direkte und 313 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
npm@actions/core1.10.0direkt
npm@actions/core2.0.3direkt
npm@actions/exec1.1.1direkt
npm@actions/exec2.0.0direkt
npm@microsoft/security-devops-actions-toolkit1.11.0direkt
npm@actions/http-client2.2.3indirekt
npm@actions/http-client3.0.2indirekt
npm@actions/io1.1.3indirekt
npm@actions/io2.0.0indirekt
npm@gulpjs/messages1.1.0indirekt
npm@gulpjs/to-absolute-glob4.0.0indirekt
npm@isaacs/cliui8.0.2indirekt
npm@nodelib/fs.scandir2.1.5indirekt
npm@nodelib/fs.stat2.0.5indirekt
npm@nodelib/fs.walk1.2.8indirekt
npm@pkgjs/parseargs0.11.0indirekt
npm@sindresorhus/merge-streams2.3.0indirekt
npm@sinonjs/commons3.0.1indirekt
npm@sinonjs/fake-timers15.4.0indirekt
npm@sinonjs/samsam10.0.2indirekt
npm@types/mocha10.0.10indirekt
npm@types/node25.6.0indirekt
npm@types/q1.5.8indirekt
npm@types/sinon21.0.1indirekt
npm@types/sinonjs__fake-timers15.0.1indirekt
npmadm-zip0.5.10indirekt
npmansi-colors1.1.0indirekt
npmansi-colors4.1.3indirekt
npmansi-regex5.0.1indirekt
npmansi-regex6.2.2indirekt
npmansi-styles4.3.0indirekt
npmansi-styles6.2.3indirekt
npmansi-wrap0.1.0indirekt
npmanymatch3.1.3indirekt
npmappend-buffer1.0.2indirekt
npmargparse2.0.1indirekt
npmarr-diff4.0.0indirekt
npmarr-union3.1.0indirekt
npmarray-each1.0.1indirekt
npmarray-slice1.1.0indirekt
npmassign-symbols1.0.0indirekt
npmasync-done2.0.0indirekt
npmasync-settle2.0.0indirekt
npmb4a1.8.0indirekt
npmbach2.0.1indirekt
npmbalanced-match4.0.4indirekt
npmbare-events2.8.2indirekt
npmbase64-js1.5.1indirekt
npmbinary-extensions2.3.0indirekt
npmbl5.1.0indirekt
npmbrace-expansion5.0.5indirekt
npmbraces3.0.3indirekt
npmbrowser-stdout1.3.1indirekt
npmbuffer6.0.3indirekt
npmbuffer-equal1.0.1indirekt
npmcall-bind1.0.2indirekt
npmcamelcase6.3.0indirekt
npmchalk4.1.2indirekt
npmchokidar3.6.0indirekt
npmchokidar4.0.3indirekt
npmcliui7.0.4indirekt
npmcliui8.0.1indirekt
npmclone2.1.2indirekt
npmclone-buffer1.0.0indirekt
npmclone-stats1.0.0indirekt
npmcloneable-readable1.1.3indirekt
npmcolor-convert2.0.1indirekt
npmcolor-name1.1.4indirekt
npmconvert-source-map1.9.0indirekt
npmconvert-source-map2.0.0indirekt
npmcopy-props4.0.0indirekt
npmcore-util-is1.0.3indirekt
npmcross-spawn7.0.6indirekt
npmdebug4.4.3indirekt
npmdecamelize4.0.0indirekt
npmdecompress-response8.1.0indirekt
npmdefine-data-property1.1.0indirekt
npmdefine-properties1.2.1indirekt
npmdel8.0.1indirekt
npmdetect-file1.0.0indirekt
npmdiff7.0.0indirekt
npmdiff9.0.0indirekt
npmduplexify3.7.1indirekt
npmeach-props3.0.0indirekt
npmeastasianwidth0.2.0indirekt
npmemoji-regex8.0.0indirekt
npmemoji-regex9.2.2indirekt
npmend-of-stream1.4.4indirekt
npmescalade3.2.0indirekt
npmescape-string-regexp4.0.0indirekt
npmevents-universal1.0.1indirekt
npmexpand-tilde2.0.2indirekt
npmextend3.0.2indirekt
npmextend-shallow3.0.2indirekt
npmfast-fifo1.3.2indirekt
npmfast-glob3.3.3indirekt
npmfast-levenshtein3.0.0indirekt
npmfastest-levenshtein1.0.16indirekt
npmfastq1.20.1indirekt
npmfill-range7.1.1indirekt
npmfind-up5.0.0indirekt
npmfindup-sync5.0.0indirekt
npmfined2.0.0indirekt
npmflagged-respawn2.0.0indirekt
npmflat5.0.2indirekt
npmflush-write-stream1.1.1indirekt
npmfor-in1.0.2indirekt
npmfor-own1.0.0indirekt
npmforeground-child3.3.1indirekt
npmfs-mkdirp-stream1.0.0indirekt
npmfs-mkdirp-stream2.0.1indirekt
npmfs.realpath1.0.0indirekt
npmfsevents2.3.3indirekt
npmfunction-bind1.1.2indirekt
npmget-caller-file2.0.5indirekt
npmget-intrinsic1.2.1indirekt
npmglob10.5.0indirekt
npmglob7.2.3indirekt
npmglob-parent3.1.0indirekt
npmglob-parent5.1.2indirekt
npmglob-parent6.0.2indirekt
npmglob-stream6.1.0indirekt
npmglob-stream8.0.3indirekt
npmglob-watcher6.0.0indirekt
npmglobal-modules1.0.0indirekt
npmglobal-prefix1.0.2indirekt
npmglobby14.1.0indirekt
npmglogg2.2.0indirekt
npmgopd1.0.1indirekt
npmgraceful-fs4.2.11indirekt
npmgulp5.0.1indirekt
npmgulp-cli3.1.0indirekt
npmgulp-typescript6.0.0-alpha.1indirekt
npmgulplog2.2.0indirekt
npmhas1.0.3indirekt
npmhas-flag4.0.0indirekt
npmhas-property-descriptors1.0.0indirekt
npmhas-proto1.0.1indirekt
npmhas-symbols1.0.3indirekt
npmhasown2.0.2indirekt
npmhe1.2.0indirekt
npmhomedir-polyfill1.0.3indirekt
npmiconv-lite0.6.3indirekt
npmieee7541.2.1indirekt
npmignore7.0.5indirekt
npminflight1.0.6indirekt
npminherits2.0.4indirekt
npmini1.3.8indirekt
npminterpret3.1.1indirekt
npmis-absolute1.0.0indirekt
npmis-binary-path2.1.0indirekt
npmis-buffer1.1.6indirekt
npmis-core-module2.16.1indirekt
npmis-extendable1.0.1indirekt
npmis-extglob2.1.1indirekt
npmis-fullwidth-code-point3.0.0indirekt
npmis-glob3.1.0indirekt
npmis-glob4.0.3indirekt
npmis-negated-glob1.0.0indirekt
npmis-number7.0.0indirekt
npmis-path-cwd3.0.0indirekt
npmis-path-inside3.0.3indirekt
npmis-path-inside4.0.0indirekt
npmis-plain-obj2.1.0indirekt
npmis-plain-object2.0.4indirekt
npmis-plain-object5.0.0indirekt
npmis-relative1.0.0indirekt
npmis-unc-path1.0.0indirekt
npmis-unicode-supported0.1.0indirekt
npmis-utf80.2.1indirekt
npmis-valid-glob1.0.0indirekt
npmis-windows1.0.2indirekt
npmisarray1.0.0indirekt
npmisexe2.0.0indirekt
npmisobject3.0.1indirekt
npmjackspeak3.4.3indirekt
npmjs-yaml4.1.1indirekt
npmjson-stable-stringify-without-jsonify1.0.1indirekt
npmlast-run2.0.0indirekt
npmlazystream1.0.1indirekt
npmlead1.0.0indirekt
npmlead4.0.0indirekt
npmliftoff5.0.1indirekt
npmlocate-path6.0.0indirekt
npmlog-symbols4.1.0indirekt
npmlru-cache10.4.3indirekt
npmmap-cache0.2.2indirekt
npmmerge21.4.1indirekt
npmmicromatch4.0.8indirekt
npmmimic-response4.0.0indirekt
npmminimatch10.2.5indirekt
npmminipass7.1.3indirekt
npmmocha11.7.5indirekt
npmms2.1.3indirekt
npmmute-stdout2.0.0indirekt
npmnormalize-path2.1.1indirekt
npmnormalize-path3.0.0indirekt
npmnow-and-later2.0.1indirekt
npmnow-and-later3.0.0indirekt
npmobject-keys1.1.1indirekt
npmobject.assign4.1.4indirekt
npmobject.defaults1.1.0indirekt
npmobject.pick1.3.0indirekt
npmonce1.4.0indirekt
npmordered-read-streams1.0.1indirekt
npmp-limit3.1.0indirekt
npmp-locate5.0.0indirekt
npmp-map7.0.4indirekt
npmpackage-json-from-dist1.0.1indirekt
npmparse-filepath1.0.2indirekt
npmparse-passwd1.0.0indirekt
npmpath-dirname1.0.2indirekt
npmpath-exists4.0.0indirekt
npmpath-is-absolute1.0.1indirekt
npmpath-key3.1.1indirekt
npmpath-parse1.0.7indirekt
npmpath-root0.1.1indirekt
npmpath-root-regex0.1.2indirekt
npmpath-scurry1.11.1indirekt
npmpath-type6.0.0indirekt
npmpicocolors1.1.1indirekt
npmpicomatch4.0.4indirekt
npmplugin-error1.0.1indirekt
npmpresentable-error0.0.1indirekt
npmprocess-nextick-args2.0.1indirekt
npmpump2.0.1indirekt
npmpumpify1.5.1indirekt
npmqueue-microtask1.2.3indirekt
npmreadable-stream2.3.8indirekt
npmreadable-stream3.6.2indirekt
npmreaddirp3.6.0indirekt
npmreaddirp4.1.2indirekt
npmrechoir0.8.0indirekt
npmremove-bom-buffer3.0.0indirekt
npmremove-bom-stream1.2.0indirekt
npmremove-trailing-separator1.1.0indirekt
npmreplace-ext1.0.1indirekt
npmreplace-ext2.0.0indirekt
npmreplace-homedir2.0.0indirekt
npmrequire-directory2.1.1indirekt
npmresolve1.22.11indirekt
npmresolve-dir1.0.1indirekt
npmresolve-options1.1.0indirekt
npmresolve-options2.0.0indirekt
npmreusify1.1.0indirekt
npmrun-parallel1.2.0indirekt
npmsafe-buffer5.1.2indirekt
npmsafer-buffer2.1.2indirekt
npmsemver6.3.1indirekt
npmsemver-greatest-satisfied-range2.0.0indirekt
npmserialize-javascript7.0.5indirekt
npmshebang-command2.0.0indirekt
npmshebang-regex3.0.0indirekt
npmsignal-exit4.1.0indirekt
npmsinon22.0.0indirekt
npmslash5.1.0indirekt
npmsource-map0.7.4indirekt
npmsparkles2.1.0indirekt
npmstream-composer1.0.2indirekt
npmstream-exhaust1.0.2indirekt
npmstream-shift1.0.1indirekt
npmstreamx2.23.0indirekt
npmstring-width4.2.3indirekt
npmstring-width5.1.2indirekt
npmstring_decoder1.1.1indirekt
npmstrip-ansi6.0.1indirekt
npmstrip-ansi7.1.2indirekt
npmstrip-json-comments3.1.1indirekt
npmsupports-color7.2.0indirekt
npmsupports-color8.1.1indirekt
npmsupports-preserve-symlinks-flag1.0.0indirekt
npmsver1.8.4indirekt
npmteex1.0.1indirekt
npmtext-decoder1.2.7indirekt
npmthrough22.0.5indirekt
npmthrough23.0.2indirekt
npmthrough2-filter3.0.0indirekt
npmto-absolute-glob2.0.2indirekt
npmto-regex-range5.0.1indirekt
npmto-through2.0.0indirekt
npmto-through3.0.0indirekt
npmtunnel0.0.6indirekt
npmtype-detect4.0.8indirekt
npmtype-detect4.1.0indirekt
npmtypescript5.9.3indirekt
npmunc-path-regex0.1.2indirekt
npmundertaker2.0.0indirekt
npmundertaker-registry2.0.0indirekt
npmundici8.0.2indirekt
npmundici-types7.19.2indirekt
npmunicorn-magic0.3.0indirekt
npmunique-stream2.3.1indirekt
npmutil-deprecate1.0.2indirekt
npmuuid8.3.2indirekt
npmv8flags4.0.1indirekt
npmvalue-or-function3.0.0indirekt
npmvalue-or-function4.0.0indirekt
npmvinyl2.2.1indirekt
npmvinyl3.0.1indirekt
npmvinyl-contents2.0.0indirekt
npmvinyl-fs3.0.3indirekt
npmvinyl-fs4.0.2indirekt
npmvinyl-sourcemap1.1.0indirekt
npmvinyl-sourcemap2.0.0indirekt
npmwhich1.3.1indirekt
npmwhich2.0.2indirekt
npmworkerpool9.3.4indirekt
npmwrap-ansi7.0.0indirekt
npmwrap-ansi8.1.0indirekt
npmwrappy1.0.2indirekt
npmxtend4.0.2indirekt
npmy18n5.0.8indirekt
npmyargs16.2.0indirekt
npmyargs17.7.2indirekt
npmyargs-parser20.2.9indirekt
npmyargs-parser21.1.1indirekt
npmyargs-unparser2.0.0indirekt
npmyocto-queue0.1.0indirekt
Abhängigkeits-Advisories 6

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 318 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 6 tragen bekannte Advisories, davon 0 direkte.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
adm-zip0.5.10indirekthoch10.6.0
brace-expansion5.0.5indirekthoch35.0.8
js-yaml4.1.1indirekthoch24.3.0
undici8.0.2indirekthoch88.5.0
uuid8.3.2indirekthoch113.0.1
diff7.0.0indirektmittel18.0.3

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "security",
        "devops",
        "microsoft"
      ],
      "is_fork": false,
      "size_kb": 1515,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 31465,
        "TypeScript": 24705
      },
      "pushed_at": "2026-07-27T05:16:51Z",
      "created_at": "2019-08-26T22:50:23Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T06:52:58Z",
      "description": "Microsoft Security DevOps for GitHub Actions.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://opensource.microsoft.com",
      "name": "Microsoft",
      "type": "Organization",
      "login": "microsoft",
      "company": null,
      "location": "Redmond, WA",
      "followers": 126051,
      "avatar_url": "https://avatars.githubusercontent.com/u/6154722?v=4",
      "created_at": "2013-12-10T19:06:48Z",
      "is_verified": null,
      "public_repos": 8225,
      "account_age_days": 4612
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2024-11-07T23:27:15Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2024-07-25T15:54:23Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2023-11-15T16:17:58Z"
        },
        {
          "tag": "v1.9.1",
          "kind": "patch",
          "published_at": "2023-10-31T19:12:55Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2023-06-23T13:48:46Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2023-06-15T16:50:10Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2022-10-27T22:29:12Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2022-04-25T17:23:34Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2022-04-04T20:12:31Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2022-03-18T18:25:03Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2022-03-11T13:59:40Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2022-02-16T06:58:23Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2022-02-09T19:47:17Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "c0f73835fa1f80fc12cc96ea7f9185735705f433",
          "body": "Bumps [sinon](https://github.com/sinonjs/sinon) from 21.1.2 to 22.0.0.\n- [Release notes](https://github.com/sinonjs/sinon/releases)\n- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md)\n- [Commits](https://github.com/sinonjs/sinon/compare/v21.1.2...v22.0.0)\n\n---\nupdated-depende\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump sinon from 21.1.2 to 22.0.0 (#254)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T06:14:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af06b0e965ef85878468e354abe0c09f630912ff",
          "body": "chore: remove v2 (Defender CLI) action",
          "is_bot": false,
          "headline": "Merge pull request #253 from microsoft/omerbareket/remove_old_cli",
          "author_name": "Omer Bareket",
          "author_login": "omerb97",
          "committed_at": "2026-04-30T13:47:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03406cc5e6a517d21676a3b9c3dd86b43b1b3c4d",
          "body": "Deletes the entire v2 footprint, leaving only the v1 MSDO action:\n- src/v2/, lib/v2/, v2/action.yml\n- test/defender-*.tests.ts and test/job-summary.tests.ts\n- .github/workflows/self-hosted-validation-v2.yml\n\nv1 has no imports from v2, so the build and v1 tests still pass.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: remove v2 (Defender CLI) action",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-04-30T13:38:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b5c70846c8e5525e08bd18e6cd9ac98296db1376",
          "body": "fix(ci): enable noop on agentic workflows to stop IcM page spam",
          "is_bot": false,
          "headline": "Merge pull request #252 from microsoft/fix/agentic-workflows-noop",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2026-04-24T14:07:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c2112b65197d69394401b7d2f6af061aac3b1fc",
          "body": "…ading",
          "is_bot": false,
          "headline": "docs(ci): document v9.0.0 SHA restoration and rename noop examples he…",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-04-24T07:46:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58e0e1947023457c7a0d0480eb9cba5dc033b484",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): make msdo-issue-assistant prompt consistently call noop",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-04-24T07:39:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc950c9c170206bd5d627bbd479c21ccbdf14d0",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): enable noop on agentic workflows to stop IcM page spam",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-04-24T07:05:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9bfeb7679d7d1d3a266753e669a3da973d42990",
          "body": null,
          "is_bot": false,
          "headline": "docs: add implementation plan for agentic-workflows noop fix",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-04-24T06:40:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6b5cfa4210bde8360957c02a5027c0454494ce1",
          "body": null,
          "is_bot": false,
          "headline": "docs: add spec for agentic-workflows noop fix",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-04-24T06:34:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40edfffeec58d1b2a65a77f19627c8a11da19741",
          "body": "Bumps [sinon](https://github.com/sinonjs/sinon) from 21.0.3 to 21.1.2.\n- [Release notes](https://github.com/sinonjs/sinon/releases)\n- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md)\n- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.3...v21.1.2)\n\n---\nupdated-depende\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump sinon from 21.0.3 to 21.1.2 (#246)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-24T06:25:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0708f8c82ef8362c2486445aefc194fc72eb1519",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.5.2 to 25.6.0.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump @types/node from 25.5.2 to 25.6.0 (#245)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-24T06:24:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09cedf84635e4d180eb72f6d6f54a1d4050e8aac",
          "body": "Bumps [actions/github-script](https://github.com/actions/github-script) from 8.0.0 to 9.0.0.\n- [Release notes](https://github.com/actions/github-script/releases)\n- [Commits](https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f710\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(ci): bump actions/github-script from 8.0.0 to 9.0.0 (#244)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-24T06:24:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91a1da1d458f87adb54ade57e5f19ed44d71d56f",
          "body": "Co-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(security): resolve ReDoS in image name validation regex (#243)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-04-13T06:40:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "887bc61ff32cbdaec5a745e3fea22777a0fd0c3d",
          "body": "…alerts (#234)",
          "is_bot": false,
          "headline": "fix(deps): add npm overrides to resolve all open Dependabot security …",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-04-13T06:31:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5db8d826835d5d6180d843752583de9e786ca170",
          "body": "* feat(bot): add tool configuration knowledge to triage bot prompt\n\n* fix(ci): grant issues write permission to triage bot workflow\n\n* fix(bot): recompile lock file, revert issues:write from .md (handled by safe-outputs)\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "feat(bot): add tool configuration knowledge to triage bot (#237)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-04-13T06:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a881db44086603112c2e06eda42210f1cfd8a5f9",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.5.0 to 25.5.2.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump @types/node from 25.5.0 to 25.5.2 (#239)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-11T18:37:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c82da070456a08bb35a59e398ee88ef09c67701",
          "body": "Bumps [@types/sinon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sinon) from 21.0.0 to 21.0.1.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sinon)\n\n---\nupdated-d\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump @types/sinon from 21.0.0 to 21.0.1 (#238)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-11T18:36:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49b663b1975ce426768f004527723ac93d17edeb",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 6.0.2.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v4.2.2...v6.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-vers\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(ci): bump actions/checkout from 4.2.2 to 6.0.2 (#231)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T05:56:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06bfc6a2cbe6a181209ae69a6af0f0214ea404db",
          "body": "Signed-off-by: James Brotsos <j.brotsos@gmail.com>",
          "is_bot": false,
          "headline": "Delete sda.sarif (#233)",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2026-04-01T05:55:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e20e8b61ec139999452c8516a9e2497bf4683805",
          "body": "…branch protection (#228)\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): push versions to bot/toolchain-versions branch, bypass main …",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-23T16:41:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30ead4e92a4b622a71dda75ecf7eb5cd40be8e1d",
          "body": "…r-tool regex fallback (#226)\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): sort -V for guardian binary, semver sort for config dirs, pe…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-23T12:57:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9bc891fd0b821ca88f8cee8c87722a0022c1d0b",
          "body": "…package names (#225)\n\n* fix(ci): rewrite probe — guardian init only, weekly CLI cache, parse .gdntool XML, run daily before breach monitor\n\n* fix(ci): probe triggers breach monitor after commit — remove schedule race condition\n\n* fix(ci): sort -V for guardian binary, semver sort for config dirs, per-tool regex fallback\n\n---------\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): fix probe — correct _msdo/packages/nuget/ path and Guardian …",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-23T11:11:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dabaaf63e3969fb0856b401fe5d95d25fbb65379",
          "body": "…ispatch breach monitor (#224)\n\n* fix(ci): improve breach monitor accuracy — add ecosystems, fix advisory queries, versioned checks\n\n* feat(ci): add toolchain version probe workflow; breach monitor reads pinned versions\n\n* fix(ci): address PR review — fix NVD allowlist, empty-tools guard, version severity logic, CVE triage detail\n\n---------\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): rewrite probe — scrape .gdn/i/ dirs, fix broken cache SHA, d…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-23T10:22:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ec54a555f25b859a93d70ba5ffb9e5e2a45e898",
          "body": "…, run daily (#223)\n\n* fix(ci): rewrite probe — guardian init only, weekly CLI cache, parse .gdntool XML, run daily before breach monitor\n\n* fix(ci): probe triggers breach monitor after commit — remove schedule race condition\n\n* fix(ci): sort -V for guardian binary, semver sort for config dirs, per-tool regex fallback\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): probe — guardian init only, weekly cache, parse .gdntool XML…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-23T07:43:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de1b1a4c4d85cca75e4373c44c2d2c1a9833d2bd",
          "body": "Adding Defender CLI",
          "is_bot": false,
          "headline": "Merge pull request #213 from omerb97/main",
          "author_name": "Omer Bareket",
          "author_login": "omerb97",
          "committed_at": "2026-03-23T07:18:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a849a59d8e9fb757a28c608095475149dc4003f",
          "body": "…TO_TOOL names (#222)\n\n* fix(ci): skip commit instead of failing job when probe finds no tool versions\n\n* fix(ci): correct MSDO packages path, PKG_TO_TOOL names, and use step output for skip signal\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): fix toolchain version probe — correct packages path and PKG_…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-22T15:26:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8deec49c3692d87f6c9540610949ff8a30b02ec",
          "body": null,
          "is_bot": false,
          "headline": "cr",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-22T15:06:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79d91606aee22cc2be0c1308963ebc31afbe8e43",
          "body": "…racy (#220)\n\n* fix(ci): improve breach monitor accuracy — add ecosystems, fix advisory queries, versioned checks\n\n* feat(ci): add toolchain version probe workflow; breach monitor reads pinned versions\n\n* fix(ci): address PR review — fix NVD allowlist, empty-tools guard, version severity logic, CVE triage detail\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "feat(ci): add toolchain version probe and improve breach monitor accu…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-22T14:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "568a7d61e4e0af4e99789c4a0877eb50ff8e3968",
          "body": null,
          "is_bot": false,
          "headline": "cr",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-22T13:54:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e81db42fec5430ce3c496f51c6ca6519870248f",
          "body": "Bumps [sinon](https://github.com/sinonjs/sinon) from 21.0.2 to 21.0.3.\n- [Release notes](https://github.com/sinonjs/sinon/releases)\n- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md)\n- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.2...v21.0.3)\n\n---\nupdated-depende\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump sinon from 21.0.2 to 21.0.3 (#216)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-22T08:09:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a1ac13954ef06ac1a846d81b18c011f91ca925d",
          "body": "feat(ci): add nightly MSDO toolchain breach monitor",
          "is_bot": false,
          "headline": "Merge pull request #219 from microsoft/feat/msdo-breach-monitor",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2026-03-21T20:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe6892dabe7fb324e043f17e901af0ebbd3b69bd",
          "body": "fix(ci): migrate existing agentic workflows to gh-aw v0.61.0 schema",
          "is_bot": false,
          "headline": "Merge pull request #218 from microsoft/fix/aw-schema-v062",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2026-03-21T20:39:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2b953bdb07f608f17e97b819af37d6bb57c69c0",
          "body": null,
          "is_bot": false,
          "headline": "feat(ci): add nightly MSDO toolchain breach monitor",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-03-21T10:10:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b10d3e92d3fd243cf78b3618b22ac268e2ceed1",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): migrate agentic workflows to gh-aw v0.61.0 schema",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-03-21T09:52:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f777804a592133ec5faf32133ce5f6b3ca1ad45",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/omerb97/security-devops-action",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-19T08:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a425438f5d910f79d1a7a8446b32086eb375420",
          "body": null,
          "is_bot": false,
          "headline": "remove obselete arch",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-19T08:45:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21a4605932e74a8538880b01202a9750c79e5894",
          "body": "Signed-off-by: Omer Bareket <34472645+omerb97@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Merge branch 'main' into main",
          "author_name": "Omer Bareket",
          "author_login": "omerb97",
          "committed_at": "2026-03-19T08:29:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72731515af708882266d50c0bb2e9c0873b2b51e",
          "body": null,
          "is_bot": false,
          "headline": "merge resolution",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-19T08:17:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dfd65b48f1454a74ec7d13a4a63ef50f7dab4eb",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: change default policy from github to mdc",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-18T09:35:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "57c1be2394f73c2ba747398e7c5cb4476204fb68",
          "body": "- Policy variations: github, microsoft, none, azuredevops, mdc\n- Break on critical: image (vuln), model (vuln), fs\n- Debug logging: image with debug=true\n- PR summary toggle: image with pr-summary=false\n- Custom args: image with --defender-list-findings\n- Different images: nginx, pycontribs/ubuntu (vulnerable)\n- Defaults only: no inputs (verify all defaults)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: add comprehensive v2 test variations",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-18T08:20:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d4071e7e0000593a1393cd98de30d7516d4e104",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: gitignore copilot-instructions.md",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-17T15:33:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cfe50ee21858299c6a46449ece6553aee6a532bf",
          "body": "- Revert action.yml to v1 MSDO inputs (paths updated to lib/v1/)\n- Create v2/action.yml for Defender CLI v2\n- Split self-hosted-validation into v1 and v2 workflows\n- v1 workflow uses ./ (root action.yml)\n- v2 workflow uses ./v2/ (v2 action.yml)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "refactor: split validation into v1/v2 workflows, restore v1 action.yml",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-17T13:15:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8b42d803feb4541f94ba67f9a44802944d50ceec",
          "body": "…attern) (#212)\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): disable lockdown mode for CI Doctor (match triage workflow p…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-16T21:27:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b8fe971392ae6053b94975f794d0f131c725673",
          "body": "Co-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): relax CI Doctor role from maintainer to write (#209)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-16T18:07:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38abab4fa3cc617e1e41e96ec2ba42732697a18e",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: add filesystem scan job with azuredevops policy",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T15:48:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4341a54ddad4d0f26dd699dd5806c534abe46ecb",
          "body": "* fix(deps): bump all dependencies and workflow actions\n\n* fix(deps): downgrade @actions/core and @actions/exec to v2 (v3 is ESM-only)\n\n---------\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(deps): bump all dependencies and workflow actions (#207)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-16T15:47:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5b67238c92c36101a1ff13fa8c402b90437b97d",
          "body": "… (#206)\n\n* feat(ci): upgrade GitHub Action runtime from Node.js 20 to Node.js 24\n\n* fix(ci): use Node.js 24 in official-build.yml to match action runtime\n\n* fix(tests): rewrite tests to match ContainerMapping class refactor\n\n* feat(ci): add CI workflow to run build and tests on push/PR\n\n* feat(ci):\n[…]\nests): use sinon v4 compatible stub.restore() instead of sinon.restore()\n\n* feat(ci): compile CI Doctor agentic workflow lock file\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "feat(ci): upgrade GitHub Action runtime from Node.js 20 to Node.js 24…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-03-16T15:21:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b57d3adc309c96234b28b6e8c4e3979feef98d0b",
          "body": "…eme)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: remove upload-sarif from model scan jobs (incompatible URI sch…",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T13:30:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "148f542ff38f84063932cca0aee8611735acd161",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: add vulnerable model scan job for bert-tiny-torch-vuln",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T13:10:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d38c90d2dec1f636c815b16b70979024f58e36b7",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: call setupEnvironment in model scan to install Defender CLI",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T12:56:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "96bd7379e2d47d8e3fee61ff10e7ea0ca60a2024",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: add model scan job for Qwen3.5-35B-A3B validation",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T12:34:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "112711643b1143fb3dfbf4d54765a546f1cb82c6",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: set sarifFile output for downstream SARIF upload",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T11:48:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b3cc53f5c306ec45c860d06be2c79a26a754e9b2",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: change validation policy to mdc",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T11:41:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f941645485d7fc2b88fd908c04ad7946c62b4cf6",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: remove debug flag from validation workflow",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T09:30:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0ebbec9b1589e127ac83f30110ce0c03965e1a2e",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: update validation workflow policy to azuredevops",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T09:01:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "13f73717318af93f50d5ec09176ecd0817426e5b",
          "body": "- Add v2 Defender CLI implementation (filesystem, image, model scans)\n- Restructure src/ and lib/ into v1/ and v2/ folders\n- Port defender-client and defender-installer from AzDevOps task-lib\n- Add job summary with SARIF parsing for GitHub Actions\n- Add self-hosted validation workflow for image scan testing\n- Add 70 new tests for v2 components\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: implement Defender CLI v2 with v1/v2 folder structure",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-16T08:45:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9ce8a9a4f3d0506be0af341be3830c07a2b09f5d",
          "body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add self-hosted validation workflow for release testing",
          "author_name": "Omer Bareket",
          "author_login": null,
          "committed_at": "2026-03-15T14:50:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "31da2d74167cda8e16563ee24fedab4c7c4e1cba",
          "body": "Add declarative label taxonomy",
          "is_bot": false,
          "headline": "Merge pull request #197 from microsoft/feat/label-taxonomy",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2026-03-03T17:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "014299a905a06d32932edfd14d77202d4ba93ec5",
          "body": "- Add .github/labels.yml as source of truth for repository labels\n- Update agentic workflow to use new taxonomy labels (type:bug,\n  status:waiting-on-author, status:team-review, etc.)\n- Labels are managed directly via the GitHub API",
          "is_bot": false,
          "headline": "Add declarative label taxonomy and update workflow labels",
          "author_name": "Dima Birenbaum",
          "author_login": null,
          "committed_at": "2026-03-03T16:57:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eaf69ee6aff7104270029dbfd8d3c0ba2853174",
          "body": "…ll roles (#193)\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>",
          "is_bot": false,
          "headline": "fix(ci): disable issue creation on agentic workflow no-op and allow a…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-25T18:43:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f13546ace22a679003c2d67d5b153b189798f3df",
          "body": "Co-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): disable issue creation on agentic workflow no-op (#188)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-23T20:07:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bcb4c8765351dc9170706889498c101898b8a39",
          "body": "Bumps [actions/setup-node](https://github.com/actions/setup-node) from 2 to 6.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/v2...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-node\n  dependency-version: '\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(ci): bump actions/setup-node from 2 to 6 (#175)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-23T19:07:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f9a9b0d44dc6cc367f31e878cecb1420cfc10dc",
          "body": "Bumps [mocha](https://github.com/mochajs/mocha) from 10.8.2 to 11.7.5.\n- [Release notes](https://github.com/mochajs/mocha/releases)\n- [Changelog](https://github.com/mochajs/mocha/blob/v11.7.5/CHANGELOG.md)\n- [Commits](https://github.com/mochajs/mocha/compare/v10.8.2...v11.7.5)\n\n---\nupdated-dependenc\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): bump mocha from 10.8.2 to 11.7.5 (#181)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-23T19:06:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "688bc17e7fdad8b5df2548fddf8ecef4503eb511",
          "body": "* fix(ci): disable lockdown mode in agentic workflow for org token compatibility\n\n* Fix formatting in MSDO Issue Assistant workflow file\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\n\n* Fix formatting in MSDO Issue Assistant workflow file\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\n\n---------\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): disable lockdown mode in agentic workflow (#167)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-23T19:05:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28694ca88438cdba99e28f76e72655a14672a219",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v2...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: '6'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(ci): bump actions/checkout from 2 to 6 (#176)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-23T18:55:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c78e375faf3aed3aaeb3063cbf38271004c74f7",
          "body": "* Initial plan\n\n* Add CODEOWNERS file for team-based PR reviews\n\nCo-authored-by: DimaBir <28827735+DimaBir@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: DimaBir <28827735+DimaBir@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add CODEOWNERS for automatic team PR review requests (#185)",
          "author_name": "Copilot",
          "author_login": "Copilot",
          "committed_at": "2026-02-23T18:42:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "817af24446c0dab2fb859c4e2c6e7e77598dd217",
          "body": "* fix(deps): resolve dependabot security alerts and add dependabot.yml\n\n* fix(ci): append matrix OS to artifact name to avoid 409 conflict\n\n* fix(ci): append matrix OS to artifact name in sample-workflow.yml\n\n---------\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(deps): resolve dependabot security alerts (#162)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-19T19:47:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bf6e8b5e7d996e6db930d5341df55f06b4bccd7",
          "body": "Co-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): append matrix OS to artifact name in sample-workflow.yml (#163)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-19T19:15:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2eacb7f37d962feacf869bd322c079ceb483da8d",
          "body": "… vulnerabilities AB#36807380 (#160)\n\nCo-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "feat(break): add break-on-detections input to enable build failure on…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-19T06:05:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f53222bc40487a21bf1b05b16e236aac620f770d",
          "body": null,
          "is_bot": false,
          "headline": "fix: Replace custom issue assistant with GitHub Agentic Workflow (#158)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-19T06:00:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ed6f5a0cca0b804e65990f5b30008a1e20eea75",
          "body": "Co-authored-by: Dima Birenbaum <dbirenbaum@microsoft.com>",
          "is_bot": false,
          "headline": "fix(ci): append matrix OS to artifact name to avoid 409 conflict (#161)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-19T06:00:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f19d19b5d0600bafefe1531daf319ff564e8c53a",
          "body": "* Update CodeQL upload-sarif step\n\nCodeQL version 2 is deprecated:\r\nhttps://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/\n\nSigned-off-by: Sharon Hart <sharonh.dev@gmail.com>\n\n* Update on-push-verification.yml\n\nSigned-off-by: Sharon Hart <sharonh.dev@gmail.com>\n\n* Update sample-workflow.yml\n\nSigned-off-by: Sharon Hart <sharonh.dev@gmail.com>\n\n---------\n\nSigned-off-by: Sharon Hart <sharonh.dev@gmail.com>",
          "is_bot": false,
          "headline": "Update CodeQL upload-sarif step (#128)",
          "author_name": "Sharon Hart",
          "author_login": "SharonHart",
          "committed_at": "2026-02-15T06:37:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd1df84f37f2469199ad2bcebd3acbf77287f6c2",
          "body": "Signed-off-by: Dima Birenbaum <dvlasenko86@gmail.com>",
          "is_bot": false,
          "headline": "Refactor issue assistant workflow for clarity and fixes (#153)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-11T18:19:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c5043bbea43600cfa976896be98ac652130b068",
          "body": null,
          "is_bot": false,
          "headline": "Fix output format for should_respond in workflow (#152)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-11T17:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f42aae05a6af83dd47fb167db9ab7bc21a1b4af",
          "body": "… (#144)",
          "is_bot": false,
          "headline": "Update issue assistant workflow with rate limits and state management…",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-11T17:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8ce33496a24873f29ab52c776091a5260565f30",
          "body": null,
          "is_bot": false,
          "headline": "Fix issue assistant responding to closed issues (#141)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-11T04:01:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5dd2a379e2b346d2dbfbdff7e03b2035821888d",
          "body": "* Add issue assistant workflow for automated triage\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\n\n* Enhance issue assistant workflow with better logging\n\nRefactor wiki integration and AI response handling in issue assistant workflow. Improved logging and error handling.\n\nSigned-off-by: Dim\n[…]\nd patterns\n\nAdded security validation module documentation and design overview.\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>\n\n---------\n\nSigned-off-by: Dima Birenbaum <dvlasenko86@gmail.com>",
          "is_bot": false,
          "headline": "Add issue assistant workflow for automated triage (#138)",
          "author_name": "Dima Birenbaum",
          "author_login": "DimaBir",
          "committed_at": "2026-02-02T19:53:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0a347feb3917483d5d3ebbc1a1e7e5ae1a51cf4",
          "body": "Update sample-workflow.yml",
          "is_bot": false,
          "headline": "Merge pull request #133 from microsoft/chrisnielsen-fix-samples",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2025-07-02T20:03:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32d6cda0f532fa3488f2a72b6624b7deab4ca3fa",
          "body": null,
          "is_bot": false,
          "headline": "Fix our own pipeline as well",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2025-07-02T19:38:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1aab1b5336ef3aac8e826412c350d85600c4ae76",
          "body": "Signed-off-by: chrisnielsen-MS <110426492+chrisnielsen-MS@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update sample-workflow.yml",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2025-07-02T19:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08976cb623803b1b36d7112d4ff9f59eae704de0",
          "body": null,
          "is_bot": false,
          "headline": "Merge pull request #120 from reynoldsa/main",
          "author_name": "Adam Reynolds",
          "author_login": "Reynoldsa",
          "committed_at": "2024-11-07T22:58:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c641f74ca180eaae3b9af702a32a16cceadff46c",
          "body": null,
          "is_bot": false,
          "headline": "Support the upload verb if an existing file is set",
          "author_name": "Adam Reynolds",
          "author_login": null,
          "committed_at": "2024-11-07T22:10:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89d7ff2b07027451f922e5fba90b53c1d6c88c00",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #116 from jbrotsos/patch-1",
          "author_name": "unhorsedpine",
          "author_login": "unhorsedpine",
          "committed_at": "2024-10-21T20:34:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3df81708b2378a53b152cab352ca256a321edd68",
          "body": "Updating to node20",
          "is_bot": false,
          "headline": "Merge pull request #117 from microsoft/feature/node20",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-10-18T20:06:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7f8f71fbdb663d39dd2b48f24c25db799a7b492",
          "body": null,
          "is_bot": false,
          "headline": "Updating to node20",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-10-18T19:51:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adfc9da357e14704be03c5eaf80ebf666e55efb8",
          "body": "Signed-off-by: James Brotsos <j.brotsos@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2024-10-18T16:45:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4854159501bc1cdfd8ad88f0eaae7422e04dc57c",
          "body": "Added Checkov as a security tool\n\nSigned-off-by: James Brotsos <j.brotsos@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "James Brotsos",
          "author_login": "jbrotsos",
          "committed_at": "2024-10-18T02:36:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe9221a4e90bd9649db705e2d26b0f404294d716",
          "body": "Update insecure.py",
          "is_bot": false,
          "headline": "Merge pull request #109 from microsoft/passScan",
          "author_name": "richardtucker",
          "author_login": "richardtucker",
          "committed_at": "2024-08-23T23:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c7c4b2dff858a9600ab2ee1cff8139c1bad9dca",
          "body": "commented out code to pass scan\n\nSigned-off-by: richardtucker <158097221+richardtucker@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update insecure.py",
          "author_name": "richardtucker",
          "author_login": "richardtucker",
          "committed_at": "2024-08-23T23:01:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a701596deb7a7109ecd560cdcce41138c835c90",
          "body": "Workflow to compile TypeScript and commit resulting JavaScript",
          "is_bot": false,
          "headline": "Merge pull request #106 from microsoft/release/vNext",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-31T21:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3e48a253172bf08854146541fb2939da0ce8a25",
          "body": "Update official build to run on PRs to release/vNext instead of to main",
          "is_bot": false,
          "headline": "Merge pull request #107 from microsoft/feature/autoCompileJs",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-31T21:34:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb4fcd53814ced2045cfecc42a761df662a30e61",
          "body": null,
          "is_bot": true,
          "headline": "Official Build: Compile TypeScript to JavaScript",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2024-07-31T20:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a00ef4bf1c43d143f1c74fe9c88ded43c72dd68",
          "body": "…438a2fe2b43424d5c4aef35",
          "is_bot": false,
          "headline": "Merge 3702461008505ecfa8259308e1bea14a38908854 into 068dec3445163abff…",
          "author_name": "chrisnielsen-MS",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-31T20:58:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3702461008505ecfa8259308e1bea14a38908854",
          "body": null,
          "is_bot": false,
          "headline": "Update official build to run on PRs to release/vNext instead of to main",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-31T20:57:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "068dec3445163abff438a2fe2b43424d5c4aef35",
          "body": "… new build workflow",
          "is_bot": false,
          "headline": "Add Checkov to tool list to check effects of updating typescript with…",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-31T19:04:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68f4b76afa613d669c463695b6d27bb62dd52e59",
          "body": null,
          "is_bot": false,
          "headline": "Use force push for only javascript files to avoid any merge issues",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-30T23:51:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d14c8f8974e56ba0a451216b41fdfefa2f638d9",
          "body": null,
          "is_bot": false,
          "headline": "Ensure workflow only triggers for vNext -> main PRs",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-30T23:46:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65aadca676873a69770a8328768af64121a85268",
          "body": null,
          "is_bot": false,
          "headline": "Ensure workflow only triggers for vNext -> main PRs",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-30T23:41:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3af6ecf369ee7832d1fc3f30d2d5ad5a5a7667f6",
          "body": null,
          "is_bot": false,
          "headline": "Ensure workflow only triggers for vNext -> main PRs",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-30T23:40:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04e361d50988c028231e717ee920e5f73ad70f94",
          "body": null,
          "is_bot": false,
          "headline": "Update pipeline to pull branch before pushing",
          "author_name": "Chris Nielsen",
          "author_login": "chrisnielsen-MS",
          "committed_at": "2024-07-30T23:38:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 13,
      "commits_last_year": 77,
      "latest_release_at": "2024-11-07T23:27:15Z",
      "latest_release_tag": "v1.12.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 12,
      "days_since_latest_release": 627,
      "mean_days_between_releases": 107.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "microsoft-security-devops-action",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/microsoft-security-devops-action",
          "is_deprecated": false,
          "latest_version": "1.12.2",
          "repository_url": null,
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 262,
          "first_published_at": "2026-05-01T15:43:47.731000Z",
          "latest_published_at": "2026-05-01T16:00:57.212000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 87
        }
      ]
    },
    "popularity": {
      "forks": 61,
      "stars": 160,
      "watchers": 9,
      "fork_history": {
        "days": [
          {
            "date": "2022-02-10",
            "count": 1
          },
          {
            "date": "2022-03-03",
            "count": 1
          },
          {
            "date": "2022-03-10",
            "count": 1
          },
          {
            "date": "2022-05-10",
            "count": 1
          },
          {
            "date": "2022-08-16",
            "count": 1
          },
          {
            "date": "2022-08-30",
            "count": 1
          },
          {
            "date": "2022-09-15",
            "count": 1
          },
          {
            "date": "2022-09-21",
            "count": 1
          },
          {
            "date": "2022-09-22",
            "count": 1
          },
          {
            "date": "2022-10-13",
            "count": 1
          },
          {
            "date": "2022-11-17",
            "count": 1
          },
          {
            "date": "2022-11-28",
            "count": 1
          },
          {
            "date": "2023-01-04",
            "count": 1
          },
          {
            "date": "2023-01-25",
            "count": 1
          },
          {
            "date": "2023-01-31",
            "count": 1
          },
          {
            "date": "2023-02-13",
            "count": 1
          },
          {
            "date": "2023-02-20",
            "count": 1
          },
          {
            "date": "2023-02-27",
            "count": 1
          },
          {
            "date": "2023-02-28",
            "count": 1
          },
          {
            "date": "2023-03-01",
            "count": 1
          },
          {
            "date": "2023-03-02",
            "count": 1
          },
          {
            "date": "2023-04-05",
            "count": 1
          },
          {
            "date": "2023-04-27",
            "count": 1
          },
          {
            "date": "2023-05-02",
            "count": 1
          },
          {
            "date": "2023-05-05",
            "count": 1
          },
          {
            "date": "2023-05-08",
            "count": 1
          },
          {
            "date": "2023-05-12",
            "count": 1
          },
          {
            "date": "2023-06-04",
            "count": 2
          },
          {
            "date": "2023-06-27",
            "count": 1
          },
          {
            "date": "2023-07-27",
            "count": 1
          },
          {
            "date": "2023-09-22",
            "count": 1
          },
          {
            "date": "2023-10-10",
            "count": 1
          },
          {
            "date": "2023-11-03",
            "count": 1
          },
          {
            "date": "2024-01-08",
            "count": 1
          },
          {
            "date": "2024-02-13",
            "count": 1
          },
          {
            "date": "2024-02-22",
            "count": 1
          },
          {
            "date": "2024-04-11",
            "count": 1
          },
          {
            "date": "2024-04-23",
            "count": 1
          },
          {
            "date": "2024-05-06",
            "count": 1
          },
          {
            "date": "2024-07-10",
            "count": 1
          },
          {
            "date": "2024-08-09",
            "count": 1
          },
          {
            "date": "2024-08-26",
            "count": 1
          },
          {
            "date": "2024-10-18",
            "count": 1
          },
          {
            "date": "2024-11-21",
            "count": 1
          },
          {
            "date": "2024-11-27",
            "count": 1
          },
          {
            "date": "2024-12-03",
            "count": 1
          },
          {
            "date": "2025-01-30",
            "count": 1
          },
          {
            "date": "2025-03-02",
            "count": 1
          },
          {
            "date": "2025-03-24",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-05-30",
            "count": 1
          },
          {
            "date": "2025-06-08",
            "count": 1
          },
          {
            "date": "2025-08-03",
            "count": 1
          },
          {
            "date": "2025-08-17",
            "count": 1
          },
          {
            "date": "2025-10-09",
            "count": 1
          },
          {
            "date": "2026-03-14",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-07-12",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 60,
        "total_forks": 61
      },
      "star_history": null,
      "open_issues_and_prs": 28
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "test/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 12125,
      "source_files_sampled": 20,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "adm-zip",
            "direct": false,
            "version": "0.5.10",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-xcpc-8h2w-3j85"
            ],
            "fixed_version": "0.6.0",
            "advisory_count": 1,
            "oldest_advisory_days": 17
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp",
              "GHSA-jxxr-4gwj-5jf2",
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 3,
            "oldest_advisory_days": 70
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52cp-r559-cp3m",
              "GHSA-h67p-54hq-rp68"
            ],
            "fixed_version": "4.3.0",
            "advisory_count": 2,
            "oldest_advisory_days": 42
          },
          {
            "name": "undici",
            "direct": false,
            "version": "8.0.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-35p6-xmwp-9g52",
              "GHSA-38rv-x7px-6hhq",
              "GHSA-g8m3-5g58-fq7m",
              "GHSA-hm92-r4w5-c3mj",
              "GHSA-p88m-4jfj-68fv",
              "GHSA-pr7r-676h-xcf6",
              "GHSA-vmh5-mc38-953g",
              "GHSA-vxpw-j846-p89q"
            ],
            "fixed_version": "8.5.0",
            "advisory_count": 8,
            "oldest_advisory_days": 40
          },
          {
            "name": "uuid",
            "direct": false,
            "version": "8.3.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-w5hq-g745-h8pq"
            ],
            "fixed_version": "13.0.1",
            "advisory_count": 1,
            "oldest_advisory_days": 96
          },
          {
            "name": "diff",
            "direct": false,
            "version": "7.0.0",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-73rr-hh4g-fpgx"
            ],
            "fixed_version": "8.0.3",
            "advisory_count": 1,
            "oldest_advisory_days": 194
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 5,
          "moderate": 1
        },
        "advisory_count": 16,
        "affected_count": 6,
        "assessed_count": 318,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@actions/core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "2.0.3"
        },
        {
          "name": "@actions/exec",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "2.0.0"
        },
        {
          "name": "@microsoft/security-devops-actions-toolkit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.11.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@actions/core",
            "direct": true,
            "version": "1.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/core",
            "direct": true,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/exec",
            "direct": true,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/exec",
            "direct": true,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@microsoft/security-devops-actions-toolkit",
            "direct": true,
            "version": "1.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/http-client",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/http-client",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/io",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@actions/io",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@gulpjs/messages",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@gulpjs/to-absolute-glob",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.scandir",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.stat",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.walk",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sindresorhus/merge-streams",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/commons",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "15.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/samsam",
            "direct": false,
            "version": "10.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/mocha",
            "direct": false,
            "version": "10.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/q",
            "direct": false,
            "version": "1.5.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/sinon",
            "direct": false,
            "version": "21.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/sinonjs__fake-timers",
            "direct": false,
            "version": "15.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "adm-zip",
            "direct": false,
            "version": "0.5.10",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-colors",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-colors",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-wrap",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "append-buffer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "arr-diff",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "arr-union",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "array-each",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-slice",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "assign-symbols",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "async-done",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "async-settle",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "b4a",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "bach",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "bare-events",
            "direct": false,
            "version": "2.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "base64-js",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "binary-extensions",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "bl",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browser-stdout",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-equal",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "7.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "clone",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "clone-buffer",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "clone-stats",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cloneable-readable",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "copy-props",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "core-util-is",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decamelize",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "decompress-response",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "define-data-property",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "define-properties",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "del",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "detect-file",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "duplexify",
            "direct": false,
            "version": "3.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "each-props",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "end-of-stream",
            "direct": false,
            "version": "1.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "events-universal",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "expand-tilde",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "extend-shallow",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-fifo",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-glob",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fastest-levenshtein",
            "direct": false,
            "version": "1.0.16",
            "ecosystem": "npm"
          },
          {
            "name": "fastq",
            "direct": false,
            "version": "1.20.1",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "findup-sync",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fined",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flagged-respawn",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "flush-write-stream",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "for-in",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "for-own",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "fs-mkdirp-stream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fs-mkdirp-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob-stream",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob-stream",
            "direct": false,
            "version": "8.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-watcher",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "global-modules",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "global-prefix",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globby",
            "direct": false,
            "version": "14.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "glogg",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "gulp",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "gulp-cli",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "gulp-typescript",
            "direct": false,
            "version": "6.0.0-alpha.1",
            "ecosystem": "npm"
          },
          {
            "name": "gulplog",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "has",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-property-descriptors",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "he",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "homedir-polyfill",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "ieee754",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "interpret",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-absolute",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-binary-path",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-buffer",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "is-core-module",
            "direct": false,
            "version": "2.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extendable",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-negated-glob",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-cwd",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-object",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-object",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-relative",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-unc-path",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-utf8",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-valid-glob",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-windows",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "isarray",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isobject",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "last-run",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lazystream",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "lead",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lead",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "liftoff",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "log-symbols",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "map-cache",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "merge2",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-response",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mocha",
            "direct": false,
            "version": "11.7.5",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mute-stdout",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "now-and-later",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "now-and-later",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-keys",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.assign",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "object.defaults",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "object.pick",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "ordered-read-streams",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-map",
            "direct": false,
            "version": "7.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-filepath",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "parse-passwd",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-dirname",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-parse",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-root",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-root-regex",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "plugin-error",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "presentable-error",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "process-nextick-args",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pump",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pumpify",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "queue-microtask",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "2.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "rechoir",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "remove-bom-buffer",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "remove-bom-stream",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "remove-trailing-separator",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "replace-ext",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "replace-ext",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "replace-homedir",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "1.22.11",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-dir",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-options",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-options",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "reusify",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "run-parallel",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver-greatest-satisfied-range",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "serialize-javascript",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "sinon",
            "direct": false,
            "version": "22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "sparkles",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "stream-composer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "stream-exhaust",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "stream-shift",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "streamx",
            "direct": false,
            "version": "2.23.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string_decoder",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-preserve-symlinks-flag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "sver",
            "direct": false,
            "version": "1.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "teex",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "text-decoder",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "through2",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "through2",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "through2-filter",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-absolute-glob",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "to-through",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-through",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tunnel",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "unc-path-regex",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "undertaker",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "undertaker-registry",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "unicorn-magic",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "unique-stream",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "util-deprecate",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "uuid",
            "direct": false,
            "version": "8.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "v8flags",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "value-or-function",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "value-or-function",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl-contents",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl-fs",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl-fs",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl-sourcemap",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "vinyl-sourcemap",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "workerpool",
            "direct": false,
            "version": "9.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "xtend",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "16.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "20.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-unparser",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 318,
        "direct_count": 5,
        "indirect_count": 313
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 105,
        "open_issues": 18,
        "closed_ratio": 0.825,
        "closed_issues": 85,
        "closed_unmerged_prs": 50
      },
      "bus_factor": 1,
      "bot_contributors": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "davidknise",
          "commits": 187,
          "avatar_url": "https://avatars.githubusercontent.com/u/11544770?v=4"
        },
        {
          "type": "User",
          "login": "laragoldstein13",
          "commits": 35,
          "avatar_url": "https://avatars.githubusercontent.com/u/97191407?v=4"
        },
        {
          "type": "User",
          "login": "DimaBir",
          "commits": 27,
          "avatar_url": "https://avatars.githubusercontent.com/u/28827735?v=4"
        },
        {
          "type": "User",
          "login": "larohra",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/41490930?v=4"
        },
        {
          "type": "User",
          "login": "chrisnielsen-MS",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/110426492?v=4"
        },
        {
          "type": "User",
          "login": "jbrotsos",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/10178859?v=4"
        },
        {
          "type": "User",
          "login": "JiandongJiang",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/34362900?v=4"
        },
        {
          "type": "User",
          "login": "omerb97",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/34472645?v=4"
        },
        {
          "type": "User",
          "login": "sethRait",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/8842639?v=4"
        },
        {
          "type": "User",
          "login": "prashmo",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/8976311?v=4"
        }
      ],
      "contributors_sampled": 19,
      "top_contributor_share": 0.567
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci-doctor.lock.yml",
        "ci.yml",
        "msdo-breach-monitor.lock.yml",
        "msdo-issue-assistant.lock.yml",
        "official-build.yml",
        "on-push-verification.yml",
        "sample-workflow.yml",
        "self-hosted-validation-v1.yml",
        "toolchain-version-probe.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 3,
            "reason": "3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 8,
            "reason": "SAST tool is not run on all commits -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "16 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "c0f73835fa1f80fc12cc96ea7f9185735705f433",
        "ran_at": "2026-07-28T15:33:00Z",
        "aggregate_score": 5.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T05:16:54Z",
      "oldest_open_prs": [
        {
          "number": 159,
          "created_at": "2026-02-17T18:08:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 248,
          "created_at": "2026-04-22T14:16:30Z",
          "last_comment_at": "2026-04-24T06:41:36Z",
          "last_comment_author": "copilot-swe-agent"
        },
        {
          "number": 251,
          "created_at": "2026-04-24T06:58:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 257,
          "created_at": "2026-05-27T16:55:54Z",
          "last_comment_at": "2026-05-27T16:55:54Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 263,
          "created_at": "2026-07-01T14:08:29Z",
          "last_comment_at": "2026-07-01T14:08:30Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 264,
          "created_at": "2026-07-01T14:08:46Z",
          "last_comment_at": "2026-07-01T14:08:47Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 266,
          "created_at": "2026-07-08T14:05:25Z",
          "last_comment_at": "2026-07-08T14:05:26Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 268,
          "created_at": "2026-07-15T14:04:56Z",
          "last_comment_at": "2026-07-15T14:04:57Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 269,
          "created_at": "2026-07-15T14:05:12Z",
          "last_comment_at": "2026-07-15T14:05:13Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 271,
          "created_at": "2026-07-22T14:04:52Z",
          "last_comment_at": "2026-07-22T14:04:53Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-05-07T06:14:49Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 19,
          "created_at": "2022-05-03T08:06:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 36,
          "created_at": "2022-12-06T06:10:47Z",
          "last_comment_at": "2024-03-13T12:02:30Z",
          "last_comment_author": "kimsyversen"
        },
        {
          "number": 45,
          "created_at": "2023-02-27T10:21:09Z",
          "last_comment_at": "2023-08-14T06:09:06Z",
          "last_comment_author": "mhborg-timextender"
        },
        {
          "number": 47,
          "created_at": "2023-03-22T03:11:17Z",
          "last_comment_at": "2023-07-20T14:51:49Z",
          "last_comment_author": "pamelafox"
        },
        {
          "number": 54,
          "created_at": "2023-05-02T12:09:54Z",
          "last_comment_at": "2024-11-27T10:43:51Z",
          "last_comment_author": "pocki"
        },
        {
          "number": 58,
          "created_at": "2023-06-03T15:58:48Z",
          "last_comment_at": "2023-06-06T19:46:51Z",
          "last_comment_author": "piraces"
        },
        {
          "number": 61,
          "created_at": "2023-06-14T12:35:02Z",
          "last_comment_at": "2024-01-05T18:07:37Z",
          "last_comment_author": "CapG-SLeeke"
        },
        {
          "number": 65,
          "created_at": "2023-07-20T17:03:42Z",
          "last_comment_at": "2023-08-04T18:29:42Z",
          "last_comment_author": "pamelafox"
        },
        {
          "number": 90,
          "created_at": "2024-02-13T10:21:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 96,
          "created_at": "2024-07-03T13:54:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 97,
          "created_at": "2024-07-08T11:52:33Z",
          "last_comment_at": "2024-11-06T18:49:09Z",
          "last_comment_author": "ptmetcalf"
        },
        {
          "number": 104,
          "created_at": "2024-07-25T21:24:08Z",
          "last_comment_at": "2025-05-09T15:40:47Z",
          "last_comment_author": "manuhmm"
        },
        {
          "number": 127,
          "created_at": "2025-02-06T15:52:23Z",
          "last_comment_at": "2025-02-19T04:09:07Z",
          "last_comment_author": "jbrotsos"
        },
        {
          "number": 129,
          "created_at": "2025-03-03T14:51:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 130,
          "created_at": "2025-03-28T10:35:33Z",
          "last_comment_at": "2025-09-26T09:50:58Z",
          "last_comment_author": "newbloke82"
        },
        {
          "number": 135,
          "created_at": "2025-08-20T18:00:51Z",
          "last_comment_at": "2025-08-22T16:39:50Z",
          "last_comment_author": "sourabhsy"
        },
        {
          "number": 267,
          "created_at": "2026-07-13T12:29:03Z",
          "last_comment_at": "2026-07-15T18:20:43Z",
          "last_comment_author": "DimaBir"
        },
        {
          "number": 270,
          "created_at": "2026-07-21T13:57:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/microsoft/security-devops-action",
    "host": "github.com",
    "name": "security-devops-action",
    "owner": "microsoft"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 64 is calibrated to 73 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 64,
            "calibrated": 73,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 73,
      "inputs": {
        "security": 61,
        "vitality": 62,
        "community": 55,
        "governance": 67,
        "calibration": "2026-08-02",
        "engineering": 75,
        "ai_readiness": 58,
        "weighted_overall_raw": 64
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 62,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "commits_last_year": 77,
              "human_commit_share": 0.88,
              "days_since_last_push": 1,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "77 commits in the last year",
                "points": 17,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 77
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "moderate",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "releases_count": 13,
              "latest_release_tag": "v1.12.0",
              "releases_from_tags": false,
              "days_since_latest_release": 627,
              "mean_days_between_releases": 107.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "13 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 627 days ago",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 627
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~107.2 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 107.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 96,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 96 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 96
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "forks": 61,
              "stars": 160,
              "watchers": 9,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "160 stars",
                "points": 35.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 160
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "61 forks",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 61
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "9 watchers",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "weak",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "packages": [
                "microsoft-security-devops-action"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 262
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "262 downloads/month across npm",
                "points": 32.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 262,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 67,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "weak",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 19,
              "top_contributor_share": 0.567
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 57% of commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 57
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "19 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "merged_prs": 105,
              "open_issues": 18,
              "closed_issues": 85,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.825,
              "closed_unmerged_prs": 50,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "82% of issues closed",
                "points": 34.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "105/155 decided PRs merged",
                "points": 20.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 105,
                      "decided": 155
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "excellent",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "followers": 126051,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "microsoft",
              "public_repos": 8225,
              "account_age_days": 4612
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "126,051 followers of microsoft",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 126051,
                      "login": "microsoft"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "8225 public repos, account ~12 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 8225
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 12
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "packages": [
                "microsoft-security-devops-action"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 87
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 87 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 87
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 75,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "security",
                "devops",
                "microsoft"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "3 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 61,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "3 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 3",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "16 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 318 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 318
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 16,
              "affected_packages": 6,
              "assessed_packages": 318,
              "unassessed_packages": 0,
              "affected_by_severity": "high 5, moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 318,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 9
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 58,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.773,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "68 of 88 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 68,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "test/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.17,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.11
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "test/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "test/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "17 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 17,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "11 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 11,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 12125,
              "source_files_sampled": 20,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (test/tsconfig.json, tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "test/tsconfig.json, tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/20 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 20,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "library"
      ],
      "labels": [
        "library"
      ],
      "scores": {
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T15:33:27.578241Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/microsoft/security-devops-action.svg",
  "full_name": "microsoft/security-devops-action",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v2.5.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.