JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 3245,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 620024,
"Shell": 295,
"Makefile": 1583
},
"pushed_at": "2026-07-22T06:10:58Z",
"created_at": "2015-06-12T14:33:30Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T06:06:52Z",
"description": "Go libraries shared across Prometheus components and libraries.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://prometheus.io",
"name": "Prometheus",
"type": "Organization",
"login": "prometheus",
"company": null,
"location": null,
"followers": 4674,
"avatar_url": "https://avatars.githubusercontent.com/u/3380462?v=4",
"created_at": "2013-01-25T10:46:24Z",
"is_verified": null,
"public_repos": 58,
"account_age_days": 4932
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.70.1",
"kind": "patch",
"published_at": "2026-07-22T06:10:58Z"
},
{
"tag": "v0.70.0",
"kind": "minor",
"published_at": "2026-07-10T08:24:50Z"
},
{
"tag": "v0.69.0",
"kind": "minor",
"published_at": "2026-06-17T08:55:26Z"
},
{
"tag": "v0.68.1",
"kind": "patch",
"published_at": "2026-06-03T07:04:07Z"
},
{
"tag": "v0.68.0",
"kind": "minor",
"published_at": "2026-05-29T15:44:58Z"
},
{
"tag": "v0.67.5",
"kind": "patch",
"published_at": "2026-01-05T15:53:37Z"
},
{
"tag": "v0.67.4",
"kind": "patch",
"published_at": "2025-11-21T13:53:55Z"
},
{
"tag": "v0.67.3",
"kind": "patch",
"published_at": "2025-11-18T08:28:14Z"
},
{
"tag": "v0.67.2",
"kind": "patch",
"published_at": "2025-10-28T14:09:39Z"
},
{
"tag": "v0.67.1",
"kind": "patch",
"published_at": "2025-10-07T13:37:32Z"
},
{
"tag": "v0.67.0",
"kind": "minor",
"published_at": "2025-10-07T10:01:07Z"
},
{
"tag": "v0.66.1",
"kind": "patch",
"published_at": "2025-09-05T11:39:06Z"
},
{
"tag": "v0.66.0",
"kind": "minor",
"published_at": "2025-09-02T18:55:36Z"
},
{
"tag": "v0.65.0",
"kind": "minor",
"published_at": "2025-06-22T23:02:22Z"
},
{
"tag": "v0.64.0",
"kind": "minor",
"published_at": "2025-05-15T12:12:29Z"
},
{
"tag": "v0.63.0",
"kind": "minor",
"published_at": "2025-03-13T18:36:06Z"
},
{
"tag": "v0.62.0",
"kind": "minor",
"published_at": "2025-01-16T18:47:09Z"
},
{
"tag": "v0.61.0",
"kind": "minor",
"published_at": "2024-12-04T23:04:44Z"
},
{
"tag": "v0.60.1",
"kind": "patch",
"published_at": "2024-10-24T15:30:52Z"
},
{
"tag": "v0.60.0",
"kind": "minor",
"published_at": "2024-10-01T12:38:07Z"
},
{
"tag": "v0.59.1",
"kind": "patch",
"published_at": "2024-09-05T15:50:46Z"
},
{
"tag": "v0.59.0",
"kind": "minor",
"published_at": "2024-09-05T12:50:48Z"
},
{
"tag": "v0.58.0",
"kind": "minor",
"published_at": "2024-09-05T12:48:58Z"
},
{
"tag": "v0.57.0",
"kind": "minor",
"published_at": "2024-08-28T17:00:51Z"
},
{
"tag": "v0.56.0",
"kind": "minor",
"published_at": "2024-08-27T21:59:41Z"
},
{
"tag": "v0.55.0",
"kind": "minor",
"published_at": "2024-06-26T13:43:06Z"
},
{
"tag": "v0.54.0",
"kind": "minor",
"published_at": "2024-06-03T13:18:41Z"
},
{
"tag": "v0.53.0",
"kind": "minor",
"published_at": "2024-04-18T12:55:19Z"
},
{
"tag": "v0.52.3",
"kind": "patch",
"published_at": "2024-04-10T22:54:44Z"
},
{
"tag": "v0.52.2",
"kind": "patch",
"published_at": "2024-04-03T13:55:35Z"
},
{
"tag": "v0.51.1",
"kind": "patch",
"published_at": "2024-03-24T05:38:03Z"
},
{
"tag": "v0.51.0",
"kind": "minor",
"published_at": "2024-03-21T13:23:54Z"
},
{
"tag": "v0.50.0",
"kind": "minor",
"published_at": "2024-03-07T08:27:55Z"
},
{
"tag": "v0.49.0",
"kind": "minor",
"published_at": "2024-02-29T16:07:21Z"
},
{
"tag": "v0.48.0",
"kind": "minor",
"published_at": "2024-02-22T22:31:58Z"
},
{
"tag": "v0.47.0",
"kind": "minor",
"published_at": "2024-02-15T14:44:50Z"
},
{
"tag": "v0.46.0",
"kind": "minor",
"published_at": "2024-01-13T19:31:08Z"
},
{
"tag": "v0.45.0",
"kind": "minor",
"published_at": "2023-10-18T08:57:41Z"
},
{
"tag": "v0.44.0",
"kind": "minor",
"published_at": "2023-05-22T12:24:56Z"
},
{
"tag": "v0.43.0",
"kind": "minor",
"published_at": "2023-05-05T06:25:22Z"
},
{
"tag": "v0.42.0",
"kind": "minor",
"published_at": "2023-03-09T13:56:23Z"
},
{
"tag": "v0.41.0",
"kind": "minor",
"published_at": "2023-03-01T21:48:06Z"
},
{
"tag": "v0.40.0",
"kind": "minor",
"published_at": "2023-03-01T21:47:43Z"
},
{
"tag": "v0.39.0",
"kind": "minor",
"published_at": "2022-12-14T09:09:41Z"
},
{
"tag": "v0.37.1",
"kind": "patch",
"published_at": "2022-12-09T09:36:33Z"
},
{
"tag": "v0.38.0",
"kind": "minor",
"published_at": "2022-12-08T13:28:04Z"
},
{
"tag": "v0.37.0",
"kind": "minor",
"published_at": "2022-12-08T13:23:39Z"
},
{
"tag": "v0.36.0",
"kind": "minor",
"published_at": "2022-12-08T13:24:51Z"
},
{
"tag": "v0.35.0",
"kind": "minor",
"published_at": "2022-12-08T13:25:38Z"
},
{
"tag": "v0.34.0",
"kind": "minor",
"published_at": "2022-04-20T07:47:34Z"
},
{
"tag": "v0.33.0",
"kind": "minor",
"published_at": "2022-03-29T00:36:09Z"
},
{
"tag": "v0.32.0",
"kind": "minor",
"published_at": "2021-10-20T07:58:32Z"
},
{
"tag": "v0.31.1",
"kind": "patch",
"published_at": "2021-09-28T09:06:45Z"
},
{
"tag": "v0.30.1",
"kind": "patch",
"published_at": "2021-09-28T06:55:05Z"
},
{
"tag": "v0.31.0",
"kind": "minor",
"published_at": "2021-09-26T21:12:06Z"
},
{
"tag": "v0.30.0",
"kind": "minor",
"published_at": "2021-07-26T16:24:19Z"
},
{
"tag": "sigv4/v0.1.0",
"kind": "other",
"published_at": "2021-06-23T13:40:52Z"
},
{
"tag": "v0.29.0",
"kind": "minor",
"published_at": "2021-06-23T13:40:35Z"
},
{
"tag": "v0.28.0",
"kind": "minor",
"published_at": "2021-06-07T13:33:43Z"
},
{
"tag": "v0.27.0",
"kind": "minor",
"published_at": "2021-06-04T11:06:50Z"
},
{
"tag": "v0.26.0",
"kind": "minor",
"published_at": "2021-06-04T11:05:15Z"
},
{
"tag": "v0.25.0",
"kind": "minor",
"published_at": "2021-05-18T22:48:50Z"
},
{
"tag": "v0.24.0",
"kind": "minor",
"published_at": "2021-05-10T21:44:39Z"
},
{
"tag": "v0.23.0",
"kind": "minor",
"published_at": "2021-04-30T11:34:23Z"
},
{
"tag": "v0.21.0",
"kind": "minor",
"published_at": "2021-04-30T11:33:10Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2021-04-30T11:32:53Z"
},
{
"tag": "v0.19.0",
"kind": "minor",
"published_at": "2021-03-12T18:59:04Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2021-02-26T22:53:08Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2021-02-18T22:03:27Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2021-02-17T21:41:06Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2020-11-09T17:08:49Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2020-09-23T12:55:12Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2020-08-19T14:24:36Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2019-06-18T10:46:22Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2019-06-17T16:21:27Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2019-05-22T09:38:34Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2019-05-08T15:20:01Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2019-04-10T11:44:41Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2019-01-30T14:02:50Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2019-01-23T14:36:44Z"
}
],
"recent_commits": [
{
"oid": "b63d8c0f100a0788a91445e376ec3b1598e69c99",
"body": "Bumps the golang-org-x group with 1 update in the / directory: [golang.org/x/net](https://github.com/golang/net).\n\n\nUpdates `golang.org/x/net` from 0.56.0 to 0.57.0\n- [Commits](https://github.com/golang/net/compare/v0.56.0...v0.57.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n d\n[…]\nersion-update:semver-minor\n dependency-group: golang-org-x\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net (#947)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T06:06:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4109c3e862a826f51ae4c1cdb75d391f29724ee3",
"body": "Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](http\n[…]\nype: version-update:semver-minor\n dependency-group: codeql\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the codeql group with 4 updates (#948)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T06:03:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5270b6283c393b55810df4fd901c9dfc51d1a7d9",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356fb5720e22ba16...b7ad1dad31e06c5925ef5d2fc7ad053ef454303e)\n\n---\nupdated\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#949)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T06:03:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1167ca3c3ca6ea23c903061557f204b70b84f1cd",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#950)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T06:02:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d28d38298f4e7e7e2977122caca8573a58166192",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#946)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-07-21T05:48:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f91587680202dae36afa84f68e0537cb52c7b00e",
"body": "…r-comment\n\nconfig: clarify sensitive redirect headers match net/http",
"is_bot": false,
"headline": "Merge pull request #924 from roidelapluie/roidelapluie/redirect-heade…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T12:43:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dfbebd026ac57466d81ff0a1a1598ea3dae85826",
"body": "Update CHANGELOG for v0.70.0",
"is_bot": false,
"headline": "Merge pull request #945 from roidelapluie/roidelapluie/changelog-0.70.0",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T09:41:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c8a00193a337caff496fc1ae0a318e2921377b9e",
"body": "Signed-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "Update CHANGELOG for v0.70.0",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:40:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5eff7a827920b6f175ea02b222f7c827a0fe80ad",
"body": "…ions/checkout-7.0.0\n\nbuild(deps): bump actions/checkout from 3.1.0 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #941 from prometheus/dependabot/github_actions/act…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:22:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a23c5b344ad9200c0073133920fe60a9882c9d28",
"body": "…f/scorecard-action-2.4.3\n\nbuild(deps): bump ossf/scorecard-action from 2.1.2 to 2.4.3",
"is_bot": false,
"headline": "Merge pull request #939 from prometheus/dependabot/github_actions/oss…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:21:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e1eb871ced38b03648a38558ac3de66edeff2b5",
"body": "…ions/upload-artifact-7.0.1\n\nbuild(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1",
"is_bot": false,
"headline": "Merge pull request #942 from prometheus/dependabot/github_actions/act…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:21:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ab2736d28a9fce77b0186e36b5d3318b74115298",
"body": "…ions/setup-go-6.5.0\n\nbuild(deps): bump actions/setup-go from 6.2.0 to 6.5.0",
"is_bot": false,
"headline": "Merge pull request #940 from prometheus/dependabot/github_actions/act…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:20:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e596873192a72855876b1c38cdb634bb73f5ba00",
"body": "…eql-ac07fb48a3\n\nbuild(deps): bump the codeql group with 4 updates",
"is_bot": false,
"headline": "Merge pull request #938 from prometheus/dependabot/github_actions/cod…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-10T08:19:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97c066a87b2345f146b345141f0f14aaab7ad387",
"body": "…trics 1.0 encoders (#943)\n\nSigned-off-by: David Ashpole <dashpole@google.com>",
"is_bot": false,
"headline": "Add BenchmarkConvertMetricFamily comparing Prometheus text and OpenMe…",
"author_name": "David Ashpole",
"author_login": "dashpole",
"committed_at": "2026-07-08T15:29:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62e9d0f61d355b574225f66628a5f94be2bc1c29",
"body": "route: add support for the QUERY HTTP method",
"is_bot": false,
"headline": "Merge pull request #932 from roidelapluie/roidelapluie/route-query",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-03T12:18:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c312397a5da723c995ee9c16263f252c1d6b4a1",
"body": "Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1.\n- [Release notes](https://github.com/actions/upload-artifact/releases)\n- [Commits](https://github.com/actions/upload-artifact/compare/ea165f8d65b6e75b540449e92b4886f43607fa02...043fb46d1a93c77aae656e7c1c\n[…]\ndency-name: actions/upload-artifact\n dependency-version: 7.0.1\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T09:55:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "755e9d686dec00400191cc8483872831aff1b9cd",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 3.1.0 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v3.1.0...9c091bb21b7c1c\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/checkout from 3.1.0 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T09:55:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "556d7402ea9a80cab60297e4dc98149b5410e24f",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.2.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n dependency-version: 6.5.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/setup-go from 6.2.0 to 6.5.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T09:55:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8bf6b86024bdc8c64fab60c63505e2a5d465f4a",
"body": "Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.1.2 to 2.4.3.\n- [Release notes](https://github.com/ossf/scorecard-action/releases)\n- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)\n- [Commits](https://github.com/ossf/scorecard-action/compare/\n[…]\nendency-name: ossf/scorecard-action\n dependency-version: 2.4.3\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump ossf/scorecard-action from 2.1.2 to 2.4.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T09:55:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bbe02b9a363fb0d7de98aff126a3f02aebf9131b",
"body": "Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](http\n[…]\nd-sarif\n dependency-version: 4.36.3\n dependency-type: direct:production\n update-type: version-update:semver-major\n dependency-group: codeql\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump the codeql group with 4 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T09:55:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b228a8312c84b8d162d42c2bd6a70ead5c356ee",
"body": "Synchronize common files from prometheus/prometheus",
"is_bot": false,
"headline": "Merge pull request #937 from prombot/repo_sync",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-07-03T09:53:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "17c316570edb69bdeb63ddc9154680d36486fd6d",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files",
"author_name": "prombot",
"author_login": "prombot",
"committed_at": "2026-07-02T16:03:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b43149c6d50c7668c82898674788febad68c488",
"body": "Manually go mod tidy",
"is_bot": false,
"headline": "Merge pull request #934 from prometheus/superq/tidy",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-30T14:38:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d945891d093e2a5e2a858efb95fe7244f9b86c4",
"body": "For some reason go mod tidy doesn't cleanup a couple indirects\ncorrectly.\n* Bump indirect Prometheus packages.\n\nSigned-off-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "Manually go mod tidy",
"author_name": "SuperQ",
"author_login": "SuperQ",
"committed_at": "2026-06-30T07:28:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9c9e13caf81aab2347c3e0e1a0d79fab35346f0",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.55.0 to 0.56.0.\n- [Commits](https://github.com/golang/net/compare/v0.55.0...v0.56.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.56.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.55.0 to 0.56.0 (#933)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T07:08:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d120ca91886414878562efde96b5f9f46ffb853",
"body": "config: fix TLSVersion.String() printing pointer address",
"is_bot": false,
"headline": "Merge pull request #929 from s3onghyun/fix-tlsversion-stringer",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-24T09:36:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc216b8996f620fb5b33cf6574375ceeb5163f22",
"body": "QUERY is a safe, idempotent method that carries a request body\n(RFC 10008). It is not yet part of net/http, so register it using a\nlocally defined MethodQuery constant.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "route: add support for the QUERY HTTP method",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-24T09:35:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b2cb09946510493aca10bdb3cc6415fa631d408",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#930)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-06-23T06:11:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a28b311335ecd0be4dc2601f338c41404008ed71",
"body": "The fallback branch passed the *TLSVersion pointer to fmt.Sprintf(\"%d\"),\nso an unknown TLS version (one not in the TLSVersions map) rendered as the\npointer's memory address instead of the numeric version. Dereference the\npointer like the MarshalYAML/MarshalJSON methods already do.\n\nSigned-off-by: Seonghyun Hong <s3onghyun.hong@gmail.com>",
"is_bot": false,
"headline": "config: fix TLSVersion.String() printing pointer address",
"author_name": "Seonghyun Hong",
"author_login": "s3onghyun",
"committed_at": "2026-06-20T04:21:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "43de10cc658055c6b5e4d619edc917d5af493409",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#927)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-06-18T10:56:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "541bbcb2114b41d475034ddad7bc82eb72a4578b",
"body": "Update CHANGELOG",
"is_bot": false,
"headline": "Merge pull request #926 from roidelapluie/roidelapluie/changelog",
"author_name": "George Krajcsovits",
"author_login": "krajorama",
"committed_at": "2026-06-17T09:45:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "436e0fe552c433fb7e579358db9f5e95aed6d006",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#923)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-06-17T09:00:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ac87120292466d012c21739755bd9bb005b900f",
"body": "Signed-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "Update CHANGELOG",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-17T08:56:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3c14a039d494d866242b36ac253dfecf9c7210b",
"body": "…nfigfile-dir\n\nconfig: resolve LoadHTTPConfigFile paths relative to the config file",
"is_bot": false,
"headline": "Merge pull request #925 from roidelapluie/roidelapluie/fix-loadhttpco…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-17T08:40:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7b791d0a0cd8e7be164d7f3fdb33450c1868b1c",
"body": "LoadHTTPConfigFile called SetDirectory with filepath.Dir(filepath.Dir(filename)),\nresolving relative file paths (http_headers files, *_file credentials) against the\nconfig file's grandparent directory instead of its own directory. This contradicts\nthe SetDirectory contract and every other config loa\n[…]\n a\nregression test that loads a config from a temp dir and asserts a plain relative\npath resolves next to the config file.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "config: resolve LoadHTTPConfigFile paths relative to the config file",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-17T07:40:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f684fc7af8f9ae1826b79697c62eb0133315d9eb",
"body": "The stripped header list (including Proxy-Authorization and\nProxy-Authenticate) now matches makeHeadersCopier in net/http, which\ngained the Proxy-* entries in the fix for CVE-2025-4673.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "config: clarify sensitive redirect headers match net/http",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-17T07:23:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f84efec4e4deb31a8afd39c4f4f7ba2b30f39df3",
"body": "model: reduce allocations in Time.UnmarshalJSON",
"is_bot": false,
"headline": "Merge pull request #918 from prometheus/time-split",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-12T14:14:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2269d3d1af9a40c9324bb523087f7704fabe7f1d",
"body": "…empty-braces-panic\n\nexpfmt: fix nil pointer panic when parsing empty braces \"{}\"",
"is_bot": false,
"headline": "Merge pull request #922 from roidelapluie/roidelapluie/fix-textparse-…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-12T14:09:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a1600af967b7eaa77360339b402b447855c24915",
"body": "The text exposition parser panics with a nil pointer dereference when it\nencounters a closing brace before any metric name has been read, e.g. for\nthe input \"{}\". In startOfLine a leading \"{\" sets currentMetricIsInsideBraces\nand jumps straight to label parsing without going through readingMetricName\n[…]\ne. currentMF is checked rather than\ncurrentMetric because reset only clears currentMF between parses.\n\nIntroduced in #670.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "expfmt: fix nil pointer panic when parsing empty braces \"{}\"",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T15:49:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "56fe3954537fa60da94055f19172fafa25347948",
"body": "…ost-check\n\nconfig: check cross-host redirect before OAuth2 token fetch",
"is_bot": false,
"headline": "Merge pull request #921 from roidelapluie/roidelapluie/oauth2-cross-h…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T14:55:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0fcda471410c91d285776092b7d768d8ac199bc9",
"body": "config: make isCrossHostRedirect sticky across the redirect chain",
"is_bot": false,
"headline": "Merge pull request #920 from roidelapluie/roidelapluie/cross-host-sticky",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T14:55:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "30ba470f4f55107af9dbe7fbe9c95c0617c13f43",
"body": "Modernize Go",
"is_bot": false,
"headline": "Merge pull request #919 from prometheus/superq/modernize",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T12:33:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b55b3e9e7e899f2cbcbcb7afdcb55c2db6a1754",
"body": "Move isCrossHostRedirect early in oauth2RoundTripper.RoundTrip so that\ncross-host redirects bypass token-source initialisation entirely and go\nstraight to Base.RoundTrip. Base is read under the RLock to avoid a\ndata race with concurrent reconfigurations.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "config: check cross-host redirect before OAuth2 token fetch",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T12:28:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "428856f9a5d0d790dacdf03e789c2ef87b03fc40",
"body": "Walk every hop in the redirect chain rather than only checking the\ncurrent request's host. Once any hop leaves the original host, the\nfunction returns true for all subsequent requests in that chain, even\nif a later hop redirects back to the original host.\n\nThis mirrors net/http's own behaviour and closes the bypass window\nwhere a cross→original→cross chain could slip credentials through.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "config: make isCrossHostRedirect sticky across the redirect chain",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T12:25:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7fb7bb8b83c55c63c21a298349d4c2c12833d31",
"body": "config: strip credentials on cross-host redirects",
"is_bot": false,
"headline": "Merge pull request #901 from roidelapluie/roidelapluie/fixredirectauth",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-06-11T12:20:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c4a71620202112c595bba1ad397a038afabad60e",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#917)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-06-09T14:48:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d6a7988672c3c081cfb74cf757bd131e3a6e65eb",
"body": "Signed-off-by: Bryan Boreham <bjboreham@gmail.com>",
"is_bot": false,
"headline": "model: fix Time.UnmarshalJSON for larger negative numbers",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2026-06-08T16:56:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8b99aea5d8085de523f583ef1b73a832c44fbae2",
"body": "We don't need to modify the string version of the number via a memory\nallocation; it's much faster to modify the integer version.\n\nSigned-off-by: Bryan Boreham <bjboreham@gmail.com>",
"is_bot": false,
"headline": "model: remove allocation in Time.UnmarshalJSON",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2026-06-08T16:56:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98ca625caff21ab45c0aef3f532140d321a99368",
"body": "Use strings.Cut instead of strings.Split.\n\nSigned-off-by: Bryan Boreham <bjboreham@gmail.com>",
"is_bot": false,
"headline": "model: reduce allocations in Time.UnmarshalJSON",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2026-06-08T16:56:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4cc12e35c8ab4b6576a752141d0edabe3c540297",
"body": "Signed-off-by: Bryan Boreham <bjboreham@gmail.com>",
"is_bot": false,
"headline": "model: Add BenchmarkUnmarshalTime",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2026-06-08T16:56:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "56870db815d97a034c16766bcd1e63cd0431f6c2",
"body": "* Enable modernize linter\n* Add linter exceptions to match upstream Prometheus.\n* Apply linter improvements.\n\nSigned-off-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "Modernize Go",
"author_name": "SuperQ",
"author_login": "SuperQ",
"committed_at": "2026-06-08T14:47:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "212057321e897d625d07379aaddaca01afca7710",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#915)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-06-03T07:02:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "228386adfe1e9c8ede570fbca47782a9abca1a35",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.53.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.53.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.55.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.53.0 to 0.55.0 (#914)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T20:46:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8c88b4866403159e523c588dc7563b0f78c0418",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.52.0 to 0.53.0.\n- [Commits](https://github.com/golang/net/compare/v0.52.0...v0.53.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.53.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0 (#903)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T05:40:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e0ae832fb26a2c20c2c0d6ee1289111c668be18",
"body": "newOauth2TokenSource builds its own http.Transport to fetch tokens but\ndoesn't set DialContext on it. Any DialContextFunc passed via\nWithDialContextFunc is applied to the main request transport but silently\nskipped for the token endpoint.\n\nSet DialContext on the token transport the same way it is se\n[…]\nlt dialer.\n\nAdded TestOAuth2DialContextFunc to verify that WithDialContextFunc blocks\nthe token endpoint fetch, not only the final request.\n\nSigned-off-by: Yuri Tseretyan <yuriy.tseretyan@grafana.com>",
"is_bot": false,
"headline": "config: apply DialContextFunc to OAuth2 token-fetch transport (#911)",
"author_name": "Yuri Tseretyan",
"author_login": "yuri-tceretian",
"committed_at": "2026-05-28T23:44:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b51d01ba2175d103309dcee11f6c01bd03487a64",
"body": "Signed-off-by: Arthur Silva Sens <arthursens2005@gmail.com>",
"is_bot": false,
"headline": "Remove CircleCI (#910)",
"author_name": "Arthur Silva Sens",
"author_login": "ArthurSens",
"committed_at": "2026-05-27T19:34:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d8de871b3f26108faccbd9c935f406012b3d776",
"body": "When FollowRedirects is true, credentials (Authorization header, Cookie\nheaders set via HTTPHeaders) were forwarded to any redirect target,\nincluding cross-host redirects.\n\nFix by detecting cross-host redirects via isCrossHostRedirect, which\nwalks the req.Response chain to find the original request'\n[…]\na custom http.Client built from\nNewRoundTripperFromConfigWithContext directly.\n\nThis aligns to Go's HTTP client behaviour.\n\nSigned-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>",
"is_bot": false,
"headline": "config: strip credentials on cross-host redirects",
"author_name": "Julien Pivotto",
"author_login": "roidelapluie",
"committed_at": "2026-05-27T09:28:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0f3c348807322ea84d92fc7688b1b37a08e17d1f",
"body": "fix(http_config): fix client cert rotation when no CA is configured",
"is_bot": false,
"headline": "Merge pull request #908 from machine424/ttlsco",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-05-20T09:20:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "732a9cf781621a8d8f895ef933b78cf4e9f5d6af",
"body": "enabling client cert/key hot-reloading. However, RoundTrip() still\nunconditionally called updateRootCA on every transport rebuild. With\nno CA data it returned false, and the code called\nsettings.CA.Description() on nil, panicking (prometheus/prometheus#16622).\nstill failed with \"unable to use specif\n[…]\nt a CA as\n\nSee https://github.com/prometheus/prometheus/pull/18727/changes/a11607834e4fcdcc4f37570c6944f321734e3dc2\nfor a reproducer on Prometheus\n\nSigned-off-by: Ayoub Mrini <ayoubmrini424@gmail.com>",
"is_bot": false,
"headline": "fix(http_config): fix client cert rotation when no CA is configured",
"author_name": "Ayoub Mrini",
"author_login": "machine424",
"committed_at": "2026-05-19T22:34:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce9215c53d8c8e507c5f72a69d80568c072be3d9",
"body": "This is the only dependency on YAML in the model package.\nMoving it to the tests avoids pulling a dependency into the\nmain module of applications that don't otherwise use YAML.\n\nSigned-off-by: Michael Siegenthaler <msiegen@google.com>",
"is_bot": false,
"headline": "Move interface assertions to a test file (#839)",
"author_name": "Michael Siegenthaler",
"author_login": "msiegen",
"committed_at": "2026-04-24T16:52:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ba5ed78ffdaf199c6dded3ff8ac88edbdb53712",
"body": "Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.34.0 to 0.36.0.\n- [Commits](https://github.com/golang/oauth2/compare/v0.34.0...v0.36.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/oauth2\n dependency-version: 0.36.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.36.0 (#892)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-24T16:52:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f8ada69df73ad76cabef710856070a42ef420c0",
"body": "Bumps [go.yaml.in/yaml/v2](https://github.com/yaml/go-yaml) from 2.4.3 to 2.4.4.\n- [Commits](https://github.com/yaml/go-yaml/compare/v2.4.3...v2.4.4)\n\n---\nupdated-dependencies:\n- dependency-name: go.yaml.in/yaml/v2\n dependency-version: 2.4.4\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump go.yaml.in/yaml/v2 from 2.4.3 to 2.4.4 (#891)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-24T16:51:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5bf00a403bb54802756bd375c8e8ca92b9323c69",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.51.0 to 0.52.0.\n- [Commits](https://github.com/golang/net/compare/v0.51.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.52.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.51.0 to 0.52.0 (#890)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-22T12:15:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4fac5c9b6d9557a8bedfb177f4e87a8b26a41a1",
"body": "* config: guard against nil oauth2 credential in RoundTrip\n\ntoSecret returns (nil, nil) when no source is configured. Most callers\nguarded the returned SecretReader with an `!= nil` check before\ninvoking Fetch, but oauth2RoundTripper.RoundTrip reached directly into\nrt.oauthCredential.Immutable() and\n[…]\np nil guard: replace verbose explanation\n with a single-line note matching reviewer's suggestion\n\nSigned-off-by: Ali <alliasgher123@gmail.com>\n\n---------\n\nSigned-off-by: Ali <alliasgher123@gmail.com>",
"is_bot": false,
"headline": "config: guard against nil oauth2 credential in RoundTrip (#897)",
"author_name": "Ali Asghar",
"author_login": null,
"committed_at": "2026-04-15T13:07:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e2836377f2f792542d0eb4a42c073da751fa520",
"body": "…orted-options\n\nconfig: change NewOAuth2RoundTripper to accept variadic HTTPClientOption",
"is_bot": false,
"headline": "Merge pull request #898 from alliasgher/fix/NewOAuth2RoundTripper-exp…",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-04-15T12:54:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fa8f6bdedf035f61fba04747a06ade20103050e",
"body": "The fourth parameter was *httpClientOptions, an unexported type, making\nNewOAuth2RoundTripper effectively uncallable with a non-nil options\nargument from any package outside prometheus/common/config. Callers were\nforced to resort to reflection or unsafe pointer tricks.\n\nChange the signature to accep\n[…]\nassed &defaultHTTPClientOptions now pass no options\n(equivalent behaviour, defaultHTTPClientOptions is the zero value).\n\nFixes prometheus/prometheus#18329\n\nSigned-off-by: Ali <alliasgher123@gmail.com>",
"is_bot": false,
"headline": "config: change NewOAuth2RoundTripper to accept variadic HTTPClientOption",
"author_name": "Ali",
"author_login": null,
"committed_at": "2026-04-15T12:44:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a26ab27e8c9c9c85b010ab6904491d100c51dd9",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#896)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-04-09T08:12:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f7d77e97c10b80f5d231f32e7872dd6f009337cb",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#895)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-04-08T15:28:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0dfcdfb00df68e0b14a98f20d90f4b3ff12432e6",
"body": "Remove Arthur from maintainers list",
"is_bot": false,
"headline": "Merge pull request #885 from prometheus/remove-arthur",
"author_name": "Arthur Silva Sens",
"author_login": "ArthurSens",
"committed_at": "2026-03-17T20:48:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8392757d7ff6f7c1209210638728c5d702ec330e",
"body": "Add a function to enable structured logging of version info.\n\nExample use:\n```go\nlogger := promslog.New(promslog.Config{})\nlogger.Info(\"Starting Prometheus Server\", version.Slog()...)\n```\n\nSigned-off-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "version: Add a slog helper (#886)",
"author_name": "Ben Kochie",
"author_login": "SuperQ",
"committed_at": "2026-03-16T11:12:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9b9d15b160506c8b53429b694570bffafa2dfac",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.49.0 to 0.51.0.\n- [Commits](https://github.com/golang/net/compare/v0.49.0...v0.51.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.51.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.49.0 to 0.51.0 (#882)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-09T14:16:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a902616afe6cfb0cdd0f335ed3326c728fc85ade",
"body": "* Update minimum Go version to 1.26.0.\n* Update tests for Go 1.26.x.\n* Migrate to GitHub Actions.\n* Ignore package naming issues.\n\nSigned-off-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "Update for Go 1.26 (#883)",
"author_name": "Ben Kochie",
"author_login": "SuperQ",
"committed_at": "2026-03-09T14:00:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa19a4c096dab91167a6c97e515235c18eec53ac",
"body": "Signed-off-by: Arthur Silva Sens <arthursens2005@gmail.com>",
"is_bot": false,
"headline": "Remove Arthur from maintainers list",
"author_name": "Arthur Silva Sens",
"author_login": "ArthurSens",
"committed_at": "2026-03-09T13:08:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "afbd47d5f579d939e7d27ffb7abc649355ee7f6a",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#881)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-03-01T18:16:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4c38a0aea471ca7f831b352f08463e8b8d399f7",
"body": "* Remove withUnit flag and automatic adding of unit to metric name, change tests accordingly\n\nSigned-off-by: Arianna Vespri <arianna.vespri@yahoo.it>\n\n* Remove redundant tests and comments for OM creation\n\nSigned-off-by: Arianna Vespri <arianna.vespri@yahoo.it>\n\n* fix fmt number in test\n\nSigned-off-by: Arianna Vespri <arianna.vespri@yahoo.it>\n\n---------\n\nSigned-off-by: Arianna Vespri <arianna.vespri@yahoo.it>",
"is_bot": false,
"headline": "Remove logic adding unit to metrics name (#877)",
"author_name": "Arianna Vespri",
"author_login": "vesari",
"committed_at": "2026-02-24T09:23:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "adea6285c1c7447fcb7bfdeb6abfc6eff893e0a7",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#880)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-02-09T14:10:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28b645dd96866da2c1f6b2ba7acd9c7271732332",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#875)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-02-02T09:00:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f15ba0e989dcab790ac40072d2464f291201263",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.48.0 to 0.49.0.\n- [Commits](https://github.com/golang/net/compare/v0.48.0...v0.49.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.49.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.48.0 to 0.49.0 (#878)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-02T08:59:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f195342200b5cf49aa46c409ce490db66b8d28f9",
"body": "…879)\n\nBumps [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt) from 5.3.0 to 5.3.1.\n- [Release notes](https://github.com/golang-jwt/jwt/releases)\n- [Commits](https://github.com/golang-jwt/jwt/compare/v5.3.0...v5.3.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/golang-jwt\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump github.com/golang-jwt/jwt/v5 from 5.3.0 to 5.3.1 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-02T08:58:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5859ca128c9fbb30522c5d59273619ab03e9f0b7",
"body": "Synchronize common files from prometheus/prometheus",
"is_bot": false,
"headline": "Merge pull request #874 from prometheus/repo_sync",
"author_name": "Julien",
"author_login": "roidelapluie",
"committed_at": "2026-01-20T10:58:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d69b10a741139df1891d310bcad2bd7ed2efb39",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files",
"author_name": "prombot",
"author_login": "prombot",
"committed_at": "2026-01-19T17:52:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "578c7500fe0f69843d7cbb0fe1426887ce384793",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#873)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-01-15T16:07:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "934ff3789ee17026206fe4f7e5f59c0a09fbe511",
"body": "…(#870)\n\nBumps google.golang.org/protobuf from 1.36.10 to 1.36.11.\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/protobuf\n dependency-version: 1.36.11\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump google.golang.org/protobuf from 1.36.10 to 1.36.11 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-05T14:14:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e298042a032b79df579092a37dfe8b0364109f9",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.46.0 to 0.48.0.\n- [Commits](https://github.com/golang/net/compare/v0.46.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.48.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.46.0 to 0.48.0 (#872)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-05T14:10:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bd1c4009cceb4c76bc99f157e29493190520bd1",
"body": "* Update common Prometheus files\n\nSigned-off-by: prombot <prometheus-team@googlegroups.com>\n\n* Fixup linting issues.\n\nSigned-off-by: SuperQ <superq@gmail.com>\n\n---------\n\nSigned-off-by: prombot <prometheus-team@googlegroups.com>\nSigned-off-by: SuperQ <superq@gmail.com>\nCo-authored-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "Synchronize common files from prometheus/prometheus (#866)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2026-01-05T14:10:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b644201c5cd901cc580ab596f9f620c4f51d859d",
"body": "Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.32.0 to 0.34.0.\n- [Commits](https://github.com/golang/oauth2/compare/v0.32.0...v0.34.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/oauth2\n dependency-version: 0.34.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/oauth2 from 0.32.0 to 0.34.0 (#871)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-05T13:43:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d80d8544703e59a080a204b6f7429ac6561fb24f",
"body": "* chore: Add omitempty tag to all config fields\n\nSigned-off-by: Jorge Turrado <jorge.turrado@mail.schwarz>\n\n* chore: Add omitempty tag to all config fields\n\nSigned-off-by: Jorge Turrado <jorge.turrado@mail.schwarz>\n\n* chore: Add omitempty tag to all config fields\n\nSigned-off-by: Jorge Turrado <jorge.turrado@mail.schwarz>\n\n---------\n\nSigned-off-by: Jorge Turrado <jorge.turrado@mail.schwarz>",
"is_bot": false,
"headline": "chore: Add omitempty tag to all config fields (#865)",
"author_name": "Jorge Turrado Ferrero",
"author_login": "JorTurFer",
"committed_at": "2025-11-21T13:28:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04686b2cfc6804598d99b86070135f9266998c59",
"body": "…ng them (#864)\n\nSigned-off-by: Jorge Turrado <jorge.turrado@mail.schwarz>",
"is_bot": false,
"headline": "chore: 'omitempty' to Oauth2 fields with type Secret to avoid requiri…",
"author_name": "Jorge Turrado Ferrero",
"author_login": "JorTurFer",
"committed_at": "2025-11-20T08:17:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b2fbf31f0e2c21d9e1a4e51e698188fae258cb2",
"body": "* chore: clean up golangci-lint configuration\n\nSigned-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>\n\n* Update .golangci.yml to remove unused linters\n\nSigned-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>\n\n* Update .golangci.yml to remove excluded paths\n\nRemoved specific paths from the gol\n[…]\nieu MOREL <matthieu.morel35@gmail.com>\n\n---------\n\nSigned-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>\nSigned-off-by: Ben Kochie <superq@gmail.com>\nCo-authored-by: Ben Kochie <superq@gmail.com>",
"is_bot": false,
"headline": "chore: clean up golangci-lint configuration (#782)",
"author_name": "Matthieu MOREL",
"author_login": "mmorel-35",
"committed_at": "2025-11-18T10:24:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2cdb0785c1498399587cb0bf42aa960d810633a",
"body": "Config: remove outdated comment about HTTP/2 issues",
"is_bot": false,
"headline": "Merge pull request #863 from prometheus/remove-http2-comment",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2025-11-14T17:29:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd1ab56cc1e1d41dbc286d2e501e26515400b9be",
"body": "All the linked issues are resolved.\n\nSigned-off-by: Bryan Boreham <bjboreham@gmail.com>",
"is_bot": false,
"headline": "Config: remove outdated comment about HTTP/2 issues",
"author_name": "Bryan Boreham",
"author_login": "bboreham",
"committed_at": "2025-11-14T10:41:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4c0aea59fa97a7627730e65cb2e625ec9fc45cf",
"body": null,
"is_bot": false,
"headline": "Support JWT Profile for Authorization Grant (RFC 7523 3.1) (#862)",
"author_name": "Jorge Turrado Ferrero",
"author_login": "JorTurFer",
"committed_at": "2025-11-07T14:02:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "594f4d4a984eb5f1ca8f0983f8b1790e77a5a725",
"body": "Cut v0.67.2",
"is_bot": false,
"headline": "Merge pull request #861 from prometheus/beorn7/version",
"author_name": "Björn Rabenstein",
"author_login": "beorn7",
"committed_at": "2025-10-28T14:07:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "440c1a30a0315f2ca0dba99fd7fffb288a3e898b",
"body": "Signed-off-by: beorn7 <beorn@grafana.com>",
"is_bot": false,
"headline": "Cut v0.67.2",
"author_name": "beorn7",
"author_login": "beorn7",
"committed_at": "2025-10-28T13:07:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "acb18736bed74c218ee4023ed1e0e36cf2dd1612",
"body": "Cleanup linting issues",
"is_bot": false,
"headline": "Merge pull request #860 from prometheus/superq/linting",
"author_name": "Björn Rabenstein",
"author_login": "beorn7",
"committed_at": "2025-10-28T13:02:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e323394d0ceaccda49f263dc81456e33af4263b",
"body": "* Remove unused linting settings from golangci-lint config.\n* Fixup linting issues.\n\nSigned-off-by: SuperQ <superq@gmail.com>",
"is_bot": false,
"headline": "Cleanup linting issues",
"author_name": "SuperQ",
"author_login": "SuperQ",
"committed_at": "2025-10-28T12:58:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93d16be24f0c8b993d7caad3ba4a204333072798",
"body": "Signed-off-by: prombot <prometheus-team@googlegroups.com>",
"is_bot": false,
"headline": "Update common Prometheus files (#859)",
"author_name": "PrometheusBot",
"author_login": "prombot",
"committed_at": "2025-10-28T11:55:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8230d3b413edacdce864277e4f19216fc00b2600",
"body": "Fix panic in `tlsRoundTripper` when CA file is absent",
"is_bot": false,
"headline": "Merge pull request #792 from ndk/main",
"author_name": "George Krajcsovits",
"author_login": "krajorama",
"committed_at": "2025-10-28T11:42:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "633281f87944b4604e7c11a38619490226415979",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.44.0 to 0.46.0.\n- [Commits](https://github.com/golang/net/compare/v0.44.0...v0.46.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.46.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.44.0 to 0.46.0 (#856)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-13T12:48:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aca279f4420c7fe7c5a4a2199afa49b76afab834",
"body": "Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.31.0 to 0.32.0.\n- [Commits](https://github.com/golang/oauth2/compare/v0.31.0...v0.32.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/oauth2\n dependency-version: 0.32.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/oauth2 from 0.31.0 to 0.32.0 (#857)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-13T12:43:00Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 80,
"commits_last_year": 156,
"latest_release_at": "2026-07-22T06:10:58Z",
"latest_release_tag": "v0.70.1",
"releases_from_tags": false,
"days_since_last_push": 6,
"active_weeks_last_year": 34,
"days_since_latest_release": 6,
"mean_days_between_releases": 32
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/prometheus/common",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/prometheus/common",
"is_deprecated": false,
"latest_version": "v0.70.1",
"repository_url": "https://github.com/prometheus/common",
"versions_count": 128,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-22T06:06:48Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "github.com/prometheus/common/assets",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/prometheus/common/assets",
"is_deprecated": false,
"latest_version": "v0.2.0",
"repository_url": "https://github.com/prometheus/common",
"versions_count": 2,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2022-06-17T14:47:55Z",
"latest_version_yanked": null,
"days_since_latest_publish": 1501
}
]
},
"popularity": {
"forks": 360,
"stars": 295,
"watchers": 9,
"fork_history": {
"days": [
{
"date": "2015-07-25",
"count": 1
},
{
"date": "2015-10-01",
"count": 1
},
{
"date": "2015-10-10",
"count": 1
},
{
"date": "2015-10-26",
"count": 1
},
{
"date": "2016-03-29",
"count": 1
},
{
"date": "2016-04-26",
"count": 1
},
{
"date": "2016-05-26",
"count": 1
},
{
"date": "2016-06-07",
"count": 1
},
{
"date": "2016-08-29",
"count": 1
},
{
"date": "2016-09-09",
"count": 1
},
{
"date": "2016-12-18",
"count": 1
},
{
"date": "2017-04-08",
"count": 1
},
{
"date": "2017-04-25",
"count": 1
},
{
"date": "2017-05-27",
"count": 1
},
{
"date": "2017-06-05",
"count": 1
},
{
"date": "2017-06-13",
"count": 1
},
{
"date": "2017-06-15",
"count": 1
},
{
"date": "2017-07-05",
"count": 1
},
{
"date": "2017-07-20",
"count": 1
},
{
"date": "2017-08-16",
"count": 1
},
{
"date": "2017-08-30",
"count": 1
},
{
"date": "2017-08-31",
"count": 1
},
{
"date": "2017-09-25",
"count": 1
},
{
"date": "2017-09-26",
"count": 1
},
{
"date": "2017-10-16",
"count": 1
},
{
"date": "2017-11-04",
"count": 1
},
{
"date": "2017-11-17",
"count": 1
},
{
"date": "2017-12-21",
"count": 1
},
{
"date": "2017-12-22",
"count": 1
},
{
"date": "2018-01-01",
"count": 1
},
{
"date": "2018-01-10",
"count": 1
},
{
"date": "2018-01-30",
"count": 1
},
{
"date": "2018-02-28",
"count": 1
},
{
"date": "2018-03-01",
"count": 1
},
{
"date": "2018-03-05",
"count": 1
},
{
"date": "2018-03-11",
"count": 1
},
{
"date": "2018-03-14",
"count": 1
},
{
"date": "2018-03-22",
"count": 1
},
{
"date": "2018-03-24",
"count": 1
},
{
"date": "2018-04-02",
"count": 1
},
{
"date": "2018-04-10",
"count": 1
},
{
"date": "2018-04-12",
"count": 1
},
{
"date": "2018-04-26",
"count": 1
},
{
"date": "2018-05-03",
"count": 1
},
{
"date": "2018-05-05",
"count": 1
},
{
"date": "2018-05-11",
"count": 1
},
{
"date": "2018-05-17",
"count": 1
},
{
"date": "2018-05-22",
"count": 1
},
{
"date": "2018-06-01",
"count": 1
},
{
"date": "2018-06-16",
"count": 1
},
{
"date": "2018-06-29",
"count": 1
},
{
"date": "2018-07-21",
"count": 1
},
{
"date": "2018-08-27",
"count": 1
},
{
"date": "2018-08-30",
"count": 1
},
{
"date": "2018-09-05",
"count": 1
},
{
"date": "2018-09-27",
"count": 2
},
{
"date": "2018-10-19",
"count": 1
},
{
"date": "2018-11-01",
"count": 1
},
{
"date": "2018-11-16",
"count": 1
},
{
"date": "2018-11-29",
"count": 1
},
{
"date": "2018-12-20",
"count": 1
},
{
"date": "2019-02-01",
"count": 1
},
{
"date": "2019-02-05",
"count": 1
},
{
"date": "2019-02-17",
"count": 1
},
{
"date": "2019-03-21",
"count": 1
},
{
"date": "2019-03-29",
"count": 1
},
{
"date": "2019-04-04",
"count": 1
},
{
"date": "2019-04-10",
"count": 1
},
{
"date": "2019-04-22",
"count": 1
},
{
"date": "2019-05-04",
"count": 1
},
{
"date": "2019-05-07",
"count": 1
},
{
"date": "2019-05-11",
"count": 1
},
{
"date": "2019-05-29",
"count": 1
},
{
"date": "2019-06-25",
"count": 1
},
{
"date": "2019-06-27",
"count": 1
},
{
"date": "2019-07-02",
"count": 1
},
{
"date": "2019-07-26",
"count": 1
},
{
"date": "2019-07-30",
"count": 1
},
{
"date": "2019-08-23",
"count": 1
},
{
"date": "2019-08-29",
"count": 1
},
{
"date": "2019-09-01",
"count": 1
},
{
"date": "2019-09-24",
"count": 1
},
{
"date": "2019-10-22",
"count": 1
},
{
"date": "2019-10-29",
"count": 1
},
{
"date": "2019-11-08",
"count": 1
},
{
"date": "2019-11-12",
"count": 1
},
{
"date": "2019-11-21",
"count": 1
},
{
"date": "2020-02-25",
"count": 2
},
{
"date": "2020-03-18",
"count": 1
},
{
"date": "2020-03-23",
"count": 1
},
{
"date": "2020-04-03",
"count": 1
},
{
"date": "2020-04-09",
"count": 1
},
{
"date": "2020-05-05",
"count": 1
},
{
"date": "2020-05-06",
"count": 1
},
{
"date": "2020-05-18",
"count": 1
},
{
"date": "2020-05-25",
"count": 1
},
{
"date": "2020-05-26",
"count": 1
},
{
"date": "2020-06-18",
"count": 1
},
{
"date": "2020-06-19",
"count": 1
},
{
"date": "2020-06-24",
"count": 1
},
{
"date": "2020-06-29",
"count": 2
},
{
"date": "2020-07-03",
"count": 1
},
{
"date": "2020-07-08",
"count": 1
},
{
"date": "2020-07-11",
"count": 1
},
{
"date": "2020-07-24",
"count": 1
},
{
"date": "2020-07-28",
"count": 1
},
{
"date": "2020-08-19",
"count": 1
},
{
"date": "2020-08-20",
"count": 1
},
{
"date": "2020-09-02",
"count": 1
},
{
"date": "2020-09-08",
"count": 1
},
{
"date": "2020-09-10",
"count": 1
},
{
"date": "2020-09-22",
"count": 1
},
{
"date": "2020-10-16",
"count": 1
},
{
"date": "2020-10-21",
"count": 1
},
{
"date": "2020-11-06",
"count": 2
},
{
"date": "2020-11-12",
"count": 1
},
{
"date": "2020-11-17",
"count": 1
},
{
"date": "2020-11-25",
"count": 1
},
{
"date": "2020-12-06",
"count": 1
},
{
"date": "2020-12-07",
"count": 1
},
{
"date": "2020-12-12",
"count": 1
},
{
"date": "2020-12-30",
"count": 1
},
{
"date": "2021-01-11",
"count": 1
},
{
"date": "2021-01-14",
"count": 1
},
{
"date": "2021-02-05",
"count": 3
},
{
"date": "2021-02-08",
"count": 1
},
{
"date": "2021-02-17",
"count": 1
},
{
"date": "2021-03-08",
"count": 1
},
{
"date": "2021-03-15",
"count": 1
},
{
"date": "2021-03-17",
"count": 2
},
{
"date": "2021-04-01",
"count": 1
},
{
"date": "2021-04-03",
"count": 1
},
{
"date": "2021-04-11",
"count": 1
},
{
"date": "2021-04-15",
"count": 1
},
{
"date": "2021-05-05",
"count": 1
},
{
"date": "2021-05-17",
"count": 1
},
{
"date": "2021-05-18",
"count": 1
},
{
"date": "2021-05-19",
"count": 2
},
{
"date": "2021-05-23",
"count": 1
},
{
"date": "2021-05-26",
"count": 1
},
{
"date": "2021-06-02",
"count": 1
},
{
"date": "2021-06-08",
"count": 2
},
{
"date": "2021-06-14",
"count": 1
},
{
"date": "2021-06-15",
"count": 1
},
{
"date": "2021-06-19",
"count": 1
},
{
"date": "2021-07-02",
"count": 1
},
{
"date": "2021-07-09",
"count": 1
},
{
"date": "2021-07-16",
"count": 2
},
{
"date": "2021-07-20",
"count": 1
},
{
"date": "2021-08-12",
"count": 1
},
{
"date": "2021-08-20",
"count": 1
},
{
"date": "2021-08-24",
"count": 1
},
{
"date": "2021-08-26",
"count": 1
},
{
"date": "2021-08-31",
"count": 1
},
{
"date": "2021-09-07",
"count": 1
},
{
"date": "2021-09-16",
"count": 1
},
{
"date": "2021-09-23",
"count": 1
},
{
"date": "2021-09-29",
"count": 1
},
{
"date": "2021-10-02",
"count": 1
},
{
"date": "2021-10-11",
"count": 1
},
{
"date": "2021-10-12",
"count": 1
},
{
"date": "2021-10-15",
"count": 1
},
{
"date": "2021-10-20",
"count": 1
},
{
"date": "2021-11-05",
"count": 1
},
{
"date": "2021-11-16",
"count": 1
},
{
"date": "2021-11-17",
"count": 1
},
{
"date": "2021-11-24",
"count": 1
},
{
"date": "2021-11-28",
"count": 1
},
{
"date": "2021-12-01",
"count": 1
},
{
"date": "2021-12-13",
"count": 1
},
{
"date": "2021-12-17",
"count": 1
},
{
"date": "2021-12-23",
"count": 1
},
{
"date": "2022-02-08",
"count": 1
},
{
"date": "2022-02-11",
"count": 1
},
{
"date": "2022-02-15",
"count": 1
},
{
"date": "2022-02-17",
"count": 1
},
{
"date": "2022-02-23",
"count": 1
},
{
"date": "2022-02-26",
"count": 2
},
{
"date": "2022-03-01",
"count": 1
},
{
"date": "2022-03-02",
"count": 1
},
{
"date": "2022-03-04",
"count": 1
},
{
"date": "2022-03-09",
"count": 2
},
{
"date": "2022-03-10",
"count": 2
},
{
"date": "2022-03-17",
"count": 1
},
{
"date": "2022-03-21",
"count": 1
},
{
"date": "2022-03-29",
"count": 1
},
{
"date": "2022-04-12",
"count": 1
},
{
"date": "2022-05-10",
"count": 1
},
{
"date": "2022-05-16",
"count": 1
},
{
"date": "2022-05-19",
"count": 1
},
{
"date": "2022-06-07",
"count": 1
},
{
"date": "2022-06-08",
"count": 1
},
{
"date": "2022-06-27",
"count": 1
},
{
"date": "2022-06-28",
"count": 1
},
{
"date": "2022-07-09",
"count": 1
},
{
"date": "2022-07-13",
"count": 1
},
{
"date": "2022-07-14",
"count": 1
},
{
"date": "2022-07-20",
"count": 1
},
{
"date": "2022-08-16",
"count": 2
},
{
"date": "2022-08-29",
"count": 1
},
{
"date": "2022-09-26",
"count": 1
},
{
"date": "2022-10-07",
"count": 1
},
{
"date": "2022-10-14",
"count": 1
},
{
"date": "2022-10-21",
"count": 1
},
{
"date": "2022-11-11",
"count": 1
},
{
"date": "2022-11-14",
"count": 1
},
{
"date": "2022-11-17",
"count": 1
},
{
"date": "2022-11-22",
"count": 1
},
{
"date": "2022-11-26",
"count": 2
},
{
"date": "2022-11-28",
"count": 1
},
{
"date": "2022-12-05",
"count": 1
},
{
"date": "2022-12-08",
"count": 1
},
{
"date": "2022-12-12",
"count": 1
},
{
"date": "2022-12-22",
"count": 1
},
{
"date": "2022-12-28",
"count": 1
},
{
"date": "2023-01-10",
"count": 1
},
{
"date": "2023-01-26",
"count": 2
},
{
"date": "2023-02-09",
"count": 1
},
{
"date": "2023-03-23",
"count": 1
},
{
"date": "2023-03-27",
"count": 2
},
{
"date": "2023-04-14",
"count": 1
},
{
"date": "2023-04-22",
"count": 1
},
{
"date": "2023-04-24",
"count": 1
},
{
"date": "2023-05-15",
"count": 1
},
{
"date": "2023-05-22",
"count": 1
},
{
"date": "2023-06-13",
"count": 1
},
{
"date": "2023-07-06",
"count": 1
},
{
"date": "2023-07-07",
"count": 1
},
{
"date": "2023-07-13",
"count": 1
},
{
"date": "2023-07-17",
"count": 1
},
{
"date": "2023-07-31",
"count": 1
},
{
"date": "2023-08-13",
"count": 1
},
{
"date": "2023-08-15",
"count": 2
},
{
"date": "2023-08-21",
"count": 1
},
{
"date": "2023-09-18",
"count": 1
},
{
"date": "2023-10-06",
"count": 1
},
{
"date": "2023-10-12",
"count": 1
},
{
"date": "2023-10-25",
"count": 1
},
{
"date": "2023-10-30",
"count": 1
},
{
"date": "2023-11-15",
"count": 1
},
{
"date": "2023-11-18",
"count": 2
},
{
"date": "2023-11-19",
"count": 1
},
{
"date": "2023-11-30",
"count": 1
},
{
"date": "2023-12-01",
"count": 1
},
{
"date": "2023-12-10",
"count": 1
},
{
"date": "2023-12-14",
"count": 1
},
{
"date": "2024-01-02",
"count": 1
},
{
"date": "2024-01-06",
"count": 1
},
{
"date": "2024-01-12",
"count": 2
},
{
"date": "2024-01-13",
"count": 1
},
{
"date": "2024-01-31",
"count": 1
},
{
"date": "2024-02-12",
"count": 1
},
{
"date": "2024-03-21",
"count": 1
},
{
"date": "2024-04-01",
"count": 1
},
{
"date": "2024-04-03",
"count": 1
},
{
"date": "2024-04-12",
"count": 1
},
{
"date": "2024-04-19",
"count": 1
},
{
"date": "2024-04-24",
"count": 1
},
{
"date": "2024-04-29",
"count": 1
},
{
"date": "2024-05-15",
"count": 1
},
{
"date": "2024-05-18",
"count": 1
},
{
"date": "2024-06-04",
"count": 1
},
{
"date": "2024-06-12",
"count": 2
},
{
"date": "2024-07-14",
"count": 1
},
{
"date": "2024-07-16",
"count": 1
},
{
"date": "2024-07-22",
"count": 1
},
{
"date": "2024-07-23",
"count": 1
},
{
"date": "2024-07-25",
"count": 1
},
{
"date": "2024-08-01",
"count": 1
},
{
"date": "2024-08-09",
"count": 1
},
{
"date": "2024-08-12",
"count": 1
},
{
"date": "2024-08-13",
"count": 1
},
{
"date": "2024-09-21",
"count": 1
},
{
"date": "2024-10-01",
"count": 1
},
{
"date": "2024-10-10",
"count": 1
},
{
"date": "2024-10-16",
"count": 1
},
{
"date": "2024-10-21",
"count": 2
},
{
"date": "2024-11-19",
"count": 1
},
{
"date": "2025-02-08",
"count": 1
},
{
"date": "2025-02-11",
"count": 1
},
{
"date": "2025-02-28",
"count": 1
},
{
"date": "2025-03-13",
"count": 1
},
{
"date": "2025-03-16",
"count": 1
},
{
"date": "2025-03-28",
"count": 1
},
{
"date": "2025-06-02",
"count": 1
},
{
"date": "2025-06-03",
"count": 1
},
{
"date": "2025-06-17",
"count": 1
},
{
"date": "2025-06-19",
"count": 1
},
{
"date": "2025-06-24",
"count": 1
},
{
"date": "2025-07-07",
"count": 1
},
{
"date": "2025-08-01",
"count": 1
},
{
"date": "2025-08-05",
"count": 1
},
{
"date": "2025-08-13",
"count": 1
},
{
"date": "2025-09-02",
"count": 1
},
{
"date": "2025-09-05",
"count": 1
},
{
"date": "2025-09-06",
"count": 1
},
{
"date": "2025-09-07",
"count": 1
},
{
"date": "2025-09-23",
"count": 1
},
{
"date": "2025-10-07",
"count": 1
},
{
"date": "2025-10-17",
"count": 1
},
{
"date": "2025-10-30",
"count": 1
},
{
"date": "2025-11-15",
"count": 1
},
{
"date": "2025-11-26",
"count": 1
},
{
"date": "2025-12-02",
"count": 1
},
{
"date": "2026-03-15",
"count": 1
},
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-03-26",
"count": 1
},
{
"date": "2026-03-29",
"count": 2
},
{
"date": "2026-03-31",
"count": 1
},
{
"date": "2026-04-13",
"count": 1
},
{
"date": "2026-04-24",
"count": 1
},
{
"date": "2026-05-03",
"count": 1
},
{
"date": "2026-05-12",
"count": 2
},
{
"date": "2026-05-18",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-27",
"count": 2
},
{
"date": "2026-06-01",
"count": 1
},
{
"date": "2026-06-04",
"count": 1
},
{
"date": "2026-06-05",
"count": 1
},
{
"date": "2026-06-12",
"count": 1
},
{
"date": "2026-06-20",
"count": 1
},
{
"date": "2026-06-23",
"count": 1
},
{
"date": "2026-06-30",
"count": 1
},
{
"date": "2026-07-21",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
},
{
"date": "2026-07-28",
"count": 2
}
],
"complete": true,
"collected": 352,
"total_forks": 360
},
"star_history": null,
"open_issues_and_prs": 85
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"assets/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"assets/go.mod",
"go.mod"
],
"largest_source_bytes": 87102,
"source_files_sampled": 64,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"assets/go.mod",
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "1.11.0",
"severity": "high",
"ecosystem": "go",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-cg3q-j54f-5p7p",
"GO-2022-0322"
],
"fixed_version": "1.11.1",
"advisory_count": 2,
"oldest_advisory_days": 1622
},
{
"name": "github.com/aws/aws-sdk-go",
"direct": false,
"version": "1.38.35",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2022-0635",
"GO-2022-0646"
],
"fixed_version": null,
"advisory_count": 2,
"oldest_advisory_days": 1627
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 1,
"unknown": 1
},
"advisory_count": 4,
"affected_count": 2,
"assessed_count": 30,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/stretchr/testify",
"manifest": "assets/go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/alecthomas/kingpin/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.3.1"
},
{
"name": "github.com/google/go-cmp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/julienschmidt/httprouter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "github.com/munnerz/goautoneg",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20191010083416-a7dc8b61c822"
},
{
"name": "github.com/mwitkow/go-conntrack",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20190716064945-2f068394615f"
},
{
"name": "github.com/prometheus/client_model",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "go.yaml.in/yaml/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.4"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.57.0"
},
{
"name": "golang.org/x/oauth2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/alecthomas/kingpin/v2",
"direct": true,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"direct": true,
"version": "v5.3.1",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": true,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/julienschmidt/httprouter",
"direct": true,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/munnerz/goautoneg",
"direct": true,
"version": "v0.0.0-20191010083416-a7dc8b61c822",
"ecosystem": "go"
},
{
"name": "github.com/mwitkow/go-conntrack",
"direct": true,
"version": "v0.0.0-20190716064945-2f068394615f",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": true,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "1.7.0",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v2",
"direct": true,
"version": "v2.4.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.57.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": true,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": true,
"version": "v1.36.11",
"ecosystem": "go"
},
{
"name": "github.com/alecthomas/units",
"direct": false,
"version": "v0.0.0-20240927000941-0f3dac36c52b",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go",
"direct": false,
"version": "1.38.35",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/jpillora/backoff",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "1.11.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.23.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "0.29.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "github.com/xhit/go-str2duration/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v2",
"direct": false,
"version": "2.4.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": false,
"version": "v3.0.1",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 30,
"direct_count": 14,
"indirect_count": 16
}
},
"maintainership": {
"issues": {
"open_prs": 44,
"merged_prs": 589,
"open_issues": 41,
"closed_ratio": 0.719,
"closed_issues": 105,
"closed_unmerged_prs": 171
},
"bus_factor": 5,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "fabxc",
"commits": 102,
"avatar_url": "https://avatars.githubusercontent.com/u/4948210?v=4"
},
{
"type": "User",
"login": "SuperQ",
"commits": 85,
"avatar_url": "https://avatars.githubusercontent.com/u/1320667?v=4"
},
{
"type": "User",
"login": "prombot",
"commits": 79,
"avatar_url": "https://avatars.githubusercontent.com/u/18470668?v=4"
},
{
"type": "User",
"login": "beorn7",
"commits": 61,
"avatar_url": "https://avatars.githubusercontent.com/u/5609886?v=4"
},
{
"type": "User",
"login": "roidelapluie",
"commits": 41,
"avatar_url": "https://avatars.githubusercontent.com/u/291750?v=4"
},
{
"type": "User",
"login": "juliusv",
"commits": 27,
"avatar_url": "https://avatars.githubusercontent.com/u/538008?v=4"
},
{
"type": "User",
"login": "ywwg",
"commits": 23,
"avatar_url": "https://avatars.githubusercontent.com/u/888940?v=4"
},
{
"type": "User",
"login": "ArthurSens",
"commits": 21,
"avatar_url": "https://avatars.githubusercontent.com/u/24193764?v=4"
},
{
"type": "User",
"login": "zenador",
"commits": 21,
"avatar_url": "https://avatars.githubusercontent.com/u/9277453?v=4"
},
{
"type": "User",
"login": "simonpasquier",
"commits": 20,
"avatar_url": "https://avatars.githubusercontent.com/u/2587585?v=4"
}
],
"contributors_sampled": 99,
"top_contributor_share": 0.139
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"approve-workflows.yml",
"ci.yml",
"codeql.yml",
"golangci-lint.yml",
"govulncheck.yml",
"scorecard.yml"
],
"has_docs_dir": false,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "20 out of 20 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 28 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 9,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "b63d8c0f100a0788a91445e376ec3b1598e69c99",
"ran_at": "2026-07-28T13:02:43Z",
"aggregate_score": 9.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-28T03:42:06Z",
"oldest_open_prs": [
{
"number": 318,
"created_at": "2021-07-21T14:38:38Z",
"last_comment_at": "2023-02-25T11:17:00Z",
"last_comment_author": "SuperQ"
},
{
"number": 320,
"created_at": "2021-08-02T16:41:41Z",
"last_comment_at": "2021-10-12T23:03:57Z",
"last_comment_author": "mem"
},
{
"number": 323,
"created_at": "2021-09-07T10:35:00Z",
"last_comment_at": "2021-09-07T13:12:26Z",
"last_comment_author": "asuffield"
},
{
"number": 324,
"created_at": "2021-09-12T20:40:26Z",
"last_comment_at": "2022-12-21T13:56:06Z",
"last_comment_author": "LeviHarrison"
},
{
"number": 333,
"created_at": "2021-10-11T21:56:10Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 369,
"created_at": "2022-04-04T17:32:36Z",
"last_comment_at": "2022-04-21T22:01:11Z",
"last_comment_author": "roidelapluie"
},
{
"number": 392,
"created_at": "2022-07-14T11:12:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 394,
"created_at": "2022-07-20T17:14:13Z",
"last_comment_at": "2022-11-03T14:36:27Z",
"last_comment_author": "roidelapluie"
},
{
"number": 406,
"created_at": "2022-10-14T18:33:53Z",
"last_comment_at": "2022-11-03T14:21:49Z",
"last_comment_author": "roidelapluie"
},
{
"number": 426,
"created_at": "2022-12-17T02:19:25Z",
"last_comment_at": "2022-12-17T07:54:31Z",
"last_comment_author": "roidelapluie"
},
{
"number": 464,
"created_at": "2023-03-23T02:56:15Z",
"last_comment_at": "2023-04-27T04:56:15Z",
"last_comment_author": "roidelapluie"
},
{
"number": 502,
"created_at": "2023-07-07T06:24:55Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 503,
"created_at": "2023-07-13T05:00:11Z",
"last_comment_at": "2023-10-23T06:46:48Z",
"last_comment_author": "bartsmykla"
},
{
"number": 505,
"created_at": "2023-07-31T06:57:08Z",
"last_comment_at": "2023-09-26T10:03:56Z",
"last_comment_author": "roidelapluie"
},
{
"number": 510,
"created_at": "2023-08-22T02:28:33Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 512,
"created_at": "2023-09-18T12:58:19Z",
"last_comment_at": "2023-10-27T04:59:46Z",
"last_comment_author": "dongjiang1989"
},
{
"number": 553,
"created_at": "2023-12-14T12:23:36Z",
"last_comment_at": "2024-10-01T19:33:24Z",
"last_comment_author": "muety"
},
{
"number": 645,
"created_at": "2024-06-03T17:21:44Z",
"last_comment_at": "2025-01-21T18:15:15Z",
"last_comment_author": "jkroepke"
},
{
"number": 706,
"created_at": "2024-10-10T18:55:09Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 758,
"created_at": "2025-02-10T19:31:42Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-22T06:06:48Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 33,
"created_at": "2016-03-08T10:18:17Z",
"last_comment_at": "2021-10-17T13:02:58Z",
"last_comment_author": "roidelapluie"
},
{
"number": 50,
"created_at": "2016-08-02T11:07:37Z",
"last_comment_at": "2016-09-09T14:44:47Z",
"last_comment_author": "beorn7"
},
{
"number": 51,
"created_at": "2016-08-19T21:59:13Z",
"last_comment_at": "2017-08-08T16:48:29Z",
"last_comment_author": "beorn7"
},
{
"number": 97,
"created_at": "2017-08-10T09:54:53Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 98,
"created_at": "2017-08-11T11:10:56Z",
"last_comment_at": "2019-08-07T17:20:57Z",
"last_comment_author": "brian-brazil"
},
{
"number": 143,
"created_at": "2018-09-13T14:55:27Z",
"last_comment_at": "2018-09-13T15:03:38Z",
"last_comment_author": "brian-brazil"
},
{
"number": 214,
"created_at": "2019-11-28T12:51:28Z",
"last_comment_at": "2020-01-20T12:10:54Z",
"last_comment_author": "beorn7"
},
{
"number": 222,
"created_at": "2020-02-07T09:17:49Z",
"last_comment_at": "2020-02-07T12:28:53Z",
"last_comment_author": "brian-brazil"
},
{
"number": 223,
"created_at": "2020-02-18T17:27:24Z",
"last_comment_at": "2024-07-14T12:18:51Z",
"last_comment_author": "SuperQ"
},
{
"number": 245,
"created_at": "2020-07-21T10:17:41Z",
"last_comment_at": "2020-07-24T14:02:52Z",
"last_comment_author": "simonpasquier"
},
{
"number": 253,
"created_at": "2020-08-27T23:51:24Z",
"last_comment_at": "2020-09-07T20:22:59Z",
"last_comment_author": "beorn7"
},
{
"number": 254,
"created_at": "2020-09-01T08:39:29Z",
"last_comment_at": "2021-09-20T20:16:59Z",
"last_comment_author": "isabelgiang"
},
{
"number": 319,
"created_at": "2021-07-25T11:55:31Z",
"last_comment_at": "2021-07-26T14:31:58Z",
"last_comment_author": "beorn7"
},
{
"number": 341,
"created_at": "2021-11-02T10:00:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 342,
"created_at": "2021-11-04T11:39:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 349,
"created_at": "2021-12-20T13:17:34Z",
"last_comment_at": "2024-03-22T19:09:51Z",
"last_comment_author": "shurkus"
},
{
"number": 352,
"created_at": "2021-12-25T11:02:53Z",
"last_comment_at": "2024-10-07T14:10:28Z",
"last_comment_author": "roidelapluie"
},
{
"number": 361,
"created_at": "2022-03-16T19:16:36Z",
"last_comment_at": "2022-09-18T21:22:02Z",
"last_comment_author": "dswarbrick"
},
{
"number": 381,
"created_at": "2022-05-19T23:11:54Z",
"last_comment_at": "2023-06-05T02:15:06Z",
"last_comment_author": "edoger"
},
{
"number": 398,
"created_at": "2022-08-03T08:09:26Z",
"last_comment_at": "2022-08-03T08:13:30Z",
"last_comment_author": "kitianFresh"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/prometheus/common",
"host": "github.com",
"name": "common",
"owner": "prometheus"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"security": 93,
"vitality": 93,
"community": 75,
"governance": 86,
"engineering": 70
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 93,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 88,
"inputs": {
"commits_last_year": 156,
"human_commit_share": 0.77,
"days_since_last_push": 6,
"active_weeks_last_year": 34
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "34/52 weeks with commits",
"points": 23.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 34
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "156 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 156
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 80,
"latest_release_tag": "v0.70.1",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 32
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "80 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 80
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~32 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 32
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 7,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 7 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 7
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 75,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"forks": 360,
"stars": 295,
"watchers": 9,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "295 stars",
"points": 40,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 295
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "360 forks",
"points": 21.3,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 360
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "9 watchers",
"points": 5,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 9
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "excellent",
"name": "Sustainability & Governance",
"value": 86,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "excellent",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 89,
"inputs": {
"bus_factor": 5,
"contributors_sampled": 99,
"top_contributor_share": 0.139
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "5 contributor(s) cover half of all commits",
"points": 45.9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 5
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 14% of commits",
"points": 19.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 14
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "99 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 99
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 28 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"merged_prs": 589,
"open_issues": 41,
"closed_issues": 105,
"issue_closed_ratio": 0.719,
"closed_unmerged_prs": 171
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "72% of issues closed",
"points": 33.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 72
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "589/760 decided PRs merged",
"points": 29.6,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 589,
"decided": 760
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"followers": 4674,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "prometheus",
"public_repos": 58,
"account_age_days": 4932
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "4,674 followers of prometheus",
"points": 25,
"status": "met",
"details": [
{
"code": "owner_followers",
"params": {
"count": 4674,
"login": "prometheus"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "58 public repos, account ~13 yr old",
"points": 24.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 58
}
},
{
"code": "account_age_years",
"params": {
"years": 13
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/prometheus/common",
"github.com/prometheus/common/assets"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "128 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 128
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 70,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "20 out of 20 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "excellent",
"name": "Security",
"value": 93,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "excellent",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 91,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 9.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "20 out of 20 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 28 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 30 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 30
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 4,
"affected_packages": 2,
"assessed_packages": 30,
"unassessed_packages": 0,
"affected_by_severity": "high 1, unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 30,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 8
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 74,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.909,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "70 of 77 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 70,
"sampled": 77
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"assets/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"assets/go.mod",
"go.mod"
],
"dependency_bot_commit_share": 0.23
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, assets/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, assets/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "23 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 23,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 87102,
"source_files_sampled": 64,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/64 source files over 60KB",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 64,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-28T13:03:11.243984Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/prometheus/common.svg",
"full_name": "prometheus/common",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}