JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"documentation",
"hosting",
"static",
"static-docs-hosting",
"static-documentation-hosting"
],
"is_fork": false,
"size_kb": 46272,
"has_wiki": true,
"homepage": "https://git.mmo.to/qwc-open/asiakirjat",
"languages": {
"Go": 707880,
"CSS": 18861,
"HTML": 73738,
"Dockerfile": 738,
"JavaScript": 49647
},
"pushed_at": "2026-07-13T12:20:08Z",
"created_at": "2026-02-04T11:58:04Z",
"owner_type": "User",
"updated_at": "2026-07-13T12:20:38Z",
"description": "Documentation hosting app, that just works. Including auth through LDAP, OAuth2 or built-in and full-text search in all docs. (Mirror from private forgejo instance)",
"is_archived": false,
"is_disabled": false,
"license_spdx": "AGPL-3.0",
"default_branch": "main",
"license_spdx_raw": "AGPL-3.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://gitea.mmo.to",
"name": "Marcel M. Otte",
"type": "User",
"login": "qwc",
"company": "@Zeiss, mmo.to",
"location": "Earth",
"followers": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/1408353?v=4",
"created_at": "2012-02-04T17:02:30Z",
"is_verified": null,
"public_repos": 15,
"account_age_days": 5287
},
"license": {
"state": "standard",
"spdx_id": "AGPL-3.0",
"raw_spdx": "AGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.8.2",
"kind": "patch",
"published_at": "2026-07-07T18:01:53Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2026-06-18T11:32:38Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-06-18T09:01:52Z"
},
{
"tag": "v0.8.0-rc3",
"kind": "prerelease",
"published_at": "2026-06-18T09:01:52Z"
},
{
"tag": "v0.8.0-rc2",
"kind": "prerelease",
"published_at": "2026-06-18T08:04:49Z"
},
{
"tag": "v0.8.0-rc1",
"kind": "prerelease",
"published_at": "2026-06-18T06:04:07Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-05-19T05:26:59Z"
},
{
"tag": "v0.7.0-rc2",
"kind": "prerelease",
"published_at": "2026-05-19T05:26:59Z"
},
{
"tag": "v0.7.0-rc1",
"kind": "prerelease",
"published_at": "2026-05-18T21:09:24Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-03-06T10:29:51Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-03-05T08:17:01Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-02-20T07:31:19Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-02-20T06:46:19Z"
},
{
"tag": "v0.5.0-beta-pdf-2",
"kind": "prerelease",
"published_at": "2026-02-17T09:49:24Z"
},
{
"tag": "v0.5.0-beta-searchable-pdf",
"kind": "prerelease",
"published_at": "2026-02-16T17:29:36Z"
},
{
"tag": "v0.5.0-beta-pdf",
"kind": "prerelease",
"published_at": "2026-02-16T17:07:49Z"
},
{
"tag": "v0.5.0-beta+pdfsupport",
"kind": "prerelease",
"published_at": "2026-02-16T17:07:49Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-02-16T16:32:02Z"
},
{
"tag": "v0.4.0-test1",
"kind": "prerelease",
"published_at": "2026-02-16T16:39:35Z"
},
{
"tag": "v0.3.9",
"kind": "patch",
"published_at": "2026-02-10T14:46:19Z"
},
{
"tag": "v0.3.8",
"kind": "patch",
"published_at": "2026-02-10T14:34:42Z"
},
{
"tag": "v0.3.7",
"kind": "patch",
"published_at": "2026-02-10T13:33:52Z"
},
{
"tag": "v0.3.6",
"kind": "patch",
"published_at": "2026-02-10T13:01:40Z"
},
{
"tag": "v0.3.5",
"kind": "patch",
"published_at": "2026-02-09T16:40:04Z"
},
{
"tag": "v0.3.4",
"kind": "patch",
"published_at": "2026-02-06T13:36:59Z"
},
{
"tag": "v0.3.3",
"kind": "patch",
"published_at": "2026-02-05T14:58:47Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-02-05T09:52:51Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-02-05T06:35:11Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-02-04T18:48:00Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-02-04T13:43:52Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-02-04T13:14:46Z"
},
{
"tag": "v0.1.3",
"kind": "patch",
"published_at": "2026-02-04T10:48:26Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2026-02-04T08:02:59Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-02-04T07:31:01Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-02-04T07:14:50Z"
}
],
"recent_commits": [
{
"oid": "fd663cb90fe19a4beea7926e12150eec6b0559c6",
"body": "…4) from chore/relicense-agpl into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/124",
"is_bot": false,
"headline": "Merge pull request 'Relicense from GPL-3.0 to AGPL-3.0-or-later' (#12…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-07-09T20:15:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0b3c451addd94ff031a2a73a017d5da758ecd1d",
"body": "- Add a License section (AGPL-3.0-or-later) alongside the relicense.\n- Add shipped features that were missing from the list: /latest/ permalink\n with pinned version, version comparison/diff view, inline PDF viewer.\n- Drop the \"stretch-goal\" framing for full-text search — it's implemented.\n- Add a short Building and Running / configuration section.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update readme: AGPL license, missing features, run/config notes",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-07-09T16:13:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2d96fdf0548ad1bf185cbab27d7b339c792975f1",
"body": "Asiakirjat is primarily used as a hosted network service, where GPLv3's\ncopyleft doesn't reach: operators can run modified versions over the\nnetwork without conveying a copy, so they owe nothing back (GPLv3 sec 0).\nAGPLv3 sec 13 closes this by requiring modified versions offered over a\nnetwork to ma\n[…]\npdate the in-app /licenses page to point at AGPL-3.0-or-later\n\nSole copyright holder, so relicensing needs no third-party consent.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Relicense from GPL-3.0 to AGPL-3.0-or-later",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-07-09T16:09:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29a0c9f03cc5fab6e130edcd420ad2f156f1dda0",
"body": "…22)' (#123) from fix/project-rename-unreachable-docs into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/123",
"is_bot": false,
"headline": "Merge pull request 'Migrate deployed docs on project rename (fixes #1…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-07-07T18:01:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b916b832e89ab319ec6a0994261d15f2ba4dff93",
"body": "Covers the pieces added for the project-rename fix that lacked direct\ntests:\n\n- keyedMutex (locks_test.go): same-key sections are serialized (max\n concurrency 1), different keys are independent, and unlock releases.\n- handleAdminUpdateProject: renaming a project keeps its deployed docs\n reachable \n[…]\n the pool makes concurrent access share one\nin-memory DB — a test-harness fix; production uses a shared file/SQL DB.\n\nAI-assisted.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add tests for rename race guard and handler rename path",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-07-07T16:41:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2562e3055975653a8e45cde8c3bffde629686c5d",
"body": "Doc storage and the search index are keyed on the project slug, so\nrenaming a project (changing its slug) left the deployed files stranded\nat the old-slug path and every doc URL 404'd. Search results pointed at\nthe old slug too.\n\n- docs.Storage.MoveProject relocates a project's directory on rename\n \n[…]\nrectory out from under an in-flight upload.\n- Built-in docs: document rename behavior in the first-project tutorial.\n\nAI-assisted.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Migrate deployed docs on project rename (fixes #122)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-07-07T16:25:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1975bf75ed667754d3fb7d41edc31104bd419a2f",
"body": "…st/ permalink' (#121) from feature/frontpage-card-latest-link into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/121",
"is_bot": false,
"headline": "Merge pull request 'Point frontpage card \"Latest\" button at the /late…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-06-18T11:32:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91a435663f63347b744ace64ce5fa6456b574946",
"body": "The home-page project cards' Latest button linked to the concrete newest\nversion (/project/{slug}/{tag}/), so a visitor landed on a version-pinned\nURL. Link it to the rolling /project/{slug}/latest/ permalink instead, so\nthe URL someone lands on (and can copy/share) always tracks the newest\nversion.\n[…]\nversion.\n\nAdds a frontpage test asserting the card links to /latest/ and not the\nconcrete tag; notes it in the first-project docs.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Point frontpage card \"Latest\" button at the /latest/ permalink",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T11:27:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9994f423625a93b9c9be826cf20d65f39f8bf3c2",
"body": "…x/diff-view-on-latest into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/120",
"is_bot": false,
"headline": "Merge pull request 'Fix diff view on the /latest/ URL' (#120) from fi…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-06-18T09:01:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d42182771fa0468499e28eeb801ccbb05996609",
"body": "Guards the overlay regressions that broke the diff view on the /latest/\npermalink. Loads the real static/js/overlay.js into jsdom (no browser\nbinary; Node is already in CI), mocks the versions API and document fetch,\nand drives the compare flow:\n\n- compare from a /latest/ URL must fetch /project/doc\n[…]\n + jsdom only; `npm ci && npm test`. Wired\ninto the CI test job (which already had nodejs; added npm). node_modules is\ngitignored.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add browserless E2E tests for the doc overlay",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T08:58:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "84614e9679544d4e656dd05199d04af698612d27",
"body": "Two issues surfaced using the diff view from a /latest/ URL:\n\n1. The compare handler still computed the in-doc path suffix by stripping\n the resolved tag (`current`, e.g. v1.5) from window.location.pathname —\n but the path contains \"latest\", so the target-version fetch URL came out\n malformed \n[…]\ns on /latest/ (showing the indicator\nvia the correctly-positioned success path); (2) ensures any genuine error\nbar is visible too.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix diff on /latest/: compare suffix + mispositioned error bar",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T08:49:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "69ed71f7023f5d9f04099ed416a694f4b68be9eb",
"body": "…19) from feature/latest-version-permalink into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/119",
"is_bot": false,
"headline": "Merge pull request 'Add stable /project/{slug}/latest/ permalink' (#1…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-06-18T08:04:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aeb2eb6a021e7d344f3e87e1b60513721e585c08",
"body": "Serving the latest version in place means the URL segment (\"latest\")\ndiffers from the resolved concrete tag the overlay reports in data-current\n(e.g. v1.5). The overlay JS computed the in-doc path suffix by stripping\n\"/project/{slug}/{current}\" from window.location.pathname — but the path\nactually c\n[…]\ny; added\na test asserting /latest/ serves data-current=\"v2.0.0\" so the JS always has\na real version to build comparison URLs from.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix overlay version switch/compare on the /latest/ URL",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T08:01:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "54b5875ca6458359a6b2228b7dd8b5661818ad88",
"body": "Switch the /project/{slug}/latest/ permalink from a 302 redirect to\nserving the resolved version's content directly at the /latest/ URL. The\naddress bar stays /latest/, so relative links inside the docs keep\nresolving under /latest/ and a visitor who lands on the permalink keeps\nbrowsing \"latest\" ra\n[…]\no\n /latest/ so the served index page's relative links resolve correctly.\n- Docs/tests updated to reflect serve-in-place behavior.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Serve latest in place instead of redirecting",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T07:42:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b33b470f812fcf809187551f5cb56add291390d9",
"body": "There was no shareable URL that always points to a project's newest\nversion — links had to bake in a concrete version tag, so they went stale\non the next upload. Add a rolling permalink that redirects to the current\nlatest:\n\n- GET /project/{slug}/latest and /project/{slug}/latest/{path...} resolve\n \n[…]\nlows the pin.\n- Tests: redirect-to-newest, path preservation, pin precedence, no-versions\n 404, and anonymous-on-private → login.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add stable /project/{slug}/latest/ permalink",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T07:29:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4b1e43d9fbfcf72a78882d1a0511221177cd54d8",
"body": "…ject created_by' (#118) from feature/editor-manage-own-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/118",
"is_bot": false,
"headline": "Merge pull request 'Let editors manage projects they created; add pro…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-06-18T06:04:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dbff469f35f6a7650b2e61306ea77e6f4256df61",
"body": "Editors could create projects (and were auto-granted editor access) but\ncould not edit them or grant access to others — the edit, delete, and\naccess routes were admin-only. Custom projects an editor created were thus\nunusable: nobody could be granted access to them without an admin.\n\nChanges:\n- Migr\n[…]\ngap it exposed — creators having no way to\ngrant access to their own projects — is closed by the per-project access\nchanges above.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Let editors manage projects they created; add project created_by",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-06-18T05:54:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c5c323f42395dddcb663ae45b89cad953bc6a90c",
"body": "…4)' (#117) from fix/private-honors-per-project-grant into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/117",
"is_bot": false,
"headline": "Merge pull request 'Honor per-project grants on private projects (M-1…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-19T05:26:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d34da9b0ed58f0f6dba498ac8d79911cf85ef07b",
"body": "Service.Create auto-grants a non-admin creator editor access on every\nnon-public project they create, but CanView/FilterAccessible for `private`\nonly consulted GlobalAccess — so the grant was dead weight on the default\nvisibility. An editor without an org-wide global grant could create a\nprivate pro\n[…]\n one project without putting them on the org-wide list.\n\nBuilt-in docs updated alongside (visibility model and permission matrix).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Honor per-project grants on private projects (M-14)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-19T05:23:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4ed364ef6baf6c8f248edf4df2a8ca6a09c27c89",
"body": "…-12 partial)' (#116) from fix/migration-008-mysql-default into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/116",
"is_bot": false,
"headline": "Merge pull request 'Align MySQL migration 008 with sqlite/postgres (H…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-19T05:17:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02fb3c660ca6ddbd792960598741ad4a2628ee8d",
"body": "The `upload_logs.filename` column was declared `TEXT NOT NULL` on\nMySQL but `TEXT NOT NULL DEFAULT ''` on sqlite/postgres. Current code\nalways passes a value, so this is harmless today — but the drift is the\nexact kind of thing the audit's full H-12 fix (multi-dialect migration\nparity test) is meant to catch. Doing the reconcile now; the\ntestcontainers-based parity test is deferred (needs CI Docker).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Align MySQL migration 008 with sqlite/postgres (H-12 partial)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-19T05:06:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ef54890f6289491cba8f1925cf5134cc18ff913f",
"body": "… routes (L-3)' (#115) from feature/security-headers into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/115",
"is_bot": false,
"headline": "Merge pull request 'Add baseline security headers; exempt doc-serving…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-19T05:03:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6571625c55bff2442aae6085329d0e36710d6e3e",
"body": "Sets X-Content-Type-Options, Referrer-Policy, and CSP frame-ancestors on\nresponses for app-owned UI (admin, login, profile, upload, API, project\npages). The doc-serving route is exempt because uploaded HTML may rely\non inline scripts, third-party embeds, or be intentionally framed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add baseline security headers; exempt doc-serving routes (L-3)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-19T04:23:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d5f3c314d8c0c8b234023c6b630d336cc5e499ec",
"body": "…3)' (#114) from refactor/token-authenticator-deps into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/114",
"is_bot": false,
"headline": "Merge pull request 'Construct TokenAuthenticator once on Handler (H-1…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T21:09:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d6df4e0a5b8a8713a6784086374cb33314355cc",
"body": "Audit finding H-13. handleAPIUploadWithSlug and handleAPICreateProject\neach called auth.NewTokenAuthenticator(h.tokens, h.users) per request\n— cheap but a sign that token auth wasn't a first-class member of the\nhandler. Any new token-auth call site would have re-constructed it the\nsame way, and the \n[…]\n call sites. Matches the established pattern for projectService\nand checker (also wired in handler.New from existing Deps fields).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Construct TokenAuthenticator once on Handler (H-13)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T21:01:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7ef086a139270769ddca66249a0b9dbbdc726d55",
"body": "…ord (M-9)' (#113) from fix/reject-default-admin-password into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/113",
"is_bot": false,
"headline": "Merge pull request 'Refuse to start with insecure initial-admin passw…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T20:59:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ba58ef5d4aedcb589ec1831859ddc50c336fff2",
"body": "Audit finding M-9: config.yaml.example ships with password: \"changeme\"\nand config.Defaults uses \"admin\". A deployment copying either unchanged\nended up with working admin/changeme (or admin/admin) credentials, which\nhas happened in real setups.\n\nensureInitialAdmin now refuses to create the initial a\n[…]\nnsecureInitialAdminPassword for testability;\nmain_test.go covers the banned defaults, empty, just-too-short, and\nacceptable cases.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Refuse to start with insecure initial-admin password (M-9)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T20:51:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d1cbee14a50ac5b9de9e43baa806966ee85532c2",
"body": "…cleanup (M-12, M-13)' (#112) from fix/background-jobs-lifecycle into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/112",
"is_bot": false,
"headline": "Merge pull request 'Track background jobs; wire session + rate-limit …",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T20:48:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0362c8d71752375a6b543b484375340de4748f7f",
"body": "Audit findings M-12 and M-13: background goroutines and unused cleanup\npaths were both lifecycle gaps that this PR closes together.\n\nM-13 — fire-and-forget goroutines:\n Three sites started goroutines that the process abandoned on shutdown:\n - upload.go and api.go: searchIndex.IndexVersion (post-\n[…]\nst.go) cover runJob's WaitGroup behavior,\ncontext cancellation propagation, and idle-Stop being a no-op. All\nverified under -race.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Track background jobs; wire session + rate-limit cleanup (M-12, M-13)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T20:44:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "17198458cf9d9cdea5d5adcfe615380e8646465a",
"body": "…ility warning, M-4 demotion sweep' (#111) from fix/lifecycle-cleanups into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/111",
"is_bot": false,
"headline": "Merge pull request 'Lifecycle cleanups: M-1 mapping revoke, M-3 visib…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T20:38:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "230c2ae33cfb7fed73ed5ebbc17a9ca9d96b08aa",
"body": "…emotion sweep\n\nThree audit findings under the lifecycle/cascade-gap theme.\n\nM-1 — Group-mapping deletion previously dropped the mapping row but left\nthe project_access rows that were granted via that source untouched.\nUntil the affected user's next login (which would re-run syncProjectAccess\nand re\n[…]\nuntouched.\n\nsetupTestApp gained GroupMappings in Deps (it was missing, which the\nM-1 test surfaced by panicking on the nil store).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Lifecycle cleanups: M-1 mapping revoke, M-3 visibility warning, M-4 d…",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T20:26:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "67d77866139c3f7fcdc99e6bc9b21a1de0114f7b",
"body": "…M-7)' (#110) from feature/oauth2-state-ttl-pkce into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/110",
"is_bot": false,
"headline": "Merge pull request 'OAuth2: bound state map with TTL, add PKCE S256 (…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T20:19:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "23e7ef5ec7f9f0f7d3e4327537cfbf298f3bdc34",
"body": "Audit finding M-7. Two issues in the OAuth2 flow:\n\n 1. states map[string]bool grew on every /auth/oauth2 hit and was only\n pruned when the corresponding callback consumed the state. An\n unauthenticated attacker spamming the endpoint kept entries forever.\n\n 2. No PKCE (RFC 7636). A public-c\n[…]\nes + age-out + 1 more issuance → sweep leaves only 1\n\nExisting tests updated for the new HandleCallback / ConsumeState\nsignatures.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "OAuth2: bound state map with TTL; add PKCE S256 (M-7)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T19:56:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e94fdf225f49f67779710457f063b45126de1ca7",
"body": "…STs (M-6)' (#109) from feature/csrf-protection into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/109",
"is_bot": false,
"headline": "Merge pull request 'Per-session CSRF tokens on state-changing form PO…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T19:50:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3262c98a210e0025500be6e9a09eefc8da3c5257",
"body": "Audit finding M-6. SameSite=Lax cookies alone protect against cross-site\nform POSTs today, but the audit flagged it as the single point of\nfailure: a future SameSite=None, lenient lax handling on sibling\nsubdomains, or any GET-with-side-effects regression would re-open CSRF.\nAdds defense-in-depth.\n\n\n[…]\nthe expected token from the test\n handler's secret; bulk-injected into every existing test that sends\n a state-changing POST\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add per-session CSRF tokens on state-changing form POSTs (M-6)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T19:20:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "912917496208883bbf007d1c0d7d8a2f139af6de",
"body": "… (H-5, H-6)' (#108) from fix/archive-extraction-limits into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/108",
"is_bot": false,
"headline": "Merge pull request 'Cap archive extraction; stream zip/7z to tempfile…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T18:54:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b088c5ea1d350a17f519074a888a1f59c8337318",
"body": "Audit findings H-5 (decompression bomb / disk DoS) and H-6 (memory\namplification from buffering whole archives in RAM).\n\nH-5 — extraction limits. Each archive entry was capped at maxFileSize\n(100 MB) but there was no aggregate cap and no entry-count cap. A 100 MB\nupload of bz2/xz could expand to mul\n[…]\ntal-byte bomb (11×100MB → rejected mid-stream, well before\n writing 1.1 GB to disk)\n - normal small zip still extracts cleanly\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Cap archive extraction; stream zip/7z to tempfile (H-5, H-6)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T18:46:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5467cc4d7c446d2d06c4fa1c6bbfb221ca8c5731",
"body": "…rom fix/handler-state-race into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/107",
"is_bot": false,
"headline": "Merge pull request 'Synchronize Handler shared state (H-10)' (#107) f…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T18:40:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2c3f8acb71022ab7065ce0199d63cd895da46b2",
"body": "Audit finding H-10. reindexRunning, reindexProgress, latestTagsCache,\nand latestTagsCacheTime lived as bare fields on Handler. They were\nread and written from concurrent HTTP goroutines and from the worker\ngoroutine started in handleAdminReindex — a real data race in production,\nnot a hypothetical o\n[…]\ning tests don't exercise this\nshape and so wouldn't have flagged H-10 either.\n\n`go test -race ./...` clean across the whole suite.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Synchronize Handler shared state with explicit mutex types (H-10)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T18:35:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "57c99d5e0359e2d96c46fc477e3ff7249353efd4",
"body": "…ped tokens creating projects (H-3)' (#106) from fix/inline-authz-and-token-scope into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/106",
"is_bot": false,
"headline": "Merge pull request 'Fix inline authz drift (H-1, H-2) and project-sco…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T18:27:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8e3291f1353512752ef6806b6e9b031f98ebb84",
"body": "…POST /api/projects\n\nThree small fixes the access.Checker refactor (H-11, PR #105) unblocked.\n\nH-1: handleDeleteVersion had an inline check (admin/editor or per-project\nProjectAccess) that ignored GlobalAccessGrant editor grants. A user with\na global editor grant could upload to a private project vi\n[…]\nAccess\n - TestAPICreateProjectRejectsProjectScopedToken\n - TestAPICreateProjectAllowsGlobalToken (sanity: global token still OK)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix H-1/H-2 inline authz copies; H-3 reject project-scoped tokens on …",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T18:07:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "184f78078790ec7a4fd2db8345f24dcf6fbcf847",
"body": "…om refactor/access-checker into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/105",
"is_bot": false,
"headline": "Merge pull request 'Extract internal/access.Checker (H-11)' (#105) fr…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T18:02:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "252797a4b7a438cc1e40eb54d4872be9a4ca9573",
"body": "Audit finding H-11. The three authorization helpers — canViewProject,\ncanUpload, filterAccessibleProjects — lived as methods on Handler and\ntook *Handler as receiver. Each consulted ProjectAccessStore +\nGlobalAccessStore directly. Three consequences:\n\n - Tests of the authorization rules needed a fu\n[…]\nrAccessible verifies the batch form returns the same\n subset CanView would on each project.\n\nNet handler diff: -85 / +12 lines.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Extract internal/access.Checker (H-11)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T17:53:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cb6712c7209b855d28d38fd18ef457bc27cdc9be",
"body": "…#104) from refactor/projects-service-create into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/104",
"is_bot": false,
"headline": "Merge pull request 'Extract internal/projects.Service.Create (H-9)' (…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T17:48:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3b45e1274fc66661b54b76f86a7974526e2dc96",
"body": "Audit finding H-9. Three project-create paths each duplicated the same\nsequence: slug validation, visibility defaulting and validation,\npublic-visibility-admin-only gate, projects.Create, EnsureProjectDir,\nauto-grant editor access to the creator. They had already drifted in\nsubtle ways: the admin fo\n[…]\nant for admin, slug\nconflict. Full test suite still passes (validates handler paths still\nbehave the same as before the refactor).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Extract internal/projects.Service.Create (H-9)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T17:42:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4fe3260036d606ad872cea6857f26552e962d97a",
"body": "…4)' (#103) from fix/uploaded-by-on-delete-set-null into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/103",
"is_bot": false,
"headline": "Merge pull request 'Make uploaded_by nullable, ON DELETE SET NULL (H-…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T17:35:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5141d0eba02c336b9b28e33db6565ce051d0775b",
"body": "Audit finding H-4 (High). Before this change, versions.uploaded_by and\nupload_logs.uploaded_by had FK without ON DELETE, NOT NULL. With\nPRAGMA foreign_keys=ON (sqlite) and the equivalent FK enforcement on\npostgres/mysql, deleting any user who had ever uploaded returned an FK\nconstraint error from ha\n[…]\nndler;\nasserts (a) 303 redirect (FK doesn't block); (b) user gone; (c) version\nand upload_log still present with uploaded_by NULL.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Make versions/upload_logs uploaded_by nullable, ON DELETE SET NULL (H-4)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T16:19:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ad833464a95b32b09a87356d7b5cb8976ceee64e",
"body": "… (#102) from fix/sibling-prefix-leak into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/102",
"is_bot": false,
"headline": "Merge pull request 'Make ServeDoc prefix check separator-aware (H-8)'…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T16:09:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ec1aebc83ff7cbf1f64f6e3d1fdd77d434b1a56",
"body": "Audit finding H-8: ServeDoc rejected escape attempts with\nstrings.HasPrefix(absFile, absStorage), which treats \"/data/proj/v1\" as\na valid prefix of its sibling \"/data/proj/v10\". Two version directories\nwhose names share a prefix could leak between each other (the prefix\nmatch without a separator is \n[…]\n from v1 to v10 is rejected. Two sanity tests cover the\nlegitimate root-directory and in-tree cases so the fix doesn't\nover-block.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Make ServeDoc prefix check separator-aware (H-8)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T16:00:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "84caeef9f9d18b88445cee39759f1e96bc5d4583",
"body": "…d proxies (H-7)' (#101) from fix/trusted-proxies-rate-limit into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/101",
"is_bot": false,
"headline": "Merge pull request 'Only honor X-Forwarded-For from configured truste…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T15:59:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b07a7cbfc829cb2ee45d773d8da60a1d64f40a1",
"body": "withRateLimit blindly used the X-Forwarded-For header as the limiter key\nwhen present, with no proxy allowlist and no chain parsing. An attacker\ncould rotate the header per request and trivially bypass the 10/60s\nlogin rate limit — enabling credential stuffing against built-in users\nand LDAP backend\n[…]\nting XFF is honored when\nthe peer is in the trusted list (the new feature).\n\nBuilt-in config docs and config.yaml.example updated.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Only honor X-Forwarded-For from configured trusted proxies (H-7)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T15:55:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "72f51fbbb161e93b17ad5d58023a0dd7e16c045a",
"body": "…rojects (C-5)' (#100) from fix/restrict-public-visibility-to-admin into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/100",
"is_bot": false,
"headline": "Merge pull request 'Reject non-admin creators for public-visibility p…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T15:49:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18f1d3e9f02551cadd92a8f67ab017c2c07429cf",
"body": "Audit finding C-5 (Critical, privilege escalation).\n\nPublic projects bypass all access checks (canViewProject returns true\nunconditionally at search.go:314). Both handleAdminCreateProject and\nhandleAPICreateProject accepted visibility=public from any editor — an\neditor could therefore publish intern\n[…]\ntic editor case post-fix.\n\nDocs updated: first-project tutorial flags public as admin-only; API\nreference notes the 403 condition.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Reject non-admin creators for public-visibility projects",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T14:19:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "762127325ca8ad1dc02dafed23aada3f0760c26f",
"body": "…ct (C-4)' (#99) from fix/api-versions-access-check into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/99",
"is_bot": false,
"headline": "Merge pull request 'Gate /api/project/{slug}/versions by canViewProje…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T14:16:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1083b64d7a37d3c4ee517844c4a03b933f6117e9",
"body": "Audit finding C-4 (Critical). handleAPIVersions did no access check and\nreturned the version list — tags, content types, creation timestamps —\nfor any project regardless of visibility, to any caller (including\nunauthenticated). Contrast handleAPIProjects (already filtered) and\nhandleAPISearch (resul\n[…]\n4. A second test confirms a viewer with a per-project grant on a\ncustom-visibility project still sees the list (no over-blocking).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Gate /api/project/{slug}/versions by canViewProject",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T14:08:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "380e22f797b1eb75b5053ecde7de7491b5953314",
"body": "… test (C-3 investigation)' (#98) from fix/search-snippet-xss into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/98",
"is_bot": false,
"headline": "Merge pull request 'Lock in search snippet escaping with a regression…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T14:05:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d922e3343d936165fe1d00f1f8b77335302ec966",
"body": "Audit finding C-3 claimed `{{safe .Snippet}}` in search.html could ship\nraw HTML/JS from indexed documents to the browser. Investigation showed\nthis is **not exploitable today**: Bleve's html highlighter (selected at\nindexer.go:381) uses the html FragmentFormatter, which html.EscapeString's\nthe surr\n[…]\nture change swaps in a different highlighter or custom formatter\nthat doesn't escape, this test fails before the regression ships.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add regression test for search snippet HTML escaping",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T14:04:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "da8278c6bf38aa4f326aa39ad1aba96e9f6927fd",
"body": "…ored XSS (C-2, L-6)' (#97) from fix/pdf-viewer-xss into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/97",
"is_bot": false,
"headline": "Merge pull request 'Move PDF viewer wrapper to html/template — fix st…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T14:00:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82b5ad85fd82e3f0fe84e8baf123e4b2ca36b8a9",
"body": "Audit findings C-2 (Critical, stored XSS) and L-6 (hand-formatted HTML\nfragile to maintain).\n\nservePDFViewer built the wrapper page with fmt.Fprintf, interpolating the\nproject name and version tag directly into HTML. Project names are\nfree-form text set by editors/admins; version tags are now constr\n[…]\nns the </title><script>\npayload, fetches the viewer wrapper, and asserts the raw payload is absent\nand an escaped form is present.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Move PDF viewer wrapper from fmt.Fprintf to html/template (fix XSS)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T13:55:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7cf170002ec2c9819bfc42ffdf36f17ad0e8ed7d",
"body": "…tion at all boundaries (C-1, M-5, M-8)' (#96) from fix/input-validation-boundaries into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/96",
"is_bot": false,
"headline": "Merge pull request 'Validate slugs, version tags, and Content-Disposi…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-05-18T13:51:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78759322ec940a880e56c241b31d856499c66cf6",
"body": "…Content-Disposition values\n\nThree findings from the local audit, all involving attacker-controlled\nstrings flowing into filesystem paths or response headers without validation:\n\nC-1 (Critical): r.FormValue(\"version\") flowed directly into the project's\nstorage filesystem path via storage.EnsureVersi\n[…]\nhe\n malicious-input rejection on both the upload and admin-create endpoints.\n\nAudit findings: C-1, M-5, M-8 (workstream item #1).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add internal/validation; reject path-unsafe slugs, version tags, and …",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-05-18T13:47:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9ebe73815cedc1caf542496955bb957e25be18e5",
"body": "…(#93) from fix/session-delete-expired-timezone into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/93",
"is_bot": false,
"headline": "Merge pull request 'Fix DeleteExpired timezone mismatch with SQLite' …",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-03-17T12:57:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f3a08d8b9693c6eb53025362f9ae020031928b82",
"body": "CURRENT_TIMESTAMP is UTC in SQLite, but sessions are stored with\nlocal time. Pass time.Now().UTC() as a parameter instead so the\ncomparison is consistent regardless of server timezone.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix DeleteExpired timezone mismatch with SQLite",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-03-17T12:55:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "712825229320ba015330d1cf6c65ef43d88845d0",
"body": "… endpoint' (#92) from feature/auto-create-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/92",
"is_bot": false,
"headline": "Merge pull request 'Add auto-create projects on upload and API create…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-03-06T10:29:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52fccd36560cc64f93a7f924194f39cef14db23e",
"body": "- Add projects.auto_create config option (default: false) to allow\n automatic project creation when uploading to a non-existent slug\n- Add POST /api/projects endpoint for explicit project creation via API\n- Auto-created projects get private visibility and creator gets editor access\n- API auto-creat\n[…]\nts\n- Change default visibility for new projects from custom to private\n- Add slug validation (lowercase alphanumeric with hyphens, 1-128 chars)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add auto-create projects on upload and API create project endpoint",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-03-06T10:25:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ee768be9bee3135f17ff8d193dc147d304d7556a",
"body": "… from feature/upload-log-and-pin-version into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/91",
"is_bot": false,
"headline": "Merge pull request 'Add upload log and pinnable latest version' (#91)…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-03-05T08:17:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "589f023c679c17b0a4dbe7ba302175dd9eaacb54",
"body": "… from fix/version-reupload-date into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/90",
"is_bot": false,
"headline": "Merge pull request 'Fix version date not updating on re-upload' (#90)…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-03-05T07:54:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dad8e570bc9cfbeb1e0fdcffdd8e573f0e3faed0",
"body": "Upload log: Records every upload (new and re-upload) with version tag,\ncontent type, filename, and uploader. Displayed as a collapsible section\non the project detail page for editors/admins.\n\nPinnable latest version: Adds \"Pin\" and \"Temp. pin\" buttons to each\nversion. Permanent pins persist across n\n[…]\nr semver sorting for the frontpage and search.\n\nIncludes migration 008, UploadLogStore, handler tests, and store tests.\n\nCloses #88, closes #89\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add upload log and pinnable latest version",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-03-05T07:52:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "47bf45b6b5b6b94aaa297b7af3708f7a77bf6a0a",
"body": "When overwriting an existing version, set created_at to the current\ntime and include it in the UPDATE query so the version list reflects\nthe actual re-upload date.\n\nCloses #87\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix version date not updating on re-upload",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-03-05T07:29:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9732b1edaee837b1e48ebacdfb7b6762dce6c814",
"body": "…h results' (#86) from feature/pdf-search-page-jump into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/86",
"is_bot": false,
"headline": "Merge pull request 'Index PDF pages individually for page-level searc…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T07:31:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f0d4cdb15510d10fd5d4288916fbbf6e9d7556e",
"body": "PDF text is now extracted per page instead of as a single blob.\nSearch results for PDFs include the page number and link directly\nto the matching page using #page=N fragments. The PDF viewer\nreads the fragment and passes it to the embedded PDF, and shows\na search hint banner when arriving from a search result.\n\nRequires a search index rebuild after deploying.\n\nCloses #79\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Index PDF pages individually for page-level search results",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T07:22:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "499530e8c0b2a61d312b2986cb352b668bed8b81",
"body": "…) from docs/fill-documentation-gaps into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/84",
"is_bot": false,
"headline": "Merge pull request 'Fill documentation gaps for recent features' (#84…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:46:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cea63411fc280117426ae199a8405bbf7edb08a",
"body": "- Add docs-must-stay-current policy to CLAUDE.md\n- Document editor admin panel access (filtered project list, auto-grant)\n- Document auto-slug derivation on project creation\n- Document version deletion\n- Create how-to guide for Global Access management\n- Add Global Access section to roles-permissions reference\n- Document admin table live filtering\n- Clarify project-scoped API token restrictions\n- Add new how-to to docs index\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fill documentation gaps for recent features",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T06:43:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "103e6b5a6d375fd220ca9963e68e0936b6ec0612",
"body": "…feature/pdf-upload-support into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/72",
"is_bot": false,
"headline": "Merge pull request 'Add PDF documentation upload support' (#72) from …",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:34:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "619c5eee6d2ec3f7e76d502d02fc89739d817a2d",
"body": "…3) from feature/project-create-form-reorder into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/83",
"is_bot": false,
"headline": "Merge pull request 'Reorder project creation form with auto-slug' (#8…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:34:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8509313df81090774320d2ee1cdcdd03e70cf32e",
"body": "Reorganizes the create project card:\n- Row 1: Name + Slug (with auto-generate checkbox)\n- Row 2: Description textarea (resizable)\n- Row 3: Visibility + Create button\n\nWhen \"Auto slug\" is checked (default), the slug is derived from the\nname automatically. Unchecking allows manual editing.\n\nCloses #82\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Reorder project creation form with auto-slug derivation",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T06:31:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f312f40e6f808987d989c62d4dbc9c675d4ff5bf",
"body": "…bles' (#81) from feature/admin-table-filtering into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/81",
"is_bot": false,
"headline": "Merge pull request 'Add live filtering to admin projects and users ta…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:29:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4069fe5a0b256d509b1b7958ce43a3713ba4afef",
"body": "Client-side filter inputs above each table that hide non-matching rows\nin real-time, making it easier to find entries in large lists.\n\nCloses #74\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add live filtering to admin projects and users tables",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T06:26:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "de55f4df64b30b1b94f5f77a4fefbb1b14dbc5e5",
"body": "… on create' (#80) from fix/editor-project-list-filtering into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/80",
"is_bot": false,
"headline": "Merge pull request 'Filter admin project list for editors, auto-grant…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:23:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1bd725eb32743b14aae27153f0da7998c0831308",
"body": "…8) from fix/pdf-viewer-height into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/78",
"is_bot": false,
"headline": "Merge pull request 'Fix PDF viewer only filling ~1/6 of viewport' (#7…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-20T06:23:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ffacebba434703bf462037ad363a8daa19af9c12",
"body": "Editors previously saw all projects in the admin panel regardless of\nvisibility. Now non-admin users only see projects they actually have\naccess to (public, private with global grant, or custom with explicit\naccess), using the same filtering logic as the frontpage.\n\nWhen an editor creates a non-public project, they are automatically\ngranted editor-level access so they don't lose visibility of their\nown project.\n\nFixes #77\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Filter admin project list for editors and auto-grant access on create",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T06:18:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a38caff9eb63b7aab04cc39c53cdfa11686959d5",
"body": "The <embed> element is a replaced element that doesn't compute its\nheight from top+bottom constraints like block elements do. Set an\nexplicit height via calc(100vh - overlayHeight) and re-calculate on\nwindow resize so the PDF always fills the space below the overlay.\n\nFixes #76\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix PDF viewer only filling ~1/6 of viewport",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-20T06:13:25Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "695c8e56f44626476b86e5e9f1772d581f6d19ad",
"body": "…pport\n\n# Conflicts:\n#\tinternal/docs/builtin/docs/how-to/configure-ldap.md\n#\tinternal/docs/builtin/docs/reference/configuration.md",
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/main' into feature/pdf-upload-su…",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-17T09:49:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64cbba1e1d38ec408493e79e2bf303d434558af9",
"body": "… from feature/ldap-recursive-groups into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/75",
"is_bot": false,
"headline": "Merge pull request 'Add opt-in recursive LDAP group resolution' (#75)…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-17T09:47:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05b828f173bed0cf6cbfd2de6d0cce6dd7a37425",
"body": "Walk up each group's memberOf chain to resolve nested group memberships,\nenabling role assignment via transitive groups (e.g., user in team-a,\nteam-a member of editors → user gets editor role). Controlled by\nrecursive_groups and group_prefix config options.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add opt-in recursive LDAP group resolution",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-17T09:44:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "278cb2f348e3b5280e3204c1220b8cf8e77d9a36",
"body": "- Fix config field names (host->address, user_base_dn->base_dn, storage default)\n- Rewrite LDAP/OAuth2 config docs to match actual config.go fields\n- Add PDF upload support documentation across all relevant pages\n- Add retention, proxy_strip_path, log_level config documentation\n- Fix editor role: ca\n[…]\ns (not just admin)\n- Add 100 MB upload size limit (was incorrectly \"no hard-coded limit\")\n- Add version diffing and PDF support to feature list\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix built-in documentation gaps and inaccuracies",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-17T07:33:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d8f61cf1a5fe77a45ff5d24eaeadc7123d5f56f8",
"body": "…rom feature/pdf-search-and-diff-denial into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/73",
"is_bot": false,
"headline": "Merge pull request 'Add PDF full-text search and diff denial' (#73) f…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T17:29:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be0145dda56b0716e08d93194cb81346c69c9627",
"body": "- Extract text from PDFs for Bleve search indexing using pdftotext\n (poppler-utils) with pure Go fallback (ledongthuc/pdf)\n- Add poppler-utils to Docker runtime image for best extraction quality\n- Re-enable search indexing for PDF uploads (was skipped in #68)\n- Add content_type to versions API so o\n[…]\ns which are PDFs\n- Block diff comparison for PDF versions with clear error message\n instead of confusing \"Could not find content area\" failure\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add PDF full-text search and graceful diff denial",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T17:27:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "800ad3fab07299e2256bb3443ad1340047624845",
"body": "Accept .pdf file uploads alongside archives. PDF versions are stored as\na single file and served in an HTML wrapper with the overlay toolbar.\nSearch indexing is skipped for PDF versions (no text extraction yet).\n\n- Add content_type column to versions (migration 007)\n- Detect PDF uploads in web and A\n[…]\nServe PDF in embedded viewer with overlay\n- Show PDF badge in version list, serve raw PDF on download\n- Update upload form to accept .pdf files\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add PDF documentation upload support (#68)",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T17:07:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c1482d07e659a6cc32425b4e9aa73892ef455928",
"body": "…1) from feature/arm64-release-binary into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/71",
"is_bot": false,
"headline": "Merge pull request 'Add arm64 release binary to release workflow' (#7…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T16:47:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15c5f910f741d8ad963c613849dafcb88b3a0858",
"body": "Build and upload linux/arm64 binary alongside amd64. Also includes\nthe jq fix for release ID extraction (supersedes #70).\n\nCloses #32 (binary portion — multi-arch Docker deferred)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add arm64 release binary to release workflow",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T16:46:48Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "26e802b2302ee1edd605c69ebbe26ea075820d89",
"body": "…70) from fix/release-id-extraction into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/70",
"is_bot": false,
"headline": "Merge pull request 'Fix release ID extraction in release workflow' (#…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T16:45:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e30d67e77eb15d64417e8a4707d7f05c82100df1",
"body": "The sed regex was greedy and matched the last \"id\": in the JSON\n(the author's user ID) instead of the release ID. Replaced with\njq for reliable JSON parsing.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix release ID extraction in release workflow",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T16:39:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6173cc82a1bafd1a6f56b59f7f755ef2cc1bcafd",
"body": "…from feature/diff-navigation-and-persistence into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/69",
"is_bot": false,
"headline": "Merge pull request 'Add diff navigation and state persistence' (#69) …",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T16:32:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d154d60eab3538c5205832df87de2d09a8ac64a2",
"body": "Adds prev/next navigation buttons and keyboard shortcuts (n/p) to jump\nbetween changes in diff mode, with an amber outline highlighting the\ncurrent change. Persists diff state via ?compare= URL parameter so\ndiffs survive page navigation and reloads. Intercepts in-doc link\nclicks during diff mode to carry the compare parameter forward.\n\nCloses #58, closes #59\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add diff navigation and state persistence to document overlay",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T16:26:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "22db13a85bde77b80474015ce247258ba2decbed",
"body": "…down hint' (#67) from feature/multiline-project-description into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/67",
"is_bot": false,
"headline": "Merge pull request 'Use textarea for project description and add mark…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T15:25:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "092a95d7dd42616364b95290870886988a16b4a2",
"body": "…feature/editor-create-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/66",
"is_bot": false,
"headline": "Merge pull request 'Allow editors to create new projects' (#66) from …",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T15:25:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3da6c75571989c26765d05b13178dbf2ca257814",
"body": "… (#65) from feature/download-version into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/65",
"is_bot": false,
"headline": "Merge pull request 'Add download endpoint for documentation versions'…",
"author_name": "qwc",
"author_login": null,
"committed_at": "2026-02-16T15:25:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "08c4956c3b8f30be4027e90e6cc1ed26374df5ea",
"body": "Changes the create project form description field from a single-line\ninput to a multiline textarea, matching the edit form. Adds a markdown\nhint to both forms. The frontpage card CSS already truncates long\ndescriptions to 2 lines via line-clamp.\n\nCloses #64\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Use textarea for project description and add markdown hint",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T15:20:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "85327364e73d27e6d018a7b1f2a521ce3546944a",
"body": "Adds requireEditorOrAdmin middleware and applies it to the project list\nand create routes. The admin projects page conditionally hides admin-only\nfeatures (edit, delete, reindex, deploy, admin nav) for editor users.\nEditors see a \"Manage Projects\" link in the navbar.\n\nCloses #63\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Allow editors to create new projects",
"author_name": "Marcel M. Otte",
"author_login": null,
"committed_at": "2026-02-16T15:19:02Z",
"body_truncated": false,
"is_coding_agent": true
}
],
"releases_count": 35,
"commits_last_year": 222,
"latest_release_at": "2026-07-07T18:01:53Z",
"latest_release_tag": "v0.8.2",
"releases_from_tags": true,
"days_since_last_push": 14,
"active_weeks_last_year": 10,
"days_since_latest_release": 20,
"mean_days_between_releases": 13.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/qwc/asiakirjat",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/qwc/asiakirjat",
"is_deprecated": false,
"latest_version": "v0.8.2",
"repository_url": "https://github.com/qwc/asiakirjat",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-07T18:01:53Z",
"latest_version_yanked": null,
"days_since_latest_publish": 20
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile",
"vendor/github.com/golang-migrate/migrate/v4/Makefile",
"vendor/github.com/jmoiron/sqlx/Makefile",
"vendor/github.com/yuin/goldmark/Makefile",
"vendor/go.etcd.io/bbolt/Makefile",
"vendor/modernc.org/libc/Makefile",
"vendor/modernc.org/mathutil/Makefile",
"vendor/modernc.org/memory/Makefile",
"vendor/modernc.org/sqlite/Makefile"
],
"api_schema_files": [
"vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 309927,
"source_files_sampled": 107,
"oversized_source_files": 2,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3258
},
"dependencies": {
"manifests": [
"go.mod",
"package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/blevesearch/bleve/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.5.7"
},
{
"name": "github.com/bodgit/sevenzip",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.1"
},
{
"name": "github.com/go-ldap/ldap/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.4.12"
},
{
"name": "github.com/go-sql-driver/mysql",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.3"
},
{
"name": "github.com/golang-migrate/migrate/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.19.1"
},
{
"name": "github.com/jackc/pgx/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.8.0"
},
{
"name": "github.com/jmoiron/sqlx",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/ledongthuc/pdf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250511090121-5959a4027728"
},
{
"name": "github.com/ulikunitz/xz",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.15"
},
{
"name": "github.com/yuin/goldmark",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.16"
},
{
"name": "golang.org/x/crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.47.0"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.49.0"
},
{
"name": "golang.org/x/oauth2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.3"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "qwc",
"commits": 26,
"avatar_url": "https://avatars.githubusercontent.com/u/1408353?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": false,
"has_tests": true,
"ci_workflows": [],
"has_docs_dir": false,
"linter_configs": [
".golangci.yaml",
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "31 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "fd663cb90fe19a4beea7926e12150eec6b0559c6",
"ran_at": "2026-07-28T08:35:16Z",
"aggregate_score": 2.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": null,
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/qwc/asiakirjat",
"host": "github.com",
"name": "asiakirjat",
"owner": "qwc"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"security": 25,
"vitality": 74,
"community": 24,
"governance": 37,
"engineering": 67
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"commits_last_year": 222,
"human_commit_share": 1,
"days_since_last_push": 14,
"active_weeks_last_year": 10
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 14 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 14
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "10/52 weeks with commits",
"points": 6.9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 10
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "222 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 222
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 35,
"latest_release_tag": "v0.8.2",
"releases_from_tags": true,
"days_since_latest_release": 20,
"mean_days_between_releases": 13.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "35 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 35
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 20 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 20
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~13.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 13.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 24,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (AGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "AGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 37,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 51,
"inputs": {
"followers": 22,
"owner_type": "User",
"is_verified": null,
"owner_login": "qwc",
"public_repos": 15,
"account_age_days": 5287
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "22 followers of qwc",
"points": 9.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 22,
"login": "qwc"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "15 public repos, account ~14 yr old",
"points": 20.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 15
}
},
{
"code": "account_age_years",
"params": {
"years": 14
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/qwc/asiakirjat"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 20
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 20 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 20
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "34 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 34
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 67,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"has_ci": false,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yaml, .golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"documentation",
"hosting",
"static",
"static-docs-hosting",
"static-documentation-hosting"
],
"has_wiki": true,
"homepage": "https://git.mmo.to/qwc-open/asiakirjat",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://git.mmo.to/qwc-open/asiakirjat",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "5 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 5
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 25,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"dangerous_workflow",
"packaging",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 25,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 13,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 5,
"scorecard_aggregate": 2.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "31 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 79,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3258
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile",
"vendor/github.com/golang-migrate/migrate/v4/Makefile",
"vendor/github.com/jmoiron/sqlx/Makefile",
"vendor/github.com/yuin/goldmark/Makefile",
"vendor/go.etcd.io/bbolt/Makefile",
"vendor/modernc.org/libc/Makefile",
"vendor/modernc.org/mathutil/Makefile",
"vendor/modernc.org/memory/Makefile",
"vendor/modernc.org/sqlite/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.52,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yaml, .golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "52 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 52,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 309927,
"source_files_sampled": 107,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/107 source files over 60KB",
"points": 54,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 107,
"oversized": 2
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [],
"has_mcp_signal": false,
"api_schema_files": [
"vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-28T08:35:33.078399Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/qwc/asiakirjat.svg",
"full_name": "qwc/asiakirjat",
"license_state": "standard",
"license_spdx": "AGPL-3.0"
}