JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"html-sanitization",
"web",
"crates",
"security"
],
"is_fork": false,
"size_kb": 418,
"has_wiki": false,
"homepage": null,
"languages": {
"Rust": 208109,
"Python": 1384
},
"pushed_at": "2026-07-22T03:48:46Z",
"created_at": "2015-08-22T23:08:27Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T03:48:15Z",
"description": "Repair and secure untrusted HTML",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "master",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Rust",
"significant_languages": [
"Rust"
]
},
"owner": {
"blog": null,
"name": "The Ammonia HTML Sanitizer",
"type": "Organization",
"login": "rust-ammonia",
"company": null,
"location": "Icon provided by Chameleon Design from Noun Project",
"followers": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/32849598?v=4",
"created_at": "2017-10-16T18:08:22Z",
"is_verified": null,
"public_repos": 2,
"account_age_days": 3201
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v4.1.4",
"kind": "patch",
"published_at": "2026-07-22T03:48:57Z"
},
{
"tag": "v4.0.3",
"kind": "patch",
"published_at": "2026-07-22T03:47:29Z"
},
{
"tag": "v3.3.3",
"kind": "patch",
"published_at": "2026-07-22T03:45:52Z"
},
{
"tag": "v4.1.3",
"kind": "patch",
"published_at": "2026-06-30T08:11:12Z"
},
{
"tag": "v4.0.2",
"kind": "patch",
"published_at": "2026-06-30T07:39:53Z"
},
{
"tag": "v3.3.2",
"kind": "patch",
"published_at": "2026-06-30T07:38:17Z"
},
{
"tag": "v3.3.1",
"kind": "patch",
"published_at": "2025-09-22T01:15:56Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2025-09-22T01:15:26Z"
},
{
"tag": "v4.1.2",
"kind": "patch",
"published_at": "2025-09-22T01:03:06Z"
},
{
"tag": "v4.1.1",
"kind": "patch",
"published_at": "2025-07-08T16:27:18Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2025-04-21T20:38:29Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2024-03-25T15:00:35Z"
},
{
"tag": "v3.3.0",
"kind": "minor",
"published_at": "2022-11-29T19:31:40Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2022-08-15T20:34:56Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2022-04-07T20:35:06Z"
},
{
"tag": "v3.1.4",
"kind": "patch",
"published_at": "2022-02-16T20:53:02Z"
},
{
"tag": "v3.1.3",
"kind": "patch",
"published_at": "2022-01-19T22:09:12Z"
},
{
"tag": "v2.1.4",
"kind": "patch",
"published_at": "2022-01-19T22:08:19Z"
},
{
"tag": "v3.1.2",
"kind": "patch",
"published_at": "2021-07-08T19:34:29Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2021-03-05T02:25:56Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2020-03-10T05:14:24Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2019-07-25T18:27:00Z"
},
{
"tag": "v2.1.3",
"kind": "patch",
"published_at": "2021-07-08T19:36:13Z"
},
{
"tag": "v2.1.2",
"kind": "patch",
"published_at": "2019-06-28T18:18:37Z"
},
{
"tag": "v2.1.1",
"kind": "patch",
"published_at": "2019-05-08T18:19:31Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2019-04-27T18:33:31Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2018-12-28T19:51:16Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2018-07-18T20:49:44Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2018-03-04T21:17:01Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2017-12-24T17:56:00Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2017-11-12T16:56:21Z"
},
{
"tag": "v1.0.0-rc3",
"kind": "prerelease",
"published_at": "2017-10-26T20:45:00Z"
},
{
"tag": "v1.0.0-rc2",
"kind": "prerelease",
"published_at": "2017-10-24T19:41:37Z"
},
{
"tag": "v1.0.0-rc1",
"kind": "prerelease",
"published_at": "2017-09-26T13:50:31Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2017-09-05T17:56:49Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2017-09-05T17:55:40Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2017-08-21T20:41:25Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2017-06-16T15:12:03Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2017-06-09T20:42:59Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2017-06-09T20:46:08Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2017-03-14T19:58:43Z"
}
],
"recent_commits": [
{
"oid": "fba751216ad8eb7a4e71882350016f810e4d925a",
"body": "Release 4.1.4: fix XSS caused by not sanitizing svg animations",
"is_bot": false,
"headline": "Merge pull request #250 from rust-ammonia/release-4.1.4",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-22T03:47:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e3335e2dd8ab07346ff7997f20662a3da4023f6",
"body": "The following SVG used to produce a link with a javascript scheme.\nIf the user clicks this link, they will run it.\n\n```xml\n<svg xmlns=\"http://www.w3.org/2000/svg\">\n <a>\n <set attributeName=\"href\" to=\"javascript:alert('SET_XSS')\"></set>\n <text y=\"30\">Click set</text>\n </a>\n</svg>\n```",
"is_bot": false,
"headline": "Fix XSS caused by not sanitizing svg animations",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-22T03:30:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c64409a5db03cf0a1a3b12462294089b4df422b",
"body": "Fix credit in changelog by request",
"is_bot": false,
"headline": "Merge pull request #249 from rust-ammonia/notriddle-patch-1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-21T05:58:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "75d58d19e4607d3dcd0fcaf45d1fc61c6ad91d72",
"body": null,
"is_bot": false,
"headline": "Fix credit in changelog by request",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-16T23:09:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06b868a2951ad51065817b6137a1f31f07bc5582",
"body": "Add credit to changelog",
"is_bot": false,
"headline": "Merge pull request #246 from rust-ammonia/notriddle-patch-1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-01T04:03:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04ea01aecea5d505b974d44d8b5480227139b722",
"body": "I put it in the release notes, but forgot to put it here. Sorry!",
"is_bot": false,
"headline": "Add credit to changelog",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-07-01T04:01:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c56268b885dbb390f3dafed939d31f8eb369b07",
"body": "Release 4.1.3 with security fix",
"is_bot": false,
"headline": "Merge pull request #245 from rust-ammonia/release-4.1.3",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-06-30T07:43:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b51bf4f9749ed3cd518330105f20a2c39c9ee274",
"body": null,
"is_bot": false,
"headline": "Release 4.1.3 with security fix",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-06-30T07:41:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7bf16021f027c54ce05e01163b15460add82220",
"body": "…vel-tags\n\nDocument fragment-parsing limit on html/head/body tags (closes #183)",
"is_bot": false,
"headline": "Merge pull request #242 from gghez/worktree-issue-183-doc-document-le…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-05-26T21:27:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4eadffcab6bd29b788e6990255f732328ef436c9",
"body": "Ammonia parses input in fragment mode, so the parser strips the\ndocument-level html, head, and body tags before the sanitizer ever\nsees them. Adding these tags through Builder::tags or add_tags is\ntherefore a no-op. Note the limitation on Builder::tags and add a\ntest that pins the behavior.",
"is_bot": false,
"headline": "Document fragment-parsing limit on html/head/body tags (closes #183)",
"author_name": "gghez",
"author_login": "gghez",
"committed_at": "2026-05-26T19:32:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82955e78f132f0d152a0d1d32c867043dc0f4c90",
"body": "…-doc\n\nFix to_dom_node doctest by wrapping Handle in SerializableHandle",
"is_bot": false,
"headline": "Merge pull request #239 from gghez/worktree-issue-190-fix-to-dom-node…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-05-26T18:55:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "879997e8a6c6bab23515e5e7c732b897b08e6f88",
"body": "…erflow-tests\n\nRename deeply_nested_* tests to express stack-overflow regression intent",
"is_bot": false,
"headline": "Merge pull request #238 from gghez/worktree-issue-211-rename-stack-ov…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-05-26T18:54:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e9d22b05d0e40ba3def2cdf98b3b8a1c743aaea9",
"body": "The example for `Document::to_dom_node` passed a `Handle` directly\nto `serialize`, but `serialize` requires a type that implements\n`Serialize` — `Handle` does not, only `SerializableHandle` does.\n\nThe example only compiles under `--cfg ammonia_unstable`, so the\nbreakage went unnoticed. Refs #190.",
"is_bot": false,
"headline": "Fix to_dom_node doctest by wrapping Handle in SerializableHandle",
"author_name": "gghez",
"author_login": "gghez",
"committed_at": "2026-05-26T18:50:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf1de31f2d6557c571ebc35781c79cb96e9ad524",
"body": "These tests have no assertion because their purpose is to verify the\nsanitizer does not stack-overflow on deeply nested input. Renaming them\nto spell out that intent (matching the existing no_panic_* convention)\nmakes their purpose obvious from cargo test output.\n\nCloses #211.",
"is_bot": false,
"headline": "Rename deeply_nested_* tests to express stack-overflow regression intent",
"author_name": "gghez",
"author_login": "gghez",
"committed_at": "2026-05-26T18:44:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "186f7b72a1d450306b3dd3e25b2a02e28e25ca82",
"body": "Disable cssparser proc macros",
"is_bot": false,
"headline": "Merge pull request #235 from rust-ammonia/macros",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-05-06T17:16:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f7e2213217f38543d82120b86aadcfc2e0312e5a",
"body": "We don't actually use them.",
"is_bot": false,
"headline": "Disable cssparser proc macros",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-03-25T03:22:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "991141d476444feee2583b18d799a83f6147e950",
"body": "…0.37.0\n\nUpdate cssparser requirement from 0.36.0 to 0.37.0",
"is_bot": false,
"headline": "Merge pull request #234 from rust-ammonia/dependabot/cargo/cssparser-…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-03-25T03:16:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cbc6e0fb38e54ede5f152762cc708185bf1f20f0",
"body": "Updates the requirements on [cssparser](https://github.com/servo/rust-cssparser) to permit the latest version.\n- [Release notes](https://github.com/servo/rust-cssparser/releases)\n- [Commits](https://github.com/servo/rust-cssparser/commits)\n\n---\nupdated-dependencies:\n- dependency-name: cssparser\n dependency-version: 0.37.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update cssparser requirement from 0.36.0 to 0.37.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-23T10:55:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe4c69febb7dbb67cb8e4f3ac08c9ad70bbf3ce3",
"body": "…0.39\n\nUpdate html5ever requirement from 0.38 to 0.39",
"is_bot": false,
"headline": "Merge pull request #232 from rust-ammonia/dependabot/cargo/html5ever-…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-03-17T01:30:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "339c4c879b385a15120dc2fe82200c85f89a86a5",
"body": "Updates the requirements on [html5ever](https://github.com/servo/html5ever) to permit the latest version.\n- [Release notes](https://github.com/servo/html5ever/releases)\n- [Commits](https://github.com/servo/html5ever/commits)\n\n---\nupdated-dependencies:\n- dependency-name: html5ever\n dependency-version: 0.39.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update html5ever requirement from 0.38 to 0.39",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-16T10:55:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea2d6a5b71542288013c079d99ba56210fe6fdb3",
"body": "Add test for selectedcontent not within select",
"is_bot": false,
"headline": "Merge pull request #231 from rust-ammonia/selectedcontent",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-26T13:16:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d664802cfe1d59074f6fbeeff6e35fda59c611e",
"body": null,
"is_bot": false,
"headline": "Add test for selectedcontent not within select",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-26T13:15:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce6182e1e518f10dca05de0b403a6dbf00ee3517",
"body": "Clean up and test handling of customizable select",
"is_bot": false,
"headline": "Merge pull request #229 from rust-ammonia/selectedcontent",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-26T13:04:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fa091dde6cd2def9aef655edc78063845961c9b",
"body": null,
"is_bot": false,
"headline": "Bump html5ever requirement to 0.38",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-26T12:56:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a15de220f080da6bcb3fdb9143a07088c7981af0",
"body": "Becaue `<selectedcontent>`'s contents are always replaced by the browser\nwhen inserted, this patches the sanitizer to clear it entirely.\n\nIt also adds a test case, originally from the whatwg bug tracker, for\nhandling a potential mxss in the select element.",
"is_bot": false,
"headline": "Clean up and test handling of customizable select",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-14T06:21:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0ebe263665931a16ff42c48b446465c52e8a78c",
"body": "…0.37\n\nUpdate html5ever requirement from 0.35 to 0.37",
"is_bot": false,
"headline": "Merge pull request #228 from rust-ammonia/dependabot/cargo/html5ever-…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-14T04:30:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "30c1ee911bae94f3f598c03d43fe0db4d2c94616",
"body": null,
"is_bot": false,
"headline": "Fix tendril and rcdom",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2026-01-14T04:25:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53ccaeb46757921d781962a79a33c2c31b32a093",
"body": "Updates the requirements on [html5ever](https://github.com/servo/html5ever) to permit the latest version.\n- [Release notes](https://github.com/servo/html5ever/releases)\n- [Commits](https://github.com/servo/html5ever/commits)\n\n---\nupdated-dependencies:\n- dependency-name: html5ever\n dependency-version: 0.37.1\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update html5ever requirement from 0.35 to 0.37",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-12T12:33:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d803b5677006947da7d2f495dbae83090db4909",
"body": "…0.36.0\n\nUpdate cssparser requirement from 0.35.0 to 0.36.0",
"is_bot": false,
"headline": "Merge pull request #225 from rust-ammonia/dependabot/cargo/cssparser-…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-11-13T17:19:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "022920f33dd9375056587e32c85b0077e32c0223",
"body": "Updates the requirements on [cssparser](https://github.com/servo/rust-cssparser) to permit the latest version.\n- [Release notes](https://github.com/servo/rust-cssparser/releases)\n- [Commits](https://github.com/servo/rust-cssparser/compare/v0.35.0...v0.36.0)\n\n---\nupdated-dependencies:\n- dependency-name: cssparser\n dependency-version: 0.36.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update cssparser requirement from 0.35.0 to 0.36.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-10T11:14:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c8eb52f9910b1e2e2727b689ae1e7eed12a4d44",
"body": "Add missing credits to CHANGELOG",
"is_bot": false,
"headline": "Merge pull request #222 from rust-ammonia/credits",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-23T22:32:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05fcadfe1178e215e031f4333a3aa667eb09d8d8",
"body": null,
"is_bot": false,
"headline": "Add credit to README",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-23T22:31:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "343e6c0cf804e834a6e8ba284f74cdd445516563",
"body": null,
"is_bot": false,
"headline": "Add missing credits to CHANGELOG",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-23T22:29:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a0aa52081f24e86d0f1ba0a24afacf4c32ef989",
"body": "Add missing entries to changelog",
"is_bot": false,
"headline": "Merge pull request #221 from rust-ammonia/changelog",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-22T01:19:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c6e45081f3709b8e16770dde3ac0670cfcfa125",
"body": null,
"is_bot": false,
"headline": "Add missing entries to changelog",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-22T01:18:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6aa8a128c3ececa5dead6dbe0da47fb30511f30b",
"body": "Release 4.1.2 with security fix",
"is_bot": false,
"headline": "Merge pull request #220 from rust-ammonia/release-4.1.2",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-22T01:00:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de0297111a3a1273275b670960bcd47a0481718e",
"body": null,
"is_bot": false,
"headline": "Release 4.1.2 with security fix",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-22T00:52:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e9754b3fda9c46780f2cf84d21eabced5404cf9",
"body": "Delete .travis.yml",
"is_bot": false,
"headline": "Merge pull request #218 from atouchet/trav",
"author_name": "Laurențiu Nicola",
"author_login": "lnicola",
"committed_at": "2025-09-16T05:13:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1e732cadf85d9010a38dcb0627515349e02ad69",
"body": null,
"is_bot": false,
"headline": "Delete .travis.yml",
"author_name": "Alex Touchet",
"author_login": "atouchet",
"committed_at": "2025-09-15T22:27:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5d54a862f7f07e833c5bd6eb75266f0977054def",
"body": "Update Readme",
"is_bot": false,
"headline": "Merge pull request #216 from atouchet/urls",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-09-08T18:05:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52a7d97300d644d7defe73a1ae009173c818dbbd",
"body": null,
"is_bot": false,
"headline": "Update Readme",
"author_name": "Alex Touchet",
"author_login": "atouchet",
"committed_at": "2025-09-05T20:38:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a14a5eb78281e1316b100bd7aeb8e5e9b243c958",
"body": "Release 4.1.1",
"is_bot": false,
"headline": "Merge pull request #214 from rust-ammonia/release-4.1.1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-07-08T16:13:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "262d0d3edd6d13b4053f0df99d443185acb3f66e",
"body": null,
"is_bot": false,
"headline": "Release 4.1.1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-07-07T16:41:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84e7284226fa0d2853a0d9919f1b0df9a50a5e2b",
"body": "…0.35\n\nUpdate html5ever requirement from 0.31 to 0.35",
"is_bot": false,
"headline": "Merge pull request #213 from rust-ammonia/dependabot/cargo/html5ever-…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-07-07T16:35:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5ad1ec948e34d88ea188f887171960e29800fa7",
"body": "This flags seems to be used for parsing `<noscript>`, which\nshouldn't matter (if we keep it, we want to normalize it as DOM\ncontent, not as RCDATA).",
"is_bot": false,
"headline": "Add bool flag to mark scripting as disabled",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-07-07T16:29:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "00aac0f2eba41359abe90668beb33b197d995b07",
"body": "---\nupdated-dependencies:\n- dependency-name: html5ever\n dependency-version: 0.35.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update html5ever requirement from 0.31 to 0.35",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-07-07T12:47:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96b30961998868972af2eb73dd343bc09ff68277",
"body": "Release 4.1",
"is_bot": false,
"headline": "Merge pull request #209 from rust-ammonia/release-4.1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-04-21T20:37:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f76bd6f52dd778434f30d2f37007aeccd10039e9",
"body": null,
"is_bot": false,
"headline": "Bump html5ever",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-04-14T22:53:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8ebbdc217828f992cb2f30e3a4705606e361f70",
"body": null,
"is_bot": false,
"headline": "Update RELEASE_PROCESS.md",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T18:21:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a468500561b6bc09e4b8fbc734193b04390339c6",
"body": null,
"is_bot": false,
"headline": "Add docs for security and README version pull",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T18:17:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f7a217092cf0b1ac4091e751dad4454808f2738",
"body": null,
"is_bot": false,
"headline": "Fix MSRV build",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T18:14:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c53075d19ec74175a0b2c567717c110438074c75",
"body": null,
"is_bot": false,
"headline": "Remove once_cell dependency, bump msrv",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T18:09:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e12876dbf66c1ef6a8efdb989be66dfe1fc0727d",
"body": null,
"is_bot": false,
"headline": "Fix changelog, bump msrv",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T18:04:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97ab2d70c39ba9109d10826557fe4bb185175bce",
"body": null,
"is_bot": false,
"headline": "Clean up unused code",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T17:58:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91b07b553d183a2887e5493ac82022591877d5b1",
"body": null,
"is_bot": false,
"headline": "release 4.1: bump dependencies",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2025-03-27T17:57:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce280e26ea9f2a7a1fcee061a4d491e391beaca3",
"body": null,
"is_bot": false,
"headline": "Update CHANGELOG.md",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-10-29T18:06:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b0aaf4747b300c8c7085fa0babf213a98417cf3",
"body": "Add support for sanitizing (filtering) style properties",
"is_bot": false,
"headline": "Merge pull request #208 from xmo-odoo/style-sanitizer",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-10-29T18:05:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52de9772633debc162ca36586b080e17e46582ef",
"body": "Matches what I understand of Bleach's `CSSSanitizer`: CSS properties\nare filtered by name and global.\n\nFixes #179",
"is_bot": false,
"headline": "Add support for sanitizing (filtering) style properties",
"author_name": "Xavier Morel",
"author_login": "xmo-odoo",
"committed_at": "2024-10-29T10:09:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d11ff7605ae42730b44cb51b473493366eae668c",
"body": "Upgrade html5ever",
"is_bot": false,
"headline": "Merge pull request #206 from kornelski/html5up",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-09-20T19:25:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2da069a41725e5f5d0e616d9be83ced2aac32f5",
"body": null,
"is_bot": false,
"headline": "Follow MSRV of html5ever",
"author_name": "Kornel",
"author_login": "kornelski",
"committed_at": "2024-09-20T17:41:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "50d02c62894d4579a30043bf3515fbc9c1cb9ee3",
"body": null,
"is_bot": false,
"headline": "Upgrade html5ever",
"author_name": "Kornel",
"author_login": "kornelski",
"committed_at": "2024-09-20T17:20:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25017a4c461563c26ff994ba0eede2dcb8b4f235",
"body": "Add simple panic messages",
"is_bot": false,
"headline": "Merge pull request #201 from rust-ammonia/notriddle/panic-msg",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-07-12T17:49:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0fda008b4759e8b185acf3f1c843a625ced80af9",
"body": null,
"is_bot": false,
"headline": "Update changelog",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-07-12T15:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a8ae0a9289422040623dbba8aaf9ce94233e0d8",
"body": null,
"is_bot": false,
"headline": "Bump MSRV",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-07-12T15:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c7f7741e6c499d15a9cecd42e6757b2ab766490",
"body": "Fixes #200\n\nCo-authored-by: Laurențiu Nicola <lnicola@users.noreply.github.com>",
"is_bot": false,
"headline": "Add simple panic messages",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-07-12T15:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b93f1c63fb9eec7187e73337451b913d68d64203",
"body": "refactor(examples/ammonia-cat.rs): consider using `eprintln!` to write error to `stderr` instead of `stdout`",
"is_bot": false,
"headline": "Merge pull request #199 from afifurrohman-id/eprintln-patch",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-04-10T14:54:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e0db4f80f2efacd62cbcc2e16784a5fa831947f4",
"body": "Co-authored-by: Laurențiu Nicola <lnicola@users.noreply.github.com>",
"is_bot": false,
"headline": "Update examples/ammonia-cat.rs",
"author_name": "Afifurrohman",
"author_login": "afifurrohman-id",
"committed_at": "2024-04-10T06:09:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e85767a004b762992d0119f0a6f6fd6802909ac",
"body": "…error to stderr instead stdout",
"is_bot": false,
"headline": "refactor: Update ammonia-cat.rs, consider using `eprintln!` to write …",
"author_name": "Afifurrohman",
"author_login": "afifurrohman-id",
"committed_at": "2024-04-10T04:41:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6b0de49c3419785b578a202588efa873e532bf8",
"body": "…on-test-case\n\nAdd a regression test for `<?xml-stylesheet?>`",
"is_bot": false,
"headline": "Merge pull request #196 from notriddle/notriddle/processing-instructi…",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-31T01:43:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a1f85654cd90c2d131baf83267c5846ec8a7625",
"body": null,
"is_bot": false,
"headline": "Mention backporting plan for v4 in changelog",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T14:59:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f676dcfb55fd6e633adb1e108209bb2e67d2181a",
"body": "Update SECURITY.md with current release info",
"is_bot": false,
"headline": "Merge pull request #197 from notriddle/release-4.0",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T14:51:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91fea94f06f51516cd4a8998673a0c0bb1de0269",
"body": null,
"is_bot": false,
"headline": "Update SECURITY.md with current release info",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T14:49:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11119385c1151556279673d0b022b47c19692963",
"body": "Prepare 4.0.0 release",
"is_bot": false,
"headline": "Merge pull request #195 from djc/prepare-4",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T14:45:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "429b1c0a3978da8273bc8359890a5d6a7cf0c275",
"body": "Ammonia already handles this case correctly,\nbut let's be sure we don't regress.",
"is_bot": false,
"headline": "Add a regression test for `<?xml-stylesheet?>`",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T14:41:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "651b39cfbada5e1c385fb015c0836734554e543f",
"body": "Since html5ever appears in the public API, this needs a\nsemver-incompatible version bump.",
"is_bot": false,
"headline": "Prepare 4.0.0 release",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T13:54:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba0e263e3cba3cf5f7cdb72079b25227854ee692",
"body": "Update html5ever to 0.27",
"is_bot": false,
"headline": "Merge pull request #193 from djc/updates",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2024-03-25T13:37:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6228bda8574561efb7da56de62d788fef9375c41",
"body": null,
"is_bot": false,
"headline": "Apply clippy suggestions",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:29:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2412f833dd84c79add4eaf2cec8ae5639d5caffe",
"body": null,
"is_bot": false,
"headline": "Fix formatting with cargo fmt",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:29:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c30043d7cdbb7375a9f3975eaca1907062ea91c3",
"body": null,
"is_bot": false,
"headline": "Update to 2021 edition",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:29:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a90f4003e1078c099b3366d0cb58a6d6e6f1827d",
"body": null,
"is_bot": false,
"headline": "Add comment about env_logger update",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:11:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4619898554477c1ec5e29a3ed07ae65bea21b8f6",
"body": null,
"is_bot": false,
"headline": "Update html5ever to 0.27",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:09:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9957d80c1b97e67f8d60453ab11fc35b15be8261",
"body": null,
"is_bot": false,
"headline": "Make MSRV explicit in Cargo metadata",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:09:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "893585431e5f6f375cdfc802826fbdeadd0b9efc",
"body": null,
"is_bot": false,
"headline": "Test MSRV at 1.60",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:08:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d0ef37a7ac22cdd32c3f5c324c90f146f221e92",
"body": null,
"is_bot": false,
"headline": "Exclude dev-dependencies from MSRV CI",
"author_name": "Dirkjan Ochtman",
"author_login": "djc",
"committed_at": "2024-03-25T09:08:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f3796d8649f9d219f0c13feb7f321612ea1618fd",
"body": "Update crates.rs README link",
"is_bot": false,
"headline": "Merge pull request #191 from adamchainz/patch-1",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2023-12-07T15:30:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "970ce5961d60b4c8f69e061411af60456016b7d8",
"body": "The [crates.rs page](https://crates.rs/crates/ammonia) says:\r\n\r\n> The official crate repository is crates.io.\r\n>\r\n> crates.rs is a former domain name of the lib.rs website.\r\n>\r\n> Please update your links/bookmarks/habits, because the crates.rs domain will be phased out.\r\n\r\nPer the message, I’ve updated the link to use crates.io (I don’t know the advantage of using lib.rs).",
"is_bot": false,
"headline": "Update crates.rs README link",
"author_name": "Adam Johnson",
"author_login": "adamchainz",
"committed_at": "2023-12-07T15:10:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98c2ebaca464ee9ee96acab43fc5a8ebb996106e",
"body": "189: Update issue templates r=lnicola a=notriddle\n\n\n\nCo-authored-by: Michael Howell <michael@notriddle.com>",
"is_bot": true,
"headline": "Merge #189",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2023-10-20T05:37:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "acf46dd6d92228a9f1cb0eb92d8637e941ef694a",
"body": null,
"is_bot": false,
"headline": "Bump MSRV",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2023-10-20T00:18:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ada32ba4060f9dff0ed0a4c07ed97b9ac7b5a1c",
"body": null,
"is_bot": false,
"headline": "Update issue templates",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2023-10-19T20:39:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa0f8d2f8cee1030acc4ecad1da089f18b4afb65",
"body": "181: Remove duplicated `kbd` tag r=notriddle a=pitdicker\n\n\n\nCo-authored-by: Paul Dicker <pitdicker@gmail.com>",
"is_bot": true,
"headline": "Merge #181",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2023-03-23T15:14:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9098c52c59878c750a404d5d51022e923cfeffe5",
"body": null,
"is_bot": false,
"headline": "Remove duplicated `kbd` tag",
"author_name": "Paul Dicker",
"author_login": "pitdicker",
"committed_at": "2023-03-23T12:05:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "935a125b07b287375e816754ef5a4b28b6cbec92",
"body": null,
"is_bot": false,
"headline": "Update CHANGELOG.md",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2022-12-12T20:23:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27cbed745c7fdc95af5819a05dbf3af99ab42c72",
"body": "177: Use the `Display` trait instead of an inherent `to_string` method r=lnicola a=notriddle\n\nFixes #167\n\nCo-authored-by: Michael Howell <michael@notriddle.com>",
"is_bot": true,
"headline": "Merge #177",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2022-12-12T20:01:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c8a510174ec5910e51a7ac19e314df6de1db8d0",
"body": "178: Bump the version of `time` used in the benchmark r=lnicola a=notriddle\n\n\n\nCo-authored-by: Michael Howell <michael@notriddle.com>",
"is_bot": true,
"headline": "Merge #178",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2022-12-12T19:55:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f101049b77a7a4b534473a7c879e115d94bb6c05",
"body": null,
"is_bot": false,
"headline": "Bump the version of `time` used in the benchmark",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2022-12-12T18:07:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b801bec79438338cba7f83fc6294a63acffd947",
"body": null,
"is_bot": false,
"headline": "Use the `Display` trait instead of an inherent `to_string` method",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2022-12-12T17:59:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32e12a0577fd9013712d40db4b06955b41214579",
"body": null,
"is_bot": false,
"headline": "Update CHANGELOG.md",
"author_name": "Michael Howell",
"author_login": "notriddle",
"committed_at": "2022-12-04T19:03:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15792e1289ecc3c97eaf0fcdfa7732e31158400e",
"body": "176: Do not require `'static` to `UrlRelativeEvaluate` r=notriddle a=rhysd\n\nFixes #175\r\n\r\nWith this patch, `UrlRelative` knows the outer lifetime `'a` and is bound by it.\r\n\r\nI confirmed that the following code works.\r\n\r\n```rust\r\nuse ammonia::*;\r\nuse std::borrow::Cow;\r\n\r\nstruct Eval<'a>(&'a str);\r\n\r\n\n[…]\nrel=\"noopener noreferrer\">link</a>\r\n```\r\n\r\nComparing with the code in #175, please notice `UrlRelativeEvaluate` is now bound as `UrlRelativeEvaluate<'a>`.\n\nCo-authored-by: rhysd <lin90162@yahoo.co.jp>",
"is_bot": true,
"headline": "Merge #176",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2022-12-04T16:59:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ca52f6dcc4069d2d8bfd6f2df69cbb69247b9a7",
"body": null,
"is_bot": false,
"headline": "Do not require `'static` to `UrlRelativeEvaluate` (fixes #175)",
"author_name": "rhysd",
"author_login": "rhysd",
"committed_at": "2022-12-04T16:41:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42ecc97e0862d741b1072ec234f51f87d5f6dcd6",
"body": "173: Release version 3.3.0 r=lnicola a=notriddle\n\n\n\nCo-authored-by: Michael Howell <michael@notriddle.com>",
"is_bot": true,
"headline": "Merge #173",
"author_name": "bors[bot]",
"author_login": "bors[bot]",
"committed_at": "2022-11-29T19:20:26Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 41,
"commits_last_year": 40,
"latest_release_at": "2026-07-22T03:48:57Z",
"latest_release_tag": "v4.1.4",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 16,
"days_since_latest_release": 0,
"mean_days_between_releases": 42.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "ammonia",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"html",
"security",
"sanitization",
"xss",
"text-processing",
"web-programming"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/ammonia",
"is_deprecated": false,
"latest_version": "4.1.4",
"repository_url": "https://github.com/rust-ammonia/ammonia",
"versions_count": 45,
"total_downloads": 13031834,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 788217,
"first_published_at": "2015-09-04T17:50:51.795474Z",
"latest_published_at": "2026-07-22T03:48:37.108087Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 54,
"stars": 668,
"watchers": 8,
"fork_history": {
"days": [
{
"date": "2017-06-09",
"count": 1
},
{
"date": "2017-08-22",
"count": 1
},
{
"date": "2017-09-26",
"count": 1
},
{
"date": "2017-09-29",
"count": 1
},
{
"date": "2017-10-24",
"count": 1
},
{
"date": "2018-02-28",
"count": 1
},
{
"date": "2018-05-03",
"count": 1
},
{
"date": "2018-05-24",
"count": 1
},
{
"date": "2018-10-04",
"count": 1
},
{
"date": "2018-12-10",
"count": 1
},
{
"date": "2019-04-11",
"count": 1
},
{
"date": "2019-04-27",
"count": 1
},
{
"date": "2019-05-04",
"count": 1
},
{
"date": "2019-05-05",
"count": 1
},
{
"date": "2019-07-29",
"count": 1
},
{
"date": "2019-12-08",
"count": 1
},
{
"date": "2020-02-18",
"count": 1
},
{
"date": "2020-02-27",
"count": 1
},
{
"date": "2020-06-22",
"count": 1
},
{
"date": "2020-12-19",
"count": 1
},
{
"date": "2021-03-24",
"count": 1
},
{
"date": "2021-05-14",
"count": 1
},
{
"date": "2021-08-06",
"count": 1
},
{
"date": "2022-04-04",
"count": 1
},
{
"date": "2022-04-07",
"count": 1
},
{
"date": "2022-09-21",
"count": 1
},
{
"date": "2022-11-07",
"count": 1
},
{
"date": "2022-12-04",
"count": 1
},
{
"date": "2023-02-10",
"count": 1
},
{
"date": "2023-10-20",
"count": 1
},
{
"date": "2023-11-17",
"count": 1
},
{
"date": "2023-12-07",
"count": 1
},
{
"date": "2024-03-03",
"count": 1
},
{
"date": "2024-03-25",
"count": 1
},
{
"date": "2024-04-10",
"count": 1
},
{
"date": "2024-04-19",
"count": 1
},
{
"date": "2024-05-04",
"count": 1
},
{
"date": "2024-07-19",
"count": 2
},
{
"date": "2024-09-14",
"count": 1
},
{
"date": "2024-09-20",
"count": 1
},
{
"date": "2024-10-29",
"count": 1
},
{
"date": "2024-12-10",
"count": 1
},
{
"date": "2024-12-18",
"count": 1
},
{
"date": "2025-02-23",
"count": 1
},
{
"date": "2025-06-04",
"count": 1
},
{
"date": "2025-07-08",
"count": 1
},
{
"date": "2025-08-04",
"count": 1
},
{
"date": "2025-09-05",
"count": 1
},
{
"date": "2025-10-28",
"count": 1
},
{
"date": "2025-12-25",
"count": 1
},
{
"date": "2026-05-26",
"count": 1
},
{
"date": "2026-06-01",
"count": 1
},
{
"date": "2026-07-11",
"count": 1
}
],
"complete": true,
"collected": 54,
"total_forks": 54
},
"star_history": null,
"open_issues_and_prs": 25
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"Cargo.toml",
"benchmarks/Cargo.toml"
],
"largest_source_bytes": 179763,
"source_files_sampled": 7,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"Cargo.toml",
"benchmarks/Cargo.toml"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 7,
"direct_affected_count": 0
},
"ecosystems": [
"crates"
],
"dependencies": [
{
"name": "html5ever",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.39"
},
{
"name": "maplit",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0"
},
{
"name": "url",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2"
},
{
"name": "cssparser",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.37.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "cssparser",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "html5ever",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "maplit",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "url",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "env_logger",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "time",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "version-sync",
"direct": false,
"version": null,
"ecosystem": "crates"
}
],
"collected": true,
"truncated": false,
"total_count": 7,
"direct_count": 4,
"indirect_count": 3
}
},
"maintainership": {
"issues": {
"open_prs": 6,
"merged_prs": 161,
"open_issues": 19,
"closed_ratio": 0.736,
"closed_issues": 53,
"closed_unmerged_prs": 12
},
"bus_factor": 1,
"bot_contributors": 3,
"top_contributors": [
{
"type": "User",
"login": "notriddle",
"commits": 242,
"avatar_url": "https://avatars.githubusercontent.com/u/1593513?v=4"
},
{
"type": "User",
"login": "lnicola",
"commits": 55,
"avatar_url": "https://avatars.githubusercontent.com/u/308347?v=4"
},
{
"type": "User",
"login": "djc",
"commits": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/158471?v=4"
},
{
"type": "User",
"login": "Eijebong",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/3650385?v=4"
},
{
"type": "User",
"login": "dingelish",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/1870436?v=4"
},
{
"type": "User",
"login": "mozfreddyb",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/5418775?v=4"
},
{
"type": "User",
"login": "stanciuadrian",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/2334569?v=4"
},
{
"type": "User",
"login": "kivikakk",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/1915?v=4"
},
{
"type": "User",
"login": "kornelski",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/72159?v=4"
},
{
"type": "User",
"login": "mattico",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/853158?v=4"
}
],
"contributors_sampled": 28,
"top_contributor_share": 0.665
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"main.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 8,
"reason": "12 out of 14 merged PRs checked by a CI test -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 3,
"reason": "Found 3/10 approved changesets -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 19 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "fba751216ad8eb7a4e71882350016f810e4d925a",
"ran_at": "2026-07-22T18:24:21Z",
"aggregate_score": 5.8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T03:48:44Z",
"oldest_open_prs": [
{
"number": 202,
"created_at": "2024-07-19T04:39:38Z",
"last_comment_at": "2024-07-19T04:58:11Z",
"last_comment_author": "oriongonza"
},
{
"number": 205,
"created_at": "2024-09-14T11:26:10Z",
"last_comment_at": "2024-09-14T19:57:42Z",
"last_comment_author": "notriddle"
},
{
"number": 224,
"created_at": "2025-10-28T13:08:21Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 233,
"created_at": "2026-03-17T01:40:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 240,
"created_at": "2026-05-26T19:02:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 241,
"created_at": "2026-05-26T19:21:36Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-22T03:47:57Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 59,
"created_at": "2017-09-28T19:26:06Z",
"last_comment_at": "2017-10-02T02:22:26Z",
"last_comment_author": "notriddle"
},
{
"number": 83,
"created_at": "2017-11-12T18:10:09Z",
"last_comment_at": "2018-05-24T09:58:53Z",
"last_comment_author": "mozfreddyb"
},
{
"number": 128,
"created_at": "2019-10-17T21:30:38Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 135,
"created_at": "2020-03-19T19:14:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 145,
"created_at": "2021-08-04T10:08:38Z",
"last_comment_at": "2026-03-03T02:53:27Z",
"last_comment_author": "notriddle"
},
{
"number": 154,
"created_at": "2022-03-09T21:52:46Z",
"last_comment_at": "2023-01-27T12:38:52Z",
"last_comment_author": "xmo-odoo"
},
{
"number": 163,
"created_at": "2022-06-23T19:16:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 164,
"created_at": "2022-07-28T20:42:16Z",
"last_comment_at": "2023-01-27T12:48:43Z",
"last_comment_author": "xmo-odoo"
},
{
"number": 174,
"created_at": "2022-12-01T11:52:36Z",
"last_comment_at": "2023-12-15T14:38:17Z",
"last_comment_author": "fdemmer"
},
{
"number": 182,
"created_at": "2023-03-23T16:09:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 185,
"created_at": "2023-08-08T09:26:52Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 190,
"created_at": "2023-10-30T22:27:48Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 198,
"created_at": "2024-03-28T14:58:09Z",
"last_comment_at": "2025-01-14T17:20:38Z",
"last_comment_author": "sebadob"
},
{
"number": 203,
"created_at": "2024-08-31T06:04:50Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 210,
"created_at": "2025-05-07T16:37:54Z",
"last_comment_at": "2025-05-08T13:14:26Z",
"last_comment_author": "notriddle"
},
{
"number": 212,
"created_at": "2025-07-04T11:04:01Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 223,
"created_at": "2025-10-27T13:54:53Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 236,
"created_at": "2026-04-04T12:49:32Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 237,
"created_at": "2026-04-28T05:27:10Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/rust-ammonia/ammonia",
"host": "github.com",
"name": "ammonia",
"owner": "rust-ammonia"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"security": 58,
"vitality": 83,
"community": 73,
"governance": 63,
"engineering": 58
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"commits_last_year": 40,
"human_commit_share": 0.89,
"days_since_last_push": 0,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "40 commits in the last year",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 40
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 41,
"latest_release_tag": "v4.1.4",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 42.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "41 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 41
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~42.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 42.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 73,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"forks": 54,
"stars": 668,
"watchers": 8,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "668 stars",
"points": 45.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 668
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "54 forks",
"points": 14.4,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 54
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "8 watchers",
"points": 4.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 8
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "excellent",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 98,
"inputs": {
"packages": [
"ammonia"
],
"dependents": null,
"ecosystems": "crates",
"total_downloads": 13031834,
"monthly_downloads": 788217
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "788,217 downloads/month across crates",
"points": 78.6,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 788217,
"ecosystems": "crates"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 63,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 28,
"top_contributor_share": 0.665
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 66% of commits",
"points": 7.5,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 66
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "28 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 28
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"merged_prs": 161,
"open_issues": 19,
"closed_issues": 53,
"issue_closed_ratio": 0.736,
"closed_unmerged_prs": 12
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "74% of issues closed",
"points": 34.4,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 74
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "161/173 decided PRs merged",
"points": 35.6,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 161,
"decided": 173
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 3/10 approved changesets -- score normalized to 3",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"followers": 4,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "rust-ammonia",
"public_repos": 2,
"account_age_days": 3201
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "4 followers of rust-ammonia",
"points": 5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 4,
"login": "rust-ammonia"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "2 public repos, account ~8 yr old",
"points": 15.5,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 2
}
},
{
"code": "account_age_years",
"params": {
"years": 8
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"ammonia"
],
"ecosystems": "crates",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on crates",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "crates"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "45 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 45
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 58,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "12 out of 14 merged PRs checked by a CI test -- score normalized to 8",
"points": 16,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [
"html-sanitization",
"web",
"crates",
"security"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "4 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 4
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 58,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 58,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "12 out of 14 merged PRs checked by a CI test -- score normalized to 8",
"points": 2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 3/10 approved changesets -- score normalized to 3",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 16
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 49,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 26,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.494,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "44 of 89 human commits state their intent (structured subject or explanatory body)",
"points": 26.4,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 44,
"sampled": 89
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"Cargo.toml",
"benchmarks/Cargo.toml"
],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Cargo.toml, benchmarks/Cargo.toml (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "Cargo.toml, benchmarks/Cargo.toml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Rust (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"primary_language": "Rust",
"largest_source_bytes": 179763,
"source_files_sampled": 7,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Rust (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/7 source files over 60KB",
"points": 47.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 7,
"oversized": 1
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index crates:ammonia@4.1.4; advisories assessed against the repository dependency graph instead",
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-07-22T18:24:47.753059Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/rust-ammonia/ammonia.svg",
"full_name": "rust-ammonia/ammonia",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}