Öffentliches Register
Software-GesundheitsberichtSchema 0.26.0 · Metriken 1.13.0 · 2026-07-22 14:02 UTC

scm-rs / packageurl.rs

Rust implementation of the Package URL specification.

RustMIT★ 16 Sterne⑂ 15 Forksseit Apr. 2018Auf GitHub ansehen ↗

scm-rs/packageurl.rs erreicht einen Gesundheitsindex von 61 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (75/100) ab, am schwächsten bei Security (46/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

61
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

61
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

scm-rsOrganisation
4 Follower9 öffentliche Reposseit Apr. 2025

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
crates.iopackageurl0.7.033.75413vor 0 Tagenpackage-urlpurldevelopment-toolsencodingparser-implementations

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

75Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
4.8/36Commit-Rhythmus — 7/52 Wochen mit Commits
13.1/18Commit-Volumen — 28 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year28
human_commit_share1
days_since_last_push0
active_weeks_last_year7
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 14 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 0 Tagen
19.8/27Release-Rhythmus — ein Release etwa alle 49,1 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count14
latest_release_tagv0.7.0
releases_from_tagsnein
days_since_latest_release0
mean_days_between_releases49,1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

48Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
19.1/60Stars — 16 Stars
9.6/25Forks — 15 Forks
0/15Watcher — 2 Watcher
Verwendete Eingangsdaten
forks15
stars16
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
60.4/80Downloads pro Monat — 33.754 Downloads/Monat über crates
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagespackageurl
dependents
ecosystemscrates
total_downloads518.701
monthly_downloads33.754
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

61Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
9.5/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 58 % der Commits
13.5/13.5Breite der Beitragenden — 11 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 22 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled11
top_contributor_share0,58
Wie die Bewertung erfolgt
38.9/46.8Issue-Lösungsquote — 83 % der Issues geschlossen
29.1/38.3PR-Annahme — 16/21 entschiedene PRs gemergt
1.5/15OpenSSF Scorecard: Code-Review — Found 4/21 approved changesets -- score normalized to 1
Verwendete Eingangsdaten
merged_prs16
open_issues2
closed_issues10
issue_closed_ratio0,833
closed_unmerged_prs5
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
5/25Reichweite des Inhabers — 4 Follower von scm-rs
9.8/25Kontohistorie — 9 öffentliche Repos, Kontoalter ca. 1 Jahre
Verwendete Eingangsdaten
followers4
owner_typeOrganization
is_verified
owner_loginscm-rs
public_repos9
account_age_days454

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf crates
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 0 Tagen
20/20Versionshistorie — 13 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagespackageurl
ecosystemscrates
any_deprecatednein
min_days_since_publish0

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

67Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 3 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://scm-rs.github.io/packageurl.rs/
10/10Repository-Beschreibung
10/10Topics — 4 Topics
0/10Wiki
Verwendete Eingangsdaten
topicspurl, package-url, rust, library
has_wikinein
homepagehttps://scm-rs.github.io/packageurl.rs/
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

46Gefährdet · 16 % des Gesamtindex

Sicherheitslage

46Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 4/21 approved changesets -- score normalized to 1
2.5/2.5Contributors — project has 22 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

58Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 84 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,84
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — Cargo.toml, afl/Cargo.toml, web/Cargo.toml (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Rust (statisch typisiert)
0/10Reproduzierbare Umgebung
10/10Belegte Agentenpraxis — 13 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,13
toolchain_manifestsCargo.toml, afl/Cargo.toml, web/Cargo.toml
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Rust (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/13 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageRust
largest_source_bytes14.674
source_files_sampled13
oversized_source_files0

Eckdaten

16GitHub-Sterne
11Mitwirkende
28Commits, letzte 12 Monate
0Tage seit letztem Push
14Releases
1Bus-Faktor
2offene Issues
crates.ioPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'packageurl-fuzz' from its registry
  • Could not fetch crates package 'packageurl-web' from its registry
  • deps.dev does not index crates:packageurl@0.7.0; advisories assessed against the repository dependency graph instead
  • No resolved dependencies carried a version and a supported ecosystem

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 15 ⇿
0Sterne
15Forks
12Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

03581013151312021-052023-122026-07
Major 0Minor 3Patch 1

Jeder Punkt umfasst 5 Tage.

OpenSSF Scorecard 4.6 / 10
4.6Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-22 14:01 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 4/21 approved changesets -- score normalized to 1
10Contributorsproject has 22 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 11
RegistryPaketVersionsvorgabeManifest
crates.iopercent-encoding2Cargo.toml
crates.iothiserror2Cargo.toml
crates.iomemchr2Cargo.toml
crates.ioserde1Cargo.toml
crates.ioafl0.10.1afl/Cargo.toml
crates.iopackageurlafl/Cargo.toml
crates.iojs-sys0.3web/Cargo.toml
crates.ioleptos0.7web/Cargo.toml
crates.iopackageurlweb/Cargo.toml
crates.iowasm-bindgen0.2web/Cargo.toml
crates.ioweb-sys0.3web/Cargo.toml
Alle Abhängigkeiten 12

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 9 direkte und 3 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
crates.ioafldirekt
crates.iojs-sysdirekt
crates.ioleptosdirekt
crates.iomemchrdirekt
crates.iopercent-encodingdirekt
crates.ioserdedirekt
crates.iothiserrordirekt
crates.iowasm-bindgendirekt
crates.ioweb-sysdirekt
crates.iocriterionindirekt
crates.ioserde_jsonindirekt
crates.iourlindirekt
Abhängigkeits-Advisories nicht bewertet

Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies carried a version and a supported ecosystem

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "purl",
        "package-url",
        "rust",
        "library"
      ],
      "is_fork": false,
      "size_kb": 216,
      "has_wiki": false,
      "homepage": "https://scm-rs.github.io/packageurl.rs/",
      "languages": {
        "CSS": 4797,
        "HTML": 270,
        "Rust": 56096,
        "Shell": 1567
      },
      "pushed_at": "2026-07-22T11:24:48Z",
      "created_at": "2018-04-12T17:50:57Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T11:44:30Z",
      "description": "Rust implementation of the Package URL specification.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "scm-rs",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/208945941?v=4",
      "created_at": "2025-04-24T09:48:03Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 454
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-22T11:29:59Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2025-12-11T07:36:48Z"
        },
        {
          "tag": "v0.6.0-rc.1",
          "kind": "prerelease",
          "published_at": "2025-09-09T07:51:12Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2025-08-11T08:49:55Z"
        },
        {
          "tag": "v0.5.0-rc.9",
          "kind": "prerelease",
          "published_at": "2025-05-06T15:28:08Z"
        },
        {
          "tag": "v0.5.0-rc.8",
          "kind": "prerelease",
          "published_at": "2025-05-06T15:15:58Z"
        },
        {
          "tag": "v0.5.0-rc.7",
          "kind": "prerelease",
          "published_at": "2025-05-06T15:04:42Z"
        },
        {
          "tag": "v0.5.0-rc.6",
          "kind": "prerelease",
          "published_at": "2025-05-06T14:54:22Z"
        },
        {
          "tag": "v0.5.0-rc.5",
          "kind": "prerelease",
          "published_at": "2025-05-06T14:41:52Z"
        },
        {
          "tag": "v0.5.0-rc.3",
          "kind": "prerelease",
          "published_at": "2025-05-06T13:54:26Z"
        },
        {
          "tag": "v0.5.0-rc.2",
          "kind": "prerelease",
          "published_at": "2025-05-06T12:51:48Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2025-04-07T14:35:31Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2024-05-27T09:03:22Z"
        },
        {
          "tag": "0.1.0",
          "kind": "minor",
          "published_at": "2018-04-13T20:55:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d048a178b51145e0761e8974cdd6e15631f32d2f",
          "body": "Drop CARGO_REGISTRY_TOKEN secret and use OIDC instead. Requires\nconfiguring a trusted publisher on crates.io for this repo.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: switch to trusted publishing for crates.io",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T10:50:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "28ca4fcbdf2eaf5d4d234b6ec21cf43fc0dbdde2",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: use workspace version and edition for all crates",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T08:48:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b61e5a0445a651be4de84fb3422a2f8c28f17784",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: update upload-pages-artifact to v5",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T08:29:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e1a63299d40bfa0457b407a51a4d223c46ef4029",
          "body": "cargo binstall was falling back to source compilation, which failed\nbecause lightningcss doesn't build on the CI's Rust version.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: install trunk from prebuilt binary instead of compiling",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T08:28:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "877e50a79570031338ad9bcf17844f536243a429",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "style: apply cargo fmt",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T08:17:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1aacea8f2e2c6db19a238ec8b3256f85033cbdfa",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: avoid let-chains to stay compatible with MSRV 1.85",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T08:13:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e2d7dec669c4bb4e80afd9a8855e0547399c1529",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: collapse nested if-let to satisfy clippy",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T07:57:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9c067d536a53bb91e0cc3dc436022177c0a2d133",
          "body": "The browser URL bar now updates via history.replaceState as the user\ntypes, making the URL always shareable. A \"Share\" button copies the\nfull link to clipboard with brief \"Copied!\" feedback.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add share button and sync URL bar with purl input",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T07:33:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1b0ea69ec78f362f3c97909405150ea743c037b7",
          "body": "The Swatinem cache restores binstall metadata that marks trunk as\nalready installed, but the actual binary is missing. Use --force\nto ensure the binary is always downloaded.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: force-install trunk to avoid stale cache hit",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T07:24:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "154a13438c799adb7a6fa028f84edf2039414dab",
          "body": "Remove the broken logo image. Add a pkg: badge as visual identity,\npolish the CSS with better focus states, dark mode, and a footer.\nSupport pre-populating the input via ?purl= query parameter.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: drop logo, improve styling, add ?purl= URL pre-population",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T07:21:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cfabd3d9b6178b51f48ffa879f53e8d1b6dcfa6e",
          "body": "Adds a CSR Leptos web app that validates PackageURL strings in real-time,\nshowing parsed components or error messages. Built with Trunk and\ndeployed to GitHub Pages via a new workflow.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add Leptos-based PackageURL validator web app",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-22T07:02:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e243371dc774d6740c508efe896ce2d4b07764b",
          "body": "Update to latest action versions (checkout v7, upload-pages-artifact v4,\ndeploy-pages v5) and add Swatinem/rust-cache for faster builds.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: update pages workflow actions and add rust cache",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-21T15:49:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e9a75aa63efee42d289dbdacf12938432bf72fcb",
          "body": "Adds a CSR Leptos web app that validates PackageURL strings in real-time,\nshowing parsed components or error messages. Built with cargo-leptos and\ndeployed to GitHub Pages via a new workflow.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add Leptos-based PackageURL validator web app",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2026-07-21T15:42:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fedbedc233170fb68b5dc92837680fbceaa2475a",
          "body": "The new Error variants are a breaking change against 0.6.0.",
          "is_bot": false,
          "headline": "chore: prepare for 0.7.0",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T15:10:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "755b51c9363a31331b381be5c12b0b99cfa21409",
          "body": "Adding a variant is no longer a breaking change for downstream matches.",
          "is_bot": false,
          "headline": "feat: mark Error as non_exhaustive",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T15:10:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76e0789d9504ff8ce6554cd9e2a3864b9c7649fe",
          "body": "A rules table (src/types.rs) replaces the per-type match arms scattered over the constructors and the parser: namespace required or prohibited, required qualifiers, and name, namespace, and version case rules.\nThe new PackageUrl::validate checks rules that span components — parsing applies it automa\n[…]\nparsing.\nThe builder rejects an empty name, and a trailing '/' no longer hides one from the parser.\nThe known-gaps list ends empty: every one of the 537 suite cases at the pinned commit is conformant.",
          "is_bot": false,
          "headline": "feat: enforce the per-type rules from the purl-spec type definitions",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T15:10:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d6f5e34af875f815aa9fbb274e2878e3a1c2f8c",
          "body": "An '@' followed by a further '/' belongs to the namespace, as in the scope of pkg:npm/@babel/core#/googleapis/api/annotations/, which now parses instead of failing with a missing name.",
          "is_bot": false,
          "headline": "fix: split the version only at an '@' in the final path segment",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T15:10:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2367d1fb24945344d83e3989956569878cb5bffb",
          "body": "A dedicated encode set covers qualifier values, whose canonical form percent-encodes '/' and ','.\n44 known gaps close; one mlflow input stays listed under normalization, which the encoding fix uncovered.",
          "is_bot": false,
          "headline": "fix: percent-encode '/' and ',' in canonical qualifier values",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T15:10:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1d30c00b8be450f98b19d03184f13c17c9b5e76",
          "body": "Run the official purl-spec suite (537 cases: parse, build, round-trip) against the public API, replacing the stale 25-case snapshot under `tests/spec/`.\nThe 77 currently non-conformant cases are tracked in `KNOWN_GAPS` as a two-sided guard: an unlisted failure is a regression, and a fixed case must \n[…]\nlongside); `scripts/update-purl-spec-tests.sh` refreshes them and verifies every file against `scripts/purl-spec-tests.sha256`.\nThe vendored files run under plain `cargo test`, so CI needs no changes.",
          "is_bot": false,
          "headline": "test: add purl-spec conformance suite with known-gap tracking",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T12:25:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c20da3b6269eb2d28e083c2bc05d30c8a5e829ea",
          "body": "The builders return `Result<&mut Self>`, but `test_serde` chained on the `Result`, so it failed to compile under the `serde` feature.\nAdd the missing `unwrap` calls, matching `test_to_str`.",
          "is_bot": false,
          "headline": "test: fix serde round-trip test builder chaining",
          "author_name": "Stefan Grönke",
          "author_login": "gronke",
          "committed_at": "2026-07-21T12:25:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d24f20f3d3c0242d88687119a5353dbc681eac2e",
          "body": null,
          "is_bot": false,
          "headline": "style: apply cargo fmt 2024",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-12-02T08:29:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "360f427d5b7f3651d7e50605f59469d826d7b496",
          "body": null,
          "is_bot": false,
          "headline": "build: uptick MSRV because of edition 2024",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-12-02T08:27:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8416b56f306f451086961b64427854780af5306a",
          "body": "Also switch to edition 2024 for the release, this should\nmake it easier working with dependencies.",
          "is_bot": false,
          "headline": "chore: prepare for 0.6.0",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-12-02T08:16:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69ec826438c01d5210e3b987867cab6aa5a426ce",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.6.0-rc.2",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-12-02T08:13:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23f1aab3dc623784962fb8b8d596748580476d6d",
          "body": null,
          "is_bot": false,
          "headline": "fix: clippy",
          "author_name": "Jim Crossley",
          "author_login": "jcrossley3",
          "committed_at": "2025-12-02T07:53:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b87b37bbccc8ea7a1ff7f14e80507c68dc31fc15",
          "body": "Fixes: #28\n\nIf upstream decides that slashes in qualifiers should be encoded to\n%2F, then we can remove the name-specific encode set and `.add(b'/')`\nto the ENCODE_SET constant.",
          "is_bot": false,
          "headline": "fix: introduce 2nd encode set to handle encoded slashes in names",
          "author_name": "Jim Crossley",
          "author_login": "jcrossley3",
          "committed_at": "2025-12-02T07:53:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a725aa0ab332934c350641508017eb09ddfa0813",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix formatting",
          "author_name": "Michael Lux",
          "author_login": "milux",
          "committed_at": "2025-09-08T08:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12ea7792b45ab4283c82008dbbb2158be5675004",
          "body": null,
          "is_bot": false,
          "headline": "chore: update deps",
          "author_name": "Michael Lux",
          "author_login": "milux",
          "committed_at": "2025-09-08T08:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8b1f7e4b58be8b6c8d267934301de1d4238141a",
          "body": null,
          "is_bot": false,
          "headline": "refactor!: Use `Result` for all `with_` methods, bump version",
          "author_name": "Michael Lux",
          "author_login": "milux",
          "committed_at": "2025-09-08T08:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12e2e1d638353d1242104e9e6e3cd321123ca9f9",
          "body": "…package types",
          "is_bot": false,
          "headline": "fix!: Enforce namespace restrictions and error handling for specific …",
          "author_name": "Michael Lux",
          "author_login": "milux",
          "committed_at": "2025-09-08T08:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a33017966382356375fb3303bc93666260533610",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix cargo metadata link",
          "author_name": "Helio Frota",
          "author_login": "helio-frota",
          "committed_at": "2025-09-05T10:01:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "887e669bc211316c9d3bb647ea9d7765e786ae79",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.5.0",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-08-11T08:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d910aba3393221b5e628cd3cf4caa60516c06aa4",
          "body": "Also, added some test cases.\n\nCloses: #21",
          "is_bot": false,
          "headline": "fix: proper handling of lowercase type and name, fixed",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-08-11T08:28:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "632a11864ce6538c5f036a00543d7c894f2499b2",
          "body": null,
          "is_bot": false,
          "headline": "chore: make clippy 1.89.0 happy",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-08-11T08:14:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e098760ce819441f677ce57d9530a658e69115a1",
          "body": "Closes: #21",
          "is_bot": false,
          "headline": "fix: proper handling of lowercase type and name",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-08-11T08:14:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97aa5050ceacad4706657c65f8080c05893d3ad5",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix typo",
          "author_name": "n4n5",
          "author_login": "Its-Just-Nans",
          "committed_at": "2025-08-01T07:20:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f86850b7675d37d318b01992f1a204665c1186f0",
          "body": null,
          "is_bot": false,
          "headline": "build: uptick MSRV due to dependencies",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-07-31T06:18:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20a634f8168d7e710c8b54974ee712c46650e859",
          "body": null,
          "is_bot": false,
          "headline": "ci: we don't need a scheduled run",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-07-31T06:18:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfc068c626f448962bb96ba99928b6396271ebe8",
          "body": "Updating to the canonical repository. This helps crates.io (and friends) point to the correct place",
          "is_bot": false,
          "headline": "chore: update repository in Cargo.toml",
          "author_name": "Justin \"J.R.\" Hill",
          "author_login": "booniepepper",
          "committed_at": "2025-07-31T06:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "853551aa3264af6efa90e74ca1f16f3a8b48bdf6",
          "body": null,
          "is_bot": false,
          "headline": "refactor: replace lazy_static with std equivalent",
          "author_name": "Helio Frota",
          "author_login": "helio-frota",
          "committed_at": "2025-05-07T14:29:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11ac57a499726353bc8c6948b9ec5443cd038c94",
          "body": null,
          "is_bot": false,
          "headline": "ci: add merge queue",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-07T06:22:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89dd632796c4465a9e99be66de2475c499e1eb05",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T15:22:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5a1f26c0215571642179ba8a606f419ac019ce9",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T15:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d18a0347a51cbe76b104e3ed4ac44ad18f9b9e1a",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T14:58:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6ae04ed433c73527b226f861bdb0c471d333d0d",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.5.0-rc.6",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T14:49:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99642a821d7181f111c1e25ea18f37561d8080f1",
          "body": null,
          "is_bot": false,
          "headline": "build: fix up benchmark runs",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T14:45:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0b3c875b5acb2eeb13ebc055f941fd77b45d9df",
          "body": null,
          "is_bot": false,
          "headline": "chore: update version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T14:07:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62744d0343ae0dddd5e2310d7a7e3ceb4d25e8f3",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T13:59:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c14dc3f53517e54b8519bdcb79d9eefaf0ccc14",
          "body": null,
          "is_bot": false,
          "headline": "build: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T13:49:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25e7ee181a91d5a8fca3b43bdb56b2e18df90ac1",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix up one more link",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T13:12:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fdc62b49c81f86c484d1106fb6ba629453913bc",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T12:28:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb4376914cbe0febb420b8cb990dca81f5269fb8",
          "body": "For one, I don't think it was ever used. Second, we would need an\nadditional 0.4 layer now. And third, I doesn't work well with\n`cargo ws`.",
          "is_bot": false,
          "headline": "chore: drop the 0.3 compatibility later",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T11:57:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a1ddcfb6f347832b3c8267651b4cbf21895510",
          "body": null,
          "is_bot": false,
          "headline": "docs: clean up before release",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T11:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75d58ebd0bc78afe7ce444ffb971257746aa708d",
          "body": null,
          "is_bot": false,
          "headline": "chore: update Rust edition and dependencies",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T11:38:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "031ef3f5d8110050660694d30e25ad6f8c7668fa",
          "body": null,
          "is_bot": false,
          "headline": "docs: update readme after transfer",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T11:34:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "376feafb7c2f8d40e8183e0d364d80e935464025",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick version to 0.5.0-rc.1",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T11:29:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "933bfd89ee994c60ee6f63e17d1fcc07247f2810",
          "body": null,
          "is_bot": false,
          "headline": "ci: use shared publish workflow",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T10:32:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "448283681bc314f7d3b26c486281560466a15b08",
          "body": null,
          "is_bot": false,
          "headline": "chore: work around bench deprecation",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T10:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc75eb700fa836f354ac28e7c6ce16b3ea56a804",
          "body": null,
          "is_bot": false,
          "headline": "chore: uptick MSRV",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T10:10:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c76dc081003665e411295c4d2f5278b3ee90db50",
          "body": null,
          "is_bot": false,
          "headline": "build: set MSRV",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T08:31:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b04e8b2e8a4d8a36e41090e6ed73f54a12fd48b4",
          "body": null,
          "is_bot": false,
          "headline": "ci: replace ci workflow with shared one",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-05-06T08:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1654d01730ac0ee1ed889bbaf7571dcef7d7df7",
          "body": null,
          "is_bot": false,
          "headline": "chore: Release packageurl version 0.4.2",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-04-07T14:33:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1b8a9d7d6d110b7c72e63fd7e82376eb26c7bcd",
          "body": "See https://github.com/package-url/purl-spec/blob/main/PURL-SPECIFICATION.rst#character-encoding\n\n\"All other characters MUST be encoded as UTF-8 and then percent-encoded\"",
          "is_bot": false,
          "headline": "fix: encode '+' per the latest version of the spec",
          "author_name": "Jim Crossley",
          "author_login": "jcrossley3",
          "committed_at": "2025-04-07T14:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72c0a2f35cae94dc711bcacafadede2c38cad7ab",
          "body": null,
          "is_bot": false,
          "headline": "chore: make newer clippy happy",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-04-07T09:48:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0328a073d1caf2a4d095907ed43fd975ca00e60e",
          "body": null,
          "is_bot": false,
          "headline": "ci: try using newer ubuntu for glibc issues and code coverage",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2025-04-07T09:46:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ad593baf92070901ce7bd4644adb00a09d8283d",
          "body": "BREAKING-CHANGE: This also sets the edition to 2018. While that is a\nbreaking change, I still think it's acceptable, as I am not sure how\nmuch of edition 2015 is still being used. Let's move on.",
          "is_bot": false,
          "headline": "feat: add a compatibility layer for the 0.3 version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-08-30T07:11:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe11e5421be422df10ea85fd5fd31d89b565ab4e",
          "body": null,
          "is_bot": false,
          "headline": "build: uptick version",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-08-30T06:41:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dcc4ec6dbf1f8d7ad054a74afc93a7d6df1d03c",
          "body": "Since the % sign is used for the escape in percent encoding, we need to\nensure that that is itself escaped if found in the input. Debian git tags\nin vcs_urls in particular seem to be moving to replacing the : in a\nversion like `1:41.1` into `1%41.1`. The correct encoding of that winds\nup being `1%2541.1`. Without this, adding the vcs_url as it is given\nwill wind up forcing the _parsing_ of the subsequent displayed\nPackageUrl to decode the `1%41.1` as `1A.1`.\n\nFixes #12.",
          "is_bot": false,
          "headline": "ensure that % is escaped during percent encoding",
          "author_name": "Jonathan Creekmore",
          "author_login": "jcreekmore",
          "committed_at": "2024-08-30T06:39:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dd4756e1ade17e75814c633dfdb9cdb3c82041a",
          "body": null,
          "is_bot": false,
          "headline": "ci: fix publish workflow",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:48:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95509a562ac1e157d8e592607abae24dcc5b8a44",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix changelog link",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba9527c090739760f565444bc222e3ec1679a83c",
          "body": null,
          "is_bot": false,
          "headline": "doc: clean up readme",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:44:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f80a0ab29c88915a5bbca242148fd393f710c8c",
          "body": "I am not sure about the state of cargo-make, so let's not advertise it\nthat much.",
          "is_bot": false,
          "headline": "chore: changelong goes to github releases, don't advertise cargo make",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a67a4323874f875fcd19094e736095bcefc6d3cc",
          "body": null,
          "is_bot": false,
          "headline": "build: next version, add author",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:35:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d39f9c97b5486ef847a416265529df2a3bddefc",
          "body": null,
          "is_bot": false,
          "headline": "feat: allow clearing namespace, version, sub path, and qualifiers",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2cbf53fbd2415578a4135f829f7c923b3d154af",
          "body": null,
          "is_bot": false,
          "headline": "test: allow unused code in tests, warned be beta and nightly",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6935ea6c9d4651ccd23bb33bf3af75a9ea4c6c63",
          "body": null,
          "is_bot": false,
          "headline": "chore: make clippy happy",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4146d557e74d6e4366fcc3acff3471f5e7d0b69",
          "body": null,
          "is_bot": false,
          "headline": "chore: prevent intellij from complaining, it's a string",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39d6aef6fd6bad01ffeaa3f1d94403affa06cdb5",
          "body": null,
          "is_bot": false,
          "headline": "build: looks like tarpaulin requires an explicit default feature",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1be1c67c2a2e3a04a9be78490ddde2b24ffe001",
          "body": null,
          "is_bot": false,
          "headline": "ci: migrate tarpaulin to non-deprecated action",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae1de9b047db4ce795553f49075c158367574dc4",
          "body": "We might reconsider this if it makes sense (for release branches, etc).",
          "is_bot": false,
          "headline": "ci: limit targeting to master",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6cdcf4592a9b6d63a9950ce0648f9a38c70eb7c",
          "body": null,
          "is_bot": false,
          "headline": "ci: refresh a lot of long deprecated CI actions",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0de215e068d6b46e4e46ac71aa107006bc4da51b",
          "body": null,
          "is_bot": false,
          "headline": "ci: publish based on `v*` tags, after removing ruby/gem publishing",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3180b9bd3ec5fe01423d1b55ab0f971d413f5a9",
          "body": null,
          "is_bot": false,
          "headline": "ci: drop ruby publishing, doesn't seem to be used anyway",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9550b952acba5be780b8837151f9c3d6abfcf8a7",
          "body": null,
          "is_bot": false,
          "headline": "chore: ignore intellij files",
          "author_name": "Jens Reimann",
          "author_login": "ctron",
          "committed_at": "2024-05-27T08:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75c79bafff5c4817900c8310d368c0ca0e4e1597",
          "body": null,
          "is_bot": false,
          "headline": "Derive Eq for Full Equivalence Relations",
          "author_name": "Blake Johnson",
          "author_login": "voteblake",
          "committed_at": "2024-05-27T07:32:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eddaaedfe9541ac99367a5b17d8ba53edeaa8b52",
          "body": null,
          "is_bot": false,
          "headline": "Release v0.3.0",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:30:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ae6d0da5c30c75b176b728baa95ddaee86ede96",
          "body": null,
          "is_bot": false,
          "headline": "Add additional tests with the `serde` feature enabled",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:19:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed4c1a835a690938d0aef68232a4344b5bb75c62",
          "body": null,
          "is_bot": false,
          "headline": "Reformat code with `cargo fmt`",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:19:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3d331ea6f86f1599316183841a60050c967d7f2",
          "body": null,
          "is_bot": false,
          "headline": "Update badges and sections in `README.md`",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "952ccbd6f679693f858026497074f836a6b13d61",
          "body": null,
          "is_bot": false,
          "headline": "Make `PackageUrl` canonicalize its components on the fly",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:07:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a0d4ea746e47a9c35528fa99eb885b07d4ca546",
          "body": "… type",
          "is_bot": false,
          "headline": "Make `PackageUrl` lowercase given `name` and `namespace` if needed by…",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T15:04:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9208550ab71aa1fc97b28d4019f3db14d7174f4c",
          "body": null,
          "is_bot": false,
          "headline": "Derive `PartialEq` for `PackageUrl`",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T14:49:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f686c61cb7bd3dae719d75ced337e2083eb38cc",
          "body": "… feature is enabled",
          "is_bot": false,
          "headline": "Optionally derive `Serialize` and `Deserialize` for `PackageUrl` when…",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T14:46:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e19844c528fcef78e71f0bc84edf218911c2545",
          "body": null,
          "is_bot": false,
          "headline": "Make some `PackageUrl` methods validate their arguments",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T14:31:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33df7704bcd8a0d7d4210815e33f99070afd8e40",
          "body": null,
          "is_bot": false,
          "headline": "Make `PackageUrl::new` return a `Result` in case the type is invalid",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T14:12:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0856b6727c42aa5cb9661ad9d561d55e7d7cf066",
          "body": null,
          "is_bot": false,
          "headline": "Add proper validation for subpath, namespaces, andtypes",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T14:04:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77177025da1bb68663a060ffa6c53127ee56b53b",
          "body": null,
          "is_bot": false,
          "headline": "Remove trailing slashes from the URI in `logo.png`",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T13:50:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98029a1e0f216b1777b7b3eae12f3772b4bf89bc",
          "body": null,
          "is_bot": false,
          "headline": "Fix parser not percent-decoding the version",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T13:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d72bd4978f91acd27657711c9a294e0c24aa5487",
          "body": null,
          "is_bot": false,
          "headline": "Make the PURL parser validate qualifier keys",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T13:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7dc657f6f7a55c8f567a7bdef8d550a9be347764",
          "body": null,
          "is_bot": false,
          "headline": "Bump tests cases to the latest version of the specification",
          "author_name": "Martin Larralde",
          "author_login": "althonos",
          "committed_at": "2021-07-02T13:33:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 14,
      "commits_last_year": 28,
      "latest_release_at": "2026-07-22T11:29:59Z",
      "latest_release_tag": "v0.7.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 49.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "packageurl",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "package-url",
            "purl",
            "development-tools",
            "encoding",
            "parser-implementations"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/packageurl",
          "is_deprecated": false,
          "latest_version": "0.7.0",
          "repository_url": "https://github.com/scm-rs/packageurl.rs",
          "versions_count": 13,
          "total_downloads": 518701,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 33754,
          "first_published_at": "2018-04-13T20:27:30.304765Z",
          "latest_published_at": "2026-07-22T11:33:32.300920Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 15,
      "stars": 16,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2021-05-18",
            "count": 1
          },
          {
            "date": "2021-12-09",
            "count": 1
          },
          {
            "date": "2022-11-04",
            "count": 1
          },
          {
            "date": "2023-05-03",
            "count": 1
          },
          {
            "date": "2023-06-02",
            "count": 1
          },
          {
            "date": "2024-08-29",
            "count": 1
          },
          {
            "date": "2025-04-04",
            "count": 1
          },
          {
            "date": "2025-04-07",
            "count": 1
          },
          {
            "date": "2025-05-06",
            "count": 1
          },
          {
            "date": "2025-07-29",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2025-08-22",
            "count": 1
          },
          {
            "date": "2026-07-04",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 13,
        "total_forks": 15
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "afl/Cargo.toml",
        "web/Cargo.toml"
      ],
      "largest_source_bytes": 14674,
      "source_files_sampled": 13,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "afl/Cargo.toml",
        "web/Cargo.toml"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 12,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "percent-encoding",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "thiserror",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "memchr",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "afl",
          "manifest": "afl/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10.1"
        },
        {
          "name": "packageurl",
          "manifest": "afl/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "js-sys",
          "manifest": "web/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "leptos",
          "manifest": "web/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "packageurl",
          "manifest": "web/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "wasm-bindgen",
          "manifest": "web/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "web-sys",
          "manifest": "web/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "afl",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "js-sys",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "leptos",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "memchr",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "percent-encoding",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "web-sys",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "criterion",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "url",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 12,
        "direct_count": 9,
        "indirect_count": 3
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 16,
        "open_issues": 2,
        "closed_ratio": 0.833,
        "closed_issues": 10,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "ctron",
          "commits": 65,
          "avatar_url": "https://avatars.githubusercontent.com/u/202474?v=4"
        },
        {
          "type": "User",
          "login": "althonos",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/8660647?v=4"
        },
        {
          "type": "User",
          "login": "gronke",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/473924?v=4"
        },
        {
          "type": "User",
          "login": "milux",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/765213?v=4"
        },
        {
          "type": "User",
          "login": "jcrossley3",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/9213?v=4"
        },
        {
          "type": "User",
          "login": "helio-frota",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/6443576?v=4"
        },
        {
          "type": "User",
          "login": "voteblake",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/5585957?v=4"
        },
        {
          "type": "User",
          "login": "jcreekmore",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/385202?v=4"
        },
        {
          "type": "User",
          "login": "booniepepper",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/17605298?v=4"
        },
        {
          "type": "User",
          "login": "TedDriggs",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/4805575?v=4"
        }
      ],
      "contributors_sampled": 11,
      "top_contributor_share": 0.58
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yaml",
        "pages.yaml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 4/21 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 22 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d048a178b51145e0761e8974cdd6e15631f32d2f",
        "ran_at": "2026-07-22T14:01:53Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T11:33:38Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-21T15:13:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 6,
          "created_at": "2022-11-04T22:56:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 9,
          "created_at": "2023-05-25T18:08:30Z",
          "last_comment_at": "2023-05-27T14:19:07Z",
          "last_comment_author": "alilleybrinker"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/scm-rs/packageurl.rs",
    "host": "github.com",
    "name": "packageurl.rs",
    "owner": "scm-rs"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 61,
      "inputs": {
        "security": 46,
        "vitality": 75,
        "community": 48,
        "governance": 61,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "commits_last_year": 28,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "28 commits in the last year",
                "points": 13.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "releases_count": 14,
              "latest_release_tag": "v0.7.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 49.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "14 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~49.1 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 49.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 48,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "forks": 15,
              "stars": 16,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "16 stars",
                "points": 19.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "15 forks",
                "points": 9.6,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 76,
            "inputs": {
              "packages": [
                "packageurl"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 518701,
              "monthly_downloads": 33754
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "33,754 downloads/month across crates",
                "points": 60.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 33754,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 61,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 11,
              "top_contributor_share": 0.58
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 58% of commits",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 58
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "11 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 22 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "merged_prs": 16,
              "open_issues": 2,
              "closed_issues": 10,
              "issue_closed_ratio": 0.833,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "83% of issues closed",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "16/21 decided PRs merged",
                "points": 29.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 16,
                      "decided": 21
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 4/21 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "scm-rs",
              "public_repos": 9,
              "account_age_days": 454
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of scm-rs",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "scm-rs"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~1 yr old",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "packageurl"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "13 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "purl",
                "package-url",
                "rust",
                "library"
              ],
              "has_wiki": false,
              "homepage": "https://scm-rs.github.io/packageurl.rs/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://scm-rs.github.io/packageurl.rs/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 4/21 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 22 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "20 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 13
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 58,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.84,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "84 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 84,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.13,
              "toolchain_manifests": [
                "Cargo.toml",
                "afl/Cargo.toml",
                "web/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml, afl/Cargo.toml, web/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml, afl/Cargo.toml, web/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "13 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 14674,
              "source_files_sampled": 13,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/13 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 13,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'packageurl-fuzz' from its registry",
    "Could not fetch crates package 'packageurl-web' from its registry",
    "deps.dev does not index crates:packageurl@0.7.0; advisories assessed against the repository dependency graph instead",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T14:02:10.470384Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/scm-rs/packageurl.rs.svg",
  "full_name": "scm-rs/packageurl.rs",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.26.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikencrates.io.