Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 15:38 UTC

spree / spree-rails-storefront

Spree 5 storefront built with Ruby on Rails with a visual page builder

Ruby · HTMLKeine Lizenz erkannt★ 3 Sterne⑂ 11 Forksseit Feb. 2026Auf GitHub ansehen ↗

spree/spree-rails-storefront erreicht einen Gesundheitsindex von 57 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (92/100) ab, am schwächsten bei Community & Adoption (29/100). Zuletzt vor 1 Tag aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

57
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

57
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Spree CommerceOrganisation
198 Follower26 öffentliche Reposseit Feb. 2009

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
RubyGemsspree_storefront5.4.6-52vor 0 Tagen
RubyGemsspree_page_builder5.4.6-14vor 0 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

92Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 1 Tagen
28.4/36Commit-Rhythmus — 41/52 Wochen mit Commits
18/18Commit-Volumen — 170 Commits im letzten Jahr
5/10OpenSSF Scorecard: Maintained — 7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
Verwendete Eingangsdaten
commits_last_year170
human_commit_share1
days_since_last_push1
active_weeks_last_year41

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 4 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 1 Tagen
27/27Release-Rhythmus — ein Release etwa alle 36,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count4
latest_release_tagv5.4.6
releases_from_tagsnein
days_since_latest_release1
mean_days_between_releases36,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

29Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
4.9/60Stars — 3 Stars
8.3/25Forks — 11 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks11
stars3
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
0/22.5Lizenz — keine Lizenzdatei erkannt
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
49.8/80Downloads gesamt — 61.371 Downloads insgesamt über rubygems
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesspree_storefront, spree_page_builder
dependents
ecosystemsrubygems
total_downloads61.371
monthly_downloads
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

58Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
6.4/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 72 % der Commits
13.5/13.5Breite der Beitragenden — 16 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled16
top_contributor_share0,716
Wie die Bewertung erfolgt
3.6/46.8Issue-Lösungsquote — 8 % der Issues geschlossen
33.5/38.3PR-Annahme — 14/16 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 2/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs14
open_issues12
closed_issues1
issue_closed_ratio0,077
closed_unmerged_prs2
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
16.5/25Reichweite des Inhabers — 198 Follower von spree
22.4/25Kontohistorie — 26 öffentliche Repos, Kontoalter ca. 17 Jahre
Verwendete Eingangsdaten
followers198
owner_typeOrganization
is_verified
owner_loginspree
public_repos26
account_age_days6.365

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 2 Paket(e) auf rubygems
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 0 Tagen
20/20Versionshistorie — 52 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesspree_storefront, spree_page_builder
ecosystemsrubygems
any_deprecatednein
min_days_since_publish0

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

57Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 1 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 10 out of 14 merged PRs checked by a CI test -- score normalized to 7
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

38Gefährdet · 16 % des Gesamtindex

Sicherheitslage

38Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
1.8/2.5CI-Tests — 10 out of 14 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 2/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Lizenz — license file not detected
3.8/7.5Maintained — 7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
2.5/5SAST — SAST tool is not run on all commits -- score normalized to 5
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,8
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

51Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md, CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
28.3/40Lesbare Commit-Historie — 53 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,53
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes7.322
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
0/10Reproduzierbare Umgebung
10/10Belegte Agentenpraxis — 10 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,1
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — Ruby ohne Typprüfungs-Konfiguration
55/55Handhabbare Dateigrößen — 0/308 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageRuby
largest_source_bytes51.837
source_files_sampled308
oversized_source_files0

Eckdaten

3GitHub-Sterne
16Mitwirkende
170Commits, letzte 12 Monate
1Tage seit letztem Push
4Releases
1Bus-Faktor
12offene Issues
RubyGemsPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • No resolved dependencies carried a version and a supported ecosystem

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 11 ⇿
0Sterne
11Forks
3Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

0246810121122026-022026-042026-07
Major 0Minor 1Patch 2
OpenSSF Scorecard 3.8 / 10
3.8Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 15:38 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
7CI-Tests10 out of 14 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 2/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
5Maintained7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
5SASTSAST tool is not run on all commits -- score normalized to 5
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 28
RegistryPaketVersionsvorgabeManifest
RubyGemsrailspage_builder/Gemfile
RubyGemstzinfo-datapage_builder/Gemfile
RubyGemsmysql2page_builder/Gemfile
RubyGemspgpage_builder/Gemfile
RubyGemssqlite3>= 2.0page_builder/Gemfile
RubyGemsspreepage_builder/Gemfile
RubyGemsspree_adminpage_builder/Gemfile
RubyGemsspree_custom_domainspage_builder/Gemfile
RubyGemsspree_custom_domainspage_builder/Gemfile
RubyGemsspree_postspage_builder/Gemfile
RubyGemsspree_dev_tools>= 0.6.0.rc1page_builder/Gemfile
RubyGemsdevisepage_builder/Gemfile
RubyGemspropshaftpage_builder/Gemfile
RubyGemsrailsstorefront/Gemfile
RubyGemstzinfo-datastorefront/Gemfile
RubyGemsmysql2storefront/Gemfile
RubyGemspgstorefront/Gemfile
RubyGemssqlite3>= 2.0storefront/Gemfile
RubyGemsspreestorefront/Gemfile
RubyGemsspree_adminstorefront/Gemfile
RubyGemsspree_page_builderstorefront/Gemfile
RubyGemsspree_custom_domainsstorefront/Gemfile
RubyGemsspree_custom_domainsstorefront/Gemfile
RubyGemsspree_postsstorefront/Gemfile
RubyGemsspree_dev_tools>= 0.6.0.rc1storefront/Gemfile
RubyGemsdevisestorefront/Gemfile
RubyGemskaminaristorefront/Gemfile
RubyGemspropshaftstorefront/Gemfile
Alle Abhängigkeiten 22

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 11 direkte und 11 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
RubyGemsdevisedirekt
RubyGemskaminaridirekt
RubyGemsmysql2direkt
RubyGemspgdirekt
RubyGemspropshaftdirekt
RubyGemsspree_custom_domainsdirekt
RubyGemsspree_dev_toolsdirekt
RubyGemsspree_page_builderdirekt
RubyGemsspree_postsdirekt
RubyGemssqlite3direkt
RubyGemstzinfo-datadirekt
RubyGemsactive_link_toindirekt
RubyGemsheroiconindirekt
RubyGemsimportmap-railsindirekt
RubyGemsinline_svgindirekt
RubyGemslocal_timeindirekt
RubyGemsmail_formindirekt
RubyGemspagyindirekt
RubyGemsstimulus-railsindirekt
RubyGemstailwindcss-railsindirekt
RubyGemstailwindcss-rubyindirekt
RubyGemsturbo-railsindirekt
Abhängigkeits-Advisories nicht bewertet

Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies carried a version and a supported ecosystem

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 4245,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "CSS": 38582,
        "HTML": 438988,
        "Ruby": 606277,
        "Shell": 378,
        "JavaScript": 51422
      },
      "pushed_at": "2026-07-27T12:21:49Z",
      "created_at": "2026-02-07T16:38:34Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T12:22:31Z",
      "description": "Spree 5 storefront built with Ruby on Rails with a visual page builder",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Ruby",
      "significant_languages": [
        "Ruby",
        "HTML"
      ]
    },
    "owner": {
      "blog": "https://spreecommerce.org",
      "name": "Spree Commerce",
      "type": "Organization",
      "login": "spree",
      "company": null,
      "location": null,
      "followers": 198,
      "avatar_url": "https://avatars.githubusercontent.com/u/56702?v=4",
      "created_at": "2009-02-22T00:54:00Z",
      "is_verified": null,
      "public_repos": 26,
      "account_age_days": 6365
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v5.4.6",
          "kind": "patch",
          "published_at": "2026-07-27T12:22:51Z"
        },
        {
          "tag": "v5.4.3",
          "kind": "patch",
          "published_at": "2026-04-28T10:42:37Z"
        },
        {
          "tag": "v5.4.1",
          "kind": "patch",
          "published_at": "2026-04-11T12:01:15Z"
        },
        {
          "tag": "v5.4.0",
          "kind": "minor",
          "published_at": "2026-04-08T16:36:01Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f828fe1f3ba03b33994e0e5748fc568f251999d0",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.6",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-07-27T12:21:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6362001cef12a278c2972872a0a283fe5b04ea93",
          "body": "* Fixes Spree 5.6 compatibilyt\n\n* Create address_country_select_spec.rb",
          "is_bot": false,
          "headline": "Fixes Spree 5.6 compatibilyt (#32)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-07-27T12:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86bda92171d774aa1a62b1d7389bcad82f1f3855",
          "body": null,
          "is_bot": false,
          "headline": "Dropped multi store dev dependency (#28)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-06-29T16:33:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd3a4286bc02336747b76bfd21ba85e8c7a9eb6a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.5",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-06-29T16:13:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "464c03af5cac9c847bef11ca82bc31b80c446e94",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.4",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-06-29T16:13:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e960b86a87e191b61f2f1233a34da76183718901",
          "body": "…(#27)\n\n* Extract translations from core used in storefront / page builder gem\n\n* Fix failing storefront specs after translation extraction.\n\nConfigure i18n-tasks for page_builder usage, harden address and sort specs against test pollution, and add missing locale keys.\n\nCo-authored-by: Cursor <curso\n[…]\ne unreliable in postgres/mysql CI; sort UI coverage remains in other product list examples.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Extract translations from core used in storefront / page builder gem …",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-06-24T09:54:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dcc7530903fd58ec180d0d901d5fe270985bd733",
          "body": null,
          "is_bot": false,
          "headline": "Fix respecting of explore more button preference from theme editor (#25)",
          "author_name": "carl-lee-lu",
          "author_login": "carl-lee-lu",
          "committed_at": "2026-06-04T18:44:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84020b391d4cd5db2c4a07d5b30e60b3135ecdbe",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.3",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-28T10:41:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17a29c40c72bca9badc0ed84652433557edbfd22",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.2",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-28T10:39:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58a2eb41d5a80d30a1e1de3e71e1201dd5e7860b",
          "body": "`image_count` was renamed to `media_count` in Spree 5.4, however it's already redundant as `has_images?` already runs a proper check",
          "is_bot": false,
          "headline": "Fixed bad image check (#24)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-28T10:38:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df2ca1658dd251994ba3bccefca8f6023eca971b",
          "body": "* Fix potential XSS (low)\n\n* Include locale/currency/user in JSON-LD variant offer cache key\n\nThe previous key passed `spree_base_cache_scope` (a lambda) by identity\nrather than invoking it, so locale/currency/user never varied the cache.\nSplat `spree_base_cache_key` to put the actual values in the key.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix potential XSS (low) in JSON LD tags (#23)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-28T10:09:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3a45466dc850c636ffd6c64edf3f2d41326569df",
          "body": "Replace raw() with sanitize() to prevent stored XSS via product\ndescriptions. The raw() helper disabled all HTML escaping, allowing\nmalicious scripts injected through TinyMCE source view or direct\nAPI calls to execute on the storefront for all visitors.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix XSS vulnerability in product description rendering (#22)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-24T17:28:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "751b806a75477b4325085e70b21146a7364221b5",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to 5.4.1",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-11T12:00:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfe4a73c98f092d6916e08843fef8098fdc4ce42",
          "body": null,
          "is_bot": false,
          "headline": "add release rake task",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-11T12:00:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28426df5c2adc1257c02aa7b3cd62dc64b2b6ab6",
          "body": "The admin views referenced `default_custom_domain` unconditionally, which\nonly exists when `spree_multi_store` is installed. Guard the calls with\n`respond_to?` so stores without the extension don't crash, and add a CI\nmatrix entry that runs the page_builder specs with spree_multi_store\ndisabled (via `DISABLE_SPREE_MULTI_STORE=true`) to catch regressions.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix: page_builder should work without spree_multi_store (#19)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-11T10:24:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dee7f1bac84250ada2dae3935ec13ddfc89f69a5",
          "body": "* Prepare release for Spree 5.4\n\n* Fixed color swatches compatibility",
          "is_bot": false,
          "headline": "Prepare release for Spree 5.4 (#18)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-08T16:33:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f480487b6169b11e947fb201895b61347e857ab",
          "body": null,
          "is_bot": false,
          "headline": "Make sure we run posts migrations as well",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-02T09:42:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fd7e4e78586312e545a1e7ed35842b702251a96",
          "body": null,
          "is_bot": false,
          "headline": "Fixed: added missing require for posts",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-02T09:38:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f86d64e24a75fb4d1a6995dbc54d60aba5390515",
          "body": null,
          "is_bot": false,
          "headline": "Clean-up dependency tree",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-04-02T08:54:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3c00b11daf670c00c951a597fa3fc1895fe1c37",
          "body": "* Ability to hide system sections like announcement bar, newsletter, etc\n\n* Update update.turbo_stream.erb",
          "is_bot": false,
          "headline": "Ability to hide system sections (#17)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-24T20:44:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62b3996ef84daf77c522c8110dbf57e49b70fc10",
          "body": null,
          "is_bot": false,
          "headline": "Fixed storefront for Spree 5.4",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-24T07:55:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e1ba5ceacc653db49b7ce840c6ec4d5f37d16b4",
          "body": null,
          "is_bot": false,
          "headline": "Fix Pafe Builde test",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-23T22:01:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47018dccf952b053e35f6dcb1aa53db79b2f96d7",
          "body": null,
          "is_bot": false,
          "headline": "Brind back preferences removed from Spree Core",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-11T10:34:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab43c584ae7cb62d4f13d699ae9af8c18178f3ee",
          "body": "…age builder (#16)",
          "is_bot": false,
          "headline": "Bring over socials/checkout message removed from spree core used in p…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-07T09:15:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02476ba82d2d80b4f2290a4881fc107cc7f011f3",
          "body": "…methods as this will cause error. (#15)",
          "is_bot": false,
          "headline": "When a payment through coupon becomes free, need to not load payment …",
          "author_name": "carl-lee-lu",
          "author_login": "carl-lee-lu",
          "committed_at": "2026-03-06T10:56:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee97d6af68b6bb2c3c5f4ef0d4bc13dd5e8e7b64",
          "body": "* Add missing files from spree core and fix CI\n\n* Add spree_posts dependency to both gems\n\nSpree::Post was extracted from spree_core into the spree_posts gem.\nBoth page_builder (post_decorator) and storefront need it.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add missing files from spree core and fix CI (#14)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-03-06T10:48:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "296da9bdce27388b12f18207b2d4309453b7917d",
          "body": "Updated SDK link in README.md to point to the correct path.",
          "is_bot": false,
          "headline": "Fix SDK link in README.md",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-19T18:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12fcc29247dc92cc730148280d9c63d8ddfa6ccd",
          "body": "Added instructions for creating the first theme.",
          "is_bot": false,
          "headline": "Update README with theme creation instructions",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-19T18:54:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bba6b6a1a7abdd38ad20ada2d26a634167ccec1b",
          "body": "Update Gemfiles for new spree gem location",
          "is_bot": false,
          "headline": "Merge pull request #1 from spree/fix/spree-gem-path",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-11T19:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "442949ed94439dd63973951c8fde9f72ecb86784",
          "body": null,
          "is_bot": false,
          "headline": "[Skip CI] README update",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-07T17:50:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "695c8501cfa323c13a5149b96f74cb87675fe8e8",
          "body": null,
          "is_bot": false,
          "headline": "Setup gems and CI",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-07T17:34:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a76dab8210d30cdf99ec4df3aa11fa59a63ef824",
          "body": "Consolidate agent rules into CLAUDE.md, remove stale cursor rules\n\nDeleted outdated .cursor/rules directory with duplicate and incorrect content. Created AGENTS.md symlink to CLAUDE.md as single source of truth for AI agents (Cursor, Windsurf, Claude).\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Consolidate agent rules into CLAUDE.md (#13539)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-07T09:14:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "73ff277a69a2e168b4e516059b0a7eedcf7541ec",
          "body": "API v3 + Authentication Strategies + SDK + PrefixedIDs",
          "is_bot": false,
          "headline": "Merge pull request #13507 from spree/feature/api-v3",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-06T18:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47fc8631766dabc41d3577b566fe6a794be7ecf5",
          "body": "…g_master\n\nMaster variants don't have option values - only non-master variants do.\nThis fixes the FiltersAggregator GROUP BY error when using taxon scopes\nand updates all option value joins throughout the codebase.\n\nChanges:\n- FiltersAggregator: Use subquery with option_value_variants join for count\n[…]\n product_filters_aggregations and product_single_filter_aggregations\n- Fix filters_controller_spec to create proper variants with option values\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix option value queries to use variants instead of variants_includin…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-06T17:23:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a4338a62629aa49e4ea387e281d7ceecd737ba3",
          "body": "This is finally the end of N+1 and memory bloat saga of product images!",
          "is_bot": false,
          "headline": "Added `Product#thumbnail` and `Variant#thumbnail`",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-06T17:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54c8a00324df3283bb9f5f7b610cb44da39f8fab",
          "body": null,
          "is_bot": false,
          "headline": "Fixed storefront so it works with both new prefixed IDs and old URLs",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-06T17:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21c62ccee3d691be20a16be1329ece77e8cd1f08",
          "body": "* Add parallel_tests support for running specs locally in parallel\n\nAdd the parallel_tests gem and supporting infrastructure so developers\ncan run per-gem RSpec specs in parallel locally, significantly reducing\ntest execution time.\n\nChanges:\n- Add parallel_tests gem to shared test dependencies\n- Upd\n[…]\neply@anthropic.com>\n\n* Add parallel tests documentation to developing guide\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add parallel_tests for local parallel spec execution (#13532)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-06T17:21:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "891d0ed2e073ebb957abee807c1bb123613db0aa",
          "body": "The OrdersController#show action permitted viewing completed guest\norders by order number alone, without requiring the associated order\ntoken.",
          "is_bot": false,
          "headline": "Merge commit from fork",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-05T11:10:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "987f442aca8402d80e51e6b00fe6a8651fe83a24",
          "body": "* Remove redundant DatabaseCleaner transaction wrapping in core and api specs\n\nRails' transactional fixtures (use_transactional_fixtures = true) already\nwrap each test in a transaction. The additional DatabaseCleaner.cleaning\nblock was creating double transaction wrapping, adding unnecessary overhea\n[…]\nny missing gems.\n\nBumped cache key to v13 to start fresh with new strategy.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CI Database Cleaner cleanup and improvements (#13524)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-02-05T09:29:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f038fc8780a3f772bc667440184c0f45367f3d9",
          "body": null,
          "is_bot": false,
          "headline": "fix mobile nav initial transform (#13515)",
          "author_name": "Dimitrios Panagkasidis",
          "author_login": "dimidev",
          "committed_at": "2026-02-03T10:36:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a450673d7cc89cbeae9e9d9e31d336516957f694",
          "body": "Rails 8.1 raises EagerLoadPolymorphicError when using includes() on\npolymorphic associations. This affects the :linkable association on\nPageLink which is polymorphic (can be Page, Product, Taxon, etc.).\n\nChanges:\n- Remove includes(:linkable) from has_many :links default scope\n- Use preload() instead\n[…]\nomponentsJob\n\npreload() uses separate queries per type which works with polymorphic\nassociations, while includes() attempts a JOIN which fails.\n\nCo-authored-by: Claude Opus 4.5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix Rails 8.1 ActiveRecord::EagerLoadPolymorphicError (#13504)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-29T16:33:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e8a146c5b72b40fa83cab0e88843e166d63f9e2b",
          "body": null,
          "is_bot": false,
          "headline": "FIX clear token cookie (#13499)",
          "author_name": "brozek",
          "author_login": "brozek95",
          "committed_at": "2026-01-27T11:24:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40ad88289f8c2d7ae233880784933f9ed1fe7069",
          "body": null,
          "is_bot": false,
          "headline": "[skip CI] Added README files for all gems",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-23T15:57:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5ca9296776c894998a6974935746788d03c6b32",
          "body": "…… (#13480)\n\n1. The new installer installs headless spree\n2. Admin/storefront installers need to be run separately\n3. Clear seperation of concerns\n4. Added CLI installer installing `bin/spree` in host apps - this will be our entry point later for new CLI build",
          "is_bot": false,
          "headline": "Move Spree installer to the `spree` gem, remove auto admin/storefront…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-22T14:15:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e05a8faa5bd88f022131d71da3573338411aae21",
          "body": "We will move all packages to the packages directoty all ot once after 5.3 release and merging new API",
          "is_bot": false,
          "headline": "Move `page_builder` back to the main directory (#13486)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-22T12:45:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74f2a879b5b46c3a9176beb8215b847eaa5a6d4f",
          "body": "* Add `ar_lazy_preload` to API and admin as well\n\n+ squash some more N+1s\n\n* Update product_spec.rb",
          "is_bot": false,
          "headline": "Add `ar_lazy_preload` to API and admin as well (#13479)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T21:07:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b95a8a48e633ded169a253c1cd2f85a5cbc664e2",
          "body": null,
          "is_bot": false,
          "headline": "Use more lazy preload in storefront",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T16:05:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed3d66acc41e6a4cd17288e55d2d2eb083f2d647",
          "body": "…#13477)",
          "is_bot": false,
          "headline": "Use `ar_lazy_preload` gem in storefront to reduce number of queries (…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T15:25:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f17ca1cf2d56d4c7f9806ab24039b76ad4c39576",
          "body": "* Fixes images preloading on product lists\n\n* fix N+1s",
          "is_bot": false,
          "headline": "Fixes images preloading on product lists (#13476)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T14:21:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0ae3ec4a8dcfbf95a1c5d285dc5c5cf091ccc95",
          "body": null,
          "is_bot": false,
          "headline": "Fixed color swatches on storefront image check",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T12:36:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0458d1bbe3b1e9d99756146cb2d337dcd40bbe00",
          "body": "* Added Image Counter Cache for Products and Variants\n\n* Reduce SQL queries and squash N+1s\n* Reduce object instantiation (no more loading hundreds of images on PLPs)\n\n* Spec fixes, more methods deprecated\n\n* Update product_serializer_spec.rb\n\n* Update webhooks.rb",
          "is_bot": false,
          "headline": "Added Image Counter Cache for Products and Variants (#13474)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-20T11:20:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a4c6a9ed415ffa26b207e18cfe2a5bd92bdc3cb",
          "body": "* Replace `destroy_all` with `delete_all` to speed up tests\n\n* Removed previously deprecated code\n\n* More `delete_all`\n\n* Use build instead of create\n\n* Update page_section_spec.rb\n\n* Use cached store and do not create new ones\n\n* some small serializers speed ups\n\n* Fixed: remove usage of deprecated brand/brand_name from storefront templates",
          "is_bot": false,
          "headline": "Test Suite Cleanup (#13473)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T21:34:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42a7c10ee244056ed5bdb57887d7b161684c0d46",
          "body": "* Added Taxon counter cache\n\n* fixed flaky testes",
          "is_bot": false,
          "headline": "Added Taxon counter cache (#13472)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T19:41:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "074051eb4dcdc6f98000da9686d8772bf48c5e49",
          "body": "* Disable Events in specs by default\n\nTo speed them up :) Re-enable selectively\n\n* fix",
          "is_bot": false,
          "headline": "Disable Events in specs by default (#13471)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T17:39:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc62c528705b44f3a439a4d4a37dce2d563de474",
          "body": "Move page builder into it's own job on CI",
          "is_bot": false,
          "headline": "Merge pull request #13468 from spree/fix/ci-page-builder",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T14:21:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df3fa315d742602c4c295cca38367f51cd116aad",
          "body": null,
          "is_bot": false,
          "headline": "Disable Spree Events in some specs to speed them up",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T13:55:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af0b028b272646d072cdedaec95e8065f24fcf9b",
          "body": "By default generate minimal rails apps (headless/api mode)",
          "is_bot": false,
          "headline": "Speed-up creating of test apps",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T13:42:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43a585175d9b8c011fff9c06471564ca8f308a52",
          "body": "* Introduce Store Product Metrics\n\nTo migrate existing products to metrics run:\n\n```\nbin/rake spree:product_metrics:populate\n```\n\n* fixes",
          "is_bot": false,
          "headline": "Introduce Store Product Metrics (#13467)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-19T10:35:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d87c3d151cc7d205e047bd36bbf820e2ff1df3b6",
          "body": "* Simplify `ascend_by_taxons_min_position` scope + pagy fixes",
          "is_bot": false,
          "headline": "Simplify `ascend_by_taxons_min_position` scope + pagy fixes (#13465)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-18T21:20:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9df9e8687932e6fb479edd4299545e50d072bbcc",
          "body": "* Migrate to Pagy for pagination\n\nWhy: performance and memory management - https://ddnexus.github.io/pagination-comparison/gems.html\n\nHow:\n\nAdmin: moved entirely to pagy\nStorefront: backward compatible with kaminari for existing installations\n\n* Move API to pagy as well\n\nRemove kaminari from depende\n[…]\noduct#ascend_by_taxons_min_position` for pagy\n\n* Refactor select_options actions\n\nAlso added accessible_by\n\n* fixes for having/group queries\n\n* Remove obsolete specs, deprecate bunch of old UI methods",
          "is_bot": false,
          "headline": "Migrate to Pagy for pagination (#13464)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-18T18:11:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34da06f113c770fdd158f7ee689bad6dcd557a8a",
          "body": "…-ld (#13450)",
          "is_bot": false,
          "headline": "Include translations when fetching product breadcrumb taxons for json…",
          "author_name": "m.b.",
          "author_login": "mbajur",
          "committed_at": "2026-01-15T10:14:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e3f9ec7dcc9e801aca253d2bc1829f48830603d",
          "body": "* Fixed: properly compare User/Zone IDs in User/Zone Rule casting them to strings\n\n* Expire Price List cache key when adding/removing products\n\n* Include Price List cache key in `spree_storefront_base_cache_key`",
          "is_bot": false,
          "headline": "Price List Storefront fixes (#13448)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-14T14:15:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79f4d1b796d73f20d633cc435fb64de5c73d58ca",
          "body": null,
          "is_bot": false,
          "headline": "Include Price List cache key in `spree_storefront_base_cache_key`",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-14T13:53:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0430ac3ff929556a37f8fa4771e0ebf0879614e8",
          "body": null,
          "is_bot": false,
          "headline": "Fixed: remove double caching of checkout line items",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-14T13:24:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4cbdf4defb9b8ac6dd3f9796d606fad1bbb211f",
          "body": "Price Lists",
          "is_bot": false,
          "headline": "Merge pull request #13408 from spree/feature/price-lists",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-09T20:52:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a35bfd372824a82a8dc2ab49df0aff404888266",
          "body": "* Default Homepage: Accessibility & Best Practices adjustments\n\n* Homepage sections: Accessibility & Best Practices adjustments\n\n* fix: cursor bot suggestions\n\n* mod: better aria label\n\n* normalize i18n\n\n* Update storefront/app/views/themes/default/spree/products/_quantity_selector.html.erb\n\n* Updat\n[…]\n Update storefront/config/locales/en.yml\n\n* Update storefront/app/views/themes/default/spree/products/_quantity_selector.html.erb\n\n---------\n\nCo-authored-by: Damian Legawiec <damian@sparksolutions.co>",
          "is_bot": false,
          "headline": "Pagespeed insights adjustments (#13424)",
          "author_name": "Filip Cichorek",
          "author_login": "Cichorek",
          "committed_at": "2026-01-09T15:17:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4a0945bbffbda4843de47db93fea90dce5432c2",
          "body": null,
          "is_bot": false,
          "headline": "UI update",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-08T21:36:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8ee0e3ffbec0680fd7d991c8a9b7e42f39cc38d",
          "body": null,
          "is_bot": false,
          "headline": "Fixed API specs",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-08T21:32:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44ac45fc8d6bf9f3a76faff6f7e4b36f538368fd",
          "body": null,
          "is_bot": false,
          "headline": "Initial pass on Price Lists",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-08T21:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3f1a577c676d613e5bb843d58cfe19481c9d704",
          "body": "Fixed ability check for address management in storefront exposing ability for guest users to edit/view other guest users addresses. This required knowing Address ID and internal Spree Address Book URLs.",
          "is_bot": false,
          "headline": "Fixes GHSA-3ghg-3787-w2xr Unauthenticated IDOR - Guest Address (#13422)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-08T08:32:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "941456c00866ff9fabc880976f36cbfd54e848c2",
          "body": null,
          "is_bot": false,
          "headline": "Remove canonical-rails as a dependency (#13419)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-05T12:25:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bb22766b7f7d00caa9f998ba36ba06c38628796",
          "body": "* fix: Header overlay is misaligned in page builder\n\n* mod: better caching body class",
          "is_bot": false,
          "headline": "fix: Header overlay is misaligned in page builder (#13414)",
          "author_name": "Filip Cichorek",
          "author_login": "Cichorek",
          "committed_at": "2026-01-05T08:33:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8794b90e1a00b0b981b320220a1a2e66f7b6cd88",
          "body": "* Update deprecation EOL for some items to Spree 5.5\n\n* Update gift_card_presenter_spec.rb",
          "is_bot": false,
          "headline": "Update deprecation EOL for some items to Spree 5.5 (#13412)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2026-01-02T14:30:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e53eac5974b3fd5141da89d88f3a980f9aa8386f",
          "body": null,
          "is_bot": false,
          "headline": "Use Ruby 3.2+ Data for Event registry (#13409)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-30T10:34:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42877ebede360f4afbad7be5b71b1b6bee85a5ac",
          "body": "* Move `page_builder` into `packages` dir\n\n* Update Gemfile\n\n* Update build-ci.rb",
          "is_bot": false,
          "headline": "Move `page_builder` into `packages` dir (#13405)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-28T21:00:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65513073559ec0ef2d32aa08918987f7a68969c8",
          "body": "Events & Subscribers engine",
          "is_bot": false,
          "headline": "Merge pull request #13327 from spree/feature/spree-event-subscribers",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-28T20:19:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6ec45d2e23ed5740ee04fe2f35cbca9fd18d851",
          "body": "… (#13404)",
          "is_bot": false,
          "headline": "Fixed: don't update tracking params in checkout if they didn't change…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-27T13:55:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2e28bc10f8bfd7ca1f8082b335722541d91482a",
          "body": null,
          "is_bot": false,
          "headline": "Extract current (legacy) webhooks system into spree_legacy_webhooks gem",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-27T11:14:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "909f5aa0a6dcabefc2ba939976a54cc615bf38c0",
          "body": "* Use new Dependencies 2.0 DSL everywhere\n\n* Update account_spec.rb",
          "is_bot": false,
          "headline": "Use new Dependencies 2.0 DSL everywhere (#13398)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-22T22:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c7e9611318d9bd1f8cbe3dc14b4975d9cd7b0fa",
          "body": "Promo Engine performance improvements",
          "is_bot": false,
          "headline": "Merge pull request #13396 from spree/fix/promotion-engine-optimizations",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-22T20:06:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f82650227b874fc98d2ff89e3f0bdac32e438165",
          "body": null,
          "is_bot": false,
          "headline": "Added caching for storefront `CheckoutHelper#quick_checkout_enabled?`",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-22T19:07:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68f9db82ea92906740eca3d79baa49daf257042d",
          "body": "These migrations were previously in the core gem, so now people would have to re-download them",
          "is_bot": false,
          "headline": "Fix: remove page builder migration warning (#13397)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-22T18:45:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68f5b8f1da875251ed7154425ad1d794528ca216",
          "body": null,
          "is_bot": false,
          "headline": "Fixed N+1s on Storefront cart",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-22T17:50:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39f614503f5944a6867c4d9e59fd878c304ffb7a",
          "body": "Rails 8.1 support",
          "is_bot": false,
          "headline": "Merge pull request #13392 from spree/fix/rails-8-1",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-20T20:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be9b12196fd52bc05c30b39c3bc4446a75e3ef4b",
          "body": null,
          "is_bot": false,
          "headline": "Properly setup test apps for non views gems",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-20T13:04:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28592037f5525fa637489a4304c33c07a2047687",
          "body": null,
          "is_bot": false,
          "headline": "Rails 8.1 support",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-20T11:34:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8207fd447acb3244bbc34d12c29d4be272629d1f",
          "body": null,
          "is_bot": false,
          "headline": "Cleanup old dotfiles",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T17:32:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267486a80737c924e3df2a10030e0eec9fb1c20f",
          "body": "Extract Page Builder into a standalone gem",
          "is_bot": false,
          "headline": "Merge pull request #13388 from spree/feature/page-builder-gem",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T17:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b46041d782cf61f6b5a2c48cc8b9752ec0be5de6",
          "body": "…hatn user_class",
          "is_bot": false,
          "headline": "Fixed factories and devise login when admin_user_class is different t…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T17:06:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d4199809335476ae56f2265106083bc9a5d0177",
          "body": null,
          "is_bot": false,
          "headline": "Make admin views not dependant on page builder",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T16:47:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b202943cc12a8c05b034f1cd01c84657452e2b8f",
          "body": null,
          "is_bot": false,
          "headline": "Setup proper test environment in page_builder gem, move more specs",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T16:32:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5dd087c2669d9e91b8be297ce5ccd9235051b4f3",
          "body": null,
          "is_bot": false,
          "headline": "Move more code from core to page builder",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T14:27:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e93012660363de969ce8ba44354ac223867959e4",
          "body": null,
          "is_bot": false,
          "headline": "Fixed: include PageBuilder helper manually",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T14:09:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0486a4aa20e2f166ef03a8d806ab9e7e9b164a04",
          "body": "Required by storefront. This will allow us to have clean headless builds without any page builder logic surfaced in the admin/core if not using rails storefront.",
          "is_bot": false,
          "headline": "Setup Page Builder as a standalone gem",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-19T13:59:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fb743da49cad7a44465c4a31acf84f322f33bd7",
          "body": "Skips tandard devise routes during installation",
          "is_bot": false,
          "headline": "Merge pull request #13384 from spree/fix/devise-skip-routes",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-18T13:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14cbff66512d7ef29d91c665b8f8910004262bcc",
          "body": null,
          "is_bot": false,
          "headline": "Ensure we always setup tailwind environment during installation",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-18T13:01:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "078c06cd807b2c005f7c6bee411e40fd30f527a5",
          "body": "…d migration",
          "is_bot": false,
          "headline": "Fix: revert storefront changes accidently performed via admin tailwin…",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-17T15:00:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bc900250904990095eb8e3cf7befda006732c11",
          "body": null,
          "is_bot": false,
          "headline": "Migrate Admin CSS to Tailwind CSS (#13342)",
          "author_name": "Damian Legawiec",
          "author_login": "damianlegawiec",
          "committed_at": "2025-12-17T14:52:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcff3aae4ffa09a6756eb1176c65e55424476429",
          "body": "* fix: toogle menu height\n\n* mod: adapting changes to the updated spree.\n\n* fix: missing </div>",
          "is_bot": false,
          "headline": "Fix toggle menu (#13377)",
          "author_name": "Filip Cichorek",
          "author_login": "Cichorek",
          "committed_at": "2025-12-16T11:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d98c9010c3d8541020de96c61f25427eb2ffe5b",
          "body": null,
          "is_bot": false,
          "headline": "Fix indentation in product details template (#13366)",
          "author_name": "Dimitrios Panagkasidis",
          "author_login": "dimidev",
          "committed_at": "2025-12-11T12:12:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 4,
      "commits_last_year": 170,
      "latest_release_at": "2026-07-27T12:22:51Z",
      "latest_release_tag": "v5.4.6",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 41,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 36.6
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "spree_storefront",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "rubygems",
          "matches_repo": true,
          "registry_url": "https://rubygems.org/gems/spree_storefront",
          "is_deprecated": false,
          "latest_version": "5.4.6",
          "repository_url": "https://github.com/spree/spree-rails-storefront/tree/v5.4.6",
          "versions_count": 52,
          "total_downloads": 49518,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2025-04-01T20:15:17.631000Z",
          "latest_published_at": "2026-07-28T15:25:37.433000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "spree_page_builder",
          "exists": true,
          "license": "AGPL-3.0-or-later",
          "keywords": [],
          "ecosystem": "rubygems",
          "matches_repo": true,
          "registry_url": "https://rubygems.org/gems/spree_page_builder",
          "is_deprecated": false,
          "latest_version": "5.4.6",
          "repository_url": "https://github.com/spree/spree-rails-storefront/tree/v5.4.6",
          "versions_count": 14,
          "total_downloads": 11853,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-01-22T14:36:10.346000Z",
          "latest_published_at": "2026-07-28T15:25:20.676000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 11,
      "stars": 3,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-11",
            "count": 1
          },
          {
            "date": "2026-02-24",
            "count": 1
          },
          {
            "date": "2026-03-02",
            "count": 2
          },
          {
            "date": "2026-03-29",
            "count": 1
          },
          {
            "date": "2026-03-31",
            "count": 1
          },
          {
            "date": "2026-04-13",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 1
          },
          {
            "date": "2026-07-02",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 11,
        "total_forks": 11
      },
      "star_history": null,
      "open_issues_and_prs": 15
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 51837,
      "source_files_sampled": 308,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 7322
    },
    "dependencies": {
      "manifests": [
        "page_builder/Gemfile",
        "storefront/Gemfile"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 22,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "rubygems"
      ],
      "dependencies": [
        {
          "name": "rails",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "tzinfo-data",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "mysql2",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "pg",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "sqlite3",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": ">= 2.0"
        },
        {
          "name": "spree",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_admin",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_custom_domains",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_custom_domains",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_posts",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_dev_tools",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": ">= 0.6.0.rc1"
        },
        {
          "name": "devise",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "propshaft",
          "manifest": "page_builder/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "rails",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "tzinfo-data",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "mysql2",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "pg",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "sqlite3",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": ">= 2.0"
        },
        {
          "name": "spree",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_admin",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_page_builder",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_custom_domains",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_custom_domains",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_posts",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "spree_dev_tools",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": ">= 0.6.0.rc1"
        },
        {
          "name": "devise",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "kaminari",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        },
        {
          "name": "propshaft",
          "manifest": "storefront/Gemfile",
          "ecosystem": "rubygems",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "devise",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "kaminari",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "mysql2",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "pg",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "propshaft",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "spree_custom_domains",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "spree_dev_tools",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "spree_page_builder",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "spree_posts",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "sqlite3",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "tzinfo-data",
            "direct": true,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "active_link_to",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "heroicon",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "importmap-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "inline_svg",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "local_time",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "mail_form",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "pagy",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "stimulus-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "tailwindcss-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "tailwindcss-ruby",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "turbo-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 22,
        "direct_count": 11,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 3,
        "merged_prs": 14,
        "open_issues": 12,
        "closed_ratio": 0.077,
        "closed_issues": 1,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "damianlegawiec",
          "commits": 305,
          "avatar_url": "https://avatars.githubusercontent.com/u/55154?v=4"
        },
        {
          "type": "User",
          "login": "Vegann",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/25418284?v=4"
        },
        {
          "type": "User",
          "login": "mad-eel",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/18441660?v=4"
        },
        {
          "type": "User",
          "login": "brozek95",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/39567956?v=4"
        },
        {
          "type": "User",
          "login": "lovison",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/5762017?v=4"
        },
        {
          "type": "User",
          "login": "caiodsc",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/23347722?v=4"
        },
        {
          "type": "User",
          "login": "Cichorek",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/26910597?v=4"
        },
        {
          "type": "User",
          "login": "resool",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/6610488?v=4"
        },
        {
          "type": "User",
          "login": "chrislaai",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/134155599?v=4"
        },
        {
          "type": "User",
          "login": "simlegate",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/2359726?v=4"
        }
      ],
      "contributors_sampled": 16,
      "top_contributor_share": 0.716
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "10 out of 14 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 2/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 5,
            "reason": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 5,
            "reason": "SAST tool is not run on all commits -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f828fe1f3ba03b33994e0e5748fc568f251999d0",
        "ran_at": "2026-07-28T15:38:28Z",
        "aggregate_score": 3.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T12:33:29Z",
      "oldest_open_prs": [
        {
          "number": 20,
          "created_at": "2026-04-13T15:31:22Z",
          "last_comment_at": "2026-04-13T15:33:15Z",
          "last_comment_author": "umeshravani"
        },
        {
          "number": 26,
          "created_at": "2026-06-09T13:21:40Z",
          "last_comment_at": "2026-06-09T13:22:28Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 31,
          "created_at": "2026-07-14T13:37:39Z",
          "last_comment_at": "2026-07-14T13:37:47Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-27T12:08:54Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 11,
          "created_at": "2025-07-16T05:50:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 10,
          "created_at": "2025-08-25T12:57:41Z",
          "last_comment_at": "2025-11-26T21:08:28Z",
          "last_comment_author": "christopherpickering"
        },
        {
          "number": 8,
          "created_at": "2025-09-04T10:57:33Z",
          "last_comment_at": "2025-10-01T17:29:44Z",
          "last_comment_author": "MSaami"
        },
        {
          "number": 7,
          "created_at": "2025-09-14T09:56:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 9,
          "created_at": "2025-09-28T09:46:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2025-10-01T19:51:12Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 12,
          "created_at": "2025-11-05T22:16:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4,
          "created_at": "2025-12-04T22:44:04Z",
          "last_comment_at": "2025-12-04T23:29:22Z",
          "last_comment_author": "christopherpickering"
        },
        {
          "number": 6,
          "created_at": "2025-12-04T22:46:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2,
          "created_at": "2026-01-27T23:04:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3,
          "created_at": "2026-02-04T08:48:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 13,
          "created_at": "2026-02-25T19:11:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/spree/spree-rails-storefront",
    "host": "github.com",
    "name": "spree-rails-storefront",
    "owner": "spree"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 57,
      "inputs": {
        "security": 38,
        "vitality": 92,
        "community": 29,
        "governance": 58,
        "engineering": 57
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "commits_last_year": 170,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 41
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "41/52 weeks with commits",
                "points": 28.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 41
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "170 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 170
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 4,
              "latest_release_tag": "v5.4.6",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 36.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "4 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~36.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 36.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "forks": 11,
              "stars": 3,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "3 stars",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "11 forks",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "spree_storefront",
                "spree_page_builder"
              ],
              "dependents": null,
              "ecosystems": "rubygems",
              "total_downloads": 61371,
              "monthly_downloads": null
            },
            "components": [
              {
                "key": "total_downloads",
                "name": "Total downloads",
                "detail": "61,371 downloads all-time across rubygems",
                "points": 49.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_total",
                    "params": {
                      "count": 61371,
                      "ecosystems": "rubygems"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 16,
              "top_contributor_share": 0.716
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 72% of commits",
                "points": 6.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 72
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "16 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "merged_prs": 14,
              "open_issues": 12,
              "closed_issues": 1,
              "issue_closed_ratio": 0.077,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "8% of issues closed",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 8
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "14/16 decided PRs merged",
                "points": 33.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 14,
                      "decided": 16
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "followers": 198,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "spree",
              "public_repos": 26,
              "account_age_days": 6365
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "198 followers of spree",
                "points": 16.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 198,
                      "login": "spree"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "26 public repos, account ~17 yr old",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 26
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 17
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "spree_storefront",
                "spree_page_builder"
              ],
              "ecosystems": "rubygems",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on rubygems",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "rubygems"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "52 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 52
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 57,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "10 out of 14 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 38,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "10 out of 14 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 5",
                "points": 2.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 51,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "good",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.53,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 7322
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "53 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 28.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 53,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.1,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "10 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "Ruby",
              "largest_source_bytes": 51837,
              "source_files_sampled": 308,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Ruby without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Ruby"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/308 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 308,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T15:38:46.791848Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/spree/spree-rails-storefront.svg",
  "full_name": "spree/spree-rails-storefront",
  "license_state": "absent",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenRubyGems.