Öffentliches Register
Software-GesundheitsberichtSchema 0.11.0 · Metriken 1.13.0 · 2026-07-14 17:36 UTC

supabase / realtime

Broadcast, Presence, and Postgres Changes via WebSockets

ElixirApache-2.0★ 7.605 Sterne⑂ 448 Forksseit Sept. 2019Auf GitHub ansehen ↗

supabase/realtime erreicht einen Gesundheitsindex von 66 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (99/100) ab, am schwächsten bei Security (1/100). Zuletzt heute aktualisiert. 3 Mitwirkende tragen den Großteil der jüngsten Arbeit.

66
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

66
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

SupabaseOrganisation
10.855 Follower159 öffentliche Reposseit Aug. 2019

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Hexrealtime0.0.0111vor 1900 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

99Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
35.3/36Commit-Rhythmus — 51/52 Wochen mit Commits
18/18Commit-Volumen — 618 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — keine Daten
Verwendete Eingangsdaten
commits_last_year618
human_commit_share
days_since_last_push0
active_weeks_last_year51

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 100 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 0 Tagen
27/27Release-Rhythmus — ein Release etwa alle 0,7 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count100
latest_release_tagv2.113.2
releases_from_tagsnein
days_since_latest_release0
mean_days_between_releases0,7

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

74Gut · 18 % des Gesamtindex
Wie die Bewertung erfolgt
60/60Stars — 7.605 Stars
22.1/25Forks — 448 Forks
11.2/15Watcher — 105 Watcher
Verwendete Eingangsdaten
forks448
stars7.605
watchers105
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templateja
Wie die Bewertung erfolgt
14.4/80Downloads pro Monat — 11 Downloads/Monat über hex
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesrealtime
dependents
ecosystemshex
total_downloads252
monthly_downloads11
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

74Gut · 24 % des Gesamtindex
Wie die Bewertung erfolgt
36/54Bus-Faktor — 3 Beitragende decken die Hälfte aller Commits ab
17.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 22 % der Commits
13.5/13.5Breite der Beitragenden — 46 Beitragende
0/10OpenSSF Scorecard: Contributors — keine Daten
Verwendete Eingangsdaten
bus_factor3
contributors_sampled46
top_contributor_share0,22
Wie die Bewertung erfolgt
38.4/46.8Issue-Lösungsquote — 82 % der Issues geschlossen
33.6/38.3PR-Annahme — 1.323/1.507 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — keine Daten
Verwendete Eingangsdaten
merged_prs1.323
open_issues50
closed_issues231
issue_closed_ratio0,822
closed_unmerged_prs184
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
25/25Reichweite des Inhabers — 10.855 Follower von supabase
25/25Kontohistorie — 159 öffentliche Repos, Kontoalter ca. 6 Jahre
Verwendete Eingangsdaten
followers10.855
owner_typeOrganization
is_verified
owner_loginsupabase
public_repos159
account_age_days2.516

Paketpflege

53Mittel
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf hex
4/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 1.900 Tagen
4/20Versionshistorie — 1 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesrealtime
ecosystemshex
any_deprecatednein
min_days_since_publish1.900

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

66Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 13 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://supabase.com/realtime
10/10Repository-Beschreibung
10/10Topics — 11 Topics
10/10Wiki
Verwendete Eingangsdaten
topicscdc, change-data-capture, crdt, distributed-systems, elixir, phoenix, phoenix-framework, postgres, postgresql, pubsub, realtime
has_wikija
homepagehttps://supabase.com/realtime
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

1Kritisch · 16 % des Gesamtindex
Wie die Bewertung erfolgt
0/30Sicherheitsrichtlinie (SECURITY.md)
0/25Dependabot-Konfiguration
0/25Lockfiles für Abhängigkeiten — veröffentlichte Bibliothek — Lockfiles sind Sache der Anwendung, hier nicht erwartet
0/20CodeQL-Workflow
Verwendete Eingangsdaten
sourcefile_signals
lockfilesmix.lock, package-lock.json
manifestsassets/package.json, forum/mix.exs, mix.exs
has_codeql_workflownein
has_security_policynein
has_dependabot_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Lockfiles für Abhängigkeiten. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

43Gefährdet · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
0/40Lesbare Commit-Historie — keine Daten
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share
agent_instruction_files
agent_instruction_max_bytes
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Lesbare Commit-Historie. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — mise.toml
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
10/10Reproduzierbare Umgebung — Dockerfile, Nix, lockfile
0/10Belegte Agentenpraxis — keine Daten
0/8Automatisierte Wartung — keine Daten
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixja
has_testsja
lockfilesmix.lock, package-lock.json
has_dockerfileja
typed_languagenein
bootstrap_filesmise.toml
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share
toolchain_manifests
dependency_bot_commit_share
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Belegte Agentenpraxis, Automatisierte Wartung. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — Elixir ohne Typprüfungs-Konfiguration
54.8/55Handhabbare Dateigrößen — 2/452 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageElixir
largest_source_bytes91.034
source_files_sampled452
oversized_source_files2

Eckdaten

7.605GitHub-Sterne
46Mitwirkende
618Commits, letzte 12 Monate
0Tage seit letztem Push
100Releases
3Bus-Faktor
50offene Issues
Hex, npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Could not fetch hex package 'forum' from its registry
  • OpenSSF Scorecard timed out after 240s; skipping Scorecard checks

Weitere Details

Direkte Abhängigkeiten 46
RegistryPaketVersionsvorgabeManifest
npm@supabase/supabase-js2.110.3assets/package.json
Hextelemetry~> 1.3forum/mix.exs
Hexno_warnpriv/plts/dialyzer.pltmix.exs
Hexphoenix_ecto~> 4.4.0mix.exs
Hexecto_sql~> 3.11mix.exs
Hexecto_psql_extras~> 0.8mix.exs
Hexpostgrex~> 0.22mix.exs
Hexdb_connectionelixir-ecto/db_connectionmix.exs
Hexphoenix_html~> 3.2mix.exs
Hexphoenix_live_view~> 0.18mix.exs
Hexphoenix_live_dashboard~> 0.7mix.exs
Hexphoenix_view~> 2.0mix.exs
Hexesbuild~> 0.4mix.exs
Hextailwind~> 0.1mix.exs
Hextelemetry_metrics~> 1.0mix.exs
Hextelemetry_poller~> 1.0mix.exs
Hexgettext~> 0.19mix.exs
Hexjason~> 1.3mix.exs
Hexplug_cowboy~> 2.8mix.exs
Hexlibcluster~> 3.3mix.exs
Hexlibcluster_postgres~> 0.2mix.exs
Hexuuid~> 1.1mix.exs
Hexprom_ex~> 1.10mix.exs
Hexpeep~> 4.3mix.exs
Hexjoken~> 2.5.0mix.exs
Hexnimble_zta~> 0.1mix.exs
Hexex_json_schema~> 0.11mix.exs
Hexrecon~> 2.5mix.exs
Hexmint~> 1.4mix.exs
Hexlogflare_logger_backend~> 0.11mix.exs
Hexsyn~> 3.3mix.exs
Hexforum./forummix.exs
Hexcachex~> 4.0mix.exs
Hexopen_api_spex~> 3.16mix.exs
Hexcorsica~> 2.0mix.exs
Hexobserver_cli~> 1.7mix.exs
Hexopentelemetry_exporter~> 1.6mix.exs
Hexopentelemetry~> 1.3mix.exs
Hexopentelemetry_api~> 1.2mix.exs
Hexopentelemetry_phoenix~> 2.0mix.exs
Hexopentelemetry_cowboy~> 1.0mix.exs
Hexopentelemetry_ecto~> 1.2mix.exs
Hexgen_rpchttps://github.com/emqx/gen_rpc.gitmix.exs
Hexreq~> 0.6.2mix.exs
Hexphoenixmix.exs
Hexphoenixsupabase/phoenixmix.exs
Alle Abhängigkeiten 17

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 1 direkte und 16 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
npm@supabase/supabase-js2.110.3direkt
npm@opentelemetry/api^1.9.1indirekt
npm@opentelemetry/context-async-hooks^2.7.1indirekt
npm@opentelemetry/exporter-trace-otlp-http^0.218.0indirekt
npm@opentelemetry/resources^2.7.1indirekt
npm@opentelemetry/sdk-trace-base^2.7.1indirekt
npm@opentelemetry/semantic-conventions^1.41.1indirekt
npm@supabase/auth-js2.110.3indirekt
npm@supabase/functions-js2.110.3indirekt
npm@supabase/phoenix0.4.4indirekt
npm@supabase/postgrest-js2.110.3indirekt
npm@supabase/realtime-js2.110.3indirekt
npm@supabase/storage-js2.110.3indirekt
npmcommander^14.0.3indirekt
npmiceberg-js0.8.1indirekt
npmkleur^4.1.5indirekt
npmtslib2.8.1indirekt
JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "cdc",
        "change-data-capture",
        "crdt",
        "distributed-systems",
        "elixir",
        "phoenix",
        "phoenix-framework",
        "postgres",
        "postgresql",
        "pubsub",
        "realtime"
      ],
      "is_fork": false,
      "size_kb": 11925,
      "has_wiki": true,
      "homepage": "https://supabase.com/realtime",
      "languages": {
        "CSS": 10368,
        "Nix": 2467,
        "HTML": 32267,
        "Shell": 6243,
        "Elixir": 2418063,
        "Batchfile": 100,
        "Dockerfile": 4419,
        "JavaScript": 11003,
        "TypeScript": 112844
      },
      "pushed_at": "2026-07-14T17:29:22Z",
      "created_at": "2019-09-23T12:15:45Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-14T08:15:45Z",
      "description": "Broadcast, Presence, and Postgres Changes via WebSockets",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "primary_language": "Elixir",
      "significant_languages": [
        "Elixir"
      ]
    },
    "owner": {
      "blog": "https://supabase.com",
      "name": "Supabase",
      "type": "Organization",
      "login": "supabase",
      "company": null,
      "location": "United States of America",
      "followers": 10855,
      "avatar_url": "https://avatars.githubusercontent.com/u/54469796?v=4",
      "created_at": "2019-08-24T09:21:56Z",
      "is_verified": null,
      "public_repos": 159,
      "account_age_days": 2516
    },
    "activity": {
      "releases_count": 100,
      "commits_last_year": 618,
      "latest_release_at": "2026-07-14T08:15:44Z",
      "latest_release_tag": "v2.113.2",
      "days_since_last_push": 0,
      "active_weeks_last_year": 51,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "realtime",
          "exists": true,
          "license": "Apache-2.0",
          "ecosystem": "hex",
          "matches_repo": true,
          "registry_url": "https://hex.pm/packages/realtime",
          "is_deprecated": false,
          "latest_version": "0.0.0",
          "repository_url": "https://github.com/supabase/realtime",
          "versions_count": 1,
          "total_downloads": 252,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 11,
          "first_published_at": "2021-05-01T03:24:43.042349Z",
          "latest_published_at": "2021-05-01T03:24:43.042349Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1900
        }
      ]
    },
    "popularity": {
      "forks": 448,
      "stars": 7605,
      "watchers": 105,
      "open_issues_and_prs": 67
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "mise.toml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "largest_source_bytes": 91034,
      "source_files_sampled": 452,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "assets/package.json",
        "forum/mix.exs",
        "mix.exs"
      ],
      "ecosystems": [
        "hex",
        "npm"
      ],
      "dependencies": [
        {
          "name": "@supabase/supabase-js",
          "manifest": "assets/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.110.3"
        },
        {
          "name": "telemetry",
          "manifest": "forum/mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.3"
        },
        {
          "name": "no_warn",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "priv/plts/dialyzer.plt"
        },
        {
          "name": "phoenix_ecto",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 4.4.0"
        },
        {
          "name": "ecto_sql",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 3.11"
        },
        {
          "name": "ecto_psql_extras",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.8"
        },
        {
          "name": "postgrex",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.22"
        },
        {
          "name": "db_connection",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "elixir-ecto/db_connection"
        },
        {
          "name": "phoenix_html",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 3.2"
        },
        {
          "name": "phoenix_live_view",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.18"
        },
        {
          "name": "phoenix_live_dashboard",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.7"
        },
        {
          "name": "phoenix_view",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.0"
        },
        {
          "name": "esbuild",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.4"
        },
        {
          "name": "tailwind",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.1"
        },
        {
          "name": "telemetry_metrics",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.0"
        },
        {
          "name": "telemetry_poller",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.0"
        },
        {
          "name": "gettext",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.19"
        },
        {
          "name": "jason",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.3"
        },
        {
          "name": "plug_cowboy",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.8"
        },
        {
          "name": "libcluster",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 3.3"
        },
        {
          "name": "libcluster_postgres",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.2"
        },
        {
          "name": "uuid",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.1"
        },
        {
          "name": "prom_ex",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.10"
        },
        {
          "name": "peep",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 4.3"
        },
        {
          "name": "joken",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.5.0"
        },
        {
          "name": "nimble_zta",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.1"
        },
        {
          "name": "ex_json_schema",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.11"
        },
        {
          "name": "recon",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.5"
        },
        {
          "name": "mint",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.4"
        },
        {
          "name": "logflare_logger_backend",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.11"
        },
        {
          "name": "syn",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 3.3"
        },
        {
          "name": "forum",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "./forum"
        },
        {
          "name": "cachex",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 4.0"
        },
        {
          "name": "open_api_spex",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 3.16"
        },
        {
          "name": "corsica",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.0"
        },
        {
          "name": "observer_cli",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.7"
        },
        {
          "name": "opentelemetry_exporter",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.6"
        },
        {
          "name": "opentelemetry",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.3"
        },
        {
          "name": "opentelemetry_api",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.2"
        },
        {
          "name": "opentelemetry_phoenix",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 2.0"
        },
        {
          "name": "opentelemetry_cowboy",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.0"
        },
        {
          "name": "opentelemetry_ecto",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 1.2"
        },
        {
          "name": "gen_rpc",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "https://github.com/emqx/gen_rpc.git"
        },
        {
          "name": "req",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "~> 0.6.2"
        },
        {
          "name": "phoenix",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": null
        },
        {
          "name": "phoenix",
          "manifest": "mix.exs",
          "ecosystem": "hex",
          "version_constraint": "supabase/phoenix"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@supabase/supabase-js",
            "direct": true,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": false,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/context-async-hooks",
            "direct": false,
            "version": "^2.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": false,
            "version": "^0.218.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": false,
            "version": "^2.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-base",
            "direct": false,
            "version": "^2.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "^1.41.1",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/auth-js",
            "direct": false,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/functions-js",
            "direct": false,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/phoenix",
            "direct": false,
            "version": "0.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/postgrest-js",
            "direct": false,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/realtime-js",
            "direct": false,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/storage-js",
            "direct": false,
            "version": "2.110.3",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "^14.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "iceberg-js",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "kleur",
            "direct": false,
            "version": "^4.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 17,
        "direct_count": 1,
        "indirect_count": 16
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 17,
        "merged_prs": 1323,
        "open_issues": 50,
        "closed_ratio": 0.822,
        "closed_issues": 231,
        "closed_unmerged_prs": 184
      },
      "bus_factor": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "abc3",
          "commits": 634,
          "avatar_url": "https://avatars.githubusercontent.com/u/1172600?u=8349dc56f0c1cf9d1ae6af0cd41165882fe4c82a&v=4"
        },
        {
          "type": "User",
          "login": "filipecabaco",
          "commits": 502,
          "avatar_url": "https://avatars.githubusercontent.com/u/1697301?u=89c1d70163ea56981515b72827edad3195f30be4&v=4"
        },
        {
          "type": "User",
          "login": "chasers",
          "commits": 426,
          "avatar_url": "https://avatars.githubusercontent.com/u/1019814?v=4"
        },
        {
          "type": "User",
          "login": "w3b6x9",
          "commits": 422,
          "avatar_url": "https://avatars.githubusercontent.com/u/5532241?u=19b8f763228c042ab14453bf35360de7fd06c47d&v=4"
        },
        {
          "type": "User",
          "login": "edgurgel",
          "commits": 269,
          "avatar_url": "https://avatars.githubusercontent.com/u/30873?u=ab5398ec9a362983b555e702d3044fc752843bde&v=4"
        },
        {
          "type": "User",
          "login": "kiwicopple",
          "commits": 173,
          "avatar_url": "https://avatars.githubusercontent.com/u/10214025?u=c6775be2ae667e2acae3ccd347fed62bb3f5b3e7&v=4"
        },
        {
          "type": "User",
          "login": "semantic-release-bot",
          "commits": 171,
          "avatar_url": "https://avatars.githubusercontent.com/u/32174276?u=e0b5aa0b78811d4b099e35197d855c364778108d&v=4"
        },
        {
          "type": "Bot",
          "login": "dependabot[bot]",
          "commits": 56,
          "avatar_url": "https://avatars.githubusercontent.com/in/29110?v=4"
        },
        {
          "type": "User",
          "login": "leandrocp",
          "commits": 53,
          "avatar_url": "https://avatars.githubusercontent.com/u/36407?u=1deb1601d85068a30af723d5f1f58fd1b2b22cca&v=4"
        },
        {
          "type": "User",
          "login": "soedirgo",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/31685197?u=518e136f1b8ffcf973df9d0f56564efda52a4119&v=4"
        }
      ],
      "contributors_sampled": 46,
      "top_contributor_share": 0.22
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "dispatch_deploy.yml",
        "docker-build.yml",
        "fix-nix-hash.yml",
        "forum_tests.yml",
        "integration_tests.yml",
        "lint.yml",
        "manual_prod_build.yml",
        "mirror.yml",
        "prod_build.yml",
        "prod_linter.yml",
        "tests.yml",
        "update-supabase-js.yml",
        "update-tenant-db-catalog.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "mix.lock",
        "package-lock.json"
      ],
      "scorecard": null,
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/supabase/realtime",
    "host": "github.com",
    "name": "realtime",
    "owner": "supabase"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 66,
      "inputs": {
        "security": 1,
        "vitality": 99,
        "community": 74,
        "governance": 74,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 99,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 618,
              "human_commit_share": null,
              "days_since_last_push": 0,
              "active_weeks_last_year": 51
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "51/52 weeks with commits",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "618 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 618
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v2.113.2",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "no_commit_sample",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 74,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "excellent",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "forks": 448,
              "stars": 7605,
              "watchers": 105,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "7,605 stars",
                "points": 60,
                "status": "met",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 7605
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "448 forks",
                "points": 22.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 448
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "105 watchers",
                "points": 11.2,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 105
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "critical",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 18,
            "inputs": {
              "packages": [
                "realtime"
              ],
              "dependents": null,
              "ecosystems": "hex",
              "total_downloads": 252,
              "monthly_downloads": 11
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11 downloads/month across hex",
                "points": 14.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11,
                      "ecosystems": "hex"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 74,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 46,
              "top_contributor_share": 0.22
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 22% of commits",
                "points": 17.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 22
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "46 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 46
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "merged_prs": 1323,
              "open_issues": 50,
              "closed_issues": 231,
              "issue_closed_ratio": 0.822,
              "closed_unmerged_prs": 184
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "82% of issues closed",
                "points": 38.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1323/1507 decided PRs merged",
                "points": 33.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1323,
                      "decided": 1507
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "followers": 10855,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "supabase",
              "public_repos": 159,
              "account_age_days": 2516
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "10,855 followers of supabase",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 10855,
                      "login": "supabase"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "159 public repos, account ~6 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 159
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 6
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "moderate",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "packages": [
                "realtime"
              ],
              "ecosystems": "hex",
              "any_deprecated": false,
              "min_days_since_publish": 1900
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on hex",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "hex"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1900 days ago",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1900
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "13 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "cdc",
                "change-data-capture",
                "crdt",
                "distributed-systems",
                "elixir",
                "phoenix",
                "phoenix-framework",
                "postgres",
                "postgresql",
                "pubsub",
                "realtime"
              ],
              "has_wiki": true,
              "homepage": "https://supabase.com/realtime",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://supabase.com/realtime",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "11 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 1,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dependency lockfiles. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dependency_lockfiles"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "source": "file_signals",
              "lockfiles": [
                "mix.lock",
                "package-lock.json"
              ],
              "manifests": [
                "assets/package.json",
                "forum/mix.exs",
                "mix.exs"
              ],
              "has_codeql_workflow": false,
              "has_security_policy": false,
              "has_dependabot_config": false
            },
            "components": [
              {
                "key": "security_policy_security_md",
                "name": "Security policy (SECURITY.md)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "dependabot_config",
                "name": "Dependabot config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "dependency_lockfiles",
                "name": "Dependency lockfiles",
                "detail": "published library — lockfiles are an application concern, not expected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "lockfiles_not_expected",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "codeql_workflow",
                "name": "CodeQL workflow",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 43,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": "Excluded from scoring (no data or not applicable): Legible commit history. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "legible_commit_history"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": null,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): Demonstrated agent practice, Automated maintenance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "demonstrated_agent_practice",
                    "automated_maintenance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 69,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "mix.lock",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "mise.toml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": null,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": null
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "mise.toml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "mise.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "OpenSSF Scorecard unavailable",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "Elixir",
              "largest_source_bytes": 91034,
              "source_files_sampled": 452,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Elixir without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Elixir"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/452 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 452,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch hex package 'forum' from its registry",
    "OpenSSF Scorecard timed out after 240s; skipping Scorecard checks"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-14T17:36:11.895661Z",
  "schema_version": "0.11.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/supabase/realtime.svg",
  "full_name": "supabase/realtime",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.11.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenHex.