Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-29 01:05 UTC

tbckr / sgpt

SGPT is a command-line tool that provides a convenient way to interact with OpenAI models, enabling users to run queries, generate shell commands and produce code directly from the terminal.

GoMIT★ 457 Sterne⑂ 36 Forksseit Feb. 2023Auf GitHub ansehen ↗

tbckr/sgpt erreicht einen Gesundheitsindex von 80 von 100 und liegt damit im Bereich Gut. Am stärksten schneidet es bei Vitality (99/100) ab, am schwächsten bei Sustainability & Governance (60/100). Zuletzt vor 2 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

80
gesamt / 100
Gut

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

80
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

TimPersönliches Konto
48 Follower14 öffentliche Reposseit März 2015

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/tbckr/sgpt/v2v2.21.2-40vor 8 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

99Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 2 Tagen
34.6/36Commit-Rhythmus — 50/52 Wochen mit Commits
18/18Commit-Volumen — 300 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year300
human_commit_share0,21
days_since_last_push2
active_weeks_last_year50
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 61 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 8 Tagen
27/27Release-Rhythmus — ein Release etwa alle 21,4 Tage
8/10OpenSSF Scorecard: Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
Verwendete Eingangsdaten
releases_count61
latest_release_tagv2.21.2
releases_from_tagsnein
days_since_latest_release8
mean_days_between_releases21,4

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

74Gut · 18 % des Gesamtindex
Wie die Bewertung erfolgt
43.1/60Stars — 457 Stars
12.9/25Forks — 36 Forks
2.7/15Watcher — 4 Watcher
Verwendete Eingangsdaten
forks36
stars457
watchers4
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templateja

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

60Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.9/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 96 % der Commits
8.1/13.5Breite der Beitragenden — 6 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled6
top_contributor_share0,958
Wie die Bewertung erfolgt
46/46.8Issue-Lösungsquote — 98 % der Issues geschlossen
37.3/38.3PR-Annahme — 309/317 entschiedene PRs gemergt
1.5/15OpenSSF Scorecard: Code-Review — Found 3/29 approved changesets -- score normalized to 1
Verwendete Eingangsdaten
merged_prs309
open_issues1
closed_issues66
issue_closed_ratio0,985
closed_unmerged_prs8
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
12.2/25Reichweite des Inhabers — 48 Follower von tbckr
20.6/25Kontohistorie — 14 öffentliche Repos, Kontoalter ca. 11 Jahre
Verwendete Eingangsdaten
followers48
owner_typeUser
is_verified
owner_logintbckr
public_repos14
account_age_days4.150
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
20/20Versionshistorie — 40 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/tbckr/sgpt/v2
ecosystemsgo
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

90Exzellent · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 7 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — .golangci.yaml
9.6/9.6Pre-Commit-Hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfigja
has_linter_configja
has_precommit_configja
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
10/10Topics — 19 Topics
0/10Wiki
Verwendete Eingangsdaten
topicscli, bash, gpt-3, gpt-4, openai, shell, go, gpt-4-vision, gpt-4-vision-preview, gpt-4o, o1-mini, o1-preview, anthropic, anthropic-claude, gemini, gemini-api, gemini-pro, openrouter, openrouter-api
has_wikinein
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

77Gut · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 3/29 approved changesets -- score normalized to 1
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate7,1
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories2
affected_packages2
assessed_packages26
unassessed_packages3
affected_by_severityunknown 2
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories, Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. 26 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. 3 konnten nicht bewertet werden — keine aufgelöste Version, ein nicht unterstütztes Ökosystem oder außerhalb der ausgewiesenen Paketliste. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

89Exzellent · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — docs/usage/gemini.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 21 von 21 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_filesdocs/usage/gemini.md
agent_instruction_max_bytes2.249
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Taskfile.yml
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — .golangci.yaml
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — Dockerfile, Nix, lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
8/8Automatisierte Wartung — 74 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Verwendete Eingangsdaten
has_nixja
has_testsja
lockfilesgo.sum
has_dockerfileja
typed_languageja
bootstrap_filesTaskfile.yml
has_devcontainernein
has_linter_configja
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0,74
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
53.6/55Handhabbare Dateigrößen — 1/38 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes123.307
source_files_sampled38
oversized_source_files1

Eckdaten

457GitHub-Sterne
6Mitwirkende
300Commits, letzte 12 Monate
2Tage seit letztem Push
61Releases
1Bus-Faktor
1offene Issues
Go, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 36 ⇿
0Sterne
36Forks
39Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

01325383322023-052024-122026-06
Major 1Minor 21Patch 17

Jeder Punkt umfasst 3 Tage.

OpenSSF Scorecard 7.1 / 10
7.1Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-29 01:05 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 3/29 approved changesets -- score normalized to 1
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
8Signed-Releases5 out of the last 5 releases have a total of 5 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
8Vulnerabilities2 existing vulnerabilities detected
Direkte Abhängigkeiten 9
RegistryPaketVersionsvorgabeManifest
Gogithub.com/atotto/clipboardv0.1.4go.mod
Gogithub.com/jarcoal/httpmockv1.4.1go.mod
Gogithub.com/muesli/mango-cobrav1.3.0go.mod
Gogithub.com/muesli/roffv0.1.0go.mod
Gogithub.com/sashabaranov/go-openaiv1.41.2go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/viperv1.21.0go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Alle Abhängigkeiten 29

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 9 direkte und 20 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Gogithub.com/atotto/clipboardv0.1.4direkt
Gogithub.com/jarcoal/httpmockv1.4.1direkt
Gogithub.com/muesli/mango-cobrav1.3.0direkt
Gogithub.com/muesli/roffv0.1.0direkt
Gogithub.com/sashabaranov/go-openaiv1.41.2direkt
Gogithub.com/spf13/cobrav1.10.2direkt
Gogithub.com/spf13/viperv1.21.0direkt
Gogithub.com/stretchr/testifyv1.11.1direkt
Gogopkg.in/yaml.v3v3.0.1direkt
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirekt
Gogithub.com/fsnotify/fsnotifyv1.9.0indirekt
Gogithub.com/go-viper/mapstructure/v2v2.4.0indirekt
Gogithub.com/inconshreveable/mousetrapv1.1.0indirekt
Gogithub.com/muesli/mangov0.2.0indirekt
Gogithub.com/muesli/mango-pflagv0.1.0indirekt
Gogithub.com/pelletier/go-toml/v2v2.2.4indirekt
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirekt
Gogithub.com/sagikazarmark/locaferov0.11.0indirekt
Gogithub.com/sourcegraph/concv0.3.1-0.20240121214520-5f936abd7ae8indirekt
Gogithub.com/spf13/aferov1.15.0indirekt
Gogithub.com/spf13/castv1.10.0indirekt
Gogithub.com/spf13/pflagv1.0.10indirekt
Gogithub.com/subosito/gotenvv1.6.0indirekt
Gogo.yaml.in/yaml/v3v3.0.4indirekt
Gogolang.org/x/sysv0.29.0indirekt
Gogolang.org/x/textv0.28.0indirekt
PyPImkdocsindirekt
PyPImkdocs-materialindirekt
PyPIpymdown-extensionsindirekt
Abhängigkeits-Advisories 2

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 26 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 2 tragen bekannte Advisories, davon 0 direkte. 3 konnten nicht bewertet werden – keine aufgelöste Version, ein nicht unterstütztes Ökosystem, oder außerhalb der ausgewiesenen Paketliste.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
golang.org/x/sysv0.29.0indirektunbekannt10.44.0
golang.org/x/textv0.28.0indirektunbekannt10.39.0

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "cli",
        "bash",
        "gpt-3",
        "gpt-4",
        "openai",
        "shell",
        "go",
        "gpt-4-vision",
        "gpt-4-vision-preview",
        "gpt-4o",
        "o1-mini",
        "o1-preview",
        "anthropic",
        "anthropic-claude",
        "gemini",
        "gemini-api",
        "gemini-pro",
        "openrouter",
        "openrouter-api"
      ],
      "is_fork": false,
      "size_kb": 2372,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 338122,
        "Nix": 2678,
        "Shell": 6876,
        "Dockerfile": 1702
      },
      "pushed_at": "2026-07-26T05:02:40Z",
      "created_at": "2023-02-25T19:21:49Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T05:02:33Z",
      "description": "SGPT is a command-line tool that provides a convenient way to interact with OpenAI models, enabling users to run queries, generate shell commands and produce code directly from the terminal.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Tim",
      "type": "User",
      "login": "tbckr",
      "company": null,
      "location": "@home",
      "followers": 48,
      "avatar_url": "https://avatars.githubusercontent.com/u/11543666?v=4",
      "created_at": "2015-03-18T18:30:19Z",
      "is_verified": null,
      "public_repos": 14,
      "account_age_days": 4150
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.21.2",
          "kind": "patch",
          "published_at": "2026-07-20T11:19:45Z"
        },
        {
          "tag": "v2.21.1",
          "kind": "patch",
          "published_at": "2026-05-13T14:56:46Z"
        },
        {
          "tag": "v2.21.0",
          "kind": "minor",
          "published_at": "2026-05-05T12:18:32Z"
        },
        {
          "tag": "v2.20.0",
          "kind": "minor",
          "published_at": "2026-04-26T09:42:43Z"
        },
        {
          "tag": "v2.19.0",
          "kind": "minor",
          "published_at": "2026-03-01T18:38:20Z"
        },
        {
          "tag": "v2.18.0",
          "kind": "minor",
          "published_at": "2026-03-01T15:46:45Z"
        },
        {
          "tag": "v2.17.6",
          "kind": "patch",
          "published_at": "2026-02-18T16:43:41Z"
        },
        {
          "tag": "v2.17.5",
          "kind": "patch",
          "published_at": "2026-02-08T10:33:49Z"
        },
        {
          "tag": "v2.17.4",
          "kind": "patch",
          "published_at": "2026-01-08T21:49:50Z"
        },
        {
          "tag": "v2.17.3",
          "kind": "patch",
          "published_at": "2026-01-08T21:26:31Z"
        },
        {
          "tag": "v2.17.2",
          "kind": "patch",
          "published_at": "2026-01-08T21:19:59Z"
        },
        {
          "tag": "v2.17.1",
          "kind": "patch",
          "published_at": "2025-10-13T11:31:45Z"
        },
        {
          "tag": "v2.17.0",
          "kind": "minor",
          "published_at": "2025-04-11T18:32:41Z"
        },
        {
          "tag": "v2.16.0",
          "kind": "minor",
          "published_at": "2025-02-25T13:09:09Z"
        },
        {
          "tag": "v2.15.0",
          "kind": "minor",
          "published_at": "2024-09-20T13:15:10Z"
        },
        {
          "tag": "v2.14.1",
          "kind": "patch",
          "published_at": "2024-05-14T16:08:22Z"
        },
        {
          "tag": "v2.14.0",
          "kind": "minor",
          "published_at": "2024-05-14T16:02:57Z"
        },
        {
          "tag": "v2.13.0",
          "kind": "minor",
          "published_at": "2024-03-22T13:45:42Z"
        },
        {
          "tag": "v2.12.0",
          "kind": "minor",
          "published_at": "2024-01-06T10:14:32Z"
        },
        {
          "tag": "v2.11.2",
          "kind": "patch",
          "published_at": "2023-12-29T13:06:29Z"
        },
        {
          "tag": "v2.11.1",
          "kind": "patch",
          "published_at": "2023-12-29T13:02:06Z"
        },
        {
          "tag": "v2.11.0",
          "kind": "minor",
          "published_at": "2023-12-29T12:52:05Z"
        },
        {
          "tag": "v2.10.1",
          "kind": "patch",
          "published_at": "2023-12-29T10:18:36Z"
        },
        {
          "tag": "v2.10.0",
          "kind": "minor",
          "published_at": "2023-12-19T09:22:26Z"
        },
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2023-12-08T18:57:29Z"
        },
        {
          "tag": "v2.8.1",
          "kind": "patch",
          "published_at": "2023-12-05T09:35:35Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2023-12-04T09:41:27Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2023-11-27T11:44:10Z"
        },
        {
          "tag": "v2.6.1",
          "kind": "patch",
          "published_at": "2023-11-25T10:55:39Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2023-11-01T22:16:49Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2023-10-27T11:10:23Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2023-10-20T07:01:00Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2023-10-12T17:45:07Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2023-10-09T16:37:32Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2023-10-02T11:15:17Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2023-10-02T11:07:02Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2023-10-02T10:25:29Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2023-10-02T09:55:21Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2023-10-02T09:37:29Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2023-09-30T16:31:50Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2023-03-26T14:13:20Z"
        },
        {
          "tag": "v1.12.2",
          "kind": "patch",
          "published_at": "2023-03-25T10:58:08Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2023-03-25T10:51:15Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2023-03-24T19:33:45Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2023-03-24T18:48:50Z"
        },
        {
          "tag": "v1.10.1",
          "kind": "patch",
          "published_at": "2023-03-24T13:34:55Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2023-03-24T13:00:03Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2023-03-22T17:29:44Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2023-03-22T12:05:24Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2023-03-22T11:58:45Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2023-03-19T14:52:33Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2023-03-19T11:12:42Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2023-03-19T10:48:30Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2023-03-18T11:19:24Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2023-03-18T10:00:13Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2023-03-18T09:43:12Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2023-03-17T16:56:53Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2023-03-17T16:40:52Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2023-03-16T19:35:46Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2023-03-15T17:56:28Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2023-03-10T13:01:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3a79f0d6b02f9699b83236416de0ecc3fee42694",
          "body": "… 399c8cb",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-26T05:02:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49975bd9cf1f2727fcc17f816113d21c82400b0e",
          "body": "….16.5",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-23T06:39:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffb13f311595ee1e1acefaf38fd0d627ad536cf9",
          "body": "… v0.49.1",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook igorshubovych/markdownlint-cli to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T23:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "695377e3ff7abcca175a013d2e49dd9c392bb164",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update actions/checkout digest to d23441a",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T02:41:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73fad7be2ee54ead481af2933d12e060f2fc7709",
          "body": "The Local LLM section existed only in the README, so readers of the\nrendered docs site had no way to find it. Add usage/local-llm.md with\nthe base URLs of common backends (Ollama, LiteLLM, vLLM, llama.cpp)\nand the LAN hostname opt-out, and wire it into the mkdocs nav.\n\nValidation rules are not duplicated here; the page links to the\nexisting section in query-models.md instead.",
          "is_bot": false,
          "headline": "docs: add Local LLM Support page to the docs site (#388)",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-20T11:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d81676f310d90cf89e580d01abe0ae430e83cb56",
          "body": "Gemini is reachable over an OpenAI-compatible chat completions API, so\nsgpt already supports it through the existing OPENAI_API_BASE override.\nNothing in the docs said so, which made it look unsupported and drove\nrequests for a native Gemini client (#173).\n\nDocument both routes: Google's own OpenAI-\n[…]\nndpoint and\nOpenRouter's google/ prefixed models. Also call out that the key goes\ninto OPENAI_API_KEY rather than GEMINI_API_KEY, since the variable\nnames the protocol and not the provider.\n\nRefs #173",
          "is_bot": false,
          "headline": "docs: document Google Gemini support via OpenAI-compatible API (#387)",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-20T11:39:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "201e448d310702fd0144f1bd84c1e5ab62ff7980",
          "body": "Co-authored-by: tbckr-automation[bot] <146582694+tbckr-automation[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 2.21.2 (#383)",
          "author_name": "tbckr-automation[bot]",
          "author_login": "tbckr-automation[bot]",
          "committed_at": "2026-07-20T11:19:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "906aa482abedef30958dd96526884b5a90c5349e",
          "body": "* fix(shell): reuse bufio.Reader so buffered confirmation input is not lost\n\ngetUserConfirmation built a new bufio.Reader on every retry-loop\niteration, so any bytes it had already buffered from an unrecognised\nkeystroke were discarded along with it, leaving the loop waiting for\ninput the user had a\n[…]\niltin case-sensitivity behavior at both the modifier-resolution and\nCLI layers, and TestReadString_TrailingAndCRLF to characterize\nReadString's trimming across LF/CRLF and single/multiple terminators.",
          "is_bot": false,
          "headline": "fix: input/exec bugs #377, #379, #380, #381 (#385)",
          "author_name": "Stefan",
          "author_login": "zorak1103",
          "committed_at": "2026-07-20T11:15:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b3e598c95b62893699d4e84567deb240761e7595",
          "body": "…d image size (#382)\n\n* fix: validate session name in DeleteSession to block path traversal\n\nDeleteSession was the only chat session method that did not validate\nthe session name before turning it into a filesystem path, letting\nsgpt chat rm \"../../../../home/user/.bashrc\" delete arbitrary files.\nAd\n[…]\nsymlink on open.\nA symlink swapped between the check and the open could still escape the\nworking directory. Also adds coverage for the not-yet-exists path branch\nand an in-cwd symlink acceptance case.",
          "is_bot": false,
          "headline": "fix: address security issues in chat rm, --input path containment, an…",
          "author_name": "Stefan",
          "author_login": "zorak1103",
          "committed_at": "2026-07-20T09:43:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e352313ec5bf2accf3a777d51627588a74da0c6",
          "body": "goreleaser v2.16.0 made `goreleaser check` exit non-zero when the config\nuses deprecated properties. .goreleaser.yaml still uses `dockers` /\n`docker_manifests` (-> dockers_v2) and `brews` (-> homebrew_casks), so the\nCI check step has failed on main since v2.16.0 rolled out via `version: latest`.\n\nPi\n[…]\nese as\nwarnings instead of errors. The release workflow stays on `latest` since\n`goreleaser release` only warns on deprecations.\n\nUnpin after migrating .goreleaser.yaml to dockers_v2 + homebrew_casks.",
          "is_bot": false,
          "headline": "ci: pin goreleaser check to v2.15.4 (#384)",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-20T09:40:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63ef87cdc44e35234f557744a1d17782efae1e74",
          "body": null,
          "is_bot": false,
          "headline": "fix(deps): upgrade go to 1.26.5",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-20T09:20:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dee7c897ce722ae322eb0454006ca8a1b376587",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 3aff665",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T05:35:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7e500b1eed091cf5ddf63b845b64f4062b9e46d",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to ae5a231",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-16T05:11:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29f3dad8792ccfcb8f39ac90b3d131456e0dd6b0",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to d52df9c",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-14T17:37:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a9cce75faef26cceb5c412505a93103258fd9ff",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 0f70d7d",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-14T10:15:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aaa1cafcae478c732ea4ada9a710dbdaa5462b5",
          "body": "… 60582b2",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T02:30:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c9512d34652585565d52dc9e34512f62040c0b2",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 079e598",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T23:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "735c37b69b1d3e561f32bb73a8de60112caa3d20",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to b900de9",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T01:09:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f52df68dcea0199d7d724319bafc5a1e7aed4dbd",
          "body": "…a to v0.37.4",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook python-jsonschema/check-jsonschem…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-06T21:57:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3130de564d0cf7b9b243302b980794ed1bdc6f84",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): update flake inputs (nixpkgs, unstable, flake-schemas)",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-04T11:18:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dc43e330d8eb26f5423b7513a579935b1bac7e8",
          "body": null,
          "is_bot": false,
          "headline": "chore(devshell): add nodejs-slim 24 LTS to devShell",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-07-04T10:47:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b4d2b95f02dbdf88d5174dd6ab6bc762a73fb68",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to f96cc55",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T23:12:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c242face661b892d0b1d0576b7af3a8c43ae1b0",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golangci/golangci-lint-action digest to ba0d7d2",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T17:47:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd9292da845e5f940ad0ee997ffac6a126064ebd",
          "body": "….16.4",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T11:34:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9b4a32f1f98dd7d8c98cecb6ad194fea23a8061",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 32c0e6e",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T18:50:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ee263b19fe9c1371c7848768fc487b4898c1894",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 8f4cb3b",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T14:36:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfaa26f709480c25386075b90282a0168f02748f",
          "body": "… v0.49.0",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook igorshubovych/markdownlint-cli to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T10:47:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ae10e174d754a9b30829b8eaefc7b4443865571",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 478231b",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T10:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37091553949b396a130ad4ebece199f709ff3235",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update actions/setup-go digest to 924ae3a",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T04:34:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e460ef7d3469a15bd2b37010944b3166b073522f",
          "body": "Requesty is an OpenAI-compatible LLM gateway, so it works with SGPT the same\nway OpenRouter does: set OPENAI_API_BASE to https://router.requesty.ai/v1 and\nOPENAI_API_KEY, then select models with provider/model names via -m.\n\nAdds a 'Requesty API Support' README section mirroring the existing OpenRouter\nsection, plus the matching table-of-contents entry.",
          "is_bot": false,
          "headline": "chore(docs): add Requesty API support section (#374)",
          "author_name": "Thibault Jaigu",
          "author_login": "Thibaultjaigu",
          "committed_at": "2026-06-22T20:13:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baa0e88285d039f97490c7f569c6643ec2ad0d1a",
          "body": "…a to v0.37.3",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook python-jsonschema/check-jsonschem…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-19T19:43:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "904383c52fc6c6b3dc98868616e445722ebf4148",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 792443b",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-15T22:49:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1831345bf04486d980c57a30c0e2f857497e6885",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 87a41d2",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-13T19:48:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "342ada4dc92a6c3642ab411fb9685a5cd12a0e94",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 11fd8f7",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-10T04:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4918d1e3ee1e92ed58ce9a257505324186632a0",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update codecov/codecov-action digest to 0fb7174",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-09T03:10:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ab36b4e7c4855780420e56951e0762ed4debac9",
          "body": "….16.3",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-06T09:11:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "083a91f93d874119acd7f2f386386ee99194b62d",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update actions/checkout digest to df4cb1c",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-03T15:03:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15c65fbd03d4c3ed88c40327b0bbfe3b8581fb17",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 68cb6d6",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-03T06:07:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1df977d694503af878e08e5d5ba668e81b1ad8b",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 98fc714",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-03T02:30:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75a982523a066aaeacdfe5fac6372d952d25897d",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 2d6c802",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-24T21:05:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ed668ee626fc94133ac0f1870ffbf49a53634a6",
          "body": "….16.2",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-22T01:42:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d61f52a8c924997f50de7203a5b247f07eb372c2",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golangci/golangci-lint-action digest to 82606bf",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-22T01:41:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccd228aded7c66e672545ce5acb0e410b909c32c",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 6df14f4",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-20T13:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9088868cc7a658dbddd54bb5b914d864aff156e1",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 8530a4f",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-20T11:04:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d82411678733b7f902a83947e15bae1f263b73f1",
          "body": "….16.0",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-19T05:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cba0c7e17543da8c407f81acc1299fee8afeea7c",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 313faae",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-13T20:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b80015f4ab812bde731379d3a6eca06a451c63e5",
          "body": "Co-authored-by: tbckr-automation[bot] <146582694+tbckr-automation[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 2.21.1 (#373)",
          "author_name": "tbckr-automation[bot]",
          "author_login": "tbckr-automation[bot]",
          "committed_at": "2026-05-13T14:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08ccc0fa58b9fcbfcab655876c7d4972b61171d7",
          "body": "PR #367 enforced https-only on OPENAI_API_BASE to close #358, which\nbroke local LLM setups (Ollama, LiteLLM, vLLM in containers) that\nlegitimately use plain http on loopback or private networks.\n\nThe validator now accepts:\n- https for any host (unchanged)\n- http for localhost, 127.0.0.0/8, ::1, RFC1\n[…]\ndo the validation guarantee.\n\nWhen validation passes, the override is logged at debug instead of\nwarn (PR #367 emitted a warn line per request, which interleaved\nwith stderr in scripts).\n\nCloses #371.",
          "is_bot": false,
          "headline": "fix(config): allow http OPENAI_API_BASE for loopback and RFC1918 (#372)",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-05-13T14:53:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e88e70e7dd311b64a788d5167e5ada21d2338a96",
          "body": "Closes govulncheck failures for:\n- GO-2026-4971 (net: panic in Dial/LookupPort with NUL byte on Windows)\n- GO-2026-4918 (net/http internal http2: infinite loop on bad\n  SETTINGS_MAX_FRAME_SIZE)\n\nBoth fixes are in the Go 1.26.3 stdlib. CI reads `go-version-file: go.mod`\nso bumping the directive is enough; the golang:1.26 Docker tag tracks the\npatch release automatically.",
          "is_bot": false,
          "headline": "chore(deps): bump Go to 1.26.3 for net/net-http CVE fixes",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-05-13T14:46:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed421983bd704b4ea9917715359884ec3305a9d6",
          "body": "Bumps flake-schemas and nixpkgs (unstable) to current pins; brings\ngolangci-lint up to 2.12.2 (built with go1.26.2) so it runs against\nthe project's go.mod toolchain version.",
          "is_bot": false,
          "headline": "chore(deps): update flake.lock inputs",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-05-13T14:35:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55743ddb48b43af70106f79e4ff7410cf1d90d68",
          "body": "….15.1",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-13T04:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3b93c5fb573a7cfa6d2805aae791c83a2556383",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 633d23b",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-13T04:57:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f715d539260b60175bcc18a7b153bc21fd56fb6",
          "body": "….15.0",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-10T09:50:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "702b7a86bdc70e4b34831c12315c11d244b95bb4",
          "body": "…a to v0.37.2",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook python-jsonschema/check-jsonschem…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-10T04:55:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f0af17461e76dead7578adfb76e401901f9d746",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 2981696",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-09T12:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5417f2ceb488986a41269d567eb98d5e78a0d9c4",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 257c1f6",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-09T04:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a32b63809e205f1234272fc9acdcf8a7a642147",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 13605db",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-09T01:42:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8c71b8937973d24e84eb71b6ac521ed36df7367",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to efaccb5",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-07T20:28:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c7eb6c9bd25327a1873a98cea417e793622bd25",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 4039008",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-07T20:27:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ac880a63e003d353153b0230002cce7b83c1a0b",
          "body": "Co-authored-by: tbckr-automation[bot] <146582694+tbckr-automation[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 2.21.0 (#370)",
          "author_name": "tbckr-automation[bot]",
          "author_login": "tbckr-automation[bot]",
          "committed_at": "2026-05-05T12:18:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d29d3464496682bb94ec23c316aa9e1e81b39c01",
          "body": "Closes #355.\n\nSigned-off-by: SAY-5 <saiasish.cnp@gmail.com>\nCo-authored-by: SAY-5 <saiasish.cnp@gmail.com>",
          "is_bot": false,
          "headline": "feat(chat): create session files with 0600 owner-only permissions (#366)",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-05-05T12:15:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "262af0936bebf0e53393e40c3360378cc8b571f9",
          "body": "Closes #358.\n\nSigned-off-by: SAY-5 <saiasish.cnp@gmail.com>\nCo-authored-by: SAY-5 <saiasish.cnp@gmail.com>",
          "is_bot": false,
          "headline": "feat(config): validate OPENAI_API_BASE against SSRF risks (#367)",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-05-05T12:14:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "151bab9f8a130cf2e868ca5124dd77cab5f512d0",
          "body": "Closes #356.\n\nSigned-off-by: SAY-5 <saiasish.cnp@gmail.com>\nCo-authored-by: SAY-5 <saiasish.cnp@gmail.com>",
          "is_bot": false,
          "headline": "feat(stdin): cap input size to prevent unbounded memory growth (#368)",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-05-05T12:13:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "757d17378e9ff5821d62f552ea9f30ef2641b2f5",
          "body": "Closes #359.\n\nSigned-off-by: SAY-5 <say.apm35@gmail.com>",
          "is_bot": false,
          "headline": "feat(input): restrict --input file reads to safe roots (#369)",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-05-05T12:12:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdd85ade90643e614bb4943aa0147cb36ee3f9bb",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to b54cbf5",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-27T00:55:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b9620732ae1e004fcf2d2f59175dbb8e4e6505c",
          "body": "… 77d8b89",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-27T00:55:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68bd9729d3255aae849e8ee9aedf377823a34a97",
          "body": "Co-authored-by: tbckr-automation[bot] <146582694+tbckr-automation[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 2.20.0 (#364)",
          "author_name": "tbckr-automation[bot]",
          "author_login": "tbckr-automation[bot]",
          "committed_at": "2026-04-26T09:42:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3ba6ad0df0c675088d74cfafa535b85e7c35985",
          "body": "…dden commands (#365)\n\nSanitizeCommand explicitly preserved '\\n', and the sanitized\nstring was passed straight to `bash -c`. Because `bash -c`\ntreats newlines as command separators, a prompt-injected\nmulti-line LLM response like `ls\\nrm -rf ~` renders as two\napparently-harmless lines in the confirma\n[…]\nd_PreservesNewlineAndTab\nbecomes TestSanitizeCommand_PreservesTab (tab-only).\n\nSigned-off-by: SAY-5 <SAY-5@users.noreply.github.com>\n\nFixes #360\n\nCo-authored-by: SAY-5 <SAY-5@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(shell): reject multi-line LLM output so bash -c can't execute hi…",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-04-26T09:39:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61ceaaaae71b7774000137def07b82d4d47884bc",
          "body": "… bee469c",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-23T14:35:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b19cf95db08c3646c40d3f7d33b2ad3f5cc2d682",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 1e598ea",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-22T14:07:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "177a1cd755e32c2e9172ffcf27f19b87914c19d7",
          "body": "CreateClient built the OpenAI client's http.Client with a\nzero-value Timeout and a transport that only overrode Proxy, so a\nslow or unresponsive endpoint (e.g. an attacker-controlled\nOPENAI_API_BASE serving slowloris-style headers) would hang the\nsgpt process indefinitely. That's most painful in CI/\n[…]\nerTimeout is enough\nto short-circuit an endpoint that never produces headers.\n\nSigned-off-by: SAY-5 <SAY-5@users.noreply.github.com>\n\nFixes #357\n\nCo-authored-by: SAY-5 <SAY-5@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: give the OpenAI HTTP transport dial and header timeouts (#363)",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-04-21T06:50:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6dbbcc183210362253510aa49618e0c880e2947e",
          "body": "… 1f14279",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-20T19:32:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac7e0c4bfd6c6499d2f786c84fe4d5b1ff4fab7c",
          "body": "…361) (#362)\n\n* test: add SetAPIBase helper and pin httpmock URL in tests\n\nAdd testlib.SetAPIBase(t) that pins OPENAI_API_BASE to the URL\nhttpmock registers against. Call it in every test that activates\nhttpmock so tests pass regardless of the developer's shell env.\n\nPreviously, OPENAI_API_BASE=open\n[…]\n the Go bump\npropagates automatically. The Dockerfile's golang:1.26 base image\nalready satisfies the new minimum.\n\nCloses #361\n\n---------\n\nCo-authored-by: Tim <11543666+tbckr@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(deps): upgrade Go to 1.26.2 and add pymdown-extensions floor (#…",
          "author_name": "Stefan",
          "author_login": "zorak1103",
          "committed_at": "2026-04-20T09:24:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3cf7bf445ce92704682b07e0c1abc30d8415184",
          "body": "….13.10",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook commitizen-tools/commitizen to v4…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-18T08:59:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24c2c97be67f3561eaccb3e5be7736d580e5aab6",
          "body": "… 6d508f4",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-17T20:43:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0527ba39c90d697ebfe948f2758d5e85335b897",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 5f3787b",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-15T13:18:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ee08ae94727a817ea6120f2b446c49a7e84bb94",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update googleapis/release-please-action digest to 5c625bf",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-13T17:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f38f361a8029de8d5a223191b204ab75723067ed",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to fcdb3e4",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-12T13:01:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62871963b19e8c21e2c5d13e49f06a51179659c5",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update peter-evans/create-pull-request digest to 5f6978f",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-10T18:02:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9c964f79d24f56fd145261936ffacb64570e62b",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to ec4debb",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-08T01:14:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc6f8d6e20ff86d3a209f3bff27a5038f70eb26f",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to cd78d88",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-07T20:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d1d3464ed91c7ec2b2ca2f7ce751a5fbdb673b2",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 5e69504",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-07T09:30:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f0b2904f0cb487e75f9ca58b77b49b12a4eaefb",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 42ebbf7",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-07T05:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "208c529c1382b29c47f7495edbcbec7e3e1ccb92",
          "body": "…a to v0.37.1",
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook python-jsonschema/check-jsonschem…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-02T04:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "692f3a0a5c26e6e2bf0a1b588e97855af3e193e3",
          "body": "… d6d54da",
          "is_bot": true,
          "headline": "chore(deps): update cgr.dev/chainguard/static:latest docker digest to…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-02T01:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0829214065e21cba3f39373d298743cdf680f30",
          "body": "Ubuntu 20.04 LTS has been deprecated by Read the Docs.",
          "is_bot": false,
          "headline": "chore(docs): update Read the Docs build image to ubuntu-24.04",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-03-31T08:25:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a39a96deb393726845bbfe89d8d2a15eef39bd71",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update actions/setup-go digest to 4a36011",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-30T04:32:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ae71e8feeda484311e7b6f9da1f1fd18b11cb98",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update anchore/sbom-action action to v0.24.0",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-26T22:06:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d36894711098cc52056cd30e2b71b87b15a3b3aa",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update codecov/codecov-action digest to 75cd116",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-26T16:36:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b29a54114b77ed13b3222a2342695fa786c522b0",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 595c784",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-21T09:07:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98caf84782a1d64861240eb216c8a7f42ad23266",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update pre-commit hook gitleaks/gitleaks to v8.30.1",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-19T17:40:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bd4cb3f25b8c2ffa8f152e5ad0c9ff96b784ecd",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update codecov/codecov-action digest to 1af5884",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-18T21:56:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff28fb8dc7cc104edf1d466759c08df5b93ae20b",
          "body": null,
          "is_bot": true,
          "headline": "chore(docs): update TOC",
          "author_name": "tbckr-automation[bot]",
          "author_login": null,
          "committed_at": "2026-03-17T18:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "743ee2694f7f2077d10ab5022faa45598ce4709d",
          "body": null,
          "is_bot": false,
          "headline": "chore: update readme",
          "author_name": "Tim",
          "author_login": "tbckr",
          "committed_at": "2026-03-17T18:07:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d5f48f8f264f9213d9ad9c04ede2b26709b9395",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to c42e4d7",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-17T13:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd7431551f27bcd123a400c4f398e633dac904f3",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to dd25c49",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-17T08:47:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ef75a800eade802f349dba1083c813971ceae00",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to 318ba17",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-17T05:12:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f41f001b63ad8d3eb04638bb85e75554868387c8",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update anchore/sbom-action action to v0.23.1",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-16T21:57:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71c8f31ed294d057a48094faadbdcac12d02bcac",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update actions/create-github-app-token digest to fee1f7d",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-13T23:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ce3832de21f37211e7c6e0cd250b55b2e4cb277",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): update golang:1.26 docker digest to c7e98cc",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-11T06:32:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 61,
      "commits_last_year": 300,
      "latest_release_at": "2026-07-20T11:19:45Z",
      "latest_release_tag": "v2.21.2",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 50,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 21.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/tbckr/sgpt/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/tbckr/sgpt/v2",
          "is_deprecated": false,
          "latest_version": "v2.21.2",
          "repository_url": "https://github.com/tbckr/sgpt",
          "versions_count": 40,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T11:19:25Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 36,
      "stars": 457,
      "watchers": 4,
      "fork_history": {
        "days": [
          {
            "date": "2023-05-26",
            "count": 1
          },
          {
            "date": "2023-06-30",
            "count": 1
          },
          {
            "date": "2023-07-02",
            "count": 1
          },
          {
            "date": "2023-09-29",
            "count": 1
          },
          {
            "date": "2023-10-01",
            "count": 1
          },
          {
            "date": "2023-11-10",
            "count": 1
          },
          {
            "date": "2023-11-17",
            "count": 1
          },
          {
            "date": "2023-11-20",
            "count": 1
          },
          {
            "date": "2023-11-27",
            "count": 1
          },
          {
            "date": "2023-12-23",
            "count": 1
          },
          {
            "date": "2023-12-30",
            "count": 1
          },
          {
            "date": "2024-01-01",
            "count": 1
          },
          {
            "date": "2024-01-15",
            "count": 1
          },
          {
            "date": "2024-01-22",
            "count": 1
          },
          {
            "date": "2024-02-26",
            "count": 1
          },
          {
            "date": "2024-02-28",
            "count": 1
          },
          {
            "date": "2024-05-10",
            "count": 1
          },
          {
            "date": "2024-05-27",
            "count": 1
          },
          {
            "date": "2024-09-07",
            "count": 1
          },
          {
            "date": "2024-09-22",
            "count": 1
          },
          {
            "date": "2024-10-25",
            "count": 1
          },
          {
            "date": "2024-11-23",
            "count": 1
          },
          {
            "date": "2024-12-16",
            "count": 1
          },
          {
            "date": "2024-12-19",
            "count": 1
          },
          {
            "date": "2024-12-23",
            "count": 1
          },
          {
            "date": "2024-12-30",
            "count": 1
          },
          {
            "date": "2025-01-11",
            "count": 1
          },
          {
            "date": "2025-02-24",
            "count": 1
          },
          {
            "date": "2025-03-15",
            "count": 1
          },
          {
            "date": "2026-02-08",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-19",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 33,
        "total_forks": 36
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Taskfile.yml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 123307,
      "source_files_sampled": 38,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "docs/usage/gemini.md"
      ],
      "agent_instruction_max_bytes": 2249
    },
    "dependencies": {
      "manifests": [
        "docs/requirements.txt",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.29.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5024"
            ],
            "fixed_version": "0.44.0",
            "advisory_count": 1,
            "oldest_advisory_days": 67
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.28.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 2
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 26,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 3,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "github.com/atotto/clipboard",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/jarcoal/httpmock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.1"
        },
        {
          "name": "github.com/muesli/mango-cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/muesli/roff",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.0"
        },
        {
          "name": "github.com/sashabaranov/go-openai",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.41.2"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/atotto/clipboard",
            "direct": true,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jarcoal/httpmock",
            "direct": true,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/mango-cobra",
            "direct": true,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/roff",
            "direct": true,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sashabaranov/go-openai",
            "direct": true,
            "version": "v1.41.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": true,
            "version": "v1.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/mango",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/mango-pflag",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/locafero",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/conc",
            "direct": false,
            "version": "v0.3.1-0.20240121214520-5f936abd7ae8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.29.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.28.0",
            "ecosystem": "go"
          },
          {
            "name": "mkdocs",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mkdocs-material",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pymdown-extensions",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 29,
        "direct_count": 9,
        "indirect_count": 20
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 309,
        "open_issues": 1,
        "closed_ratio": 0.985,
        "closed_issues": 66,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 4,
      "top_contributors": [
        {
          "type": "User",
          "login": "tbckr",
          "commits": 455,
          "avatar_url": "https://avatars.githubusercontent.com/u/11543666?v=4"
        },
        {
          "type": "User",
          "login": "zorak1103",
          "commits": 11,
          "avatar_url": "https://avatars.githubusercontent.com/u/11332205?v=4"
        },
        {
          "type": "User",
          "login": "SAY-5",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/240962040?v=4"
        },
        {
          "type": "User",
          "login": "juantarrel",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/7213379?v=4"
        },
        {
          "type": "User",
          "login": "bodoque-01",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/63447579?v=4"
        },
        {
          "type": "User",
          "login": "Thibaultjaigu",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/84420566?v=4"
        }
      ],
      "contributors_sampled": 6,
      "top_contributor_share": 0.958
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "depsreview.yml",
        "gitleaks.yml",
        "milestone.yml",
        "oss-licenses.yml",
        "release.yml",
        "toc.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 3/29 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "5 out of the last 5 releases have a total of 5 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3a79f0d6b02f9699b83236416de0ecc3fee42694",
        "ran_at": "2026-07-29T01:05:01Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-28T06:34:13Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-20T11:44:19Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 3,
          "created_at": "2023-02-26T15:41:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/tbckr/sgpt",
    "host": "github.com",
    "name": "sgpt",
    "owner": "tbckr"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 80,
      "inputs": {
        "security": 77,
        "vitality": 99,
        "community": 74,
        "governance": 60,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 99,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 300,
              "human_commit_share": 0.21,
              "days_since_last_push": 2,
              "active_weeks_last_year": 50
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "50/52 weeks with commits",
                "points": 34.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 50
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "300 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 300
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 61,
              "latest_release_tag": "v2.21.2",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 21.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "61 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 61
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~21.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 21.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 8,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 8 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 74,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "forks": 36,
              "stars": 457,
              "watchers": 4,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "457 stars",
                "points": 43.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 457
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "36 forks",
                "points": 12.9,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 36
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "4 watchers",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 6,
              "top_contributor_share": 0.958
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 96% of commits",
                "points": 0.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 96
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "6 contributors",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "merged_prs": 309,
              "open_issues": 1,
              "closed_issues": 66,
              "issue_closed_ratio": 0.985,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "98% of issues closed",
                "points": 46,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "309/317 decided PRs merged",
                "points": 37.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 309,
                      "decided": 317
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 3/29 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 54,
            "inputs": {
              "followers": 48,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "tbckr",
              "public_repos": 14,
              "account_age_days": 4150
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "48 followers of tbckr",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 48,
                      "login": "tbckr"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "14 public repos, account ~11 yr old",
                "points": 20.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 14
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/tbckr/sgpt/v2"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "40 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 40
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "cli",
                "bash",
                "gpt-3",
                "gpt-4",
                "openai",
                "shell",
                "go",
                "gpt-4-vision",
                "gpt-4-vision-preview",
                "gpt-4o",
                "o1-mini",
                "o1-preview",
                "anthropic",
                "anthropic-claude",
                "gemini",
                "gemini-api",
                "gemini-pro",
                "openrouter",
                "openrouter-api"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "19 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 3/29 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 26 resolved dependencies against OSV; 3 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 26
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 3
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 26,
              "unassessed_packages": 3,
              "affected_by_severity": "unknown 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 26,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 89,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "docs/usage/gemini.md"
              ],
              "agent_instruction_max_bytes": 2249
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "docs/usage/gemini.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/usage/gemini.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "21 of 21 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 21,
                      "sampled": 21
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Taskfile.yml"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.74
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Taskfile.yml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Taskfile.yml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "74 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 74,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 123307,
              "source_files_sampled": 38,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/38 source files over 60KB",
                "points": 53.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 38,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T01:05:15.320747Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tbckr/sgpt.svg",
  "full_name": "tbckr/sgpt",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.