Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-23 16:04 UTC

trezor / trezor-mcu

:lock: Don't use this repo, use the new monorepo instead:

CLGPL-3.0★ 312 Sterne⑂ 249 Forksseit Nov. 2012archiviertAuf GitHub ansehen ↗

trezor/trezor-mcu erreicht einen Gesundheitsindex von 17 von 100 und liegt damit im Bereich Kritisch. Am stärksten schneidet es bei Community & Adoption (67/100) ab, am schwächsten bei Vitality (17/100). Das Repository ist archiviert, weitere Wartung ist daher nicht zu erwarten.

17
gesamt / 100
Kritisch

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

17
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Abandonment Policy applies a 40% multiplier to weighted overall health and gives it a ceiling of 29.

Eigentümerschaft

TrezorOrganisation
1.245 Follower67 öffentliche Reposseit Apr. 2013

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

17Kritisch · 22 % des Gesamtindex
Wie die Bewertung erfolgt
0/36Push-Aktualität — letzter Push vor 2.661 Tagen
0/36Commit-Rhythmus — 0/52 Wochen mit Commits
0/18Commit-Volumen — 0 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project is archived
Verwendete Eingangsdaten
commits_last_year0
human_commit_share1
days_since_last_push2.661
active_weeks_last_year0

Release-Disziplin

40Gefährdet
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 26 Versions-Tags (keine GitHub-Releases)
0/36Release-Aktualität — letztes Release vor 2.705 Tagen
19.8/27Release-Rhythmus — ein Release etwa alle 61,9 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count26
latest_release_tagv1.8.0
releases_from_tagsja
days_since_latest_release2.705
mean_days_between_releases61,9
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

67Mittel · 18 % des Gesamtindex
Wie die Bewertung erfolgt
40.4/60Stars — 312 Stars
20/25Forks — 249 Forks
3.9/15Watcher — 6 Watcher
Verwendete Eingangsdaten
forks249
stars312
watchers6
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (LGPL-3.0)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

62Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
8.4/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 63 % der Commits
13.5/13.5Breite der Beitragenden — 33 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 25 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled33
top_contributor_share0,628
Wie die Bewertung erfolgt
46.8/46.8Issue-Lösungsquote — 100 % der Issues geschlossen
26.4/38.3PR-Annahme — 177/256 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 2/25 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs177
open_issues0
closed_issues202
issue_closed_ratio1
closed_unmerged_prs79
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
22.3/25Reichweite des Inhabers — 1.245 Follower von trezor
25/25Kontohistorie — 67 öffentliche Repos, Kontoalter ca. 13 Jahre
Verwendete Eingangsdaten
followers1.245
owner_typeOrganization
is_verified
owner_logintrezor
public_repos67
account_age_days4.849

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

27Kritisch · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
0/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
Verwendete Eingangsdaten
has_cinein
has_testsnein
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://github.com/trezor/trezor-firmware
10/10Repository-Beschreibung
10/10Topics — 7 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsbitcoin, trezor, hardware, wallet, open-source, embedded, arm
has_wikinein
homepagehttps://github.com/trezor/trezor-firmware
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

41Gefährdet · 16 % des Gesamtindex

Sicherheitslage

26Kritisch
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
0/2.5CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 2/25 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 25 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project is archived
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
0/7.5Vulnerabilities — 35 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate2,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection, dangerous_workflow, packaging, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories67
affected_packages10
assessed_packages25
unassessed_packages1
affected_by_severitycritical 1, high 8, moderate 1
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories, Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. 25 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. 1 konnten nicht bewertet werden — keine aufgelöste Version, ein nicht unterstütztes Ökosystem oder außerhalb der ausgewiesenen Paketliste. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

49Gefährdet · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 76 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,76
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile, bootloader/Makefile, demo/Makefile, emulator/Makefile, firmware/Makefile, firmware/protob/Makefile, gen/Makefile
0/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — C (statisch typisiert)
10/10Reproduzierbare Umgebung — Dockerfile, Nix, lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixja
has_testsnein
lockfilesPipfile.lock
has_dockerfileja
typed_languageja
bootstrap_filesMakefile, bootloader/Makefile, demo/Makefile, emulator/Makefile, firmware/Makefile, firmware/protob/Makefile, gen/Makefile
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — C (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/129 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageC
largest_source_bytes59.319
source_files_sampled129
oversized_source_files0
Wie die Bewertung erfolgt
40/40API-Schema (OpenAPI/GraphQL/proto) — firmware/protob/messages-bitcoin.proto, firmware/protob/messages-common.proto, firmware/protob/messages-crypto.proto, firmware/protob/messages-debug.proto, firmware/protob/messages-ethereum.proto, firmware/protob/messages-lisk.proto, firmware/protob/messages-management.proto, firmware/protob/messages-nem.proto, firmware/protob/messages-stellar.proto, firmware/protob/messages.proto
0/20MCP-Server
0/40Lauffähige Beispiele
Verwendete Eingangsdaten
example_dirs
has_mcp_signalnein
api_schema_filesfirmware/protob/messages-bitcoin.proto, firmware/protob/messages-common.proto, firmware/protob/messages-crypto.proto, firmware/protob/messages-debug.proto, firmware/protob/messages-ethereum.proto, firmware/protob/messages-lisk.proto, firmware/protob/messages-management.proto, firmware/protob/messages-nem.proto, firmware/protob/messages-stellar.proto, firmware/protob/messages.proto

Eckdaten

312GitHub-Sterne
33Mitwirkende
0Commits, letzte 12 Monate
2.661Tage seit letztem Push
26Releases
1Bus-Faktor
0offene Issues
PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 249 ⇿
0Sterne
249Forks
22Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

0408012016020024020762014-092019-122025-03
Major 0Minor 6Patch 16

Jeder Punkt umfasst 10 Tage.

OpenSSF Scorecard 2.6 / 10
2.6Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-23 16:03 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
0CI-Tests0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 2/25 approved changesets -- score normalized to 0
10Contributorsproject has 25 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject is archived
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
0Vulnerabilities35 existing vulnerabilities detected
Alle Abhängigkeiten 26

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 0 direkte und 26 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
PyPIatomicwrites1.1.5indirekt
PyPIattrs18.1.0indirekt
PyPIcertifi2018.4.16indirekt
PyPIchardet3.0.4indirekt
PyPIclick6.7indirekt
PyPIecdsa0.13indirekt
PyPIidna2.7indirekt
PyPIlibusb11.6.5indirekt
PyPImako1.0.7indirekt
PyPImarkupsafe1.0indirekt
PyPImnemonic0.18indirekt
PyPImock2.0.0indirekt
PyPImore-itertools4.2.0indirekt
PyPImunch2.3.2indirekt
PyPIpbkdf21.3indirekt
PyPIpbr4.2.0indirekt
PyPIpluggy0.7.1indirekt
PyPIprotobuf3.4.0indirekt
PyPIpy1.5.4indirekt
PyPIpyblake21.1.2indirekt
PyPIpytest3.6.4indirekt
PyPIrequests2.19.1indirekt
PyPIsix1.11.0indirekt
PyPItrezorindirekt
PyPItyping3.6.4indirekt
PyPIurllib31.23indirekt
Abhängigkeits-Advisories 10

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 25 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 10 tragen bekannte Advisories, davon 0 direkte. 1 konnten nicht bewertet werden – keine aufgelöste Version, ein nicht unterstütztes Ökosystem, oder außerhalb der ausgewiesenen Paketliste.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
ecdsa0.13indirektkritisch80.19.2
certifi2018.4.16indirekthoch52024.7.4
click6.7indirekthoch18.3.3
idna2.7indirekthoch43.15
mako1.0.7indirekthoch61.3.12
protobuf3.4.0indirekthoch76.33.5
py1.5.4indirekthoch21.10.0
requests2.19.1indirekthoch102.33.0
urllib31.23indirekthoch222.7.0
pytest3.6.4indirektmittel29.0.3

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "bitcoin",
        "trezor",
        "hardware",
        "wallet",
        "open-source",
        "embedded",
        "arm"
      ],
      "is_fork": false,
      "size_kb": 2877,
      "has_wiki": false,
      "homepage": "https://github.com/trezor/trezor-firmware",
      "languages": {
        "C": 721273,
        "C++": 19717,
        "Nix": 273,
        "Mako": 5280,
        "Perl": 3143,
        "Shell": 8191,
        "Python": 18894,
        "Assembly": 3340,
        "Makefile": 6675,
        "Dockerfile": 2569
      },
      "pushed_at": "2019-04-10T14:58:17Z",
      "created_at": "2012-11-16T11:43:26Z",
      "owner_type": "Organization",
      "updated_at": "2026-06-20T15:56:51Z",
      "description": ":lock: Don't use this repo, use the new monorepo instead:",
      "is_archived": true,
      "is_disabled": false,
      "license_spdx": "LGPL-3.0",
      "default_branch": "master",
      "license_spdx_raw": "LGPL-3.0",
      "primary_language": "C",
      "significant_languages": [
        "C"
      ]
    },
    "owner": {
      "blog": "https://trezor.io",
      "name": "Trezor",
      "type": "Organization",
      "login": "trezor",
      "company": null,
      "location": "Prague, Czech Republic",
      "followers": 1245,
      "avatar_url": "https://avatars.githubusercontent.com/u/4146447?v=4",
      "created_at": "2013-04-13T15:41:29Z",
      "is_verified": null,
      "public_repos": 67,
      "account_age_days": 4849
    },
    "license": {
      "state": "standard",
      "spdx_id": "LGPL-3.0",
      "raw_spdx": "LGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2019-02-24T16:42:01Z"
        },
        {
          "tag": "v1.7.3",
          "kind": "patch",
          "published_at": "2018-12-19T17:10:41Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2018-12-17T22:18:02Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2018-10-25T09:57:56Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2018-09-04T16:24:41Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2018-08-27T15:47:14Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2018-06-22T13:26:14Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2018-03-20T14:44:20Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2017-11-16T19:03:26Z"
        },
        {
          "tag": "v1.5.2",
          "kind": "patch",
          "published_at": "2017-08-16T12:28:21Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2017-07-31T20:43:28Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2017-05-19T15:41:10Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2017-01-25T13:04:20Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2016-10-26T16:06:13Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2016-08-31T12:02:53Z"
        },
        {
          "tag": "v1.3.6",
          "kind": "patch",
          "published_at": "2016-06-07T13:27:05Z"
        },
        {
          "tag": "v1.3.5",
          "kind": "patch",
          "published_at": "2016-02-15T14:29:19Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2015-08-03T22:45:59Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2015-04-02T15:47:28Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2015-03-21T09:44:30Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2015-02-16T14:23:30Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2014-12-27T15:05:34Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2014-07-31T17:44:03Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2014-07-02T23:20:34Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2014-06-11T18:42:48Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2014-04-29T12:38:32Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "8af1f3643651e1cbee6b6196401f9c63e7cfc0f9",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-common",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-04-10T14:58:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da95537e345b806b2ef6e811c6dd7ecfb94bad86",
          "body": null,
          "is_bot": false,
          "headline": "omni: add space before symbol",
          "author_name": "matejcik",
          "author_login": "matejcik",
          "committed_at": "2019-04-09T12:26:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa7095add98bb1dafa2c41059508063e6e0733eb",
          "body": null,
          "is_bot": false,
          "headline": "omni: parse data as big-endian",
          "author_name": "matejcik",
          "author_login": "matejcik",
          "committed_at": "2019-04-09T12:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc73e54d443b296290968b41177274028022d670",
          "body": null,
          "is_bot": false,
          "headline": "vendor/libopencm3: update to latest snapshot",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-04-01T15:04:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "622966383c3394209219d350c95c17dfa0dd2d61",
          "body": null,
          "is_bot": false,
          "headline": "vendor/nanopb: update to 0.3.9.3",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-04-01T14:41:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac5e3268f7591d48f0c5631898b04e136dc81e8a",
          "body": null,
          "is_bot": false,
          "headline": "firmware: fix unaligned access",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-04-01T13:31:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d37dd850d5188048df0f02dd4e6a1f4435f3687",
          "body": null,
          "is_bot": false,
          "headline": "supervise: fix last commit",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-03-29T16:20:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eba242b80690e702eb1be9aa570c42c2fa5def87",
          "body": null,
          "is_bot": false,
          "headline": "format: start using clang-format with style=Google",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-03-29T16:11:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1bc0ebc402b2b60ce72b6a774959525bcd0e0f0",
          "body": "usb: Fix segfault in usbSleep().",
          "is_bot": false,
          "headline": "Merge pull request #464 from andrewkozlik/master",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-03-14T13:43:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6d6416b50bae8544a4294ba12416cdd381c8412",
          "body": "…USB is not initialized.",
          "is_bot": false,
          "headline": "usb: Avoid segfault in usbSleep(), usbReconnect() and usbPoll() when …",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-03-13T18:21:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1dada5a6fdf8ae92d505ed7c250d621c2695a2cf",
          "body": "Return mnemonic as bytes",
          "is_bot": false,
          "headline": "Merge pull request #463 from trezor/tsusanka/mnemonic-bytes",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-03-13T11:38:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2646c0901c6fc0bb0b03320153997deaab4ce4f6",
          "body": null,
          "is_bot": false,
          "headline": "firmware: return mnemonic as bytes in debug link",
          "author_name": "Tomas Susanka",
          "author_login": "tsusanka",
          "committed_at": "2019-03-12T14:25:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57423c9f542a5fee83a044d540b0d0d6f803f29f",
          "body": "The field has been changed to optional in\nhttps://github.com/trezor/trezor-common/commit/84f5a0e39376409863c58a9ede1b61403306894b\n.",
          "is_bot": false,
          "headline": "firmware: set bitcoin's has_node",
          "author_name": "Tomas Susanka",
          "author_login": "tsusanka",
          "committed_at": "2019-03-12T14:25:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4668bedb4e6a649fba78588468748b2a11f06dc",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-common",
          "author_name": "Tomas Susanka",
          "author_login": "tsusanka",
          "committed_at": "2019-03-12T14:25:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbde3f4fdbf528cb6502dd71f09990b6b0c71083",
          "body": null,
          "is_bot": false,
          "headline": "firmware: refactor U2F known apps, add WebAuthn entries",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-03-09T17:24:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "358ea93e80a8c4dfe26501e702c578b3c54cc6fa",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'secfix'",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-03-06T16:31:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f40219dbb609ed468aa74db25d1295fed826e547",
          "body": null,
          "is_bot": false,
          "headline": "fsm: correctly set node in EthereumPublicKey response",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-28T15:38:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b65f61650a8249c4af3c85e8f6b74e699d69bfbd",
          "body": "…Callback() may be called.",
          "is_bot": false,
          "headline": "config: Set usbTiny whenever there is a possibility that protectPinUi…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-25T12:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b457797c555d1bc1a0620d8eae5f27354b4dbf20",
          "body": null,
          "is_bot": false,
          "headline": "changelog: update",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-25T11:44:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "964a622bb512aa85cfcc3e451fc70729cc15bb4f",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: fix typo",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-24T16:42:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "222c9ea46c7574cb52d4713c481438a32b85e692",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: compatibility with old bootloaders",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-24T13:01:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7baa8c29fc8c306d577e88a7b0013d3b7d608bca",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: move timer_init to jump_to_firmware",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-24T11:24:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cda903a1d08cdbf1b6fe9dfc2be3685525536e3",
          "body": null,
          "is_bot": false,
          "headline": "setup: change mpu definition for bootloader, fix typo",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-23T19:47:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91d9bd28c2b70ca0beeb3e5e46e562a49c417487",
          "body": null,
          "is_bot": false,
          "headline": "build: don't try to sign emulator build",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-23T18:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f05664fdf30239f1715bb081e14c2f30d7a10ee7",
          "body": null,
          "is_bot": false,
          "headline": "config: Avoid unlocking storage after wipe.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-23T16:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b62ab43b952d902a63998d0cd9b554a336ee7c7e",
          "body": null,
          "is_bot": false,
          "headline": "config: Avoid wiping storage twice.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-23T16:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db47ff4e515bcd3c28abffa955393a8743744e88",
          "body": "…ith improved ui_callback() reporting.",
          "is_bot": false,
          "headline": "config: Auto-unlock storage if no PIN is set. Update trezor-storage w…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-23T16:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2482e111126821273cf4a6782305dddd3fbdc5e3",
          "body": null,
          "is_bot": false,
          "headline": "protect: check old PIN before requesting new PIN",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-23T16:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae0395f0f417f1e4c72a924e3ac0e1d948613f77",
          "body": null,
          "is_bot": false,
          "headline": "protect: Update protectPinUiCallback() to show arbitrary message.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-23T16:55:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "806f943116f4df8a666b6bd7182bfcbe5cf3c13a",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: require only left button to start the bootloader",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-22T14:47:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99c6777c7c45fa02230fe6590c423313f3340bb5",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-storage",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-22T12:47:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7a9eab4454e2f3756ca4bb0d42028c0691412df",
          "body": null,
          "is_bot": false,
          "headline": "config: Fix pointer arithmetic in config_upgrade_v10().",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-22T12:45:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "276cd4b44addf6fc1295c1d0823530c3f4904a8b",
          "body": null,
          "is_bot": false,
          "headline": "firmware: set NORCOW_HEADER_LEN to 0",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T19:40:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08b462b2b94d6b4c907a0a3be08a8f0df40ccc3c",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-storage",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T16:42:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80840b23212bc87254bba2bc1e2c7fd6089be0cb",
          "body": null,
          "is_bot": false,
          "headline": "firmware: change bootloader 1.8.0 hash in the whitelist",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T16:24:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "400ac968730e94d2868e4f54058e7e4ff1e1d33d",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: refactor to save space",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T16:12:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07231d936e41335b3ec44c4c6eb336be006890d0",
          "body": "firmware header is now stored with code, not within the storage sectors",
          "is_bot": false,
          "headline": "introduce new memory layout",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T14:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe39d10211c53f81379b5cfd0f565e97cf94b27b",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-storage",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T13:51:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b26e90daf986a21fc25eb2432c84b41ecfd23a82",
          "body": null,
          "is_bot": false,
          "headline": "firmware: add bootloader 1.8.0 to whitelist",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T13:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9841c29e4b7c280f71b719a93d54be27af37e4d",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-crypto",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T11:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22f37e81a3270da5e8e5d6c55abc8f15f3a35567",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: enable MPU, introduce delays to USB stack",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-21T08:06:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f5c96926cef227e83aba211efa5838bef3413e3",
          "body": null,
          "is_bot": false,
          "headline": "firmware/u2f: memzero the readbuffer",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-20T19:34:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7492cf07fc96e830ff69c9af470add8e78abe42a",
          "body": null,
          "is_bot": false,
          "headline": "firmware: fix buffer size in address_n_str",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-20T19:34:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd46339f5cc2971cd202697503c81a04d4b402f3",
          "body": null,
          "is_bot": false,
          "headline": "ethereum: clear local variables in layoutEthereumFee",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-20T19:34:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7af39bf8dab11816ef977527c976ddc54f1d32e",
          "body": null,
          "is_bot": false,
          "headline": "use shutdown from startup.s",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-20T07:52:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44bb5864d42e95bb5c15a351f21792df83f4fc61",
          "body": null,
          "is_bot": false,
          "headline": "fix whitespace",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-19T17:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a00c7f9720762cabdcfd7995bfbe8669ae1304e8",
          "body": null,
          "is_bot": false,
          "headline": "mpu: rename mpu_config to mpu_config_firmware",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-19T16:52:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e82f275536ec85c83eec25f6860134de6093857",
          "body": null,
          "is_bot": false,
          "headline": "protect: make waiting UI more sexy",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-19T14:32:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d95112ba052a371336cfa3dc7f5a7598a96d8a5d",
          "body": "+ update trezor-storage",
          "is_bot": false,
          "headline": "firmware/protect: show progressbar in verifying pin dialog",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-18T18:58:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c58c265d9c9c7845b3f62b2089d1c9b356dfd49f",
          "body": "…onics, to mitigate side-channel attacks.",
          "is_bot": false,
          "headline": "config: Check mnemonic by comparing hashes instead of the actual mnem…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-18T17:45:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "827df268a6b60008bf6466634827a0e96c825469",
          "body": null,
          "is_bot": false,
          "headline": "firmware: fix unused argument in collect_hw_entropy",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-18T17:24:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "540be4989729d93fb2e40a86865962fbff28e535",
          "body": null,
          "is_bot": false,
          "headline": "firmware: use OTP block 3 for storing randomness",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-18T16:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "402e7c4ec633ed18810ebfb0af3cad42e03d867c",
          "body": null,
          "is_bot": false,
          "headline": "firmware: fix undefined symbol in emulator",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-17T23:54:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07d2994d0ccbb5e86a4467f0c90e0da7bb4ed38e",
          "body": "The submodule does not contain .gitignore and we produce .d and .o\nfiles in their directory :-/",
          "is_bot": false,
          "headline": "vendor: add ignore=untracked to QR code generator submodule",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-17T18:16:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79e9ae28b78b39f61a7190f524f92683aa684a9f",
          "body": null,
          "is_bot": false,
          "headline": "vendor: replace vendor/trezor-qrenc with vendor/QR-Code-generator",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-16T16:21:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92382d3f2cfab28ff37e6bcf638350c32e450825",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'trezor-storage-integration'",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-15T14:52:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67c0f8b8a1e03047adfda73dacbe85cbae099f34",
          "body": null,
          "is_bot": false,
          "headline": "storage: use fixed hw_entropy in unprivileged mode",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a9c537afdf940c809b46cf660afafc16e559284",
          "body": null,
          "is_bot": false,
          "headline": "vendor: update trezor-storage",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5230a0f8468176862025ece3894997562b3b7f6a",
          "body": null,
          "is_bot": false,
          "headline": "config: Do not lock storage after completing loadDevice().",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4c0b59c8973298e55ca22c1a69a7399a7abb8c4",
          "body": "…ckup, unfinished_backup and no_backup, even if the value is not available in storage.",
          "is_bot": false,
          "headline": "msg: GetFeatures should always return passphrase_protection, needs_ba…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e18a489a817c2b1079b34163204d2a04c3bcab",
          "body": null,
          "is_bot": false,
          "headline": "Update trezor-storage.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55bc3c74302dcd06c9908614d4d88f50b8d78cd2",
          "body": "…. Bump config version.",
          "is_bot": false,
          "headline": "config: Check metadata magic before upgrading storage from version 10…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b79d0e59687cb4ce9d98d30f830e41c5df3e9f7",
          "body": null,
          "is_bot": false,
          "headline": "config: Store cleartext PIN for DEBUG_LINK.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b66c7540c1f0feec2ed531e12e6babb92bb95d3",
          "body": "…de(). Since mnemonic and node are protected entries, these functions would always return false when storage is locked. We now instead use the INITIALIZED flag which is public.",
          "is_bot": false,
          "headline": "config: Remove unused functions config_hasMnemonic() and config_hasNo…",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45193ffc1dd3813ad036b769b7d8743b6af5c9e7",
          "body": null,
          "is_bot": false,
          "headline": "config: Use secbool instead of bool at least internally.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc848be167b183562c2a268df648f8c0087c73a8",
          "body": null,
          "is_bot": false,
          "headline": "config: Cache auto-lock delay.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e48a1a39a481b67463ab3233f683f24787d2e7d",
          "body": null,
          "is_bot": false,
          "headline": "Fix spaces/tabs so that a single convention is used in each file.",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8502ee61a365ac8f5479a4689abf8950e74bca03",
          "body": "…your device'.",
          "is_bot": false,
          "headline": "Upon fatal error display 'Contact TREZOR support' instead of 'Unplug …",
          "author_name": "Andrew Kozlik",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f9010824da41ce01d7dd1b514acd865fbd90add",
          "body": null,
          "is_bot": false,
          "headline": "config: Erase HW_ENTROPY_DATA when no longer needed.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "faa0664b625cf75e99bcc4e070be5f4d3525a3fe",
          "body": null,
          "is_bot": false,
          "headline": "config: Use efficient implementation of U2F counter from trezor-storage.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c05a2da12e4fc7115c6a3e38cfc00cf4f38281c",
          "body": null,
          "is_bot": false,
          "headline": "Fix rebase.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05f3b74b65e8605c8d704f284d4430a86fc0251e",
          "body": null,
          "is_bot": false,
          "headline": "Fix rebase.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae48b528a9497f6b5e877720ae5f68438bd1dfaf",
          "body": "…GetFeatures to always return pin_cached=false if PIN is not set, in order to maintain the same behavior as before.",
          "is_bot": false,
          "headline": "config: Rename session_isPinCached() to session_isUnlocked(). Change …",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66ffa4c7dc1010392fdeabee7c22234016e82abe",
          "body": null,
          "is_bot": false,
          "headline": "config: Add hardware entropy to storage_init().",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c592a09459050281cbf9e30c57488cfed92b8f05",
          "body": "…the PIN_UI_WAIT_CALLBACK.",
          "is_bot": false,
          "headline": "protect.c: Display 'Verifying PIN' instead of 'Wrong PIN entered' in …",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b0f5e031d7344ebc27448a58613e4ee745c4764",
          "body": "…eration.",
          "is_bot": false,
          "headline": "config: Change config_get*() functions to return status of the get op…",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d4fb5556196c688713b49e69d9791a819663985",
          "body": null,
          "is_bot": false,
          "headline": "Improve __fatal_error() layout.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03e9ea4f5cd7f216e2c27da3e3acb6b0947a2e35",
          "body": "…messages.",
          "is_bot": false,
          "headline": "Support interruption of the PIN wait dialog by Cancel and Initialize …",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e49e84ea5a95b4801b6211c37cbdabca09ff1019",
          "body": "…dd KEY_INITIALIZED. Add CHECK_PIN to fsm_msgApplyFlags() and to other fsm_msg functions in order to unlock storage. Improve error handling in reset.c and recovery.c.",
          "is_bot": false,
          "headline": "Reorder storage keys in config.c to correspond with trezor-core and a…",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "247337c63d587b7bc08490d0ce6227e0f8dc9539",
          "body": "…ay '0 seconds' when wait is 0.",
          "is_bot": false,
          "headline": "Do not lock after wipe. Fix protectPinUiCallback() to correctly displ…",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d433401311807305fde7a1fdf4aa6787e99941c8",
          "body": null,
          "is_bot": false,
          "headline": "Update trezor-storage.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7fcf9b036f648e30fcd71e88187e98986794458",
          "body": null,
          "is_bot": false,
          "headline": "Fix key constant in config_setLanguage(). Update trezor-storage.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "679174ea7a26243765b3e795088866183e965de7",
          "body": "…K build.",
          "is_bot": false,
          "headline": "Fix separated backup. Fix forgotten config_getMnemonic() in DEBUG_LIN…",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "681137c2eff61fdce56b95714e5ca26b702d5a19",
          "body": null,
          "is_bot": false,
          "headline": "Unlock for testing.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8932205cec416d6fa3ee2a1a5b911b47d0ed939",
          "body": null,
          "is_bot": false,
          "headline": "Update trezor-storage.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d970597ddd41f41fa7cb0e68c76b260f2cf70e3e",
          "body": null,
          "is_bot": false,
          "headline": "Fix emulator memory access.",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f32cb508383ec0e65843d037f6ac6473a668359",
          "body": null,
          "is_bot": false,
          "headline": "firmware: integrate trezor-storage",
          "author_name": "andrew",
          "author_login": "andrewkozlik",
          "committed_at": "2019-02-15T14:12:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5137f4ec00fa9c0ad506078859ce7e854a50de90",
          "body": null,
          "is_bot": false,
          "headline": "firmware: bump version to 1.8.0",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-15T13:25:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bc37c6b8227d0c49fc52c883fc5bb9c59d6969b",
          "body": null,
          "is_bot": false,
          "headline": "signing: add default values for branch_id (zcash)",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-15T00:44:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26f9b5ba8106f504fcc77aa80c6152b245e5e958",
          "body": null,
          "is_bot": false,
          "headline": "flash: unify lock/unlock sequences",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-10T12:22:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c609d10c3f465cbb7ced91b45935dfd4b265e2b1",
          "body": null,
          "is_bot": false,
          "headline": "util: readprotobufint uses const argument",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-10T12:22:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7288d056a16d25c30d774985d347f130623cb958",
          "body": null,
          "is_bot": false,
          "headline": "util: readprotobufint uses const argument",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-10T12:17:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ab3eee37d97437f230972ca52935ed15c644e22",
          "body": null,
          "is_bot": false,
          "headline": "bootloader: make code smaller by changing the send_msg logic",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-10T12:08:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11311da48a453e451e4bf6b79c835d598bf0f2ad",
          "body": null,
          "is_bot": false,
          "headline": "fsm: input messages are no longer confidential",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-04T13:25:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19c7c8bc3b76a9489b9a5cce5d9b69d60b1f20cb",
          "body": "If address_n is the same for all nodes in the multisig, provide it just once\nand supply nodes directly (not in the HDNodePathType structure)",
          "is_bot": false,
          "headline": "signing: implemented simplified API for MultisigRedeemScriptType",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-04T12:53:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9ba64ea94bba28bb041a9e1aec5c27dd3ec64e5",
          "body": null,
          "is_bot": false,
          "headline": "messages: introduce messages_map_limits",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-04T12:53:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7c32248bda3b9e03c74bcaf93e340f5794557f8",
          "body": null,
          "is_bot": false,
          "headline": "reset: commit to storage unconditionally at the end of backup procedure",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-02-01T14:17:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a4e8013f10faabc7792c93303f969a468222eb8",
          "body": null,
          "is_bot": false,
          "headline": "firmware: process tx.branch_id (zcash)",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-01-31T20:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e3d0a0a77eabd1fab983edacf3b7cffeaeada41",
          "body": null,
          "is_bot": false,
          "headline": "signing: use the new hasher_InitParam API",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-01-31T18:20:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77a6718f7656c8aa19ebe4855cd063cfe3ea8d98",
          "body": null,
          "is_bot": false,
          "headline": "ethereum: address in messages is now string",
          "author_name": "Pavol Rusnak",
          "author_login": "prusnak",
          "committed_at": "2019-01-29T16:16:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 0,
      "latest_release_at": "2019-02-24T16:42:01Z",
      "latest_release_tag": "v1.8.0",
      "releases_from_tags": true,
      "days_since_last_push": 2661,
      "active_weeks_last_year": 0,
      "days_since_latest_release": 2705,
      "mean_days_between_releases": 61.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 249,
      "stars": 312,
      "watchers": 6,
      "fork_history": {
        "days": [
          {
            "date": "2014-09-20",
            "count": 1
          },
          {
            "date": "2014-10-25",
            "count": 1
          },
          {
            "date": "2014-10-28",
            "count": 1
          },
          {
            "date": "2014-10-29",
            "count": 1
          },
          {
            "date": "2014-11-11",
            "count": 1
          },
          {
            "date": "2015-01-12",
            "count": 1
          },
          {
            "date": "2015-01-23",
            "count": 1
          },
          {
            "date": "2015-01-29",
            "count": 4
          },
          {
            "date": "2015-01-30",
            "count": 2
          },
          {
            "date": "2015-02-07",
            "count": 1
          },
          {
            "date": "2015-02-08",
            "count": 1
          },
          {
            "date": "2015-03-09",
            "count": 1
          },
          {
            "date": "2015-03-21",
            "count": 1
          },
          {
            "date": "2015-03-29",
            "count": 1
          },
          {
            "date": "2015-03-30",
            "count": 1
          },
          {
            "date": "2015-04-17",
            "count": 1
          },
          {
            "date": "2015-04-27",
            "count": 1
          },
          {
            "date": "2015-05-16",
            "count": 1
          },
          {
            "date": "2015-07-05",
            "count": 1
          },
          {
            "date": "2015-08-20",
            "count": 1
          },
          {
            "date": "2015-09-05",
            "count": 1
          },
          {
            "date": "2015-09-26",
            "count": 1
          },
          {
            "date": "2015-11-02",
            "count": 1
          },
          {
            "date": "2015-11-05",
            "count": 1
          },
          {
            "date": "2015-12-27",
            "count": 1
          },
          {
            "date": "2015-12-28",
            "count": 1
          },
          {
            "date": "2016-02-11",
            "count": 1
          },
          {
            "date": "2016-03-06",
            "count": 1
          },
          {
            "date": "2016-04-10",
            "count": 1
          },
          {
            "date": "2016-05-23",
            "count": 1
          },
          {
            "date": "2016-06-06",
            "count": 1
          },
          {
            "date": "2016-07-03",
            "count": 1
          },
          {
            "date": "2016-07-22",
            "count": 1
          },
          {
            "date": "2016-08-30",
            "count": 1
          },
          {
            "date": "2016-09-28",
            "count": 1
          },
          {
            "date": "2016-10-09",
            "count": 1
          },
          {
            "date": "2016-11-07",
            "count": 1
          },
          {
            "date": "2016-11-09",
            "count": 1
          },
          {
            "date": "2016-11-15",
            "count": 1
          },
          {
            "date": "2016-11-16",
            "count": 1
          },
          {
            "date": "2016-12-25",
            "count": 1
          },
          {
            "date": "2017-01-18",
            "count": 1
          },
          {
            "date": "2017-02-04",
            "count": 1
          },
          {
            "date": "2017-02-25",
            "count": 1
          },
          {
            "date": "2017-03-02",
            "count": 1
          },
          {
            "date": "2017-03-30",
            "count": 1
          },
          {
            "date": "2017-04-10",
            "count": 1
          },
          {
            "date": "2017-04-11",
            "count": 1
          },
          {
            "date": "2017-04-26",
            "count": 1
          },
          {
            "date": "2017-05-22",
            "count": 1
          },
          {
            "date": "2017-05-27",
            "count": 1
          },
          {
            "date": "2017-06-14",
            "count": 1
          },
          {
            "date": "2017-06-20",
            "count": 2
          },
          {
            "date": "2017-07-03",
            "count": 1
          },
          {
            "date": "2017-07-14",
            "count": 2
          },
          {
            "date": "2017-07-24",
            "count": 1
          },
          {
            "date": "2017-08-12",
            "count": 1
          },
          {
            "date": "2017-08-17",
            "count": 1
          },
          {
            "date": "2017-08-29",
            "count": 1
          },
          {
            "date": "2017-09-08",
            "count": 1
          },
          {
            "date": "2017-09-24",
            "count": 1
          },
          {
            "date": "2017-09-26",
            "count": 1
          },
          {
            "date": "2017-10-04",
            "count": 1
          },
          {
            "date": "2017-10-17",
            "count": 1
          },
          {
            "date": "2017-10-22",
            "count": 1
          },
          {
            "date": "2017-10-26",
            "count": 1
          },
          {
            "date": "2017-10-28",
            "count": 2
          },
          {
            "date": "2017-10-31",
            "count": 1
          },
          {
            "date": "2017-11-03",
            "count": 1
          },
          {
            "date": "2017-11-12",
            "count": 1
          },
          {
            "date": "2017-11-18",
            "count": 1
          },
          {
            "date": "2017-11-19",
            "count": 1
          },
          {
            "date": "2017-11-20",
            "count": 1
          },
          {
            "date": "2017-11-21",
            "count": 1
          },
          {
            "date": "2017-11-27",
            "count": 1
          },
          {
            "date": "2017-11-29",
            "count": 1
          },
          {
            "date": "2017-12-01",
            "count": 1
          },
          {
            "date": "2017-12-03",
            "count": 1
          },
          {
            "date": "2017-12-04",
            "count": 1
          },
          {
            "date": "2017-12-13",
            "count": 2
          },
          {
            "date": "2017-12-16",
            "count": 1
          },
          {
            "date": "2017-12-21",
            "count": 1
          },
          {
            "date": "2017-12-28",
            "count": 1
          },
          {
            "date": "2017-12-30",
            "count": 1
          },
          {
            "date": "2018-01-01",
            "count": 1
          },
          {
            "date": "2018-01-05",
            "count": 1
          },
          {
            "date": "2018-01-07",
            "count": 1
          },
          {
            "date": "2018-01-21",
            "count": 1
          },
          {
            "date": "2018-01-27",
            "count": 1
          },
          {
            "date": "2018-01-30",
            "count": 2
          },
          {
            "date": "2018-02-06",
            "count": 1
          },
          {
            "date": "2018-02-09",
            "count": 1
          },
          {
            "date": "2018-02-10",
            "count": 1
          },
          {
            "date": "2018-02-17",
            "count": 1
          },
          {
            "date": "2018-02-18",
            "count": 1
          },
          {
            "date": "2018-02-19",
            "count": 1
          },
          {
            "date": "2018-02-20",
            "count": 1
          },
          {
            "date": "2018-02-21",
            "count": 1
          },
          {
            "date": "2018-02-23",
            "count": 1
          },
          {
            "date": "2018-02-26",
            "count": 1
          },
          {
            "date": "2018-03-02",
            "count": 1
          },
          {
            "date": "2018-03-06",
            "count": 1
          },
          {
            "date": "2018-03-08",
            "count": 1
          },
          {
            "date": "2018-03-10",
            "count": 1
          },
          {
            "date": "2018-03-17",
            "count": 1
          },
          {
            "date": "2018-03-25",
            "count": 1
          },
          {
            "date": "2018-04-02",
            "count": 2
          },
          {
            "date": "2018-04-13",
            "count": 1
          },
          {
            "date": "2018-04-20",
            "count": 1
          },
          {
            "date": "2018-05-01",
            "count": 2
          },
          {
            "date": "2018-05-02",
            "count": 1
          },
          {
            "date": "2018-05-10",
            "count": 1
          },
          {
            "date": "2018-05-14",
            "count": 1
          },
          {
            "date": "2018-05-19",
            "count": 1
          },
          {
            "date": "2018-05-24",
            "count": 1
          },
          {
            "date": "2018-06-04",
            "count": 1
          },
          {
            "date": "2018-06-12",
            "count": 1
          },
          {
            "date": "2018-06-22",
            "count": 2
          },
          {
            "date": "2018-06-28",
            "count": 2
          },
          {
            "date": "2018-07-01",
            "count": 1
          },
          {
            "date": "2018-07-02",
            "count": 1
          },
          {
            "date": "2018-07-08",
            "count": 1
          },
          {
            "date": "2018-07-09",
            "count": 1
          },
          {
            "date": "2018-07-12",
            "count": 1
          },
          {
            "date": "2018-07-16",
            "count": 1
          },
          {
            "date": "2018-07-17",
            "count": 1
          },
          {
            "date": "2018-07-18",
            "count": 1
          },
          {
            "date": "2018-07-24",
            "count": 1
          },
          {
            "date": "2018-08-02",
            "count": 1
          },
          {
            "date": "2018-08-07",
            "count": 1
          },
          {
            "date": "2018-08-13",
            "count": 2
          },
          {
            "date": "2018-08-16",
            "count": 2
          },
          {
            "date": "2018-08-21",
            "count": 1
          },
          {
            "date": "2018-08-29",
            "count": 2
          },
          {
            "date": "2018-08-30",
            "count": 1
          },
          {
            "date": "2018-08-31",
            "count": 1
          },
          {
            "date": "2018-09-01",
            "count": 1
          },
          {
            "date": "2018-09-12",
            "count": 1
          },
          {
            "date": "2018-09-13",
            "count": 1
          },
          {
            "date": "2018-09-30",
            "count": 1
          },
          {
            "date": "2018-10-01",
            "count": 1
          },
          {
            "date": "2018-10-02",
            "count": 1
          },
          {
            "date": "2018-10-03",
            "count": 1
          },
          {
            "date": "2018-10-16",
            "count": 1
          },
          {
            "date": "2018-11-05",
            "count": 1
          },
          {
            "date": "2018-11-08",
            "count": 1
          },
          {
            "date": "2018-11-09",
            "count": 1
          },
          {
            "date": "2018-11-10",
            "count": 1
          },
          {
            "date": "2018-11-27",
            "count": 1
          },
          {
            "date": "2018-11-30",
            "count": 1
          },
          {
            "date": "2018-12-11",
            "count": 1
          },
          {
            "date": "2018-12-23",
            "count": 1
          },
          {
            "date": "2019-01-09",
            "count": 1
          },
          {
            "date": "2019-01-27",
            "count": 1
          },
          {
            "date": "2019-01-28",
            "count": 1
          },
          {
            "date": "2019-01-31",
            "count": 1
          },
          {
            "date": "2019-02-07",
            "count": 1
          },
          {
            "date": "2019-02-20",
            "count": 1
          },
          {
            "date": "2019-03-11",
            "count": 1
          },
          {
            "date": "2019-03-25",
            "count": 1
          },
          {
            "date": "2019-04-11",
            "count": 1
          },
          {
            "date": "2019-04-12",
            "count": 1
          },
          {
            "date": "2019-06-09",
            "count": 1
          },
          {
            "date": "2019-06-14",
            "count": 1
          },
          {
            "date": "2019-10-10",
            "count": 1
          },
          {
            "date": "2019-10-16",
            "count": 1
          },
          {
            "date": "2019-11-30",
            "count": 1
          },
          {
            "date": "2019-12-07",
            "count": 2
          },
          {
            "date": "2020-02-27",
            "count": 1
          },
          {
            "date": "2020-03-10",
            "count": 1
          },
          {
            "date": "2020-04-25",
            "count": 1
          },
          {
            "date": "2020-11-24",
            "count": 1
          },
          {
            "date": "2021-03-03",
            "count": 1
          },
          {
            "date": "2021-04-17",
            "count": 1
          },
          {
            "date": "2021-09-05",
            "count": 1
          },
          {
            "date": "2022-01-01",
            "count": 1
          },
          {
            "date": "2022-01-20",
            "count": 1
          },
          {
            "date": "2022-01-26",
            "count": 1
          },
          {
            "date": "2022-02-01",
            "count": 1
          },
          {
            "date": "2022-05-09",
            "count": 1
          },
          {
            "date": "2022-07-06",
            "count": 1
          },
          {
            "date": "2022-07-20",
            "count": 1
          },
          {
            "date": "2022-10-15",
            "count": 1
          },
          {
            "date": "2022-11-08",
            "count": 1
          },
          {
            "date": "2023-01-26",
            "count": 1
          },
          {
            "date": "2023-05-07",
            "count": 1
          },
          {
            "date": "2024-02-22",
            "count": 1
          },
          {
            "date": "2024-11-05",
            "count": 1
          },
          {
            "date": "2024-12-08",
            "count": 1
          },
          {
            "date": "2025-03-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 207,
        "total_forks": 249
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "bootloader/Makefile",
        "demo/Makefile",
        "emulator/Makefile",
        "firmware/Makefile",
        "firmware/protob/Makefile",
        "gen/Makefile"
      ],
      "api_schema_files": [
        "firmware/protob/messages-bitcoin.proto",
        "firmware/protob/messages-common.proto",
        "firmware/protob/messages-crypto.proto",
        "firmware/protob/messages-debug.proto",
        "firmware/protob/messages-ethereum.proto",
        "firmware/protob/messages-lisk.proto",
        "firmware/protob/messages-management.proto",
        "firmware/protob/messages-nem.proto",
        "firmware/protob/messages-stellar.proto",
        "firmware/protob/messages.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 59319,
      "source_files_sampled": 129,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Pipfile"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "ecdsa",
            "direct": false,
            "version": "0.13",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-8qxj-f9rh-9fg2",
              "GHSA-9f5j-8jwj-x28g",
              "GHSA-pwfw-mgfj-7g3g",
              "GHSA-wj6h-64fc-37mp",
              "PYSEC-2019-177",
              "PYSEC-2020-163",
              "PYSEC-2026-1325",
              "PYSEC-2026-2467"
            ],
            "fixed_version": "0.19.2",
            "advisory_count": 8,
            "oldest_advisory_days": 2479
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2018.4.16",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-43fp-rhv2-5gv8",
              "GHSA-xqr8-7jwr-rhp7",
              "PYSEC-2022-42986",
              "PYSEC-2023-135",
              "PYSEC-2024-230"
            ],
            "fixed_version": "2024.7.4",
            "advisory_count": 5,
            "oldest_advisory_days": 1323
          },
          {
            "name": "click",
            "direct": false,
            "version": "6.7",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.2,
            "advisory_ids": [
              "PYSEC-2026-2132"
            ],
            "fixed_version": "8.3.3",
            "advisory_count": 1,
            "oldest_advisory_days": 84
          },
          {
            "name": "idna",
            "direct": false,
            "version": "2.7",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-65pc-fj4g-8rjx",
              "GHSA-jjg7-2v4v-x38h",
              "PYSEC-2024-60",
              "PYSEC-2026-215"
            ],
            "fixed_version": "3.15",
            "advisory_count": 4,
            "oldest_advisory_days": 832
          },
          {
            "name": "mako",
            "direct": false,
            "version": "1.0.7",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2h4p-vjrc-8xpq",
              "GHSA-v92g-xgxw-vvmm",
              "GHSA-v973-fxgf-6xhp",
              "PYSEC-2022-260",
              "PYSEC-2026-2617",
              "PYSEC-2026-88"
            ],
            "fixed_version": "1.3.12",
            "advisory_count": 6,
            "oldest_advisory_days": 1415
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.4.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-7gcm-g887-7qv7",
              "GHSA-8gq9-2x98-w8hf",
              "GHSA-8qvm-5x2c-j2w7",
              "PYSEC-2022-48",
              "PYSEC-2026-1805",
              "PYSEC-2026-1806",
              "PYSEC-2026-899"
            ],
            "fixed_version": "6.33.5",
            "advisory_count": 7,
            "oldest_advisory_days": 1639
          },
          {
            "name": "py",
            "direct": false,
            "version": "1.5.4",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-hj5v-574p-mj7c",
              "PYSEC-2020-92"
            ],
            "fixed_version": "1.10.0",
            "advisory_count": 2,
            "oldest_advisory_days": 2052
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.19.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-9hjg-9r4m-mvj7",
              "GHSA-9wx4-h78v-vm56",
              "GHSA-gc5v-m9x4-r6x2",
              "GHSA-j8r2-6x86-q33q",
              "GHSA-x84v-xcm2-53pg",
              "PYSEC-2018-28",
              "PYSEC-2023-74",
              "PYSEC-2026-1872",
              "PYSEC-2026-1873",
              "PYSEC-2026-2275"
            ],
            "fixed_version": "2.33.0",
            "advisory_count": 10,
            "oldest_advisory_days": 2843
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "1.23",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.1,
            "advisory_ids": [
              "GHSA-2xpw-w6gg-jr37",
              "GHSA-34jh-p97f-mpxf",
              "GHSA-38jv-5279-wg99",
              "GHSA-g4mx-q9vg-27p4",
              "GHSA-gwvm-45gx-3cf8",
              "GHSA-mh33-7rrq-662w",
              "GHSA-pq67-6m6q-mj2v",
              "GHSA-qccp-gfcp-xxvc",
              "GHSA-r64q-w8jr-g9qp",
              "GHSA-v845-jxx5-vc9f"
            ],
            "fixed_version": "2.7.0",
            "advisory_count": 22,
            "oldest_advisory_days": 2656
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "3.6.4",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-6w46-j5rx-g56g",
              "PYSEC-2026-1845"
            ],
            "fixed_version": "9.0.3",
            "advisory_count": 2,
            "oldest_advisory_days": 182
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 8,
          "critical": 1,
          "moderate": 1
        },
        "advisory_count": 67,
        "affected_count": 10,
        "assessed_count": 25,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 1,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "atomicwrites",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "18.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2018.4.16",
            "ecosystem": "pypi"
          },
          {
            "name": "chardet",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": false,
            "version": "6.7",
            "ecosystem": "pypi"
          },
          {
            "name": "ecdsa",
            "direct": false,
            "version": "0.13",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "2.7",
            "ecosystem": "pypi"
          },
          {
            "name": "libusb1",
            "direct": false,
            "version": "1.6.5",
            "ecosystem": "pypi"
          },
          {
            "name": "mako",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "pypi"
          },
          {
            "name": "markupsafe",
            "direct": false,
            "version": "1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mnemonic",
            "direct": false,
            "version": "0.18",
            "ecosystem": "pypi"
          },
          {
            "name": "mock",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "more-itertools",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "munch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pbkdf2",
            "direct": false,
            "version": "1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pbr",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "py",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pyblake2",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "3.6.4",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "trezor",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "typing",
            "direct": false,
            "version": "3.6.4",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "1.23",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 26,
        "direct_count": 0,
        "indirect_count": 26
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 177,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 202,
        "closed_unmerged_prs": 79
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "prusnak",
          "commits": 755,
          "avatar_url": "https://avatars.githubusercontent.com/u/42201?v=4"
        },
        {
          "type": "User",
          "login": "jhoenicke",
          "commits": 146,
          "avatar_url": "https://avatars.githubusercontent.com/u/897826?v=4"
        },
        {
          "type": "User",
          "login": "saleemrashid",
          "commits": 128,
          "avatar_url": "https://avatars.githubusercontent.com/u/22301423?v=4"
        },
        {
          "type": "User",
          "login": "andrewkozlik",
          "commits": 39,
          "avatar_url": "https://avatars.githubusercontent.com/u/42678794?v=4"
        },
        {
          "type": "User",
          "login": "romanz",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/9900?v=4"
        },
        {
          "type": "User",
          "login": "tsusanka",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/1835345?v=4"
        },
        {
          "type": "User",
          "login": "matejcik",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/596073?v=4"
        },
        {
          "type": "User",
          "login": "karelbilek",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/104945?v=4"
        },
        {
          "type": "User",
          "login": "axic",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/20340?v=4"
        },
        {
          "type": "User",
          "login": "mkrufky",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/1062488?v=4"
        }
      ],
      "contributors_sampled": 33,
      "top_contributor_share": 0.628
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": false,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Pipfile.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 2/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 25 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project is archived",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "35 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8af1f3643651e1cbee6b6196401f9c63e7cfc0f9",
        "ran_at": "2026-07-23T16:03:40Z",
        "aggregate_score": 2.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": "2019-04-09T12:45:49Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/trezor/trezor-mcu",
    "host": "github.com",
    "name": "trezor-mcu",
    "owner": "trezor"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "critical",
      "name": "Overall health",
      "note": "Abandonment Policy applies a 40% multiplier to weighted overall health and gives it a ceiling of 29.",
      "notes": [
        {
          "code": "abandonment_overall_adjustment",
          "params": {
            "cap": 29,
            "pct": 40
          }
        }
      ],
      "value": 17,
      "inputs": {
        "security": 41,
        "vitality": 17,
        "community": 67,
        "governance": 62,
        "engineering": 27,
        "abandonment_cap": 29,
        "abandonment_state": "declared",
        "abandonment_multiplier": 40,
        "weighted_overall_before_abandonment": 43,
        "overall_after_abandonment_multiplier": 17
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "critical",
        "name": "Vitality",
        "value": 17,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "critical",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "commits_last_year": 0,
              "human_commit_share": 1,
              "days_since_last_push": 2661,
              "active_weeks_last_year": 0
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2661 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2661
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "0/52 weeks with commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "0 commits in the last year",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project is archived",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v1.8.0",
              "releases_from_tags": true,
              "days_since_latest_release": 2705,
              "mean_days_between_releases": 61.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2705 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2705
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~61.9 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 61.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "at_risk",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "cap": 29,
              "state": "declared",
              "guards": [],
              "signals": [],
              "red_flag": true,
              "multiplier_pct": 40,
              "declared_reason": "archived",
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "the repository is archived on GitHub",
                "points": 40,
                "status": "partial",
                "details": [
                  {
                    "code": "abandonment_archived",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 67,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "forks": 249,
              "stars": 312,
              "watchers": 6,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "312 stars",
                "points": 40.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 312
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "249 forks",
                "points": 20,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 249
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "6 watchers",
                "points": 3.9,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (LGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "LGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 62,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 33,
              "top_contributor_share": 0.628
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 63% of commits",
                "points": 8.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 63
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "33 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 25 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "merged_prs": 177,
              "open_issues": 0,
              "closed_issues": 202,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 79
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "177/256 decided PRs merged",
                "points": 26.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 177,
                      "decided": 256
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "followers": 1245,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "trezor",
              "public_repos": 67,
              "account_age_days": 4849
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,245 followers of trezor",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1245,
                      "login": "trezor"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "67 public repos, account ~13 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 67
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "critical",
        "name": "Engineering Quality",
        "value": 27,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "critical",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "has_ci": false,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "bitcoin",
                "trezor",
                "hardware",
                "wallet",
                "open-source",
                "embedded",
                "arm"
              ],
              "has_wiki": false,
              "homepage": "https://github.com/trezor/trezor-firmware",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://github.com/trezor/trezor-firmware",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Dangerous-Workflow, Packaging, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "dangerous_workflow",
                    "packaging",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 26,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 2.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 25 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project is archived",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "35 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 25 resolved dependencies against OSV; 1 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 25
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 1
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 67,
              "affected_packages": 10,
              "assessed_packages": 25,
              "unassessed_packages": 1,
              "affected_by_severity": "critical 1, high 8, moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 25,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 16
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 49,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.76,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "76 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 76,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "has_nix": true,
              "has_tests": false,
              "lockfiles": [
                "Pipfile.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "bootloader/Makefile",
                "demo/Makefile",
                "emulator/Makefile",
                "firmware/Makefile",
                "firmware/protob/Makefile",
                "gen/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, bootloader/Makefile, demo/Makefile, emulator/Makefile, firmware/Makefile, firmware/protob/Makefile, gen/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, bootloader/Makefile, demo/Makefile, emulator/Makefile, firmware/Makefile, firmware/protob/Makefile, gen/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "C (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "C",
              "largest_source_bytes": 59319,
              "source_files_sampled": 129,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "C (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/129 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 129,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": false,
              "api_schema_files": [
                "firmware/protob/messages-bitcoin.proto",
                "firmware/protob/messages-common.proto",
                "firmware/protob/messages-crypto.proto",
                "firmware/protob/messages-debug.proto",
                "firmware/protob/messages-ethereum.proto",
                "firmware/protob/messages-lisk.proto",
                "firmware/protob/messages-management.proto",
                "firmware/protob/messages-nem.proto",
                "firmware/protob/messages-stellar.proto",
                "firmware/protob/messages.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "firmware/protob/messages-bitcoin.proto, firmware/protob/messages-common.proto, firmware/protob/messages-crypto.proto, firmware/protob/messages-debug.proto, firmware/protob/messages-ethereum.proto, firmware/protob/messages-lisk.proto, firmware/protob/messages-management.proto, firmware/protob/messages-nem.proto, firmware/protob/messages-stellar.proto, firmware/protob/messages.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "firmware/protob/messages-bitcoin.proto, firmware/protob/messages-common.proto, firmware/protob/messages-crypto.proto, firmware/protob/messages-debug.proto, firmware/protob/messages-ethereum.proto, firmware/protob/messages-lisk.proto, firmware/protob/messages-management.proto, firmware/protob/messages-nem.proto, firmware/protob/messages-stellar.proto, firmware/protob/messages.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T16:04:00.941426Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/trezor/trezor-mcu.svg",
  "full_name": "trezor/trezor-mcu",
  "license_state": "standard",
  "license_spdx": "LGPL-3.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistiken.