Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"containers",
"security",
"vulnerability",
"docker",
"golang",
"go",
"static-analysis",
"container-image",
"tool",
"oci",
"cyclonedx",
"vulnerabilities",
"hacktoberfest",
"openvex",
"vex"
],
"is_fork": false,
"size_kb": 9999,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 4221057,
"Shell": 44103,
"Python": 3297,
"Makefile": 8465,
"Dockerfile": 1126,
"Go Template": 65702
},
"pushed_at": "2026-07-22T14:46:20Z",
"created_at": "2020-05-26T13:44:38Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T15:20:22Z",
"description": "A vulnerability scanner for container images and filesystems",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://anchore.com/",
"name": "Anchore, Inc.",
"type": "Organization",
"login": "anchore",
"company": null,
"location": null,
"followers": 574,
"avatar_url": "https://avatars.githubusercontent.com/u/16208487?v=4",
"created_at": "2015-12-08T13:35:16Z",
"is_verified": null,
"public_repos": 105,
"account_age_days": 3879
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.116.0",
"kind": "minor",
"published_at": "2026-07-16T16:52:20Z"
},
{
"tag": "v0.115.0",
"kind": "minor",
"published_at": "2026-06-26T11:42:04Z"
},
{
"tag": "v0.114.0",
"kind": "minor",
"published_at": "2026-06-05T16:17:05Z"
},
{
"tag": "v0.113.0",
"kind": "minor",
"published_at": "2026-06-03T14:19:21Z"
},
{
"tag": "v0.112.0",
"kind": "minor",
"published_at": "2026-05-01T19:12:37Z"
},
{
"tag": "v0.111.1",
"kind": "patch",
"published_at": "2026-04-22T17:31:58Z"
},
{
"tag": "v0.111.0",
"kind": "minor",
"published_at": "2026-04-09T13:29:25Z"
},
{
"tag": "v0.110.0",
"kind": "minor",
"published_at": "2026-03-19T18:16:47Z"
},
{
"tag": "v0.109.1",
"kind": "patch",
"published_at": "2026-03-09T19:50:07Z"
},
{
"tag": "v0.109.0",
"kind": "minor",
"published_at": "2026-02-19T16:38:10Z"
},
{
"tag": "v0.108.0",
"kind": "minor",
"published_at": "2026-02-10T18:49:12Z"
},
{
"tag": "v0.107.1",
"kind": "patch",
"published_at": "2026-02-03T19:24:39Z"
},
{
"tag": "v0.107.0",
"kind": "minor",
"published_at": "2026-01-29T22:24:48Z"
},
{
"tag": "v0.106.0",
"kind": "minor",
"published_at": "2026-01-27T14:08:53Z"
},
{
"tag": "v0.105.0",
"kind": "minor",
"published_at": "2026-01-15T23:07:39Z"
},
{
"tag": "v0.104.4",
"kind": "patch",
"published_at": "2026-01-08T13:58:30Z"
},
{
"tag": "v0.104.3",
"kind": "patch",
"published_at": "2025-12-22T23:16:53Z"
},
{
"tag": "v0.104.2",
"kind": "patch",
"published_at": "2025-12-09T23:17:35Z"
},
{
"tag": "v0.104.1",
"kind": "patch",
"published_at": "2025-11-24T16:27:27Z"
},
{
"tag": "v0.104.0",
"kind": "minor",
"published_at": "2025-11-17T22:39:08Z"
},
{
"tag": "v0.103.0",
"kind": "minor",
"published_at": "2025-11-03T20:00:40Z"
},
{
"tag": "v0.102.0",
"kind": "minor",
"published_at": "2025-10-23T10:59:26Z"
},
{
"tag": "v0.101.1",
"kind": "patch",
"published_at": "2025-10-16T13:42:08Z"
},
{
"tag": "v0.101.0",
"kind": "minor",
"published_at": "2025-10-15T17:15:25Z"
},
{
"tag": "v0.100.0",
"kind": "minor",
"published_at": "2025-09-15T22:06:37Z"
},
{
"tag": "v0.99.1",
"kind": "patch",
"published_at": "2025-08-30T14:34:21Z"
},
{
"tag": "v0.99.0",
"kind": "minor",
"published_at": "2025-08-27T00:47:35Z"
},
{
"tag": "v0.98.0",
"kind": "minor",
"published_at": "2025-08-13T17:38:04Z"
},
{
"tag": "v0.97.2",
"kind": "patch",
"published_at": "2025-08-08T19:45:03Z"
},
{
"tag": "v0.97.1",
"kind": "patch",
"published_at": "2025-08-01T16:20:51Z"
},
{
"tag": "v0.97.0",
"kind": "minor",
"published_at": "2025-07-30T19:29:46Z"
},
{
"tag": "v0.96.1",
"kind": "patch",
"published_at": "2025-07-21T21:10:35Z"
},
{
"tag": "v0.96.0",
"kind": "minor",
"published_at": "2025-07-15T13:13:59Z"
},
{
"tag": "v0.95.0",
"kind": "minor",
"published_at": "2025-07-02T17:26:05Z"
},
{
"tag": "v0.94.0",
"kind": "minor",
"published_at": "2025-06-12T14:59:10Z"
},
{
"tag": "v0.93.0",
"kind": "minor",
"published_at": "2025-06-10T12:51:14Z"
},
{
"tag": "v0.92.2",
"kind": "patch",
"published_at": "2025-05-21T00:52:09Z"
},
{
"tag": "v0.92.1",
"kind": "patch",
"published_at": "2025-05-16T20:23:49Z"
},
{
"tag": "v0.92.0",
"kind": "minor",
"published_at": "2025-05-14T17:16:23Z"
},
{
"tag": "v0.91.2",
"kind": "patch",
"published_at": "2025-04-25T17:30:56Z"
},
{
"tag": "v0.91.1",
"kind": "patch",
"published_at": "2025-04-24T21:30:47Z"
},
{
"tag": "v0.91.0",
"kind": "minor",
"published_at": "2025-04-01T16:11:54Z"
},
{
"tag": "v0.90.0",
"kind": "minor",
"published_at": "2025-03-17T20:58:34Z"
},
{
"tag": "v0.89.1",
"kind": "patch",
"published_at": "2025-03-13T20:33:59Z"
},
{
"tag": "v0.89.0",
"kind": "minor",
"published_at": "2025-03-06T22:26:01Z"
},
{
"tag": "v0.88.0",
"kind": "minor",
"published_at": "2025-03-05T20:36:08Z"
},
{
"tag": "v0.87.0",
"kind": "minor",
"published_at": "2025-01-22T21:01:32Z"
},
{
"tag": "v0.86.1",
"kind": "patch",
"published_at": "2024-12-13T19:42:02Z"
},
{
"tag": "v0.86.0",
"kind": "minor",
"published_at": "2024-12-09T22:06:46Z"
},
{
"tag": "v0.85.0",
"kind": "minor",
"published_at": "2024-11-21T15:29:44Z"
},
{
"tag": "v0.84.0",
"kind": "minor",
"published_at": "2024-11-05T15:03:57Z"
},
{
"tag": "v0.83.0",
"kind": "minor",
"published_at": "2024-10-28T22:03:36Z"
},
{
"tag": "v0.82.2",
"kind": "patch",
"published_at": "2024-10-21T18:15:16Z"
},
{
"tag": "v0.82.1",
"kind": "patch",
"published_at": "2024-10-15T14:02:09Z"
},
{
"tag": "v0.82.0",
"kind": "minor",
"published_at": "2024-10-07T21:45:12Z"
},
{
"tag": "v0.81.0",
"kind": "minor",
"published_at": "2024-09-25T17:06:44Z"
},
{
"tag": "v0.80.2",
"kind": "patch",
"published_at": "2024-09-24T15:16:23Z"
},
{
"tag": "v0.80.1",
"kind": "patch",
"published_at": "2024-09-11T17:38:24Z"
},
{
"tag": "v0.80.0",
"kind": "minor",
"published_at": "2024-08-20T18:05:33Z"
},
{
"tag": "v0.79.6",
"kind": "patch",
"published_at": "2024-08-12T16:43:49Z"
},
{
"tag": "v0.79.5",
"kind": "patch",
"published_at": "2024-08-09T18:56:22Z"
},
{
"tag": "v0.79.4",
"kind": "patch",
"published_at": "2024-07-31T15:32:32Z"
},
{
"tag": "v0.79.3",
"kind": "patch",
"published_at": "2024-07-15T13:05:27Z"
},
{
"tag": "v0.79.2",
"kind": "patch",
"published_at": "2024-07-02T15:52:41Z"
},
{
"tag": "v0.79.1",
"kind": "patch",
"published_at": "2024-06-17T19:41:30Z"
},
{
"tag": "v0.79.0",
"kind": "minor",
"published_at": "2024-06-14T21:10:49Z"
},
{
"tag": "v0.78.0",
"kind": "minor",
"published_at": "2024-05-28T18:01:12Z"
},
{
"tag": "v0.77.4",
"kind": "patch",
"published_at": "2024-05-09T20:49:23Z"
},
{
"tag": "v0.77.3",
"kind": "patch",
"published_at": "2024-05-06T20:06:10Z"
},
{
"tag": "v0.77.2",
"kind": "patch",
"published_at": "2024-05-01T16:28:23Z"
},
{
"tag": "v0.77.1",
"kind": "patch",
"published_at": "2024-04-26T17:21:50Z"
},
{
"tag": "v0.77.0",
"kind": "minor",
"published_at": "2024-04-18T19:22:34Z"
},
{
"tag": "v0.76.0",
"kind": "minor",
"published_at": "2024-04-15T20:49:40Z"
},
{
"tag": "v0.75.0",
"kind": "minor",
"published_at": "2024-04-04T16:10:46Z"
},
{
"tag": "v0.74.7",
"kind": "patch",
"published_at": "2024-02-26T18:32:14Z"
},
{
"tag": "v0.74.6",
"kind": "patch",
"published_at": "2024-02-14T22:27:46Z"
},
{
"tag": "v0.74.5",
"kind": "patch",
"published_at": "2024-02-07T21:42:58Z"
},
{
"tag": "v0.74.4",
"kind": "patch",
"published_at": "2024-01-31T17:58:32Z"
},
{
"tag": "v0.74.3",
"kind": "patch",
"published_at": "2024-01-26T15:19:39Z"
},
{
"tag": "v0.74.2",
"kind": "patch",
"published_at": "2024-01-19T22:42:58Z"
},
{
"tag": "v0.74.1",
"kind": "patch",
"published_at": "2024-01-17T22:04:31Z"
},
{
"tag": "v0.74.0",
"kind": "minor",
"published_at": "2024-01-06T04:21:30Z"
},
{
"tag": "v0.73.5",
"kind": "patch",
"published_at": "2023-12-21T17:56:05Z"
},
{
"tag": "v0.73.4",
"kind": "patch",
"published_at": "2023-11-30T14:40:51Z"
},
{
"tag": "v0.73.3",
"kind": "patch",
"published_at": "2023-11-18T13:13:36Z"
},
{
"tag": "v0.73.2",
"kind": "patch",
"published_at": "2023-11-17T00:37:50Z"
},
{
"tag": "v0.73.1",
"kind": "patch",
"published_at": "2023-11-09T15:02:57Z"
},
{
"tag": "v0.73.0",
"kind": "minor",
"published_at": "2023-11-07T21:04:54Z"
},
{
"tag": "v0.72.0",
"kind": "minor",
"published_at": "2023-10-20T18:28:42Z"
},
{
"tag": "v0.71.0",
"kind": "minor",
"published_at": "2023-10-12T13:44:19Z"
},
{
"tag": "v0.70.0",
"kind": "minor",
"published_at": "2023-10-10T20:01:20Z"
},
{
"tag": "v0.69.1",
"kind": "patch",
"published_at": "2023-09-27T17:03:54Z"
},
{
"tag": "v0.69.0",
"kind": "minor",
"published_at": "2023-09-20T21:10:07Z"
},
{
"tag": "v0.68.1",
"kind": "patch",
"published_at": "2023-09-15T18:49:03Z"
},
{
"tag": "v0.68.0",
"kind": "minor",
"published_at": "2023-09-14T21:31:18Z"
},
{
"tag": "v0.67.0",
"kind": "minor",
"published_at": "2023-09-11T18:18:57Z"
},
{
"tag": "v0.66.0",
"kind": "minor",
"published_at": "2023-08-31T16:50:30Z"
},
{
"tag": "v0.65.2",
"kind": "patch",
"published_at": "2023-08-17T20:07:01Z"
},
{
"tag": "v0.65.1",
"kind": "patch",
"published_at": "2023-08-04T13:06:03Z"
},
{
"tag": "v0.65.0",
"kind": "minor",
"published_at": "2023-07-31T18:12:55Z"
}
],
"recent_commits": [
{
"oid": "4562c55cebba5fe50a0c5afc7cec50a3b2392a87",
"body": "* fix(version): do not cache a comparator that failed to build\n\nSigned-off-by: Arpit Jain <arpitjain099@gmail.com>\n\n* add more tests\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Arpit Jain <arpitjain099@gmail.com>\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\nCo-authored-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(version): do not cache a comparator that failed to build (#3567)",
"author_name": "Arpit Jain",
"author_login": "arpitjain099",
"committed_at": "2026-07-22T14:46:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccf53d6ac1eea8594a5fc7909fbb7c6a1802b06e",
"body": "… (#3589)\n\nparseVersion indexed version[0] immediately after strings.TrimPrefix(version,\n\"v\"). When an artifact supplies a version that consists solely of the \"v\"\nprefix (e.g. \"v\", or \"v+<channel>\" whose core reduces to empty), the trim\nyields an empty string and version[0] panics with \"index out of\n[…]\nrange [0]\nwith length 0\".\n\nAdd the missing length guard and regression tests covering both parseVersion\nand the end-to-end NewFromRelease path.\n\nSigned-off-by: Matías Insaurralde <matias@insaurral.de>",
"is_bot": false,
"headline": "fix(distro): prevent panic on empty version after trimming \"v\" prefix…",
"author_name": "Matias Insaurralde",
"author_login": "matiasinsaurralde",
"committed_at": "2026-07-22T14:22:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44ad33fa06307ad98382d293a3464975ea1441b6",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update anchore dependencies (#3577)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-07-21T13:52:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fadc701b693faee76fc17d54185b0790b3de4011",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update OSV schema model (#3569)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-07-21T13:30:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea5e99ae65811521d2483956a238d216762f5066",
"body": "Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "add fix date to rhel minor records created from rhsa (#3585)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-07-20T15:32:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5917fe588250b59ebe4ee2fc5ebe03b8757f0dcb",
"body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.47.0 to 0.48.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.47.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n dependency-version:\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/tools from 0.47.0 to 0.48.0 (#3582)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-17T16:20:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0a8f5709493ecd714b2c6a88bb508f6be6557cb5",
"body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github/codeql-action/upload-sarif (#3579)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-17T15:55:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94f050572cda0ce241677c0be14728387bd24433",
"body": "…23 (#3581)\n\nBumps [github.com/gkampitakis/go-snaps](https://github.com/gkampitakis/go-snaps) from 0.5.22 to 0.5.23.\n- [Release notes](https://github.com/gkampitakis/go-snaps/releases)\n- [Commits](https://github.com/gkampitakis/go-snaps/compare/v0.5.22...v0.5.23)\n\n---\nupdated-dependencies:\n- depende\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.22 to 0.5.…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-17T15:54:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "537c2fec902892e1f89c7396b653788bc9fd34ce",
"body": "Bumps [golang.org/x/text](https://github.com/golang/text) from 0.39.0 to 0.40.0.\n- [Release notes](https://github.com/golang/text/releases)\n- [Commits](https://github.com/golang/text/compare/v0.39.0...v0.40.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/text\n dependency-version: 0.40\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/text from 0.39.0 to 0.40.0 (#3580)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-17T15:54:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c7b51400bfcaac6f296cb2645fa48600c8487f5",
"body": "Signed-off-by: Keith Zantow <kzantow@gmail.com>",
"is_bot": false,
"headline": "chore: fix latest schema (#3576)",
"author_name": "Keith Zantow",
"author_login": "kzantow",
"committed_at": "2026-07-16T22:08:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b014b00097d43933e5cce485e744db8289a406f",
"body": "---------\nSigned-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nSigned-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update anchore dependencies (#3536)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-07-16T16:02:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "159bf2d7c2d3533915747fbe163b8167791a1c4a",
"body": "…y Go vuln db advisories\n\n---------\nSigned-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "feat: add Go symbol matching for stdlib, golang.org/x, and third part…",
"author_name": "Christopher Angelo Phillips",
"author_login": "spiffcs",
"committed_at": "2026-07-15T19:27:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9490127803552eecaa615b72c41bfd8f0b189c73",
"body": "The 6.1.8 change (architecture_aliases table) was merged without running\nthe schema generator\n\nthe SQL schema was missing the architecture_aliases table and there were no 6.1.8\nschema files.\n\nRegenerate at the existing Addition=8 to add schema-6.1.8.sql\nand schema-6.1.8.json; refresh schema-latest.\n\n[…]\no picks up a drifted architecture-field description and normalizes the\n$defs ordering that had accumulated since 6.1.7.\n\nSigned-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(db): regenerate v6.1.8 blob and sql schemas (#3574)",
"author_name": "Christopher Angelo Phillips",
"author_login": "spiffcs",
"committed_at": "2026-07-15T17:19:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fcf08ae0a418f4ba685e7fdb2c65bf23e2e072bf",
"body": "Signed-off-by: Keith Zantow <kzantow@gmail.com>",
"is_bot": false,
"headline": "fix: rhel version streams (#3572)",
"author_name": "Keith Zantow",
"author_login": "kzantow",
"committed_at": "2026-07-15T14:42:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bcfc0e7a0833d44cab553ba6f6d3ea8c1f3dcd6b",
"body": "* add Ubuntu ESM (Ubuntu Pro) vulnerability matching\n\nHandles Ubuntu ESM as a distro `esm` channel, modeled on the existing RHEL EUS\nsupport. When a scanned Ubuntu image is Pro/ESM-enabled, a two-pass match resolves\nbase disclosures against the ESM-channel fixes, so users see `fixed in ...+esm1`\nins\n[…]\nZantow <kzantow@gmail.com>\n\n---------\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\nSigned-off-by: Keith Zantow <kzantow@gmail.com>\nCo-authored-by: Keith Zantow <kzantow@gmail.com>",
"is_bot": false,
"headline": "Add Ubuntu ESM vulnerability matching (#3546)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-07-13T13:19:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b31a42222f9ec1319374ccb01f5781f9d85a70b9",
"body": "… (#3566)\n\nBumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.18.6 to 1.19.0.\n- [Release notes](https://github.com/klauspost/compress/releases)\n- [Commits](https://github.com/klauspost/compress/compare/v1.18.6...v1.19.0)\n\n---\nupdated-dependencies:\n- dependency-name: \n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.19.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T15:59:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "488696efa45117c0b96975a5b630b4927b2094fe",
"body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github/codeql-action/upload-sarif (#3563)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T15:58:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2319b61c07b315c3ef0b341577564ff91441ea8b",
"body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.4.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...af1e73f918a031802d376d3c8bbc3fe56130a9b0)\n\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 (#3564)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T15:57:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a0581cd50aa5bcde6fe211000c24662c6d423789",
"body": "Bumps [golang.org/x/text](https://github.com/golang/text) from 0.38.0 to 0.39.0.\n- [Release notes](https://github.com/golang/text/releases)\n- [Commits](https://github.com/golang/text/compare/v0.38.0...v0.39.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/text\n dependency-version: 0.39\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0 (#3565)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T15:56:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c601b264949e46cebc5bc5d6410fcc700a8981f",
"body": "… (#3552)\n\nBumps [anchore/workflows/.github/workflows/check-gate.yaml](https://github.com/anchore/workflows) from 0.7.2 to 0.8.0.\n- [Release notes](https://github.com/anchore/workflows/releases)\n- [Commits](https://github.com/anchore/workflows/compare/b0c30a80409130d329aaa356fd64a34d8c0b3375...72129\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T19:42:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a18bdd887d73f86aadef256ba308ab52696132ef",
"body": "…-script.yaml (#3553)\n\nBumps [anchore/workflows/.github/workflows/release-install-script.yaml](https://github.com/anchore/workflows) from 0.7.2 to 0.8.0.\n- [Release notes](https://github.com/anchore/workflows/releases)\n- [Commits](https://github.com/anchore/workflows/compare/b0c30a80409130d329aaa356\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump anchore/workflows/.github/workflows/release-install…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T19:42:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc88fade29f0ac740fd84f0b25c1bbb059be0c05",
"body": "…542)\n\n* feat(rhel): duplicate RHSAs to all applicable RHEL minor versions\n\nHistorically, affected package handles for RHEL have been emitted at\nmajor versions only, modeling RHEL 9, for example, as a single namespace\nwithin which to search for vulnerabilities. However, this representation\ncannot co\n[…]\nub.com>\n\n* add generator for set of rhel minors\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(rhel): duplicate RHSAs to all applicable RHEL minor versions (#3…",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-07-08T18:36:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67d411359912ac4f47f92237269be2d3a2259ec6",
"body": "* feat(cg/transformers) INT-520: add chainguard osv transformer\n\nSigned-off-by: crosleyzack <mail@crosleyzack.com>\nSigned-off-by: Zackary Crosley <zackary.crosley@chainguard.dev>\n\n* read arch from apk metadata\n\nSigned-off-by: Zackary Crosley <zackary.crosley@chainguard.dev>\n\n* fix formatting\n\nSigned\n[…]\ned-off-by: Zackary Crosley <zackary.crosley@chainguard.dev>\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\nCo-authored-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(cg/transformers): add chainguard osv transformer (#3474)",
"author_name": "Zack Crosley",
"author_login": "crosleyzack",
"committed_at": "2026-07-08T12:19:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67ba7a178df4e1385adee1a0a4a633658170c3ec",
"body": "Bumps [gorm.io/gorm](https://github.com/go-gorm/gorm) from 1.31.1 to 1.31.2.\n- [Release notes](https://github.com/go-gorm/gorm/releases)\n- [Commits](https://github.com/go-gorm/gorm/compare/v1.31.1...v1.31.2)\n\n---\nupdated-dependencies:\n- dependency-name: gorm.io/gorm\n dependency-version: 1.31.2\n de\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump gorm.io/gorm from 1.31.1 to 1.31.2 (#3557)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T16:22:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e812b454ce9523958857da4019bb221ad23e1be6",
"body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/cache in /.github/actions/bootstrap (#3558)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:58:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23be00ce5b1ddcc71ae0dde9a460e69ab2d82d31",
"body": "Bumps [anchore/go-make/.github/actions/setup](https://github.com/anchore/go-make) from 0.6.0 to 0.8.0.\n- [Release notes](https://github.com/anchore/go-make/releases)\n- [Commits](https://github.com/anchore/go-make/compare/39fe5f71112d4dceb3ff0a92a40f272f067fc457...430e2175bb166bfd138ef75466adbcc8ddab\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump anchore/go-make/.github/actions/setup (#3555)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:58:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d69f58f10f189aed37e87738873750ebeb60b93d",
"body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/cache from 5.0.5 to 6.1.0 (#3551)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:57:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe97d4fd988d377a029d2b3acf20a3c5fc54f860",
"body": "… (#3556)\n\nBumps [actions/cache/restore](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9d\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/cache/restore in /.github/actions/bootstrap…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:57:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c315bd20de65206b52f5b3a48ea7ed2db79577ff",
"body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.46.0 to 0.47.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.46.0...v0.47.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n dependency-version:\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/tools from 0.46.0 to 0.47.0 (#3550)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:49:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "19e3e383ccb07d4598c44c4d8f7f05bc8bec6635",
"body": "…548)\n\nBumps [anchore/workflows/.github/workflows/codeql.yaml](https://github.com/anchore/workflows) from 0.7.2 to 0.8.0.\n- [Release notes](https://github.com/anchore/workflows/releases)\n- [Commits](https://github.com/anchore/workflows/compare/b0c30a80409130d329aaa356fd64a34d8c0b3375...7212994dc8fc3\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump anchore/workflows/.github/workflows/codeql.yaml (#3…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:48:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd45ba713cda7eaefde73e45d8acd7f22187e169",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#3549)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:47:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed9f3188ddd24f5ab3e64fc627f6441a8d8ea35e",
"body": "…vailable.yaml (#3547)\n\nBumps [anchore/workflows/.github/workflows/check-version-available.yaml](https://github.com/anchore/workflows) from 0.7.2 to 0.8.0.\n- [Release notes](https://github.com/anchore/workflows/releases)\n- [Commits](https://github.com/anchore/workflows/compare/b0c30a80409130d329aaa3\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump anchore/workflows/.github/workflows/check-version-a…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T15:47:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d4b3a5f6a36174b368e56abcef3f10caf6749d37",
"body": "Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>",
"is_bot": false,
"headline": "fix(zarf): swap warn messages for debug (#3545)",
"author_name": "Brandt Keller",
"author_login": "brandtkeller",
"committed_at": "2026-07-02T19:04:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4dd09a7347e35ff52fa5439bf76a36d743db0307",
"body": "* feat: populate package architecture for matching\n\nEnable matchers to filter on architecture-specific vulnerabilities or\nfixes.\n\nThere are basically three changes here: First, wire up the package\ncollection creator to populate architecture on the packages when an\nimage is scanned or an sbom is load\n[…]\n\n\n* exhaustive tests for package arch qualifier\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "feat: populate package architecture for matching (#3504)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-07-02T18:51:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ddf6482d4ce7a14ee6bfabdc1ba55f8adf51bcbc",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update quality gate database (#3543)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-07-02T16:18:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c41e34d136d957d1fb810b3fa7ef81892ea590ca",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#3535)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T15:53:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fa8b7e2a528cf1f8b098123f256c61db9e5df69c",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update anchore dependencies (#3498)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-26T10:16:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f75990527abdcd49d26d1be2364a629600c92cd3",
"body": "These packages are not covered by GHSA and generally have well-formed\nversions, so emit them.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(govulndb): emit golang.org/x/net vulns from govlundb (#3534)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-26T09:48:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "095cea96784af1ca6391ad52d3cd4f8f70b5bb78",
"body": "…(#3532)\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(units): account for changes in Syft and fix stale listing file …",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-25T16:10:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "219a3b808f03500eb0a4ed4e57f0841fd107a607",
"body": "Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "Update go-make to v0.8.0 (#3528)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-06-24T03:26:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa5977bd05eb82b621f21435e1dd16e81282d054",
"body": "* fix(govulndb): only emit records for stdlib\n\nFor third party go packages, go vuln db has some very strange version\nranges, and this has caused a number of false positive reports.\nAdditionally, for most of them, Grype currently reports both a GHSA and\na GO record, resulting in user confusion.\n\nHowe\n[…]\n.com>\n\n* Clean up some additional test fixtures\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(govulndb): only emit records for stdlib (#3527)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-23T16:30:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "80c4dcbf25e3b7be23556dd60aad16a85d9a2b73",
"body": "Previously, lower and upper bounds on vulnerable windows would be ORed\ntogether if part of the range was reported in osv standard affected\nevents and the other part was reported in OSV ecosystem-specific\ncustom_ranges events. Fix the merge logic so that floors from the custom\nranges have the correct effect.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(govulndb): mix floors from custom ranges as appropriate (#3522)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-22T20:45:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7bf3e633b7f5be278e3b21121a703b89dd7371a7",
"body": "Bumps [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) from 2.3.1 to 2.3.2.\n- [Release notes](https://github.com/containerd/containerd/releases)\n- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)\n- [Commits](https://github.com/containerd/cont\n[…]\n/v2\n dependency-version: 2.3.2\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/containerd/containerd/v2 (#3525)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T18:41:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ef6e79161441c4608306906fedf002edd2220ce0",
"body": "… dependabot/zizmor/gci cleanup (#3524)\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "refactor release pipeline: TAG_TOKEN, skip-checks gate, go-make bump,…",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-06-22T17:59:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "931e487f4ea35d4858070301df9bdde1ec3d8932",
"body": "Previous hummingbird work incorrectly marked only the search side\n(data.go) as having a rolling label. Therefore also mark hummingbird as\na rolling distro at database creation time.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(hummingbird): mark hummingbird distro as rolling (#3521)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-22T15:31:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e7b75f4a985d32c4c72d13ac0375eb7f84df233",
"body": "…updates (#3518)\n\nBumps the go-minor-patch group with 2 updates in the / directory: [golang.org/x/text](https://github.com/golang/text) and [golang.org/x/tools](https://github.com/golang/tools).\n\n\nUpdates `golang.org/x/text` from 0.37.0 to 0.38.0\n- [Release notes](https://github.com/golang/text/rele\n[…]\nsion-update:semver-minor\n dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go-minor-patch group across 1 directory with 2 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-19T15:55:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d6dae9d36dcfa1bc37712491fce39f184a94d46a",
"body": "Previously, because GHSA does not cover the go stdlib, in order to avoid\nfalse negatives on the go stdlib, CPE matching had to be used. However,\ngrype now includes the Go Vuln DB data it its database, which does\ninclude the stdlib as if a regular go module, so this CPE fallback can\nbe disabled by default, fixing many false positives.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: disable go stdlib CPE matching by default. (#3517)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-18T21:58:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70d0100826b00860b579f074cf6bcc64758df731",
"body": "* fix(go-vulndb): merge in custom ranges when applicable\n\nGo OSV data has the standard OSV ranges, but also has custom ranges.\nPackages that do non-standard go versioning, for example by pushing a\ntag that starts with v2.x.y but not adding a /v2 in their module path,\nget relegated to the custom rang\n[…]\n custom fields, and some\nreadability refactors.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(go-vulndb): merge in custom ranges when applicable (#3514)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-18T19:41:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9b837c4714944be421d86786c066993516034be",
"body": "Bumps the go-minor-patch group with 1 update in the /.make directory: [github.com/anchore/go-make](https://github.com/anchore/go-make).\n\n\nUpdates `github.com/anchore/go-make` from 0.5.0 to 0.6.0\n- [Release notes](https://github.com/anchore/go-make/releases)\n- [Commits](https://github.com/anchore/go-\n[…]\nsion-update:semver-minor\n dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/anchore/go-make (#3502)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-18T19:08:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "55b3304bcd0e782ec388d933fbd00acbb21073a6",
"body": "* Add OSV Model generator\n\nPreviously, there was an OSV scanner repository that exported a\nmodels.Vulnerability struct we could use. That repository deprecated\ntheir exported models and the models in grype are falling behind.\nTherefore, add a generator target that generates our own models based on\nt\n[…]\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\nCo-authored-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "Add OSV Model generator (#3499)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-16T13:14:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3888f9b7139e44f95120a163180438b8d7690794",
"body": "Signed-off-by: Weston Steimel <author@code.w.steimel.me.uk>",
"is_bot": false,
"headline": "exclude linux-kbuild deb indirect matches by default (#3506)",
"author_name": "Weston Steimel",
"author_login": "westonsteimel",
"committed_at": "2026-06-15T13:16:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f54a905415fb95fa47274f33241d63f4ca55d351",
"body": "…with 7 updates (#3503)\n\nBumps the actions-minor-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anchore/workflows/.github/workflows/codeql.yaml](https://github.com/anchore/workflows) | `0.7.0` | `0.7.2` |\n| [anchore/workflows/.github/workflows/check-ve\n[…]\nupdate:semver-minor\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 2 directories …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-12T15:56:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "77bf6acbbbe42f66e10a8cd81e6b8f6294112c64",
"body": "Signed-off-by: Jeremy Spilman <jeremy.spilman@anchore.com>",
"is_bot": false,
"headline": "fix: avoid panic on invalid RHEL version IDs (#3490)",
"author_name": "Jeremy Spilman",
"author_login": "jspilman",
"committed_at": "2026-06-09T17:39:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3917206e6ff706d66dd511408cea103a7930e3b",
"body": "Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "test: add test fixtures for multi RHSA records from vunnel (#3480)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-09T17:27:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef8e65adb2dec760f1f923e635da4c7696d3c295",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update anchore dependencies (#3487)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-05T15:02:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "024e26b9c93c98861db438076a1df0eb6e911c8d",
"body": "Otherwise we get false positives. Includes a matcher test to assert that\nGrype does not find withdrawn go vulns.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: respect withdrawn status of Go Vuln DB OSV records (#3495)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-04T20:33:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9879170de580886b5ddf6956a084596ceeca17cf",
"body": "Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>",
"is_bot": false,
"headline": "feat(scan): add support for a Zarf scan target (#3366)",
"author_name": "Brandt Keller",
"author_login": "brandtkeller",
"committed_at": "2026-06-04T20:29:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09dcb8c15f6851310d6b95c75a1557a9faf1c43a",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update quality gate database (#3478)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-04T18:58:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c4a53687de01ed3e7d268328fc1a8cbdcae1f05a",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update tool versions (#3488)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-04T18:56:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e47096960cb52efa5d34ba1b9e0d3387412003f",
"body": "* govulndb osv\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* add fixed dates to govulndb osv transformer\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* enforce lowercase ids on cache\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "Govulndb OSV transformer (#3485)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-03T16:08:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0c0312c6f5635816d2612cebf33c5ba8c1afc5e",
"body": "Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "give install script uploader contents: read (#3489)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-03T13:28:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "577c4cd6e4f88649e961c25775c5821c9348d1d0",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update anchore dependencies (#3412)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-02T21:05:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b5af082d64ae634f617cdbfae1d0beb7f40b6c9e",
"body": "Otherwise it doesn't have enough permissions to do its job.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "Pass contents: read to check-gate workflow (#3486)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-02T20:36:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a5ef89bbf52e54b3b2ee2a46dce57a6d68fc8c7",
"body": "* chore: rename rpm_arch to architecture\n\nThis field was initially added to support RPM architecture distinctions\n(especially arch=src), but multiple package types will eventually want\nto have fixes or vulnerabilities that apply to only one architecture.\nSince the field hasn't been released yet, ren\n[…]\nide test code it does not belong in test utils.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: rename rpm_arch to architecture (#3482)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-06-02T15:29:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a1ee6b42e18360031073324d2ecb7b2cca266a00",
"body": "Bumps [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) from 2.3.0 to 2.3.1.\n- [Release notes](https://github.com/containerd/containerd/releases)\n- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)\n- [Commits](https://github.com/containerd/cont\n[…]\n/v2\n dependency-version: 2.3.1\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/containerd/containerd/v2 (#3483)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-02T01:38:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c3b845a5a645023f8db6e93d8b0f8a5eaf36cd05",
"body": "…4 updates (#3473)\n\n* chore(deps): bump the go-minor-patch group across 2 directories with 4 updates\n\nBumps the go-minor-patch group with 3 updates in the / directory: [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go), [github.com/anchore/stereoscope](https://github.com/\n[…]\n8+spiffcs@users.noreply.github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go-minor-patch group across 2 directories with …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-02T01:08:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd26c4097c991a26193fc63e955c98dcadaf56df",
"body": "…ate (#3346)\n\nAdd Grype version (name + version) and vulnerability database metadata\nto the header section of the HTML vulnerability report template, so\nusers can verify the tool and DB versions used to generate the report.\n\nSigned-off-by: hellozzm <hellozzm@users.noreply.github.com>\nCo-authored-by: hellozzm <hellozzm@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: add Grype version and vulnerability DB info to HTML report templ…",
"author_name": "hellozzm",
"author_login": "hellozzm",
"committed_at": "2026-06-01T15:33:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe1ffa81108e40bc6196808ee37c5e2544d31b03",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update tool versions (#3335)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-06-01T14:53:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3792920f0bd6ee833fc3a45603fee3e859ba8741",
"body": "* fix(registry): warn when insecure transport is configured\n\nEmit a one-time warning during config load when either\n`insecure-skip-tls-verify` or `insecure-use-http` is enabled. These\nflags can be set silently via a config file or environment variable\nand produce no indication in normal CLI output t\n[…]\ntry traffic\nis unprotected.\n\nFixes #3101 (grype CLI half; stereoscope debug log to follow as a\nseparate PR per the issue's two-part scope)\n\nSigned-off-by: David Dashti <david.dashti@hermesmedical.com>",
"is_bot": false,
"headline": "fix(registry): warn when insecure transport is configured (#3396)",
"author_name": "David Dashti",
"author_login": "Dashtid",
"committed_at": "2026-06-01T14:50:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53845e1c96951408035f70eb9432c76e245010d2",
"body": "Signed-off-by: msnandhis <45960035+msnandhis@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: support aarch64 ruby gem platforms (#3475)",
"author_name": "Nandhis",
"author_login": "msnandhis",
"committed_at": "2026-06-01T14:45:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5ce71d8b1dcd655cd305b95393db9cb66165ea6",
"body": "Move the regexp.MustCompile call in extractCVSSInfo() from a local\nvariable to a package-level var so the pattern is compiled once at\ninit rather than on every invocation. \n\nSigned-off-by: Matías Insaurralde <matias@insaurral.de>",
"is_bot": false,
"headline": "perf: compile CVSS regex once at package level (#3447)",
"author_name": "Matias Insaurralde",
"author_login": "matiasinsaurralde",
"committed_at": "2026-06-01T14:44:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc0447e1f2b31ccd618da3457454d655ead998f1",
"body": "Ensures that CPEs are only surfaced as platforms if the versionless CPE\nis marked as non-vulnerable across all elements within a candidate node.\nThis prevents unaffected ranges of a package from being marked as a\nplatform of itself.\n\nSigned-off-by: Weston Steimel <author@code.w.steimel.me.uk>",
"is_bot": false,
"headline": "fix: improve platform CPE determination logic (#3470)",
"author_name": "Weston Steimel",
"author_login": "westonsteimel",
"committed_at": "2026-06-01T14:16:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "075eed9f24576e8c1de1b129d2072e76cc6db1a2",
"body": "…th 7 updates (#3471)\n\nBumps the actions-minor-patch group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anchore/workflows/.github/workflows/codeql.yaml](https://github.com/anchore/workflows) | `0.6.0` | `0.7.0` |\n| [anchore/workflows/.github/workflows/check-vers\n[…]\nupdate:semver-patch\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 1 directory wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T19:04:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4f57d03014f6e61fcee7d438cb3732e303debb25",
"body": "Signed-off-by: immanuwell <pchpr.00@list.ru>",
"is_bot": false,
"headline": "fix: normalize uppercase V in semantic version comparison (#3461)",
"author_name": "Immanuel Tikhonov",
"author_login": "immanuwell",
"committed_at": "2026-05-26T01:33:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82044d54c18d21186c5b2ef4721a5c57359e5118",
"body": "…with 3 updates (#3458)\n\nBumps the actions-minor-patch group with 2 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).\nBumps the actions-minor-patch group with 1 update in the /.gith\n[…]\nupdate:semver-minor\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 2 directories …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-22T15:58:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c306be24b0a26ed38bfc0c1602cddb6e99815623",
"body": "Bumps [github.com/containerd/containerd/v2](https://github.com/containerd/containerd) from 2.2.2 to 2.2.4.\n- [Release notes](https://github.com/containerd/containerd/releases)\n- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)\n- [Commits](https://github.com/containerd/cont\n[…]\n/v2\n dependency-version: 2.2.4\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/containerd/containerd/v2 (#3457)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T22:25:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a345ece29f37527158daacae2ca87d85502b34ef",
"body": "* Add Root IO vulnerability qualifier support\n\n Adds support for Root IO package qualification to enable the NAK\n (Negative Acknowledgment) pattern, where vulnerabilities with Root IO\n qualifier only match Root IO patched packages.\n\n Implementation:\n - Add RootIO field to PackageQualifiers in g\n[…]\n-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\nCo-authored-by: Alex Goodman <wagoodman@users.noreply.github.com>\nCo-authored-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "Add Root IO vulnerability qualifier support (#3137)",
"author_name": "chait-slim",
"author_login": "chait-slim",
"committed_at": "2026-05-20T15:01:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e760f4a5fbfcc8c83327b0615a12b10a01530fd7",
"body": "…#3454)\n\nBumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.19.0 to 5.19.1.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.19.0...v5.19\n[…]\nv5\n dependency-version: 5.19.1\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-19T16:34:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "95573073808c689e4214d893a6de66e274b0de96",
"body": "* remove slack notification on release\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\n\n* deal with cache and permissions usage\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "Remediate audit (#3451)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-05-18T19:20:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "445f5b7b24ed141b72a6e62280ce15387a281ee3",
"body": "…th 4 updates (#3449)\n\nBumps the actions-minor-patch group with 4 updates in the / directory: [anchore/workflows/.github/workflows/codeql.yaml](https://github.com/anchore/workflows), [anchore/workflows/.github/workflows/check-version-available.yaml](https://github.com/anchore/workflows), [anchore/wo\n[…]\nupdate:semver-minor\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 1 directory wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-18T16:39:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "052e55cc1b4ae3c388151c364b7bbc47077cb1ec",
"body": "…updates (#3448)\n\nBumps the go-minor-patch group with 2 updates in the / directory: [golang.org/x/text](https://github.com/golang/text) and [golang.org/x/tools](https://github.com/golang/tools).\n\n\nUpdates `golang.org/x/text` from 0.36.0 to 0.37.0\n- [Release notes](https://github.com/golang/text/rele\n[…]\nsion-update:semver-minor\n dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go-minor-patch group across 1 directory with 2 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-18T16:38:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc1377ff22415a47aa6d649ab17781f394bd9a72",
"body": "Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "port to go-make (#3446)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-05-18T16:00:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82d4c7a95f62b4be7ce2340830c264f275967da5",
"body": "…th 2 updates (#3444)\n\nBumps the actions-minor-patch group with 2 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action) and [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer).\n\n\nUpdates `github/codeql-action` from 4.35.3 to 4.35.4\n- [Relea\n[…]\nupdate:semver-patch\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 1 directory wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-15T15:58:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "03cbb5f8457cb6bccc4d5f92d0ec9f6651710dfe",
"body": "* test(bitnami): add dbtest style tests to bitnami matcher\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* refactor OSV transformer to use strategy per provider\n\nDifferent OSV providers are less uniform than different providers in\nother schemas, and OSV requires that identi\n[…]\nlper surface and move tests into separate files\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "OSV strategy pattern (#3441)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-05-13T18:05:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c59477eb0f8ab672d1a4777dc2fdab94f8dcb77",
"body": "…ut (#3271)\n\n* Fix finding description\n\nSigned-off-by: Stepan Dolgintsev <stepworm@yandex.ru>\n\n* chore: lint fix\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Stepan Dolgintsev <stepworm@yandex.ru>\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\nCo-authored-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: use relatedVulnerabilities description as fallback in SARIF outp…",
"author_name": "Stepan",
"author_login": "axidex",
"committed_at": "2026-05-13T17:12:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d0e03b4864ef831820d498db44507d526799f24",
"body": "Add dbtest style SLES tests and exercise SLES NAKs via this pattern.\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: exercise SLES NAKs via dbtest style tests in RPM matcher (#3421)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-05-12T17:38:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "14dc722c82850d4aedad45d028686ba6ca36feac",
"body": "Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "use released shared workflow (#3439)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-05-11T20:22:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba3b9a5b50e9b22505d1f0da39a461ff205709f9",
"body": "…#3438)\n\nBumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.18.0 to 5.19.0.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.18.0...v5.19\n[…]\nv5\n dependency-version: 5.19.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-11T16:26:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b26aa2aa40614bfbdd9798aaeb884646cc9534c",
"body": "Signed-off-by: Brandt Keller <brandt.keller@defenseunicorns.com>",
"is_bot": false,
"headline": "fix(cli): enable autocompletion for zsh (#3433)",
"author_name": "Brandt Keller",
"author_login": "brandtkeller",
"committed_at": "2026-05-09T16:16:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70459ffae47896d507a283e496936a545ebbb191",
"body": "* Tighten workflow-level permissions and modernize release gate\n\nReplace the bespoke quality-gate job in release.yaml with the canonical\ncheck-version-available + check-gate reusable workflows. Remove the\nskip_quality_gate bypass input. Set top-level permissions: {} across\nrelease.yaml, validate-git\n[…]\nly.github.com>\n\n* correct validations to check on release\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "Tighten workflow-level permissions and modernize release gate (#3434)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-05-08T21:03:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5fa2d2d25b8238a184a195f4769b5e5a77532d7c",
"body": "…th 2 updates (#3431)\n\nBumps the actions-minor-patch group with 2 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action) and [slackapi/slack-github-action](https://github.com/slackapi/slack-github-action).\n\n\nUpdates `github/codeql-action` from 4.35.2 to 4.35.3\n- \n[…]\nupdate:semver-patch\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 1 directory wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T15:59:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "28ad56743aafd6ec153b85fbda4e38a3cb606185",
"body": "Bumps the go-minor-patch group with 3 updates: [github.com/Masterminds/semver/v3](https://github.com/Masterminds/semver), [github.com/gookit/color](https://github.com/gookit/color) and [github.com/klauspost/compress](https://github.com/klauspost/compress).\n\n\nUpdates `github.com/Masterminds/semver/v3\n[…]\nsion-update:semver-patch\n dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go-minor-patch group with 3 updates (#3430)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T15:55:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ffc0abfef07f9adf5a7a11148f7a4e4f362872a9",
"body": "Signed-off-by: wasp-yash <trooper0018080@gmail.com>\nSigned-off-by: Keith Zantow <kzantow@gmail.com>\nCo-authored-by: Keith Zantow <kzantow@gmail.com>",
"is_bot": false,
"headline": "fix: version comparison with case-insensitive v prefix (#3089)",
"author_name": "Yash",
"author_login": "wasup-yash",
"committed_at": "2026-05-07T16:57:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e149729cfd11fd04e9863d405530a5beae9b22ba",
"body": "Signed-off-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>\nCo-authored-by: anchore-oss-update-bot <anchore-oss-update-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps): update quality gate database (#3407)",
"author_name": "anchore-oss-update-bot",
"author_login": "anchore-oss-update-bot",
"committed_at": "2026-05-05T15:41:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b8f6fcc85b636105dd6abf2fcc2df433b297c9d",
"body": "Bumps the go-minor-patch group with 1 update: [github.com/invopop/jsonschema](https://github.com/invopop/jsonschema).\n\n\nUpdates `github.com/invopop/jsonschema` from 0.13.0 to 0.14.0\n- [Release notes](https://github.com/invopop/jsonschema/releases)\n- [Commits](https://github.com/invopop/jsonschema/co\n[…]\nsion-update:semver-minor\n dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/invopop/jsonschema (#3408)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-05T15:41:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee62ea12b834cb1b3b9915914ebf3ba3bc64540a",
"body": "…with 4 updates (#3409)\n\nBumps the actions-minor-patch group with 4 updates in the / directory: [github/codeql-action](https://github.com/github/codeql-action), [slackapi/slack-github-action](https://github.com/slackapi/slack-github-action), [zizmorcore/zizmor-action](https://github.com/zizmorcore/z\n[…]\nupdate:semver-patch\n dependency-group: actions-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the actions-minor-patch group across 2 directories …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-05T15:40:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b040d341b04853c6a6a9ef59724660fdcc5f003f",
"body": "* chore: test cgr maven via dbtest\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* chore: better tests for cgr maven libs\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: purl handling in cgr maven libs (#3420)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-05-05T13:22:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3154f49362819c3dd6ff74322705ece3f6f81c13",
"body": "* migrate language matchers to ghsa\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* more language matcher tests\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n* add cgr libs test case\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>\n\n---------\n\nSigned-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: test language matchers via new dbtest pattern (#3419)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-05-04T20:53:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "194d6aae96c7aae08c83eba5f6b37d6ac176af3b",
"body": "Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: migrate apk matcher to dbtest pattern (#3418)",
"author_name": "Will Murphy",
"author_login": "willmurphyscode",
"committed_at": "2026-05-04T20:18:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f6bdc5b68ebc58c49d076b67ddfbced94c002df",
"body": "Removes deprecated common workflows now centralized elsewhere.\n\nSigned-off-by: Alex Goodman <wagoodman@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: remove common workflows (#3417)",
"author_name": "Alex Goodman",
"author_login": "wagoodman",
"committed_at": "2026-05-04T18:31:21Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 100,
"commits_last_year": 459,
"latest_release_at": "2026-07-16T16:52:20Z",
"latest_release_tag": "v0.116.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 50,
"days_since_latest_release": 6,
"mean_days_between_releases": 16.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/anchore/grype",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/anchore/grype",
"is_deprecated": false,
"latest_version": "v0.116.0",
"repository_url": "https://github.com/anchore/grype",
"versions_count": 209,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-16T16:02:15Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 833,
"stars": 12620,
"watchers": 82,
"fork_history": {
"days": [
{
"date": "2020-10-07",
"count": 1
},
{
"date": "2020-10-09",
"count": 1
},
{
"date": "2020-10-14",
"count": 1
},
{
"date": "2020-10-28",
"count": 2
},
{
"date": "2020-10-29",
"count": 1
},
{
"date": "2020-10-30",
"count": 3
},
{
"date": "2020-10-31",
"count": 2
},
{
"date": "2020-11-09",
"count": 1
},
{
"date": "2020-11-12",
"count": 1
},
{
"date": "2020-11-18",
"count": 1
},
{
"date": "2020-11-20",
"count": 2
},
{
"date": "2020-11-25",
"count": 1
},
{
"date": "2020-12-11",
"count": 1
},
{
"date": "2020-12-20",
"count": 1
},
{
"date": "2021-01-20",
"count": 1
},
{
"date": "2021-01-22",
"count": 2
},
{
"date": "2021-01-31",
"count": 1
},
{
"date": "2021-02-04",
"count": 1
},
{
"date": "2021-03-02",
"count": 1
},
{
"date": "2021-03-11",
"count": 2
},
{
"date": "2021-03-14",
"count": 1
},
{
"date": "2021-04-06",
"count": 1
},
{
"date": "2021-04-12",
"count": 1
},
{
"date": "2021-04-15",
"count": 1
},
{
"date": "2021-04-17",
"count": 1
},
{
"date": "2021-04-19",
"count": 2
},
{
"date": "2021-04-20",
"count": 4
},
{
"date": "2021-04-22",
"count": 2
},
{
"date": "2021-04-25",
"count": 1
},
{
"date": "2021-04-26",
"count": 1
},
{
"date": "2021-04-27",
"count": 1
},
{
"date": "2021-05-12",
"count": 1
},
{
"date": "2021-05-19",
"count": 1
},
{
"date": "2021-05-24",
"count": 2
},
{
"date": "2021-05-28",
"count": 1
},
{
"date": "2021-06-04",
"count": 1
},
{
"date": "2021-06-06",
"count": 2
},
{
"date": "2021-06-16",
"count": 1
},
{
"date": "2021-06-19",
"count": 1
},
{
"date": "2021-06-20",
"count": 1
},
{
"date": "2021-06-23",
"count": 1
},
{
"date": "2021-06-28",
"count": 1
},
{
"date": "2021-07-01",
"count": 1
},
{
"date": "2021-07-05",
"count": 1
},
{
"date": "2021-07-07",
"count": 1
},
{
"date": "2021-07-12",
"count": 1
},
{
"date": "2021-07-16",
"count": 1
},
{
"date": "2021-07-25",
"count": 1
},
{
"date": "2021-07-27",
"count": 1
},
{
"date": "2021-07-28",
"count": 3
},
{
"date": "2021-07-30",
"count": 1
},
{
"date": "2021-08-12",
"count": 1
},
{
"date": "2021-08-13",
"count": 1
},
{
"date": "2021-08-25",
"count": 1
},
{
"date": "2021-08-30",
"count": 1
},
{
"date": "2021-09-15",
"count": 2
},
{
"date": "2021-09-16",
"count": 1
},
{
"date": "2021-09-17",
"count": 1
},
{
"date": "2021-09-22",
"count": 1
},
{
"date": "2021-09-27",
"count": 1
},
{
"date": "2021-10-10",
"count": 1
},
{
"date": "2021-10-12",
"count": 1
},
{
"date": "2021-10-13",
"count": 1
},
{
"date": "2021-10-23",
"count": 1
},
{
"date": "2021-10-24",
"count": 2
},
{
"date": "2021-10-25",
"count": 2
},
{
"date": "2021-10-27",
"count": 1
},
{
"date": "2021-10-29",
"count": 1
},
{
"date": "2021-10-31",
"count": 2
},
{
"date": "2021-11-03",
"count": 1
},
{
"date": "2021-11-10",
"count": 1
},
{
"date": "2021-11-14",
"count": 1
},
{
"date": "2021-11-17",
"count": 1
},
{
"date": "2021-11-18",
"count": 1
},
{
"date": "2021-11-19",
"count": 1
},
{
"date": "2021-11-21",
"count": 1
},
{
"date": "2021-11-22",
"count": 1
},
{
"date": "2021-11-23",
"count": 2
},
{
"date": "2021-12-02",
"count": 1
},
{
"date": "2021-12-03",
"count": 1
},
{
"date": "2021-12-04",
"count": 2
},
{
"date": "2021-12-06",
"count": 1
},
{
"date": "2021-12-07",
"count": 1
},
{
"date": "2021-12-11",
"count": 1
},
{
"date": "2021-12-12",
"count": 1
},
{
"date": "2021-12-13",
"count": 3
},
{
"date": "2021-12-14",
"count": 4
},
{
"date": "2021-12-15",
"count": 11
},
{
"date": "2021-12-17",
"count": 2
},
{
"date": "2021-12-19",
"count": 1
},
{
"date": "2021-12-20",
"count": 3
},
{
"date": "2021-12-21",
"count": 2
},
{
"date": "2021-12-22",
"count": 1
},
{
"date": "2021-12-23",
"count": 1
},
{
"date": "2021-12-24",
"count": 1
},
{
"date": "2021-12-29",
"count": 1
},
{
"date": "2022-01-05",
"count": 2
},
{
"date": "2022-01-07",
"count": 3
},
{
"date": "2022-01-11",
"count": 3
},
{
"date": "2022-01-12",
"count": 1
},
{
"date": "2022-01-13",
"count": 1
},
{
"date": "2022-01-14",
"count": 2
},
{
"date": "2022-01-16",
"count": 1
},
{
"date": "2022-01-24",
"count": 2
},
{
"date": "2022-01-25",
"count": 1
},
{
"date": "2022-01-27",
"count": 1
},
{
"date": "2022-01-28",
"count": 1
},
{
"date": "2022-02-01",
"count": 1
},
{
"date": "2022-02-02",
"count": 1
},
{
"date": "2022-02-05",
"count": 2
},
{
"date": "2022-02-09",
"count": 2
},
{
"date": "2022-02-10",
"count": 1
},
{
"date": "2022-02-18",
"count": 2
},
{
"date": "2022-02-20",
"count": 1
},
{
"date": "2022-02-22",
"count": 1
},
{
"date": "2022-02-23",
"count": 1
},
{
"date": "2022-02-28",
"count": 1
},
{
"date": "2022-03-03",
"count": 1
},
{
"date": "2022-03-04",
"count": 1
},
{
"date": "2022-03-07",
"count": 1
},
{
"date": "2022-03-08",
"count": 2
},
{
"date": "2022-03-09",
"count": 5
},
{
"date": "2022-03-11",
"count": 3
},
{
"date": "2022-03-12",
"count": 1
},
{
"date": "2022-03-14",
"count": 1
},
{
"date": "2022-03-17",
"count": 1
},
{
"date": "2022-03-19",
"count": 1
},
{
"date": "2022-03-21",
"count": 1
},
{
"date": "2022-03-22",
"count": 1
},
{
"date": "2022-03-24",
"count": 1
},
{
"date": "2022-03-25",
"count": 1
},
{
"date": "2022-03-28",
"count": 1
},
{
"date": "2022-03-29",
"count": 3
},
{
"date": "2022-03-30",
"count": 1
},
{
"date": "2022-04-01",
"count": 2
},
{
"date": "2022-04-03",
"count": 1
},
{
"date": "2022-04-06",
"count": 1
},
{
"date": "2022-04-07",
"count": 1
},
{
"date": "2022-04-08",
"count": 1
},
{
"date": "2022-04-09",
"count": 1
},
{
"date": "2022-04-10",
"count": 1
},
{
"date": "2022-04-12",
"count": 2
},
{
"date": "2022-04-13",
"count": 1
},
{
"date": "2022-04-15",
"count": 1
},
{
"date": "2022-04-18",
"count": 1
},
{
"date": "2022-04-19",
"count": 1
},
{
"date": "2022-04-20",
"count": 3
},
{
"date": "2022-04-21",
"count": 1
},
{
"date": "2022-04-23",
"count": 1
},
{
"date": "2022-04-24",
"count": 1
},
{
"date": "2022-04-25",
"count": 1
},
{
"date": "2022-04-28",
"count": 1
},
{
"date": "2022-04-29",
"count": 1
},
{
"date": "2022-05-01",
"count": 1
},
{
"date": "2022-05-07",
"count": 1
},
{
"date": "2022-05-10",
"count": 3
},
{
"date": "2022-05-17",
"count": 1
},
{
"date": "2022-05-19",
"count": 1
},
{
"date": "2022-05-25",
"count": 2
},
{
"date": "2022-05-26",
"count": 1
},
{
"date": "2022-05-27",
"count": 1
},
{
"date": "2022-05-28",
"count": 1
},
{
"date": "2022-05-31",
"count": 1
},
{
"date": "2022-06-01",
"count": 1
},
{
"date": "2022-06-02",
"count": 1
},
{
"date": "2022-06-04",
"count": 1
},
{
"date": "2022-06-09",
"count": 1
},
{
"date": "2022-06-10",
"count": 3
},
{
"date": "2022-06-14",
"count": 1
},
{
"date": "2022-06-15",
"count": 1
},
{
"date": "2022-06-17",
"count": 1
},
{
"date": "2022-06-18",
"count": 1
},
{
"date": "2022-06-19",
"count": 1
},
{
"date": "2022-06-20",
"count": 1
},
{
"date": "2022-06-22",
"count": 1
},
{
"date": "2022-06-29",
"count": 1
},
{
"date": "2022-07-04",
"count": 1
},
{
"date": "2022-07-05",
"count": 1
},
{
"date": "2022-07-06",
"count": 2
},
{
"date": "2022-07-12",
"count": 1
},
{
"date": "2022-07-21",
"count": 1
},
{
"date": "2022-07-27",
"count": 2
},
{
"date": "2022-08-06",
"count": 1
},
{
"date": "2022-08-08",
"count": 1
},
{
"date": "2022-08-09",
"count": 1
},
{
"date": "2022-08-12",
"count": 1
},
{
"date": "2022-08-13",
"count": 1
},
{
"date": "2022-08-16",
"count": 1
},
{
"date": "2022-08-17",
"count": 1
},
{
"date": "2022-08-18",
"count": 1
},
{
"date": "2022-08-19",
"count": 3
},
{
"date": "2022-08-21",
"count": 1
},
{
"date": "2022-08-22",
"count": 1
},
{
"date": "2022-08-24",
"count": 1
},
{
"date": "2022-08-26",
"count": 1
},
{
"date": "2022-08-31",
"count": 1
},
{
"date": "2022-09-02",
"count": 1
},
{
"date": "2022-09-03",
"count": 1
},
{
"date": "2022-09-06",
"count": 1
},
{
"date": "2022-09-13",
"count": 1
},
{
"date": "2022-09-14",
"count": 1
},
{
"date": "2022-09-18",
"count": 1
},
{
"date": "2022-09-19",
"count": 1
},
{
"date": "2022-09-20",
"count": 1
},
{
"date": "2022-09-22",
"count": 1
},
{
"date": "2022-10-04",
"count": 1
},
{
"date": "2022-10-07",
"count": 1
},
{
"date": "2022-10-19",
"count": 1
},
{
"date": "2022-10-20",
"count": 1
},
{
"date": "2022-10-22",
"count": 1
},
{
"date": "2022-10-23",
"count": 1
},
{
"date": "2022-10-24",
"count": 1
},
{
"date": "2022-10-28",
"count": 1
},
{
"date": "2022-11-01",
"count": 2
},
{
"date": "2022-11-03",
"count": 1
},
{
"date": "2022-11-04",
"count": 2
},
{
"date": "2022-11-11",
"count": 1
},
{
"date": "2022-11-12",
"count": 1
},
{
"date": "2022-11-15",
"count": 1
},
{
"date": "2022-11-18",
"count": 1
},
{
"date": "2022-11-21",
"count": 1
},
{
"date": "2022-12-01",
"count": 1
},
{
"date": "2022-12-06",
"count": 1
},
{
"date": "2022-12-08",
"count": 1
},
{
"date": "2022-12-09",
"count": 1
},
{
"date": "2022-12-10",
"count": 1
},
{
"date": "2022-12-13",
"count": 2
},
{
"date": "2022-12-15",
"count": 1
},
{
"date": "2022-12-16",
"count": 1
},
{
"date": "2022-12-20",
"count": 1
},
{
"date": "2022-12-21",
"count": 1
},
{
"date": "2022-12-23",
"count": 1
},
{
"date": "2022-12-24",
"count": 1
},
{
"date": "2022-12-25",
"count": 1
},
{
"date": "2022-12-28",
"count": 2
},
{
"date": "2023-01-02",
"count": 1
},
{
"date": "2023-01-06",
"count": 1
},
{
"date": "2023-01-11",
"count": 1
},
{
"date": "2023-01-12",
"count": 1
},
{
"date": "2023-01-22",
"count": 1
},
{
"date": "2023-01-26",
"count": 1
},
{
"date": "2023-01-27",
"count": 1
},
{
"date": "2023-01-28",
"count": 1
},
{
"date": "2023-01-30",
"count": 1
},
{
"date": "2023-01-31",
"count": 1
},
{
"date": "2023-02-01",
"count": 1
},
{
"date": "2023-02-02",
"count": 2
},
{
"date": "2023-02-14",
"count": 2
},
{
"date": "2023-02-15",
"count": 1
},
{
"date": "2023-02-16",
"count": 1
},
{
"date": "2023-02-22",
"count": 1
},
{
"date": "2023-02-27",
"count": 1
},
{
"date": "2023-03-02",
"count": 2
},
{
"date": "2023-03-07",
"count": 2
},
{
"date": "2023-03-13",
"count": 1
},
{
"date": "2023-03-14",
"count": 1
},
{
"date": "2023-03-19",
"count": 2
},
{
"date": "2023-03-21",
"count": 1
},
{
"date": "2023-04-01",
"count": 1
},
{
"date": "2023-04-03",
"count": 1
},
{
"date": "2023-04-07",
"count": 1
},
{
"date": "2023-04-08",
"count": 1
},
{
"date": "2023-04-09",
"count": 1
},
{
"date": "2023-04-10",
"count": 1
},
{
"date": "2023-04-13",
"count": 1
},
{
"date": "2023-04-20",
"count": 2
},
{
"date": "2023-04-23",
"count": 1
},
{
"date": "2023-04-26",
"count": 1
},
{
"date": "2023-04-27",
"count": 1
},
{
"date": "2023-05-04",
"count": 1
},
{
"date": "2023-05-09",
"count": 1
},
{
"date": "2023-05-11",
"count": 1
},
{
"date": "2023-05-15",
"count": 1
},
{
"date": "2023-05-21",
"count": 1
},
{
"date": "2023-05-22",
"count": 1
},
{
"date": "2023-05-26",
"count": 2
},
{
"date": "2023-05-31",
"count": 1
},
{
"date": "2023-06-02",
"count": 1
},
{
"date": "2023-06-05",
"count": 1
},
{
"date": "2023-06-15",
"count": 1
},
{
"date": "2023-06-16",
"count": 1
},
{
"date": "2023-06-19",
"count": 1
},
{
"date": "2023-06-21",
"count": 1
},
{
"date": "2023-06-28",
"count": 1
},
{
"date": "2023-06-29",
"count": 1
},
{
"date": "2023-07-06",
"count": 2
},
{
"date": "2023-07-07",
"count": 1
},
{
"date": "2023-07-17",
"count": 2
},
{
"date": "2023-07-18",
"count": 1
},
{
"date": "2023-07-25",
"count": 3
},
{
"date": "2023-07-27",
"count": 1
},
{
"date": "2023-07-30",
"count": 1
},
{
"date": "2023-07-31",
"count": 2
},
{
"date": "2023-08-08",
"count": 2
},
{
"date": "2023-08-10",
"count": 2
},
{
"date": "2023-08-12",
"count": 1
},
{
"date": "2023-08-15",
"count": 1
},
{
"date": "2023-08-27",
"count": 1
},
{
"date": "2023-09-01",
"count": 1
},
{
"date": "2023-09-07",
"count": 1
},
{
"date": "2023-09-15",
"count": 3
},
{
"date": "2023-09-18",
"count": 1
},
{
"date": "2023-09-23",
"count": 1
},
{
"date": "2023-09-24",
"count": 1
},
{
"date": "2023-09-25",
"count": 2
},
{
"date": "2023-09-30",
"count": 1
},
{
"date": "2023-10-01",
"count": 1
},
{
"date": "2023-10-04",
"count": 1
},
{
"date": "2023-10-11",
"count": 2
},
{
"date": "2023-10-15",
"count": 1
},
{
"date": "2023-10-16",
"count": 1
},
{
"date": "2023-10-21",
"count": 1
},
{
"date": "2023-10-26",
"count": 1
},
{
"date": "2023-11-14",
"count": 1
},
{
"date": "2023-11-17",
"count": 1
},
{
"date": "2023-11-24",
"count": 1
},
{
"date": "2023-11-28",
"count": 1
},
{
"date": "2023-12-02",
"count": 1
},
{
"date": "2023-12-21",
"count": 1
},
{
"date": "2023-12-27",
"count": 1
},
{
"date": "2023-12-28",
"count": 1
},
{
"date": "2023-12-30",
"count": 2
},
{
"date": "2024-01-02",
"count": 3
},
{
"date": "2024-01-03",
"count": 2
},
{
"date": "2024-01-08",
"count": 2
},
{
"date": "2024-01-11",
"count": 1
},
{
"date": "2024-01-12",
"count": 1
},
{
"date": "2024-01-14",
"count": 1
},
{
"date": "2024-01-17",
"count": 1
},
{
"date": "2024-01-25",
"count": 1
},
{
"date": "2024-01-27",
"count": 1
},
{
"date": "2024-02-02",
"count": 1
},
{
"date": "2024-02-03",
"count": 1
},
{
"date": "2024-02-07",
"count": 1
},
{
"date": "2024-02-10",
"count": 1
},
{
"date": "2024-02-11",
"count": 1
},
{
"date": "2024-02-12",
"count": 1
},
{
"date": "2024-02-14",
"count": 1
},
{
"date": "2024-02-15",
"count": 1
},
{
"date": "2024-02-17",
"count": 1
},
{
"date": "2024-02-23",
"count": 1
},
{
"date": "2024-02-26",
"count": 1
},
{
"date": "2024-02-29",
"count": 1
},
{
"date": "2024-03-04",
"count": 1
},
{
"date": "2024-03-19",
"count": 1
},
{
"date": "2024-04-02",
"count": 1
},
{
"date": "2024-04-03",
"count": 1
},
{
"date": "2024-04-11",
"count": 1
},
{
"date": "2024-04-14",
"count": 1
},
{
"date": "2024-04-16",
"count": 2
},
{
"date": "2024-04-17",
"count": 1
},
{
"date": "2024-04-18",
"count": 1
},
{
"date": "2024-04-19",
"count": 1
},
{
"date": "2024-04-22",
"count": 1
},
{
"date": "2024-04-25",
"count": 1
},
{
"date": "2024-04-30",
"count": 1
},
{
"date": "2024-05-01",
"count": 3
},
{
"date": "2024-05-03",
"count": 1
},
{
"date": "2024-05-07",
"count": 1
},
{
"date": "2024-05-10",
"count": 3
},
{
"date": "2024-05-11",
"count": 2
},
{
"date": "2024-05-12",
"count": 2
},
{
"date": "2024-05-13",
"count": 4
},
{
"date": "2024-05-22",
"count": 1
},
{
"date": "2024-05-23",
"count": 1
},
{
"date": "2024-06-08",
"count": 2
},
{
"date": "2024-06-11",
"count": 2
},
{
"date": "2024-06-12",
"count": 1
},
{
"date": "2024-06-16",
"count": 1
},
{
"date": "2024-06-19",
"count": 2
},
{
"date": "2024-06-23",
"count": 1
},
{
"date": "2024-06-24",
"count": 1
},
{
"date": "2024-06-26",
"count": 1
},
{
"date": "2024-06-30",
"count": 1
},
{
"date": "2024-07-01",
"count": 2
},
{
"date": "2024-07-03",
"count": 2
},
{
"date": "2024-07-07",
"count": 1
},
{
"date": "2024-07-12",
"count": 1
},
{
"date": "2024-07-15",
"count": 1
},
{
"date": "2024-07-18",
"count": 1
},
{
"date": "2024-07-19",
"count": 2
},
{
"date": "2024-07-23",
"count": 1
},
{
"date": "2024-07-24",
"count": 1
},
{
"date": "2024-07-25",
"count": 1
},
{
"date": "2024-07-30",
"count": 1
},
{
"date": "2024-08-04",
"count": 1
},
{
"date": "2024-08-07",
"count": 1
},
{
"date": "2024-08-13",
"count": 2
},
{
"date": "2024-08-19",
"count": 1
},
{
"date": "2024-08-20",
"count": 1
},
{
"date": "2024-08-22",
"count": 1
},
{
"date": "2024-08-27",
"count": 1
},
{
"date": "2024-08-29",
"count": 1
},
{
"date": "2024-08-31",
"count": 1
},
{
"date": "2024-09-08",
"count": 1
},
{
"date": "2024-09-10",
"count": 1
},
{
"date": "2024-09-11",
"count": 1
},
{
"date": "2024-09-13",
"count": 1
},
{
"date": "2024-09-18",
"count": 2
},
{
"date": "2024-09-26",
"count": 1
},
{
"date": "2024-09-28",
"count": 1
},
{
"date": "2024-10-02",
"count": 2
},
{
"date": "2024-10-03",
"count": 1
},
{
"date": "2024-10-05",
"count": 1
},
{
"date": "2024-10-07",
"count": 1
},
{
"date": "2024-10-16",
"count": 1
},
{
"date": "2024-10-20",
"count": 1
},
{
"date": "2024-10-21",
"count": 1
},
{
"date": "2024-10-22",
"count": 2
},
{
"date": "2024-10-23",
"count": 1
},
{
"date": "2024-10-26",
"count": 1
},
{
"date": "2024-10-27",
"count": 1
},
{
"date": "2024-10-29",
"count": 1
},
{
"date": "2024-11-02",
"count": 2
},
{
"date": "2024-11-08",
"count": 1
},
{
"date": "2024-11-11",
"count": 1
},
{
"date": "2024-11-12",
"count": 2
},
{
"date": "2024-11-15",
"count": 2
},
{
"date": "2024-11-18",
"count": 1
},
{
"date": "2024-11-25",
"count": 1
},
{
"date": "2024-11-26",
"count": 1
},
{
"date": "2024-12-02",
"count": 1
},
{
"date": "2024-12-10",
"count": 1
},
{
"date": "2024-12-11",
"count": 1
},
{
"date": "2024-12-12",
"count": 1
},
{
"date": "2024-12-13",
"count": 1
},
{
"date": "2024-12-15",
"count": 1
},
{
"date": "2024-12-16",
"count": 2
},
{
"date": "2024-12-18",
"count": 1
},
{
"date": "2024-12-21",
"count": 1
},
{
"date": "2024-12-24",
"count": 2
},
{
"date": "2024-12-26",
"count": 1
},
{
"date": "2024-12-28",
"count": 1
},
{
"date": "2025-01-02",
"count": 1
},
{
"date": "2025-01-04",
"count": 1
},
{
"date": "2025-01-05",
"count": 1
},
{
"date": "2025-01-08",
"count": 1
},
{
"date": "2025-01-17",
"count": 1
},
{
"date": "2025-01-18",
"count": 1
},
{
"date": "2025-01-19",
"count": 2
},
{
"date": "2025-01-20",
"count": 1
},
{
"date": "2025-01-23",
"count": 1
},
{
"date": "2025-02-13",
"count": 1
},
{
"date": "2025-02-14",
"count": 1
},
{
"date": "2025-02-15",
"count": 1
},
{
"date": "2025-02-20",
"count": 1
},
{
"date": "2025-02-25",
"count": 1
},
{
"date": "2025-02-26",
"count": 2
},
{
"date": "2025-03-06",
"count": 2
},
{
"date": "2025-03-17",
"count": 2
},
{
"date": "2025-03-18",
"count": 2
},
{
"date": "2025-03-21",
"count": 2
},
{
"date": "2025-03-24",
"count": 1
},
{
"date": "2025-03-29",
"count": 1
},
{
"date": "2025-04-04",
"count": 1
},
{
"date": "2025-04-09",
"count": 2
},
{
"date": "2025-04-10",
"count": 2
},
{
"date": "2025-04-18",
"count": 1
},
{
"date": "2025-04-26",
"count": 1
},
{
"date": "2025-04-29",
"count": 2
},
{
"date": "2025-04-30",
"count": 3
},
{
"date": "2025-05-02",
"count": 2
},
{
"date": "2025-05-05",
"count": 2
},
{
"date": "2025-05-10",
"count": 1
},
{
"date": "2025-05-13",
"count": 3
},
{
"date": "2025-05-23",
"count": 1
},
{
"date": "2025-05-25",
"count": 2
},
{
"date": "2025-05-30",
"count": 1
},
{
"date": "2025-06-06",
"count": 1
},
{
"date": "2025-06-10",
"count": 2
},
{
"date": "2025-06-17",
"count": 1
},
{
"date": "2025-06-19",
"count": 1
},
{
"date": "2025-06-25",
"count": 2
},
{
"date": "2025-06-26",
"count": 1
},
{
"date": "2025-06-28",
"count": 1
},
{
"date": "2025-06-30",
"count": 1
},
{
"date": "2025-07-01",
"count": 1
},
{
"date": "2025-07-07",
"count": 1
},
{
"date": "2025-07-08",
"count": 1
},
{
"date": "2025-07-13",
"count": 1
},
{
"date": "2025-07-14",
"count": 1
},
{
"date": "2025-07-15",
"count": 1
},
{
"date": "2025-07-16",
"count": 2
},
{
"date": "2025-07-17",
"count": 2
},
{
"date": "2025-07-18",
"count": 1
},
{
"date": "2025-07-19",
"count": 1
},
{
"date": "2025-07-23",
"count": 1
},
{
"date": "2025-07-24",
"count": 1
},
{
"date": "2025-07-27",
"count": 1
},
{
"date": "2025-07-29",
"count": 1
},
{
"date": "2025-07-30",
"count": 2
},
{
"date": "2025-08-01",
"count": 1
},
{
"date": "2025-08-05",
"count": 1
},
{
"date": "2025-08-08",
"count": 1
},
{
"date": "2025-08-14",
"count": 1
},
{
"date": "2025-08-15",
"count": 1
},
{
"date": "2025-08-16",
"count": 1
},
{
"date": "2025-08-20",
"count": 1
},
{
"date": "2025-08-21",
"count": 2
},
{
"date": "2025-08-23",
"count": 1
},
{
"date": "2025-08-26",
"count": 1
},
{
"date": "2025-08-29",
"count": 1
},
{
"date": "2025-09-02",
"count": 1
},
{
"date": "2025-09-03",
"count": 1
},
{
"date": "2025-09-06",
"count": 1
},
{
"date": "2025-09-09",
"count": 2
},
{
"date": "2025-09-11",
"count": 1
},
{
"date": "2025-09-16",
"count": 1
},
{
"date": "2025-09-22",
"count": 1
},
{
"date": "2025-09-23",
"count": 1
},
{
"date": "2025-10-05",
"count": 2
},
{
"date": "2025-10-08",
"count": 1
},
{
"date": "2025-10-10",
"count": 1
},
{
"date": "2025-10-11",
"count": 1
},
{
"date": "2025-10-14",
"count": 1
},
{
"date": "2025-10-15",
"count": 1
},
{
"date": "2025-10-16",
"count": 2
},
{
"date": "2025-10-20",
"count": 1
},
{
"date": "2025-10-21",
"count": 1
},
{
"date": "2025-10-23",
"count": 1
},
{
"date": "2025-10-25",
"count": 1
},
{
"date": "2025-10-28",
"count": 1
},
{
"date": "2025-10-30",
"count": 1
},
{
"date": "2025-11-03",
"count": 4
},
{
"date": "2025-11-05",
"count": 1
},
{
"date": "2025-11-10",
"count": 1
},
{
"date": "2025-11-13",
"count": 1
},
{
"date": "2025-11-15",
"count": 1
},
{
"date": "2025-11-19",
"count": 1
},
{
"date": "2025-11-25",
"count": 1
},
{
"date": "2025-12-02",
"count": 1
},
{
"date": "2025-12-03",
"count": 1
},
{
"date": "2025-12-05",
"count": 1
},
{
"date": "2025-12-06",
"count": 2
},
{
"date": "2025-12-07",
"count": 1
},
{
"date": "2025-12-10",
"count": 1
},
{
"date": "2025-12-11",
"count": 1
},
{
"date": "2025-12-16",
"count": 1
},
{
"date": "2025-12-18",
"count": 1
},
{
"date": "2025-12-19",
"count": 1
},
{
"date": "2025-12-24",
"count": 1
},
{
"date": "2025-12-30",
"count": 2
},
{
"date": "2026-01-10",
"count": 1
},
{
"date": "2026-01-11",
"count": 1
},
{
"date": "2026-01-13",
"count": 1
},
{
"date": "2026-01-15",
"count": 2
},
{
"date": "2026-01-18",
"count": 1
},
{
"date": "2026-01-21",
"count": 1
},
{
"date": "2026-01-28",
"count": 1
},
{
"date": "2026-02-01",
"count": 2
},
{
"date": "2026-02-04",
"count": 1
},
{
"date": "2026-02-08",
"count": 1
},
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-10",
"count": 1
},
{
"date": "2026-02-12",
"count": 3
},
{
"date": "2026-02-14",
"count": 1
},
{
"date": "2026-02-18",
"count": 1
},
{
"date": "2026-02-20",
"count": 2
},
{
"date": "2026-02-21",
"count": 1
},
{
"date": "2026-02-23",
"count": 1
},
{
"date": "2026-02-26",
"count": 1
},
{
"date": "2026-02-27",
"count": 2
},
{
"date": "2026-03-02",
"count": 1
},
{
"date": "2026-03-03",
"count": 1
},
{
"date": "2026-03-05",
"count": 1
},
{
"date": "2026-03-09",
"count": 1
},
{
"date": "2026-03-10",
"count": 2
},
{
"date": "2026-03-11",
"count": 1
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-03-14",
"count": 1
},
{
"date": "2026-03-17",
"count": 1
},
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-21",
"count": 1
},
{
"date": "2026-03-22",
"count": 1
},
{
"date": "2026-03-24",
"count": 2
},
{
"date": "2026-03-25",
"count": 2
},
{
"date": "2026-03-26",
"count": 1
},
{
"date": "2026-03-30",
"count": 1
},
{
"date": "2026-03-31",
"count": 2
},
{
"date": "2026-04-01",
"count": 2
},
{
"date": "2026-04-02",
"count": 1
},
{
"date": "2026-04-03",
"count": 2
},
{
"date": "2026-04-04",
"count": 3
},
{
"date": "2026-04-06",
"count": 2
},
{
"date": "2026-04-08",
"count": 3
},
{
"date": "2026-04-09",
"count": 1
},
{
"date": "2026-04-10",
"count": 1
},
{
"date": "2026-04-12",
"count": 1
},
{
"date": "2026-04-13",
"count": 1
},
{
"date": "2026-04-15",
"count": 1
},
{
"date": "2026-04-17",
"count": 1
},
{
"date": "2026-04-18",
"count": 2
},
{
"date": "2026-04-19",
"count": 3
},
{
"date": "2026-04-20",
"count": 1
},
{
"date": "2026-04-22",
"count": 1
},
{
"date": "2026-04-23",
"count": 1
},
{
"date": "2026-04-24",
"count": 1
},
{
"date": "2026-04-27",
"count": 2
},
{
"date": "2026-05-02",
"count": 1
},
{
"date": "2026-05-04",
"count": 1
},
{
"date": "2026-05-07",
"count": 1
},
{
"date": "2026-05-09",
"count": 1
},
{
"date": "2026-05-15",
"count": 1
},
{
"date": "2026-05-16",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-21",
"count": 1
},
{
"date": "2026-05-24",
"count": 1
},
{
"date": "2026-05-25",
"count": 4
},
{
"date": "2026-05-30",
"count": 2
},
{
"date": "2026-06-01",
"count": 3
},
{
"date": "2026-06-05",
"count": 1
},
{
"date": "2026-06-09",
"count": 2
},
{
"date": "2026-06-13",
"count": 1
},
{
"date": "2026-06-14",
"count": 1
},
{
"date": "2026-06-15",
"count": 1
},
{
"date": "2026-06-18",
"count": 2
},
{
"date": "2026-06-22",
"count": 2
},
{
"date": "2026-06-25",
"count": 1
},
{
"date": "2026-06-27",
"count": 1
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-06-30",
"count": 2
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-07",
"count": 1
},
{
"date": "2026-07-08",
"count": 1
},
{
"date": "2026-07-10",
"count": 1
},
{
"date": "2026-07-15",
"count": 1
},
{
"date": "2026-07-16",
"count": 3
},
{
"date": "2026-07-17",
"count": 2
},
{
"date": "2026-07-19",
"count": 1
},
{
"date": "2026-07-20",
"count": 1
},
{
"date": "2026-07-21",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
}
],
"complete": true,
"collected": 822,
"total_forks": 833
},
"star_history": null,
"open_issues_and_prs": 376
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": true,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"grype/db/v5/distribution/testdata/tls/Makefile",
"grype/matcher/golang/testdata/Makefile",
"grype/matcher/golang/testdata/gobin-httpclient/Makefile",
"grype/matcher/golang/testdata/gobin-httpserver/Makefile",
"grype/matcher/golang/testdata/gobin-xnet-html/Makefile",
"grype/matcher/golang/testdata/gobin-xnet-http2server/Makefile",
"test/cli/testdata/Makefile",
"test/install/Makefile",
"test/integration/testdata/Makefile",
"test/quality/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
".make/go.mod",
"go.mod",
"grype/matcher/golang/testdata/gobin-httpclient/go.mod",
"grype/matcher/golang/testdata/gobin-httpserver/go.mod",
"grype/matcher/golang/testdata/gobin-xnet-html/go.mod",
"grype/matcher/golang/testdata/gobin-xnet-http2server/go.mod",
"test/integration/testdata/image-debian-match-coverage/golang/go.mod"
],
"largest_source_bytes": 51485,
"source_files_sampled": 681,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
".make/go.mod",
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "google.golang.org/grpc",
"direct": false,
"version": "v1.80.0",
"severity": "critical",
"ecosystem": "go",
"cvss_score": 9.1,
"advisory_ids": [
"GHSA-hrxh-6v49-42gf"
],
"fixed_version": "1.82.1",
"advisory_count": 1,
"oldest_advisory_days": 0
},
{
"name": "github.com/docker/docker",
"direct": true,
"version": "v28.5.2+incompatible",
"severity": "high",
"ecosystem": "go",
"cvss_score": 8.8,
"advisory_ids": [
"GHSA-pxq6-2prw-chj9",
"GHSA-rg2x-37c3-w2rh",
"GHSA-vp62-88p7-qqf5",
"GHSA-x744-4wpc-v9h2",
"GHSA-x86f-5xw2-fm2r",
"GO-2026-4883",
"GO-2026-4887",
"GO-2026-5617",
"GO-2026-5668",
"GO-2026-5746"
],
"fixed_version": "29.3.1",
"advisory_count": 10,
"oldest_advisory_days": 117
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 14
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 1,
"unknown": 1,
"critical": 1
},
"advisory_count": 12,
"affected_count": 3,
"assessed_count": 339,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 1
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/anchore/go-make",
"manifest": ".make/go.mod",
"ecosystem": "go",
"version_constraint": "v0.8.0"
},
{
"name": "github.com/CycloneDX/cyclonedx-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.11.0"
},
{
"name": "github.com/Masterminds/semver/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.5.0"
},
{
"name": "github.com/Masterminds/sprig/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.3.0"
},
{
"name": "github.com/OneOfOne/xxhash",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.8"
},
{
"name": "github.com/acarl005/stripansi",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20180116102854-5a71ef0e047d"
},
{
"name": "github.com/adrg/xdg",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.3"
},
{
"name": "github.com/anchore/bubbly",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.1"
},
{
"name": "github.com/anchore/clio",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/anchore/fangs",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/anchore/go-collections",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/anchore/go-homedir",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/anchore/go-logger",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/anchore/go-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.2-0.20210903204242-51efa5b487c4"
},
{
"name": "github.com/anchore/packageurl-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0"
},
{
"name": "github.com/anchore/stereoscope",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/aquasecurity/go-pep440-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.1"
},
{
"name": "github.com/araddon/dateparse",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210429162001-6b43995a97de"
},
{
"name": "github.com/bitnami/go-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250505154626-452e8c5ee607"
},
{
"name": "github.com/bmatcuk/doublestar/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.0.4"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/dave/jennifer",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.1"
},
{
"name": "github.com/docker/docker",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v28.5.2+incompatible"
},
{
"name": "github.com/dustin/go-humanize",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.1"
},
{
"name": "github.com/facebookincubator/nvdtools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.5"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.13"
},
{
"name": "github.com/gkampitakis/go-snaps",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.23"
},
{
"name": "github.com/glebarez/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.0"
},
{
"name": "github.com/go-test/deep",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.5.0"
},
{
"name": "github.com/gocsaf/csaf/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.5.1"
},
{
"name": "github.com/gohugoio/hashstructure",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.0"
},
{
"name": "github.com/google/go-cmp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/google/go-containerregistry",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.7"
},
{
"name": "github.com/google/shlex",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20191202100458-e7afc7fbc510"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/gookit/color",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.1"
},
{
"name": "github.com/hako/durafmt",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210608085754-5c1018a4e16b"
},
{
"name": "github.com/hashicorp/go-cleanhttp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.2"
},
{
"name": "github.com/hashicorp/go-getter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.6"
},
{
"name": "github.com/hashicorp/go-multierror",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1"
},
{
"name": "github.com/iancoleman/strcase",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/invopop/jsonschema",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "github.com/jinzhu/copier",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "github.com/klauspost/compress",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.19.0"
},
{
"name": "github.com/knqyf263/go-apk-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20200609155635-041fdbb8563f"
},
{
"name": "github.com/knqyf263/go-deb-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20241115132648-6f4aee6ccd23"
},
{
"name": "github.com/masahiro331/go-mvn-version",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250131095131-f4974fa13b8a"
},
{
"name": "github.com/mholt/archives",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.5"
},
{
"name": "github.com/muesli/termenv",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.16.0"
},
{
"name": "github.com/olekukonko/tablewriter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.4"
},
{
"name": "github.com/openvex/go-vex",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.8"
},
{
"name": "github.com/owenrumney/go-sarif",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.2-0.20231003122901-1000f5e05554"
},
{
"name": "github.com/pandatix/go-cvss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/scylladb/go-set",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.3-0.20200225121959-cc7b2070d91e"
},
{
"name": "github.com/sergi/go-diff",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/spf13/afero",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.15.0"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/ulikunitz/xz",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.15"
},
{
"name": "github.com/umisama/go-cpe",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20190323060751-cdd6c3c28a23"
},
{
"name": "github.com/wagoodman/go-partybus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20230516145632-8ccac152c651"
},
{
"name": "github.com/wagoodman/go-presenter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20211015174752-f9c01afc824b"
},
{
"name": "github.com/wagoodman/go-progress",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260303201901-10176f79b2c0"
},
{
"name": "github.com/xi2/xz",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20171230120015-48954b6210f8"
},
{
"name": "golang.org/x/exp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260410095643-746e56fc9e2f"
},
{
"name": "golang.org/x/text",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.40.0"
},
{
"name": "golang.org/x/time",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.15.0"
},
{
"name": "golang.org/x/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.48.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "gorm.io/gorm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.31.2"
},
{
"name": "github.com/anchore/syft",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.49.0"
},
{
"name": "github.com/bmatcuk/doublestar/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.10.0"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v6.0.2"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/acarl005/stripansi",
"direct": true,
"version": "v0.0.0-20180116102854-5a71ef0e047d",
"ecosystem": "go"
},
{
"name": "github.com/adrg/xdg",
"direct": true,
"version": "v0.5.3",
"ecosystem": "go"
},
{
"name": "github.com/anchore/bubbly",
"direct": true,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/clio",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/fangs",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-collections",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-homedir",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-logger",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-make",
"direct": true,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-version",
"direct": true,
"version": "v1.2.2-0.20210903204242-51efa5b487c4",
"ecosystem": "go"
},
{
"name": "github.com/anchore/packageurl-go",
"direct": true,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/anchore/stereoscope",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/anchore/syft",
"direct": true,
"version": "v1.49.0",
"ecosystem": "go"
},
{
"name": "github.com/aquasecurity/go-pep440-version",
"direct": true,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/araddon/dateparse",
"direct": true,
"version": "v0.0.0-20210429162001-6b43995a97de",
"ecosystem": "go"
},
{
"name": "github.com/bitnami/go-version",
"direct": true,
"version": "v0.0.0-20250505154626-452e8c5ee607",
"ecosystem": "go"
},
{
"name": "github.com/bmatcuk/doublestar/v2",
"direct": true,
"version": "v2.0.4",
"ecosystem": "go"
},
{
"name": "github.com/bmatcuk/doublestar/v4",
"direct": true,
"version": "v4.10.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": true,
"version": "v1.3.10",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/cyclonedx/cyclonedx-go",
"direct": true,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/dave/jennifer",
"direct": true,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "github.com/docker/docker",
"direct": true,
"version": "v28.5.2+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": true,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/facebookincubator/nvdtools",
"direct": true,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"direct": true,
"version": "v1.4.13",
"ecosystem": "go"
},
{
"name": "github.com/gkampitakis/go-snaps",
"direct": true,
"version": "v0.5.23",
"ecosystem": "go"
},
{
"name": "github.com/glebarez/sqlite",
"direct": true,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "github.com/go-test/deep",
"direct": true,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": true,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/gocsaf/csaf/v3",
"direct": true,
"version": "v3.5.1",
"ecosystem": "go"
},
{
"name": "github.com/gohugoio/hashstructure",
"direct": true,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": true,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-containerregistry",
"direct": true,
"version": "v0.21.7",
"ecosystem": "go"
},
{
"name": "github.com/google/shlex",
"direct": true,
"version": "v0.0.0-20191202100458-e7afc7fbc510",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/gookit/color",
"direct": true,
"version": "v1.6.1",
"ecosystem": "go"
},
{
"name": "github.com/hako/durafmt",
"direct": true,
"version": "v0.0.0-20210608085754-5c1018a4e16b",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-cleanhttp",
"direct": true,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-getter",
"direct": true,
"version": "v1.8.6",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-multierror",
"direct": true,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/iancoleman/strcase",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/invopop/jsonschema",
"direct": true,
"version": "v0.14.0",
"ecosystem": "go"
},
{
"name": "github.com/jinzhu/copier",
"direct": true,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": true,
"version": "v1.19.0",
"ecosystem": "go"
},
{
"name": "github.com/knqyf263/go-apk-version",
"direct": true,
"version": "v0.0.0-20200609155635-041fdbb8563f",
"ecosystem": "go"
},
{
"name": "github.com/knqyf263/go-deb-version",
"direct": true,
"version": "v0.0.0-20241115132648-6f4aee6ccd23",
"ecosystem": "go"
},
{
"name": "github.com/masahiro331/go-mvn-version",
"direct": true,
"version": "v0.0.0-20250131095131-f4974fa13b8a",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/semver/v3",
"direct": true,
"version": "v3.5.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/sprig/v3",
"direct": true,
"version": "v3.3.0",
"ecosystem": "go"
},
{
"name": "github.com/mholt/archives",
"direct": true,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": true,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/tablewriter",
"direct": true,
"version": "v1.1.4",
"ecosystem": "go"
},
{
"name": "github.com/oneofone/xxhash",
"direct": true,
"version": "v1.2.8",
"ecosystem": "go"
},
{
"name": "github.com/openvex/go-vex",
"direct": true,
"version": "v0.2.8",
"ecosystem": "go"
},
{
"name": "github.com/owenrumney/go-sarif",
"direct": true,
"version": "v1.1.2-0.20231003122901-1000f5e05554",
"ecosystem": "go"
},
{
"name": "github.com/pandatix/go-cvss",
"direct": true,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"direct": true,
"version": "v6.0.2",
"ecosystem": "go"
},
{
"name": "github.com/scylladb/go-set",
"direct": true,
"version": "v1.0.3-0.20200225121959-cc7b2070d91e",
"ecosystem": "go"
},
{
"name": "github.com/sergi/go-diff",
"direct": true,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/afero",
"direct": true,
"version": "v1.15.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "github.com/ulikunitz/xz",
"direct": true,
"version": "v0.5.15",
"ecosystem": "go"
},
{
"name": "github.com/umisama/go-cpe",
"direct": true,
"version": "v0.0.0-20190323060751-cdd6c3c28a23",
"ecosystem": "go"
},
{
"name": "github.com/wagoodman/go-partybus",
"direct": true,
"version": "v0.0.0-20230516145632-8ccac152c651",
"ecosystem": "go"
},
{
"name": "github.com/wagoodman/go-presenter",
"direct": true,
"version": "v0.0.0-20211015174752-f9c01afc824b",
"ecosystem": "go"
},
{
"name": "github.com/wagoodman/go-progress",
"direct": true,
"version": "v0.0.0-20260303201901-10176f79b2c0",
"ecosystem": "go"
},
{
"name": "github.com/xi2/xz",
"direct": true,
"version": "v0.0.0-20171230120015-48954b6210f8",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": true,
"version": "v0.0.0-20260410095643-746e56fc9e2f",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": true,
"version": "v0.15.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/tools",
"direct": true,
"version": "v0.48.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "gorm.io/gorm",
"direct": true,
"version": "v1.31.2",
"ecosystem": "go"
},
{
"name": "cel.dev/expr",
"direct": false,
"version": "v0.25.1",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go",
"direct": false,
"version": "v0.123.0",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/auth",
"direct": false,
"version": "v0.18.2",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/auth/oauth2adapt",
"direct": false,
"version": "v0.2.8",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/compute/metadata",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/iam",
"direct": false,
"version": "v1.5.3",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/monitoring",
"direct": false,
"version": "v1.24.3",
"ecosystem": "go"
},
{
"name": "cloud.google.com/go/storage",
"direct": false,
"version": "v1.61.3",
"ecosystem": "go"
},
{
"name": "dario.cat/mergo",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/acobaugh/osrelease",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/agext/levenshtein",
"direct": false,
"version": "v1.2.3",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-lzo",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-macholibre",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-rpmdb",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-struct-converter",
"direct": false,
"version": "v0.2.0-rc2",
"ecosystem": "go"
},
{
"name": "github.com/anchore/go-sync",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/andybalholm/brotli",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/apparentlymart/go-textseg/v15",
"direct": false,
"version": "v15.0.0",
"ecosystem": "go"
},
{
"name": "github.com/aquasecurity/go-version",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2",
"direct": false,
"version": "v1.41.5",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream",
"direct": false,
"version": "v1.7.8",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/config",
"direct": false,
"version": "v1.32.12",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/credentials",
"direct": false,
"version": "v1.19.12",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
"direct": false,
"version": "v1.18.20",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
"direct": false,
"version": "v1.4.21",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
"direct": false,
"version": "v2.7.21",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/ini",
"direct": false,
"version": "v1.8.6",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
"direct": false,
"version": "v1.4.22",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
"direct": false,
"version": "v1.13.7",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/checksum",
"direct": false,
"version": "v1.9.13",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
"direct": false,
"version": "v1.13.21",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/s3shared",
"direct": false,
"version": "v1.19.21",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/s3",
"direct": false,
"version": "v1.97.3",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/signin",
"direct": false,
"version": "v1.0.8",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sso",
"direct": false,
"version": "v1.30.13",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
"direct": false,
"version": "v1.35.17",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sts",
"direct": false,
"version": "v1.41.9",
"ecosystem": "go"
},
{
"name": "github.com/aws/smithy-go",
"direct": false,
"version": "v1.24.2",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bahlo/generic-list-go",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/becheran/wildmatch-go",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/bgentry/go-netrc",
"direct": false,
"version": "v0.0.0-20140422174119-9fd32a8b3d3d",
"ecosystem": "go"
},
{
"name": "github.com/blakesmith/ar",
"direct": false,
"version": "v0.0.0-20190502131153-809d4375e1fb",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/plumbing",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/sevenzip",
"direct": false,
"version": "v1.6.1",
"ecosystem": "go"
},
{
"name": "github.com/bodgit/windows",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/buger/jsonparser",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/burntsushi/toml",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbles",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.4.3",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/harmonica",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.11.6",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.15",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/displaywidth",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/uax29/v2",
"direct": false,
"version": "v2.7.0",
"ecosystem": "go"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.6.3",
"ecosystem": "go"
},
{
"name": "github.com/cncf/xds/go",
"direct": false,
"version": "v0.0.0-20251210132809-ee656c7534f5",
"ecosystem": "go"
},
{
"name": "github.com/containerd/cgroups/v3",
"direct": false,
"version": "v3.1.3",
"ecosystem": "go"
},
{
"name": "github.com/containerd/containerd/api",
"direct": false,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "github.com/containerd/containerd/v2",
"direct": false,
"version": "v2.3.3",
"ecosystem": "go"
},
{
"name": "github.com/containerd/continuity",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs/pkg",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/fifo",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/log",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/platforms",
"direct": false,
"version": "v1.0.0-rc.4",
"ecosystem": "go"
},
{
"name": "github.com/containerd/plugin",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/ttrpc",
"direct": false,
"version": "v1.2.8",
"ecosystem": "go"
},
{
"name": "github.com/containerd/typeurl/v2",
"direct": false,
"version": "v2.2.3",
"ecosystem": "go"
},
{
"name": "github.com/cyphar/filepath-securejoin",
"direct": false,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/datadog/zstd",
"direct": false,
"version": "v1.5.7",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.2-0.20180830191138-d8f796af33cc",
"ecosystem": "go"
},
{
"name": "github.com/deitch/magic",
"direct": false,
"version": "v0.0.0-20240306090643-c67ab88f10cb",
"ecosystem": "go"
},
{
"name": "github.com/diskfs/go-diskfs",
"direct": false,
"version": "v1.9.3",
"ecosystem": "go"
},
{
"name": "github.com/distribution/reference",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/cli",
"direct": false,
"version": "v29.6.1+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/docker/docker-credential-helpers",
"direct": false,
"version": "v0.9.5",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-connections",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-units",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/dsnet/compress",
"direct": false,
"version": "v0.0.2-0.20230904184137-39efe44ab707",
"ecosystem": "go"
},
{
"name": "github.com/elliotchance/phpserialize",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/emirpasic/gods",
"direct": false,
"version": "v1.18.1",
"ecosystem": "go"
},
{
"name": "github.com/envoyproxy/go-control-plane/envoy",
"direct": false,
"version": "v1.36.0",
"ecosystem": "go"
},
{
"name": "github.com/envoyproxy/protoc-gen-validate",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/fatih/color",
"direct": false,
"version": "v1.18.0",
"ecosystem": "go"
},
{
"name": "github.com/felixge/fgprof",
"direct": false,
"version": "v0.9.5",
"ecosystem": "go"
},
{
"name": "github.com/felixge/httpsnoop",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/github/go-spdx/v2",
"direct": false,
"version": "v2.7.0",
"ecosystem": "go"
},
{
"name": "github.com/gkampitakis/ciinfo",
"direct": false,
"version": "v0.3.4",
"ecosystem": "go"
},
{
"name": "github.com/glebarez/go-sqlite",
"direct": false,
"version": "v1.22.0",
"ecosystem": "go"
},
{
"name": "github.com/go-git/gcfg",
"direct": false,
"version": "v1.5.1-0.20230307220236-3a3c6141e376",
"ecosystem": "go"
},
{
"name": "github.com/go-git/go-billy/v5",
"direct": false,
"version": "v5.9.0",
"ecosystem": "go"
},
{
"name": "github.com/go-git/go-git/v5",
"direct": false,
"version": "v5.19.1",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v4",
"direct": false,
"version": "v4.1.4",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/go-restruct/restruct",
"direct": false,
"version": "v1.2.0-alpha",
"ecosystem": "go"
},
{
"name": "github.com/goccy/go-yaml",
"direct": false,
"version": "v1.19.2",
"ecosystem": "go"
},
{
"name": "github.com/gogo/protobuf",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/golang/groupcache",
"direct": false,
"version": "v0.0.0-20241129210726-2c02b8208cf8",
"ecosystem": "go"
},
{
"name": "github.com/google/licensecheck",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/google/pprof",
"direct": false,
"version": "v0.0.0-20250630185457-6e76a2b096b5",
"ecosystem": "go"
},
{
"name": "github.com/google/s2a-go",
"direct": false,
"version": "v0.1.9",
"ecosystem": "go"
},
{
"name": "github.com/googleapis/enterprise-certificate-proxy",
"direct": false,
"version": "v0.3.14",
"ecosystem": "go"
},
{
"name": "github.com/googleapis/gax-go/v2",
"direct": false,
"version": "v2.17.0",
"ecosystem": "go"
},
{
"name": "github.com/googlecloudplatform/opentelemetry-operations-go/detectors/gcp",
"direct": false,
"version": "v1.31.0",
"ecosystem": "go"
},
{
"name": "github.com/googlecloudplatform/opentelemetry-operations-go/exporter/metric",
"direct": false,
"version": "v0.55.0",
"ecosystem": "go"
},
{
"name": "github.com/googlecloudplatform/opentelemetry-operations-go/internal/resourcemapping",
"direct": false,
"version": "v0.55.0",
"ecosystem": "go"
},
{
"name": "github.com/gpustack/gguf-parser-go",
"direct": false,
"version": "v0.24.1",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/aws-sdk-go-base/v2",
"direct": false,
"version": "v2.0.0-beta.72",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/errwrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-version",
"direct": false,
"version": "v1.8.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru/v2",
"direct": false,
"version": "v2.0.7",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/hcl/v2",
"direct": false,
"version": "v2.24.0",
"ecosystem": "go"
},
{
"name": "github.com/henvic/httpretty",
"direct": false,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/huandu/xstrings",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/in-toto/attestation",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/intevation/gval",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/intevation/jsonpath",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/jbenet/go-context",
"direct": false,
"version": "v0.0.0-20150711004518-d14ea06fba99",
"ecosystem": "go"
},
{
"name": "github.com/jinzhu/inflection",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/jinzhu/now",
"direct": false,
"version": "v1.1.5",
"ecosystem": "go"
},
{
"name": "github.com/json-iterator/go",
"direct": false,
"version": "v1.1.12",
"ecosystem": "go"
},
{
"name": "github.com/kastenhq/goversion",
"direct": false,
"version": "v0.0.0-20230811215019-93b2f8823953",
"ecosystem": "go"
},
{
"name": "github.com/kevinburke/ssh_config",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/cpuid/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/pgzip",
"direct": false,
"version": "v1.2.6",
"ecosystem": "go"
},
{
"name": "github.com/kr/pretty",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/kr/text",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/maruel/natural",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/goutils",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-colorable",
"direct": false,
"version": "v0.1.14",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.2-0.20220822084749-2491eb6c1c75",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.21",
"ecosystem": "go"
},
{
"name": "github.com/mgutz/ansi",
"direct": false,
"version": "v0.0.0-20200706080929-d51e80ef957d",
"ecosystem": "go"
},
{
"name": "github.com/microsoft/go-winio",
"direct": false,
"version": "v0.6.3-0.20251027160822-ad3df93bed29",
"ecosystem": "go"
},
{
"name": "github.com/microsoft/hcsshim",
"direct": false,
"version": "v0.15.0-rc.1",
"ecosystem": "go"
},
{
"name": "github.com/mikelolasagasti/xz",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/minio/minlz",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/copystructure",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/go-homedir",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/go-wordwrap",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/reflectwalk",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/moby/docker-image-spec",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/locker",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/api",
"direct": false,
"version": "v1.55.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/client",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/atomicwriter",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/mountinfo",
"direct": false,
"version": "v0.7.2",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/sequential",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/signal",
"direct": false,
"version": "v0.7.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/user",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/userns",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/concurrent",
"direct": false,
"version": "v0.0.0-20180306012644-bacd9c7ef1dd",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/reflect2",
"direct": false,
"version": "v1.0.3-0.20250322232337-35a7c28c31ee",
"ecosystem": "go"
},
{
"name": "github.com/morikuni/aec",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/ncruces/go-strftime",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/nix-community/go-nix",
"direct": false,
"version": "v0.0.0-20250101154619-4bdde671e0a1",
"ecosystem": "go"
},
{
"name": "github.com/nwaples/rardecode/v2",
"direct": false,
"version": "v2.2.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/cat",
"direct": false,
"version": "v0.0.0-20250911104152-50322a0618f6",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/errors",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/olekukonko/ll",
"direct": false,
"version": "v0.1.6",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/go-digest",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/image-spec",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/runtime-spec",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/package-url/packageurl-go",
"direct": false,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/pb33f/ordered-map/v2",
"direct": false,
"version": "v2.3.1",
"ecosystem": "go"
},
{
"name": "github.com/pborman/indent",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml",
"direct": false,
"version": "v1.9.5",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": false,
"version": "v2.4.3",
"ecosystem": "go"
},
{
"name": "github.com/pierrec/lz4/v4",
"direct": false,
"version": "v4.1.26",
"ecosystem": "go"
},
{
"name": "github.com/piprate/json-gold",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/pjbgf/sha1cd",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/pkg/profile",
"direct": false,
"version": "v1.7.0",
"ecosystem": "go"
},
{
"name": "github.com/pkg/xattr",
"direct": false,
"version": "v0.4.12",
"ecosystem": "go"
},
{
"name": "github.com/planetscale/vtprotobuf",
"direct": false,
"version": "v0.6.1-0.20240319094008-0393e58bdf10",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
"ecosystem": "go"
},
{
"name": "github.com/pquerna/cachecontrol",
"direct": false,
"version": "v0.0.0-20180517163645-1555304b9b35",
"ecosystem": "go"
},
{
"name": "github.com/protonmail/go-crypto",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/remyoudompheng/bigfft",
"direct": false,
"version": "v0.0.0-20230129092748-24d4a6f8daec",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.14.1",
"ecosystem": "go"
},
{
"name": "github.com/rust-secure-code/go-rustaudit",
"direct": false,
"version": "v0.0.0-20250226111315-e20ec32e963c",
"ecosystem": "go"
},
{
"name": "github.com/sagikazarmark/locafero",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/saintfish/chardet",
"direct": false,
"version": "v0.0.0-20230101081208-5e3ef4b5456d",
"ecosystem": "go"
},
{
"name": "github.com/sassoftware/go-rpmutils",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/shopspring/decimal",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/sirupsen/logrus",
"direct": false,
"version": "v1.9.4",
"ecosystem": "go"
},
{
"name": "github.com/skeema/knownhosts",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/smallnest/ringbuffer",
"direct": false,
"version": "v0.0.0-20241116012123-461381446e3d",
"ecosystem": "go"
},
{
"name": "github.com/sorairolake/lzip-go",
"direct": false,
"version": "v0.3.8",
"ecosystem": "go"
},
{
"name": "github.com/sourcegraph/conc",
"direct": false,
"version": "v0.3.1-0.20240121214520-5f936abd7ae8",
"ecosystem": "go"
},
{
"name": "github.com/spdx/gordf",
"direct": false,
"version": "v0.0.0-20250128162952-000978ccd6fb",
"ecosystem": "go"
},
{
"name": "github.com/spdx/tools-golang",
"direct": false,
"version": "v0.6.0-rc4",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": false,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/spf13/viper",
"direct": false,
"version": "v1.21.0",
"ecosystem": "go"
},
{
"name": "github.com/spiffe/go-spiffe/v2",
"direct": false,
"version": "v2.6.0",
"ecosystem": "go"
},
{
"name": "github.com/starry-s/zip",
"direct": false,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/objx",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/subosito/gotenv",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/sylabs/sif/v2",
"direct": false,
"version": "v2.24.1",
"ecosystem": "go"
},
{
"name": "github.com/sylabs/squashfs",
"direct": false,
"version": "v1.0.6",
"ecosystem": "go"
},
{
"name": "github.com/tailscale/hujson",
"direct": false,
"version": "v0.0.0-20260302212456-ecc657c15afd",
"ecosystem": "go"
},
{
"name": "github.com/therootcompany/xz",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/gjson",
"direct": false,
"version": "v1.19.0",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/match",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/pretty",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/tidwall/sjson",
"direct": false,
"version": "v1.2.5",
"ecosystem": "go"
},
{
"name": "github.com/vbatts/go-mtree",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/vifraa/gopom",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/xanzy/ssh-agent",
"direct": false,
"version": "v0.3.3",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "github.com/zclconf/go-cty",
"direct": false,
"version": "v1.16.3",
"ecosystem": "go"
},
{
"name": "github.com/zyedidia/generic",
"direct": false,
"version": "v1.2.2-0.20230320175451-4410d2372cb1",
"ecosystem": "go"
},
{
"name": "go.etcd.io/bbolt",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "go.opencensus.io",
"direct": false,
"version": "v0.24.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/detectors/gcp",
"direct": false,
"version": "v1.39.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
"direct": false,
"version": "v0.68.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.68.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v4",
"direct": false,
"version": "v4.0.0-rc.2",
"ecosystem": "go"
},
{
"name": "go4.org",
"direct": false,
"version": "v0.0.0-20230225012048-214862532bf5",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": false,
"version": "v0.37.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": false,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.57.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": false,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.22.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.46.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": false,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/xerrors",
"direct": false,
"version": "v0.0.0-20240903120638-7835f813f4da",
"ecosystem": "go"
},
{
"name": "gonum.org/v1/gonum",
"direct": false,
"version": "v0.17.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/api",
"direct": false,
"version": "v0.271.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto",
"direct": false,
"version": "v0.0.0-20260128011058-8636f8732409",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": false,
"version": "v0.0.0-20260401024825-9d38bb4040a9",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260406210006-6f92a3bedf2d",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": false,
"version": "v1.80.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": false,
"version": "v1.36.12-0.20260120151049-f2248ac996af",
"ecosystem": "go"
},
{
"name": "gopkg.in/warnings.v0",
"direct": false,
"version": "v0.1.2",
"ecosystem": "go"
},
{
"name": "howett.net/plist",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "modernc.org/libc",
"direct": false,
"version": "v1.73.4",
"ecosystem": "go"
},
{
"name": "modernc.org/mathutil",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "modernc.org/memory",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "modernc.org/sqlite",
"direct": false,
"version": "v1.53.0",
"ecosystem": "go"
},
{
"name": "dataclass-wizard",
"direct": false,
"version": "0.36.2",
"ecosystem": "pypi"
},
{
"name": "tabulate",
"direct": false,
"version": "0.9.0",
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 339,
"direct_count": 75,
"indirect_count": 264
}
},
"maintainership": {
"issues": {
"open_prs": 54,
"merged_prs": 2045,
"open_issues": 322,
"closed_ratio": 0.734,
"closed_issues": 889,
"closed_unmerged_prs": 238
},
"bus_factor": 2,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "wagoodman",
"commits": 495,
"avatar_url": "https://avatars.githubusercontent.com/u/590471?v=4"
},
{
"type": "User",
"login": "willmurphyscode",
"commits": 109,
"avatar_url": "https://avatars.githubusercontent.com/u/12529630?v=4"
},
{
"type": "User",
"login": "spiffcs",
"commits": 108,
"avatar_url": "https://avatars.githubusercontent.com/u/32073428?v=4"
},
{
"type": "User",
"login": "kzantow",
"commits": 103,
"avatar_url": "https://avatars.githubusercontent.com/u/3009477?v=4"
},
{
"type": "User",
"login": "luhring",
"commits": 99,
"avatar_url": "https://avatars.githubusercontent.com/u/5199289?v=4"
},
{
"type": "User",
"login": "westonsteimel",
"commits": 82,
"avatar_url": "https://avatars.githubusercontent.com/u/1593939?v=4"
},
{
"type": "User",
"login": "anchore-oss-update-bot",
"commits": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/271010566?v=4"
},
{
"type": "User",
"login": "cpendery",
"commits": 16,
"avatar_url": "https://avatars.githubusercontent.com/u/35637443?v=4"
},
{
"type": "User",
"login": "jonasagx",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/774704?v=4"
},
{
"type": "User",
"login": "Vijay-P",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/15178387?v=4"
}
],
"contributors_sampled": 98,
"top_contributor_share": 0.414
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codeql.yaml",
"release.yaml",
"scorecards.yaml",
"validate-github-actions.yaml",
"validations.yaml"
],
"has_docs_dir": false,
"linter_configs": [
".golangci.yaml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Gemfile.lock",
"go.sum",
"mix.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 4,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 5,
"reason": "badge detected: Passing",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 7 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 6,
"reason": "dependency not pinned by hash detected -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 8,
"reason": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "33 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "4562c55cebba5fe50a0c5afc7cec50a3b2392a87",
"ran_at": "2026-07-22T18:29:38Z",
"aggregate_score": 7.8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T14:49:23Z",
"oldest_open_prs": [
{
"number": 1275,
"created_at": "2023-05-06T02:31:40Z",
"last_comment_at": "2023-09-11T19:24:50Z",
"last_comment_author": "kzantow"
},
{
"number": 1345,
"created_at": "2023-06-09T23:53:53Z",
"last_comment_at": "2024-02-14T18:34:55Z",
"last_comment_author": "spiffcs"
},
{
"number": 1619,
"created_at": "2023-11-29T04:51:23Z",
"last_comment_at": "2025-10-02T19:46:49Z",
"last_comment_author": "tommy1199"
},
{
"number": 1713,
"created_at": "2024-02-14T21:28:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1946,
"created_at": "2024-06-14T23:55:43Z",
"last_comment_at": "2025-07-30T22:07:22Z",
"last_comment_author": "zhill"
},
{
"number": 2110,
"created_at": "2024-09-12T15:52:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2449,
"created_at": "2025-02-14T05:35:07Z",
"last_comment_at": "2025-04-25T19:32:16Z",
"last_comment_author": "dfandrich"
},
{
"number": 2641,
"created_at": "2025-05-05T20:27:43Z",
"last_comment_at": "2025-05-14T15:30:53Z",
"last_comment_author": "kzantow"
},
{
"number": 2754,
"created_at": "2025-06-25T18:06:43Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2797,
"created_at": "2025-07-13T09:42:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2810,
"created_at": "2025-07-18T21:22:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2827,
"created_at": "2025-07-25T08:27:18Z",
"last_comment_at": "2025-10-20T14:25:22Z",
"last_comment_author": "spiffcs"
},
{
"number": 2845,
"created_at": "2025-08-01T21:17:30Z",
"last_comment_at": "2026-06-01T18:24:27Z",
"last_comment_author": "kzantow"
},
{
"number": 2849,
"created_at": "2025-08-05T04:28:10Z",
"last_comment_at": "2025-12-08T03:49:39Z",
"last_comment_author": "wjunLu"
},
{
"number": 3038,
"created_at": "2025-11-10T12:53:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 3048,
"created_at": "2025-11-13T19:16:00Z",
"last_comment_at": "2026-01-07T21:31:02Z",
"last_comment_author": "the-real-jeremy-coleman"
},
{
"number": 3092,
"created_at": "2025-12-05T04:36:50Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 3129,
"created_at": "2025-12-19T21:46:36Z",
"last_comment_at": "2026-02-19T10:00:25Z",
"last_comment_author": "westonsteimel"
},
{
"number": 3156,
"created_at": "2026-01-11T14:13:00Z",
"last_comment_at": "2026-05-13T18:02:20Z",
"last_comment_author": "willmurphyscode"
},
{
"number": 3255,
"created_at": "2026-02-28T01:58:42Z",
"last_comment_at": "2026-05-29T18:21:49Z",
"last_comment_author": "crosleyzack"
}
],
"last_merged_pr_at": "2026-07-22T14:46:20Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 29,
"created_at": "2020-06-22T15:44:53Z",
"last_comment_at": "2020-10-26T19:26:48Z",
"last_comment_author": "wagoodman"
},
{
"number": 42,
"created_at": "2020-07-07T12:03:15Z",
"last_comment_at": "2020-07-07T13:15:22Z",
"last_comment_author": "alfredodeza"
},
{
"number": 590,
"created_at": "2020-07-16T02:17:21Z",
"last_comment_at": "2020-07-16T12:12:27Z",
"last_comment_author": "alfredodeza"
},
{
"number": 52,
"created_at": "2020-07-16T19:09:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 68,
"created_at": "2020-07-24T18:23:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 86,
"created_at": "2020-08-04T15:48:21Z",
"last_comment_at": "2026-05-06T00:05:43Z",
"last_comment_author": "kzantow"
},
{
"number": 92,
"created_at": "2020-08-05T20:32:49Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 96,
"created_at": "2020-08-05T21:49:43Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 172,
"created_at": "2020-09-29T16:03:11Z",
"last_comment_at": "2022-04-13T14:30:48Z",
"last_comment_author": "jonmcewen"
},
{
"number": 192,
"created_at": "2020-10-15T18:44:16Z",
"last_comment_at": "2023-03-02T21:22:36Z",
"last_comment_author": "wagoodman"
},
{
"number": 197,
"created_at": "2020-11-05T20:13:59Z",
"last_comment_at": "2024-08-15T19:44:49Z",
"last_comment_author": "spiffcs"
},
{
"number": 210,
"created_at": "2020-11-17T15:26:55Z",
"last_comment_at": "2026-02-05T09:08:45Z",
"last_comment_author": "captn3m0"
},
{
"number": 214,
"created_at": "2020-11-23T16:24:29Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 223,
"created_at": "2020-12-08T18:50:00Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 236,
"created_at": "2021-02-16T02:59:47Z",
"last_comment_at": "2023-12-22T15:53:22Z",
"last_comment_author": "luhring"
},
{
"number": 239,
"created_at": "2021-02-24T22:18:07Z",
"last_comment_at": "2023-09-18T20:30:08Z",
"last_comment_author": "willmurphyscode"
},
{
"number": 265,
"created_at": "2021-03-30T18:22:11Z",
"last_comment_at": "2023-08-03T20:26:45Z",
"last_comment_author": "kzantow"
},
{
"number": 266,
"created_at": "2021-03-31T14:12:13Z",
"last_comment_at": "2021-05-19T18:17:37Z",
"last_comment_author": "luhring"
},
{
"number": 278,
"created_at": "2021-04-06T02:36:44Z",
"last_comment_at": "2022-09-08T20:37:29Z",
"last_comment_author": "wagoodman"
},
{
"number": 282,
"created_at": "2021-04-07T10:38:46Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/anchore/grype",
"host": "github.com",
"name": "grype",
"owner": "anchore"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"security": 74,
"vitality": 99,
"community": 90,
"governance": 78,
"engineering": 74
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 99,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"commits_last_year": 459,
"human_commit_share": 0.62,
"days_since_last_push": 0,
"active_weeks_last_year": 50
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "50/52 weeks with commits",
"points": 34.6,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 50
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "459 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 459
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"releases_count": 100,
"latest_release_tag": "v0.116.0",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 16.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~16.3 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 16.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "excellent",
"name": "Community & Adoption",
"value": 90,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "excellent",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 95,
"inputs": {
"forks": 833,
"stars": 12620,
"watchers": 82,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "12,620 stars",
"points": 60,
"status": "met",
"details": [
{
"code": "stars",
"params": {
"count": 12620
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "833 forks",
"points": 24.3,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 833
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "82 watchers",
"points": 10.6,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 82
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 78,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 98,
"top_contributor_share": 0.414
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 41% of commits",
"points": 13.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 41
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "98 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 98
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 7 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"merged_prs": 2045,
"open_issues": 322,
"closed_issues": 889,
"issue_closed_ratio": 0.734,
"closed_unmerged_prs": 238
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "73% of issues closed",
"points": 34.3,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 73
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2045/2283 decided PRs merged",
"points": 34.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2045,
"decided": 2283
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"followers": 574,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "anchore",
"public_repos": 105,
"account_age_days": 3879
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "574 followers of anchore",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 574,
"login": "anchore"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "105 public repos, account ~10 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 105
}
},
{
"code": "account_age_years",
"params": {
"years": 10
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/anchore/grype"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "209 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 209
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 74,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yaml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"topics": [
"containers",
"security",
"vulnerability",
"docker",
"golang",
"go",
"static-analysis",
"container-image",
"tool",
"oci",
"cyclonedx",
"vulnerabilities",
"hacktoberfest",
"openvex",
"vex"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "15 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 15
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 74,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 7.8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "badge detected: Passing",
"points": 1.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 7 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 3,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "33 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "moderate",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 339 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 339
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 58,
"inputs": {
"source": "osv",
"advisories": 12,
"affected_packages": 3,
"assessed_packages": 339,
"unassessed_packages": 0,
"affected_by_severity": "critical 1, high 1, unknown 1",
"direct_affected_packages": 1
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "1 affected: github.com/docker/docker v28.5.2+incompatible (high 8.8)",
"points": 10.4,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "github.com/docker/docker v28.5.2+incompatible (high 8.8)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 117 days ago",
"points": 32.8,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 1,
"oldest": 117
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 339,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 7
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 78,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "moderate",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"has_llms_txt": true,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": "llms.txt present",
"points": 15,
"status": "met",
"details": [
{
"code": "llms_txt_present",
"params": {}
}
],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "62 of 62 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 62,
"sampled": 62
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 86,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Gemfile.lock",
"go.sum",
"mix.lock"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"grype/db/v5/distribution/testdata/tls/Makefile",
"grype/matcher/golang/testdata/Makefile",
"grype/matcher/golang/testdata/gobin-httpclient/Makefile",
"grype/matcher/golang/testdata/gobin-httpserver/Makefile",
"grype/matcher/golang/testdata/gobin-xnet-html/Makefile",
"grype/matcher/golang/testdata/gobin-xnet-http2server/Makefile",
"test/cli/testdata/Makefile",
"test/install/Makefile",
"test/integration/testdata/Makefile",
"test/quality/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
".make/go.mod",
"go.mod",
"grype/matcher/golang/testdata/gobin-httpclient/go.mod",
"grype/matcher/golang/testdata/gobin-httpserver/go.mod",
"grype/matcher/golang/testdata/gobin-xnet-html/go.mod",
"grype/matcher/golang/testdata/gobin-xnet-http2server/go.mod",
"test/integration/testdata/image-debian-match-coverage/golang/go.mod"
],
"dependency_bot_commit_share": 0.38
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, grype/db/v5/distribution/testdata/tls/Makefile, grype/matcher/golang/testdata/Makefile, grype/matcher/golang/testdata/gobin-httpclient/Makefile, grype/matcher/golang/testdata/gobin-httpserver/Makefile, grype/matcher/golang/testdata/gobin-xnet-html/Makefile, grype/matcher/golang/testdata/gobin-xnet-http2server/Makefile, test/cli/testdata/Makefile, test/install/Makefile, test/integration/testdata/Makefile, test/quality/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, grype/db/v5/distribution/testdata/tls/Makefile, grype/matcher/golang/testdata/Makefile, grype/matcher/golang/testdata/gobin-httpclient/Makefile, grype/matcher/golang/testdata/gobin-httpserver/Makefile, grype/matcher/golang/testdata/gobin-xnet-html/Makefile, grype/matcher/golang/testdata/gobin-xnet-http2server/Makefile, test/cli/testdata/Makefile, test/install/Makefile, test/integration/testdata/Makefile, test/quality/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yaml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "38 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 38,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 51485,
"source_files_sampled": 681,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/681 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 681,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-22T18:30:08.625995Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/anchore/grype.svg",
"full_name": "anchore/grype",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}