Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-28 03:31 UTC

chainguard-dev / omnibump

Universal declarative dependency bump tool

GoApache-2.0★ 13 estrellas⑂ 10 forksdesde feb 2026Ver en GitHub ↗

chainguard-dev/omnibump tiene un índice de salud de 73 sobre 100, lo que lo sitúa en la banda Bueno. Su puntuación más alta es Vitality (88/100) y la más baja, Community & Adoption (38/100). Se actualizó por última vez hace 1 día. 2 personas concentran la mayor parte del trabajo reciente.

73
global / 100
Bueno

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

73
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

ChainguardOrganización
844 seguidores116 repositorios públicosdesde jul 2021

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/chainguard-dev/omnibumpv0.23.1-51hace 3 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

88Excelente · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 1 días
16.6/36Cadencia de commits — 24/52 semanas con commits
18/18Volumen de commits — 133 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year133
human_commit_share0,67
days_since_last_push1
active_weeks_last_year24
Cómo se puntúa
27/27Publica versiones — 42 versiones publicadas
36/36Recencia de las versiones — última versión hace 1 días
27/27Cadencia de publicación — una versión cada ~3,8 días
8/10OpenSSF Scorecard: Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
Datos de entrada utilizados
releases_count42
latest_release_tagv0.23.1
releases_from_tagsno
days_since_latest_release1
mean_days_between_releases3,8

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

38En riesgo · 18% del índice global
Cómo se puntúa
17.5/60Estrellas — 13 estrellas
8/25Forks — 10 forks
1.7/15Observadores — 3 observadores
Datos de entrada utilizados
forks10
stars13
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

71Bueno · 24% del índice global
Cómo se puntúa
25.2/54Factor bus — la mitad de los commits recae en 2 contribuyente(s)
15.5/22.5Distribución de commits — el principal contribuyente firma el 31% de los commits
9.5/13.5Amplitud de contribuyentes — 7 contribuyentes
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Datos de entrada utilizados
bus_factor2
contributors_sampled7
top_contributor_share0,31
Cómo se puntúa
18.7/46.8Resolución de issues — 40% de issues cerradas
30.8/38.3Aceptación de PR — 129/160 PR decididos fusionados
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Datos de entrada utilizados
merged_prs129
open_issues3
closed_issues2
issue_closed_ratio0,4
closed_unmerged_prs31
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
21/25Alcance del propietario — 844 seguidores de chainguard-dev
23.1/25Trayectoria — 116 repos públicos, cuenta de ~5 años
Datos de entrada utilizados
followers844
owner_typeOrganization
is_verified
owner_loginchainguard-dev
public_repos116
account_age_days1839
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 3 días
20/20Historial de versiones — 51 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/chainguard-dev/omnibump
ecosystemsgo
any_deprecatedno
min_days_since_publish3

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

80Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 7 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yaml
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
10/10Topics — 4 topics
0/10Wiki
Datos de entrada utilizados
topicscargo, go, gradle, maven
has_wikino
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

84Bueno · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 152 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate8
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages50
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos, Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejaron 50 dependencias resueltas con OSV. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

79Bueno · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 67 de 67 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yaml
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 19 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 33 de los últimos 100 commits son actualizaciones automáticas de dependencias
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Datos de entrada utilizados
has_nixno
has_tests
lockfilescomposer.lock, go.sum, uv.lock
has_dockerfileno
typed_language
bootstrap_filesMakefile
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0,19
toolchain_manifestsgo.mod, pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod, pkg/languages/golang/testdata/bye/go.mod, pkg/languages/golang/testdata/confd/go.mod, pkg/languages/golang/testdata/hello/go.mod, pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod, pkg/languages/golang/testdata/tidy-compat/go.mod, pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle, pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle, pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-style/build.gradle, pkg/languages/java/gradle/testdata/kayenta-style/build.gradle, pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts, pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts, pkg/languages/java/gradle/testdata/opensearch-style/build.gradle, pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle, pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts, pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts, pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts, testdata/maven-simple/pom.xml
dependency_bot_commit_share0,33
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.6/55Tamaños de archivo manejables — 1/157 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes88.710
source_files_sampled157
oversized_source_files1

Datos clave

13estrellas de GitHub
7contribuidores
133commits en los últimos 12 meses
1días desde el último push
42versiones publicadas
2factor bus
3issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

Historial de estrellas y forks 0 ★ / 10 ⇿
0Estrellas
10Forks
33Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

02468101012026-022026-042026-07
Mayor 0Menor 8Parche 25
OpenSSF Scorecard 8.0 / 10
8.0agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-28 03:30 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
8Signed-Releases3 out of the last 3 releases have a total of 3 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities152 existing vulnerabilities detected
Dependencias directas 18
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1go.mod
Gogithub.com/chainguard-dev/clogv1.8.1go.mod
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263go.mod
Gogithub.com/charmbracelet/logv1.0.0go.mod
Gogithub.com/ghodss/yamlv1.0.0go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/v75v75.0.0go.mod
Gogithub.com/samber/lov1.53.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tidwall/gjsonv1.19.0go.mod
Gogithub.com/tidwall/sjsonv1.2.5go.mod
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742dgo.mod
Gogolang.org/x/modv0.38.0go.mod
Gogolang.org/x/toolsv0.48.0go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gosigs.k8s.io/release-utilsv0.12.4go.mod
Todas las dependencias 50

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 18 paquetes directos y 32 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1directa
Gogithub.com/burntsushi/tomlv1.6.0directa
Gogithub.com/chainguard-dev/clogv1.8.1directa
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263directa
Gogithub.com/charmbracelet/logv1.0.0directa
Gogithub.com/ghodss/yamlv1.0.0directa
Gogithub.com/google/go-cmpv0.7.0directa
Gogithub.com/google/go-github/v75v75.0.0directa
Gogithub.com/samber/lov1.53.0directa
Gogithub.com/spf13/cobrav1.10.2directa
Gogithub.com/stretchr/testifyv1.11.1directa
Gogithub.com/tidwall/gjsonv1.19.0directa
Gogithub.com/tidwall/sjsonv1.2.5directa
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742ddirecta
Gogolang.org/x/modv0.38.0directa
Gogolang.org/x/toolsv0.48.0directa
Gok8s.io/apimachineryv0.36.2directa
Gosigs.k8s.io/release-utilsv0.12.4directa
Gogithub.com/aquasecurity/go-versionv0.0.1indirecta
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1indirecta
Gogithub.com/charmbracelet/colorprofilev0.2.3-0.20250311203215-f60798e515dcindirecta
Gogithub.com/charmbracelet/lipglossv1.1.0indirecta
Gogithub.com/charmbracelet/x/ansiv0.8.0indirecta
Gogithub.com/charmbracelet/x/cellbufv0.0.13-0.20250311204145-2c3ea96c31ddindirecta
Gogithub.com/charmbracelet/x/termv0.2.1indirecta
Gogithub.com/clipperhouse/uax29/v2v2.6.0indirecta
Gogithub.com/common-nighthawk/go-figurev0.0.0-20210622060536-734e95fb86beindirecta
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirecta
Gogithub.com/go-logfmt/logfmtv0.6.1indirecta
Gogithub.com/google/go-querystringv1.1.0indirecta
Gogithub.com/inconshreveable/mousetrapv1.1.0indirecta
Gogithub.com/kr/textv0.2.0indirecta
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0indirecta
Gogithub.com/mattn/go-isattyv0.0.20indirecta
Gogithub.com/mattn/go-runewidthv0.0.19indirecta
Gogithub.com/muesli/termenvv0.16.0indirecta
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirecta
Gogithub.com/rivo/unisegv0.4.7indirecta
Gogithub.com/spf13/pflagv1.0.9indirecta
Gogithub.com/tidwall/matchv1.1.1indirecta
Gogithub.com/tidwall/prettyv1.2.0indirecta
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41eindirecta
Gogolang.org/x/syncv0.22.0indirecta
Gogolang.org/x/sysv0.47.0indirecta
Gogolang.org/x/textv0.33.0indirecta
Gogolang.org/x/tools/go/packages/packagestestv0.1.1-deprecatedindirecta
Gogolang.org/x/xerrorsv0.0.0-20231012003039-104605ab7028indirecta
Gogopkg.in/check.v1v1.0.0-20180628173108-788fd7840127indirecta
Gogopkg.in/yaml.v2v2.4.0indirecta
Gogopkg.in/yaml.v3v3.0.1indirecta
Avisos de dependencias 1

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 50 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 1 tienen avisos conocidos, de los cuales 0 son directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
golang.org/x/textv0.33.0indirectadesconocida10.39.0

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "cargo",
        "go",
        "gradle",
        "maven"
      ],
      "is_fork": false,
      "size_kb": 3343,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1439590,
        "Makefile": 3870
      },
      "pushed_at": "2026-07-27T00:19:13Z",
      "created_at": "2026-02-12T17:41:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T08:14:18Z",
      "description": "Universal declarative dependency bump tool",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://chainguard.dev",
      "name": "Chainguard",
      "type": "Organization",
      "login": "chainguard-dev",
      "company": null,
      "location": "United States of America",
      "followers": 844,
      "avatar_url": "https://avatars.githubusercontent.com/u/87436699?v=4",
      "created_at": "2021-07-14T15:25:28Z",
      "is_verified": null,
      "public_repos": 116,
      "account_age_days": 1839
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.23.1",
          "kind": "patch",
          "published_at": "2026-07-27T00:21:30Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-22T15:56:58Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-20T16:35:30Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:12:23Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-07-07T16:05:43Z"
        },
        {
          "tag": "v0.18.6",
          "kind": "patch",
          "published_at": "2026-07-01T14:26:24Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-06-26T15:47:53Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-06-23T15:11:02Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:30:05Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:29:35Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-16T07:27:50Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-06-12T07:44:35Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-11T16:11:31Z"
        },
        {
          "tag": "v0.14.4",
          "kind": "patch",
          "published_at": "2026-06-10T07:43:39Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2026-06-09T14:28:16Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-06-05T12:59:00Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-06-04T14:54:04Z"
        },
        {
          "tag": "v0.12.5",
          "kind": "patch",
          "published_at": "2026-06-01T07:45:34Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:36Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:03Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-05-20T12:17:12Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-05-18T14:01:54Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-14T14:37:04Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-05-07T18:31:14Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-05-05T22:06:48Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-05-04T21:49:18Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-04-22T18:31:16Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-04-15T16:58:56Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-04-15T16:32:06Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-04-03T14:08:09Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-03-20T16:26:33Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-16T00:08:21Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-10T18:32:45Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-09T14:21:15Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-06T23:11:06Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-03-02T00:05:29Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-02-25T20:42:33Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-02-24T14:16:47Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-02-23T18:00:17Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-02-19T19:03:43Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-19T17:57:03Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-18T21:34:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#168)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a00441b1767210c423f86077bb4de041d82e32f4",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.7 to 0.6.0.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/192e21d79ab29983730a13d1382995c2307fbcaa...6599ee8b7a49aef6a770f6\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#166)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5f183a1149e4df649a6930b5c2c250b4ce6f1d4",
          "body": "…(#142)\n\nBumps [github.com/chainguard-dev/clog](https://github.com/chainguard-dev/clog) from 1.8.0 to 1.8.1.\n- [Release notes](https://github.com/chainguard-dev/clog/releases)\n- [Commits](https://github.com/chainguard-dev/clog/compare/v1.8.0...v1.8.1)\n\n---\nupdated-dependencies:\n- dependency-name: gi\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github.com/chainguard-dev/clog from 1.8.0 to 1.8.1 …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:41:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abbfd95893391f21a1141c017066208f6b30aea",
          "body": "…#144)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.1 to 9.3.0.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:40:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e73c3feedd05e36d937731fc43676ad95fcbfe4a",
          "body": "…145)\n\nBumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89..\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18a97210520f6ae8449c30a852ce75a48829fccd",
          "body": "…#154)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.4 to 2.20.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/9af89fc71515a100421586dfdb3dc9c984fbf411...\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5604124d31877b827a250df09164bdd3b0d342e8",
          "body": "…ersions (#164)\n\nOn a cold Go module cache, `omnibump --replaces` could write\n`<module>@downloading` into go.mod and then fail to re-parse the file.\n`resolveVersionQuery` runs `go list -m <module>@<query>` with\nCombinedOutput(), which merges stderr into stdout. On a cold cache go\nemits progress to s\n[…]\neach go.mod. Concrete requested\nversions keep flowing through resolvePackageVersion's existing verbatim\nfallback.\n\nCloses AUTO-953\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): reject download-progress output when resolving replace-pin v…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T15:38:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4aed8419ea7846eda02846b0b7b98897d7e7321",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.46.0 to 0.48.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.46.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.46.0 to 0.48.0 (#159)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:37:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6dd36b76db0563042635b30d577079e20c203087",
          "body": "…e (#163)\n\nIn Go workspace mode omnibump only applied replace pins for modules\nalready declared in a sub-module's go.mod. A purely transitive module —\npresent in no go.mod, only in the module graph — was filtered out of\nevery module and silently dropped, so an explicitly-requested pin never\ntook eff\n[…]\nmodules already\nbeing updated, mirroring the add-if-missing behaviour omnibump already\nhas in single-module mode.\n\nCloses AUTO-954\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): apply replace pins for transitive-only deps in workspace mod…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T13:56:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04819df76159dead4d278eff0dbd1c7fac7267e3",
          "body": "…lution edge cases (AUTO-525) (#162)\n\n* fix(rust): correct reverse-dependency resolution for real-world edge cases\n\nHarden the revdep resolver so coordinated upgrades stop aborting on phantom\nconflicts:\n\n- Group a parent's requirements by dependency rename key: a crate that renames a\n  second copy o\n[…]\nhe boundary loop and landedVersion read Cargo.lock (GetCurrentPackages) instead\n   of exec'ing `cargo metadata` per call.\nF10 ParseVersion and parseTerm share splitPre for the pre-release/build split.",
          "is_bot": false,
          "headline": "feat(rust): coordinate crate families and fix reverse-dependency reso…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-20T14:43:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0722ce5bc8e796d7cfbb65dc62f5dab246dbf3b",
          "body": "… bumps (#157)\n\n* feat(gradle): scan typed String vars and `<<` map appends for version bumps (AUTO-761)\n\nThe Gradle scanner only recognized a fixed set of version-definition\nsyntaxes. Two constructs in real Elasticsearch build scripts fell outside\nit, so omnibump could not rewrite the source litera\n[…]\n the\n  coordinate-literal scan still records the dependency\n\nAdds a multi-module cross-aliasing regression test plus parser edge-case\ntests for the DSL gating, annotation, and coordinate-value guards.",
          "is_bot": false,
          "headline": "feat(gradle): scan typed String vars and `<<` map appends for version…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-15T15:22:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "014583d6d081ff74c7bb72729dbbf7a118350939",
          "body": "…(#156)\n\n* fix(rust): validate and land dependency upgrades within SemVer lines\n\nTwo related fixes for updating a crate that is (or coexists with) multiple\nSemVer-incompatible versions in one Cargo.lock:\n\n- Validate: only compare the target against the locked instance in the same\n  Cargo caret line.\n[…]\nin (name@from=to)\nhandling -- the @from marker only supplies the base name, and the\nexact-match / refused-downgrade case is owned by pinPrecise and\nverifyTransitiveUpgrade, so Validate defers to them.",
          "is_bot": false,
          "headline": "fix(rust): validate and land dependency upgrades within SemVer lines …",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-14T15:46:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "127737bb840067cbd549fff03f549260817573bb",
          "body": "…toml (#155)\n\n* feat(rust): edit Cargo.toml for SemVer-breaking direct dependency bumps\n\nWhen a direct dependency must be upgraded across a SemVer boundary (e.g.\ntracing-subscriber 0.2 -> 0.3, rand 0.8 -> 0.9), cargo update alone cannot\ncross the caret line, so operators fell back to a fragile exter\n[…]\nr =precise) via invertedTreeSpec; a request matching no\nlocked line is ErrAmbiguousTarget. As a safety net, ParseTree now refuses multiple\ndepth-0 roots instead of silently dropping all but the first.",
          "is_bot": false,
          "headline": "feat(rust): resolve SemVer-constrained CVE upgrades by editing Cargo.…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-13T14:06:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41d8008f844653060e84e95b5a896ad2d12dc2a4",
          "body": "…allow-list (#150)\n\nAdd two missing endpoints to the harden-runner egress allow-list:\n\n- goreleaser.com:443 — goreleaser-action resolves download URLs through\n  this host (EAI_AGAIN failure)\n- uploads.github.com:443 — goreleaser uploads release artifacts through\n  this host, separate from api.github.com\n\nFollow-up to #147 and #148.",
          "is_bot": false,
          "headline": "fix(ci): add goreleaser.com and uploads.github.com to release egress …",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4859c6498ed4cb2df255e9de94c7d5db1f8abf",
          "body": "Add tuf-repo-cdn.sigstore.dev, fulcio.sigstore.dev, and rekor.sigstore.dev\nto the harden-runner egress allow-list. The release workflow uses cosign\nkeyless signing (sign-blob via goreleaser) which contacts Fulcio for\ncertificates and Rekor for the transparency log, and the cosign installer\nuses the TUF CDN for trust root verification.\n\nFollow-up to #147 which added raw.githubusercontent.com.",
          "is_bot": false,
          "headline": "fix(ci): add sigstore endpoints to release workflow egress allow-list",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f612a78d32bc72fcc0958a9cb3fcf150666baa59",
          "body": "…149)\n\nDerive direct dependencies from the Cargo.lock graph: a local/workspace\ncrate (no source) has a dependencies array that lists exactly the crates\ndeclared in Cargo.toml. Those are direct; everything reachable only\ntransitively is indirect.\n\n- parse the source field from Cargo.lock\n- set Depend\n[…]\n and\n  record directCount/indirectCount metadata\n- report direct/indirect counts in analyze text output; per-package\n  classification is available via the Transitive flag in json/yaml\n\nCloses AUTO-824",
          "is_bot": false,
          "headline": "feat(rust): distinguish direct vs indirect dependencies in analyze (#…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-07T14:57:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d07c8e0ac9ae13366a5d5a2a8e47f6d9c2253685",
          "body": "Add raw.githubusercontent.com:443 to the harden-runner egress allow-list.\nThe cosign-installer v4.1.2 (bumped in #70) downloads its public key from\nthis host for signature verification, causing the release workflow to fail\nwith 'Could not resolve host: raw.githubusercontent.com'.\n\nRemove attacker.example.com:443, which was auto-captured from the\nStepSecurity baseline in #41 — it's a test fixture URL from go-tests\nthat was erroneously copied into the release workflow.",
          "is_bot": false,
          "headline": "fix(ci): fix release workflow egress allow-list for cosign installer",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T20:58:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90b4995839ae2038938284776bfca20bea79b569",
          "body": "What:\n\nWhen a language ecosystem has multiple potential build tools to choose\nfrom (java, python), standardize the metadata as `buildTool` and display\nit in the text output of `omnibump analyze` and `omnibump\nanalyze-remote`. The `language` should always show the ecosystem the package belongs to.\n\nWhy:\n\nIt's useful information to have, especially when developing CVE\nremediation features, to know if the correct build tool has been\nselected.",
          "is_bot": false,
          "headline": "chore(analyze): Add build tool to text output, if set (#146)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-06T19:53:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d383de5bb22b765dd48982c1cf16aa5a993228f",
          "body": null,
          "is_bot": false,
          "headline": "docs(ruby): add Ruby language documentation to README and usage examples",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T14:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "121127028a9dd7d6d76523cf5488f8f7214afcdf",
          "body": "…n (#141)\n\npinPrecise previously pinned name@version=precise targets unconditionally, even when the precise version was older than what's currently locked. Compare against SemVer and skip the pin with a warning instead.",
          "is_bot": false,
          "headline": "fix(rust): refuse to downgrade packages when pinning a precise versio…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-02T14:39:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3c72a509911ee71b976f169a1e243fc8e0e6f59",
          "body": "Add gem-dir overlay mode to the Ruby plugin, mirroring the Python --venv\npattern. When --gem-dir is specified, omnibump installs patched gems\ndirectly into an existing gem directory using gem install --install-dir,\nreplacing freeform runs: steps in melange YAML files.\n\nKey design decisions:\n- Valida\n[…]\nrsion comparison uses segment-by-segment numeric comparison matching\n  RubyGems Gem::Version behavior, with pre-release segment ordering\n- Same-version gems are skipped to avoid unnecessary reinstalls",
          "is_bot": false,
          "headline": "feat(ruby): add --gem-dir overlay mode for CVE remediation",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-01T21:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aed36f3f49b543f567dbfb080adfc7e50a64599d",
          "body": "…ons (#135)\n\n* feat(gradle): force managed pins on bundled non-classpath configurations\n\nomnibump's managed resolutionStrategy.force block only matched the compile\nand runtime classpaths — the configurations that normally ship. A fat-jar\nbuild can bundle an extra, custom-named configuration into the\n[…]\ned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): force managed pins on bundled non-classpath configurati…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-01T14:24:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e2d05055abe858afaffee5c8c73f3866bbb2840",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#131)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T21:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ba0fee429ffac6377a3d661a171ef3a2ee7959d",
          "body": "…y matches (#139)\n\nWhen a caller passes --replaces pkg=pkg@vX with no existing replace\ndirective in go.mod, resolveAndFilterPackages was silently dropping the\npackage because semver.Compare(currentVersion, resolvedVersion) == 0.\nThe version-equality skip exists to avoid no-op require updates, but a\n\n[…]\nFilterPackagesForTest helper with\na call to the real function, stubbing resolveListCommand via a new\nresolveListCommand variable (same pattern as commandContext) so no\nexternal go list calls are made.",
          "is_bot": false,
          "headline": "fix(golang): apply new replace directives when require version alread…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-06-30T21:26:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46a62a8a64c1a00099869ca3b3f860e3954b0a03",
          "body": "…xamples\n\nAdd Python to the supported languages table, features list, and quick start\nsection in README.md. Add comprehensive Python section to usage-examples.md\nwith 10 examples covering pyproject.toml, requirements.txt, setup.cfg,\nPipfile, inline updates, venv mode, build tool override, analyze, CVE\nremediation, and version resolution.\n\nCloses AUTO-429",
          "is_bot": false,
          "headline": "docs(python): add Python language documentation to README and usage e…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-30T20:56:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c894405758fb12f42f90c813047bbeff3d394f8e",
          "body": "…ategy (#138)\n\n* fix(rust): show upgrade-from version in analyze output and harden strategy\n\nWhat:\nFix `omnibump analyze` mislabeling existing Rust crates as \"(new)\" in the\nDirect Dependency Updates section, and make RecommendStrategy resolve the fix\nversion from the crates.io index without sacrific\n[…]\nindirect resolver).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rust): show upgrade-from version in analyze output and harden str…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-30T20:15:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d80b4920ef62715102b684eb6af39026126c3890",
          "body": "…ate (#133)\n\nDo a better job when we can't find an inline version to upgrade to\ncleanly. If the SemVer is incompatible and the crate can't be upgraded, `omnibump`\nshould fail. Otherwise, proceed with the upgrade.",
          "is_bot": false,
          "headline": "fix(rust): Fix issue where Rust is passing when it can't upgrade a cr…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-26T15:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5a60228c5b11049dbe952bca819e81ed52451e2",
          "body": "* fix(ci): set persist-credentials false on checkout steps\n\nEvery actions/checkout step now explicitly sets persist-credentials: false. None of the affected jobs perform git writes relying on the persisted GITHUB_TOKEN credential store: build, go-tests, and verify run read-only operations, and relea\n[…]\n be restored into the signed-release build and\ncontaminate published artifacts. Set cache: false so the release build pulls\nno PR-writable cache (zizmor cache-poisoning, release.yaml).\n\nRefs: PSEC-923",
          "is_bot": false,
          "headline": "fix(ci): GitHub Actions security hardening (#130)",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-06-26T06:37:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c4c4b6757c9440c76597350b656574eb6c596af",
          "body": "…rgeting (#129)\n\nWhat:\nTurn the `classifier` field on a Maven dependency pin into a three-way selector:\n- unset/empty: match every variant — the classifier-less dependency and all\n  classifier'd ones (a wildcard)\n- \"none\": match only the classifier-less dependency, leaving classifier'd\n  siblings un\n[…]\nrgets one classifier, and \"none\" targets only the classifier-less dependency.\n\nCloses https://linear.app/chainguard/issue/AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): match all classifier variants by default, with opt-in ta…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-23T13:58:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4671d3855b0419de3a0b1a84f2bb2fae1cb8584a",
          "body": "…ncy graph rather than taking it directly from the advisory. (#127)\n\n* feat(rust): upgrade reverse dependencies and support precise pins\n\nReplace the per-crate updatePackage loop with upgradeReverseDependencies,\nwhich routes Rust CVE remediation through cargo's own resolver. For a given\ntarget it di\n[…]\n Wrap the ambiguous-target error with a static ErrAmbiguousTarget sentinel\n  (err113), add scoped //nolint:gosec on the cargo subprocess calls (G204),\n  and reformat utils_test.go (gofmt/gci/gofumpt).",
          "is_bot": false,
          "headline": "feat(rust): resolves the fix version using the upstream Cargo depende…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T15:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6becebfe07904b314b432f4629ef1fc1e1b7bfd",
          "body": "Maven keys dependencyManagement by groupId:artifactId:type:classifier, but\nomnibump matched and wrote dependencies by groupId:artifactId only. As a\nresult a deps entry could not pin a classifier'd artifact (e.g. the native\nnetty transports netty-transport-native-kqueue:osx-x86_64 /\n-epoll:linux-x86_\n[…]\nement entry. Validate, the version-conflict dedup key,\nand the analyzer/precedence keys are all classifier-aware.\n\nCloses AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): support <classifier> in dependency bumping (#126)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:42:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0932d8c811d336fbcfd75615ee929af01d69604",
          "body": "…ings (#122)\n\n* feat(gradle): manage pins via settings block (constraints + substitution)\n\nRework Gradle transitive/coordinate pinning: emit dependency constraints\n(require) and dependencySubstitution rules in the root settings script via\ngradle.beforeProject, so they apply before any configuration \n[…]\n to match renderManagedBlock. No behavior change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gradle): pin versions via a before-resolution force block in sett…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:33:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd44e0e6c051b4dcde59f1b36653b6dfeeaf6de7",
          "body": "For unit tests added in PR #127, we'll need access to `static.crates.io`\nin order to run live `cargo update` and `cargo metadata` commands.",
          "is_bot": false,
          "headline": "chore(go-tests): Add static.crates.io to allowed-endpoints (#128)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T13:17:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c966108f19ae8f83603a0f24205af96ecbb61f0",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:46:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "345aa6242c02dc6e50d73321884bd41fe0aaa45e",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.36.1 to 0.36.2.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.36.1...v0.36.2)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#124)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9e7a1a845e5e704df6b1ab8c53976e1cde7c9db",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.45.0 to 0.46.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.45.0...v0.46.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.45.0 to 0.46.0 (#123)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:44:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0c98e344bea347d9ac2a1c3f39161a6cf4f0ebd",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#99)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4595705eee3281aba38cf20dc3ecbf623c45e948",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 (#113)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc1f53fe73aa0e9f3cb6a4e77e9a03ac76c04d3b",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.36.0 to 0.37.0.\n- [Commits](https://github.com/golang/mod/compare/v0.36.0...v0.37.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.37.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.36.0 to 0.37.0 (#114)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f1585bac858926556f8608a4a9f7a5ad9923c",
          "body": "analyze-remote returned almost no information for Gradle projects. The\nJava case always used the Maven analyzer with the aggregated Java\nmanifest set, so a Gradle repository's build files were XML-parsed and\ndiscarded, and GradleAnalyzer.AnalyzeRemote was an unimplemented stub.\n\nBuild the Gradle pro\n[…]\n and variables the same way local analyze does, and route\nJava repositories to the correct build tool with a paths-based detector\nso each tool searches only its own manifest patterns.\n\nCloses AUTO-728",
          "is_bot": false,
          "headline": "feat(gradle): support analyze-remote for Gradle projects (#119)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-17T20:16:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6be57d2ef600cd4c33e2ba7445aef7055d745ecb",
          "body": "Match the sentinel error value instead of its message string so the\ntest stays valid if the wording changes.",
          "is_bot": false,
          "headline": "test(rust): assert ErrCargoLockNotFound with errors.Is (#121)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T19:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0727b87dd4fb6cf0a620fddbeb8460b70dc45f86",
          "body": "If we run a `cargo update`, we need to re-read the `Cargo.lock` so we're\nnot working against a stale list of packages. This is a bug that leads\nto `omnibump` failures w/ `--update`\n\n- Refactors the code that reads `Cargo.lock` so that it's reusable\n- Re-read `Cargo.lock` post-update\n- Update test data to verify fix",
          "is_bot": false,
          "headline": "fix(rust): Re-read Cargo.lock after `cargo update` (#120)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T15:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6ac23996628e6ffaab83f40f75397a8ce16499a",
          "body": "Adds Gemfile.lock parsing, direct text-based version updates (no Bundler\nCLI dependency), analysis, and validation for Ruby projects.\n\n- ruby.go: Language interface (Detect, Update, Validate, --show-diff)\n- analyzer.go: Analyzer interface (Analyze, AnalyzeRemote, RecommendStrategy)\n- parser.go: Gemf\n[…]\n performed via direct Gemfile.lock text editing — no\nRuby/Bundler CLI required — matching the deployment model where omnibump\nruns in melange build sandboxes without guaranteed toolchain availability.",
          "is_bot": false,
          "headline": "feat: implement Ruby language plugin for omnibump",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-16T15:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81d611c45bbbad6aa428d8698fa113526336da1b",
          "body": "* feat(gradlefile): add Gradle file parsing and editing library\n\nWhat: introduce pkg/gradlefile, a self-contained parsing and editing\nlibrary for the Gradle files omnibump patches - the Gradle analog of\nthe gopom library Maven support builds on. Files parse into typed\nmodels with byte spans; edits a\n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): bring Gradle support to parity with Maven (#108)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-16T07:09:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5119b4d7af90c36ae79580e2e0f67be0a596f080",
          "body": "* fix(rust): Handle package names pinned to specific versions\n\nWith Cargo, you can depend on multiple versions of a crate by pinning\nthe version to the crate name, i.e., `rand@0.9.2` to only upgrade that\nversion of the crate.\n\nThese upgrades were silently failing because we were matching on the\nenti\n[…]\nstring (`rand@0.9.2`) instead of looking for the crate by\nname (`rand`) and then checking its version.\n\n* Move function call outside of loop\n\nThe `strings.Cut(...)` doesn't need to be inside the loop.",
          "is_bot": false,
          "headline": "fix(rust): Handle package names pinned to specific crate versions (#117)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-16T02:11:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "061adbd8174891cafe0c13b09f7e5f5579e3f15e",
          "body": "…rements-pinned.txt\n\nParseInlinePackages now handles Python's == separator (e.g. urllib3==2.7.0)\nbefore the JS single-= path. Venv mode no longer requires == prefix in the\nversion field. The --manifest flag is supported via resolveManifest which\nskips auto-detection when a path is provided. resolveLanguage no longer\nassumes Maven when --manifest is set. requirements-pinned.txt is recognized\nas a valid manifest filename.",
          "is_bot": false,
          "headline": "fix(python): support == version separator, --manifest flag, and requi…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-15T14:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6532afc0842b11afbf7c4e4969f002765ddd8a60",
          "body": "…s (#110)\n\n* fix(cli): merge file and inline inputs instead of dropping inline ones\n\nWhat: loadUpdateConfig now loads file inputs (--deps/--properties files)\nand inline inputs (--packages/--replaces/--props) and merges them,\ninstead of returning only the file inputs whenever a file flag is set.\nAdds\n[…]\nionally, and quoted error values survive empty or\nwhitespace strings legibly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): merge file and inline inputs instead of dropping inline one…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:45:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8b3f3de97c4b69350339c40cb68b76557d408c7",
          "body": "… requested ref (#109)\n\n* fix(analyze-remote): discover manifest files from the git tree at the requested ref\n\nWhat: GitHubFetcher.SearchFiles now sources candidate paths from\nListFilePaths (Git Tree API at the exact ref) and filters them by\nfilename, instead of querying the GitHub Code Search API. \n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyze-remote): discover manifest files from the git tree at the…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ef89d04c4ed980275fc2a0ef7e46f12d111c879",
          "body": "* AUTO-692: Add an explicit `update` flag\n\nAdd a distinct `--update` flag to `omnibump` to handle dependency\nupdates, to disambiguate between `--tidy`, which performs a\nfundamentally different task (version bumping versus correctness and\nhygiene).\n\n* fix(omnibump): Allow endpoint for index.crates.io\n\nAllow the `index.crates.io` endpoint so we can run/test `cargo update`.\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>",
          "is_bot": false,
          "headline": "AUTO-692: Add an explicit `update` flag (#111)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-11T15:38:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33e300d1d06704cacdc26007a7ac3e73a6ddc938",
          "body": null,
          "is_bot": false,
          "headline": "feat: parse optional-dependencies and PEP 735 dependency-groups",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdf429bd0fb9df00c24a31ecd82f1c1c635bedcb",
          "body": null,
          "is_bot": false,
          "headline": "feat: wire Python language plugin and CLI flags",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd814eda9c4d02ff957eeb750f31453667e6db05",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python venv mode with PEP 440 version ordering",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01497aba38c5788ac31c3ff30e460a40b0bcc029",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python manifest parsing, updating, and build tool detection",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6eb3afbb45e822d822873e1dcdae27dbd4d93dc",
          "body": "To avoid future code duplication as support for more build tools is\nadded, extract ValidatePathWithinRoot into a new pkg/utils package so\nthe logic lives in one place.\n\nErrUnsafePomPath in the maven package is kept as an alias for\nutils.ErrUnsafePath so existing errors.Is checks continue to work\nwithout any caller changes.\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(utils): centralise path boundary validation (#107)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T16:11:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "88567739ce5cabeb6867eb8e7bc4f3576cbb7dbe",
          "body": "…e CLI (#103)\n\n* feat(maven): implement AnalyzeRemote and wire Java into analyze-remote CLI\n\nWhat:\n- Implement MavenAnalyzer.AnalyzeRemote(ctx, files map[string][]byte) to analyse\n  pom.xml files fetched by the existing remote fetcher infrastructure. Parsing\n  uses xml.Unmarshal directly (gopom.Pars\n[…]\n-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): implement AnalyzeRemote and wire Java into analyze-remot…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T15:12:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98909521b34c0c4bb0351e787eabcce604c311bb",
          "body": "* test: add failing test for non-existent path in validatePathWithinRoot\n\n* fix: skip non-existent parent POM paths instead of crashing\n\nWhen a module POM declares a <parent> whose resolved path does not\nexist on disk (e.g. a corporate super-POM not present in the build\ntree), filepath.EvalSymlinks \n[…]\nhard failure instead of letting\nthe sibling-walk fallback run.\n\nCheck os.Stat before calling validatePathWithinRoot. A non-existent\nparent path means the chain ended, not that a boundary was violated.",
          "is_bot": false,
          "headline": "fix: skip non-existent parent POM paths instead of crashing (#106)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-09T07:56:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "460b52918e0fd3395a6e22db363bc1d9a3f8660b",
          "body": "* test: add failing test for sibling module property resolution\n\nAdd test case for property resolution across sibling Maven modules.\nUpdate error text expectations to match the new fallback behavior.\nThese tests will fail until the updater gains project-tree-walk support.\n\n* fix: fall back to projec\n[…]\nthe project tree via findProjectRoot + findMavenPoms for sibling\nmodules that define it. Preserves the root-boundary security invariant\nby surfacing ErrUnsafePomPath if the parent chain was cut short.",
          "is_bot": false,
          "headline": "fix: resolve Maven properties defined in sibling modules (#105)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-08T22:53:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a8464e863689c63e48cb1da7ac5aa2e02f3c630",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/7\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 (#98)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-08T14:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0647c91c9f8dd2652524e96ac56a40bb06f6bed",
          "body": "Signed-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(README): update information about contributions (#102)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-08T12:49:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a46e11d8bb64fda4a352cb9a0d5aa55c8f931877",
          "body": "Summary\nThe --show-diff flag was only implemented for Go. Rust, PHP, and JS all copied the flag into their internal config types but never read it — --show-diff was silently ignored.\n\nThis adds the same before/after snapshot + cmp.Diff pattern to all three:\n\nRust: diffs Cargo.lock before and after D\n[…]\n\nPHP: diffs all manifest files (from the detected build tool) before and after buildTool.Update\nFollows the existing Go implementation in pkg/languages/golang/updater.go.\n\n🤖 Generated with Claude Code",
          "is_bot": false,
          "headline": "feat: implement --show-diff for rust, php, and js languages (#100)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-05T18:22:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80250b9966017d3d99afd53ac79e3c8a44b9973d",
          "body": "…sal boundary (#97)\n\nMaven projects commonly declare version properties in a parent POM\nreferenced via <parent><relativePath>. Before this change the analyzer\nhad no concept of where a property came from, showing properties in\nparent POMs as '(new)' with a warning, even though the update command\nfou\n[…]\n shows [manifest: X] next to each property in Property\n  Usage and manifest: above each property update in the Strategy section.\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven/analyze): surface property source file and add path traver…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-04T15:51:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7aed66d7c1a7819aa297e1cc7df2db98305f748c",
          "body": "….0 (#55)\n\nBumps [step-security/action-actionlint](https://github.com/step-security/action-actionlint) from 1.69.1 to 1.72.0.\n- [Release notes](https://github.com/step-security/action-actionlint/releases)\n- [Commits](https://github.com/step-security/action-actionlint/compare/d364e70a116a460ed220d67b\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/action-actionlint from 1.69.1 to 1.72…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:19:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "685c4ab1725bf595f096c2e1447da83efccee295",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003...6f9f17788090df1f26\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#70)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:18:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b07df3d107a615da6c8cd5a60c2537403fa5a32a",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.35.0 to 0.36.0.\n- [Commits](https://github.com/golang/mod/compare/v0.35.0...v0.36.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.36.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.35.0 to 0.36.0 (#76)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12535b80743b591ac7366d37115b32c48a0cde7f",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.3 to 0.36.1.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.3...v0.36.1)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.3 to 0.36.1 (#77)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f06247b15ac31f1ea26291cdee4071ef45b875c",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.0.0 to 7.2.2.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...5daf1e\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.2 (#84)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fa4d3f1a18fbbc41ef95bc69102143ba1ffac84",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.3 to 0.5.6.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...5f14fd08f7cf1cb1609c1e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 (#86)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:15:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25bf7b196fae4d9ce2b3abacf2e09ac557f6d386",
          "body": "…#91)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.0 to 9.2.1.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/1e7e51e771db61008b38414a730f564565cf7c\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:14:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "386464b48dd197b8f5025368b4c0ebf82f969dd0",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.1 to 4.36.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/c\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.35.1 to 4.36.0 (#92)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af25208e6988be721a7e0150a6c7275615440563",
          "body": "…#93)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.0 to 2.19.4.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47e3ca2831bcf2e551771a632a8361f6edf9ab1e",
          "body": "…iling (#96)\n\nWhen a dependency version references \\${project.version}, omnibump was failing\nwith an error because it could not locate where the property is set. \\${project.version}\nis a Maven built-in that refers to the project's own <version> tag, not a\nconfigurable property, so the dependency cannot be bumped this way. Instead of\nerroring, log an informational message and continue.\n\nCloses https://linear.app/chainguard/issue/AUTO-655/",
          "is_bot": false,
          "headline": "fix(maven): skip dependencies using \\${project.version} instead of fa…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-03T13:12:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfbb6e3ef25e95a0b153c54c5c4f234414e2c082",
          "body": "* feat: Wire up support for tidy-compat\n\nAdd and wire up the `--tidy-compat` flag.\n\n* chore(tests): Add Unit + Integration tests, plus supporting changes\n\nThe biggest change here is to use an interface to call\n`exec.CommandContext` in `runner.go`, so that the call can be mocked by\nthe new unit test.\n\nAlso adds an integration test, w/ test go project, to verify Go is doing\nwhat we expect it to.",
          "is_bot": false,
          "headline": "feat: add go tidy compat support to omnibump (#95)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-01T14:39:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88629f453e84633fecb6bfbb57a23f88223b1442",
          "body": "omnibump doesn't support JS right now. There's no pipeline in `melange`\nfor bumping JS dependencies either. This means that JS users have to\nmanually update their package.json with error-prone scripts or direct\ncalls to the package managers.\n\nHere we add `js` as a first-class language. JS is detecte\n[…]\nually specifying, a list may be given, for cases when there is more\nthan one manager involved (e.g. in a migration).\n\nThe updater tries to make minimal edits: to preserve existing keys and\nformatting.",
          "is_bot": false,
          "headline": "feat(js): add JavaScript language support (#72)",
          "author_name": "Iain Lane",
          "author_login": "iainlane",
          "committed_at": "2026-06-01T12:45:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbbf87765dda27715b80bee46e3e72c3cfa3773a",
          "body": "* fix(maven): update properties in the POM that defines them\n\nWhat:\n- Resolve Maven property updates to the POM where the property is declared.\n- Check the current POM first, then the direct parent POM, including parent relativePath values that point to a directory.\n- Route dependency patches that u\n[…]\neira@chainguard.dev>\n\n* fix(maven): add mavenLanguageName const\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "fix(maven): resolve property updates from parent POMs (#90)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-01T07:39:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2bee3b7985626d4dd62a0353a08c41f72007f25f",
          "body": "… manifests (#87)\n\nDetectLanguage iterates a Go map, so when multiple languages match the\nsame directory, which one wins depends on map iteration order — which is\nrandomized per-process in Go. This is currently masked for omnibump's own\nrepo by PR #79 (testdata skip), but any project where two langu\n[…]\ninel error.\n\nBoth callers (analyze.go, root.go) now handle the case where\nDetectLanguage returns a valid language name alongside a warning error,\nlogging the ambiguity instead of treating it as fatal.",
          "is_bot": false,
          "headline": "fix: make language auto-detection deterministic and prefer root-level…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-05-26T17:13:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26ff3a82dc3a052c6fd8b8678059d25d321c010d",
          "body": "…t (#82)\n\nWhat: walkXMLFiles now guards the isSkippableDirectory check with\npath != rootDir, ensuring the root of each walk is never filtered out\nregardless of its directory name. Adds regression tests for\nwalkXMLFiles, Detect(), and Analyze() covering projects rooted in\ndirectories named build, tar\n[…]\nvenPom fast-path\nbut Analyze() — which always calls analyzeAllPoms then walkXMLFiles —\nreturned ErrNoPOMsFound for every file in the project.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): do not skip walk root when its name matches skip lis…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T18:54:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6c07db24d92534d167d4ff8c69dbd2dafd668faa",
          "body": "* feat(maven): auto-resolve property refs when patching deps\n\nWhen a dependency's version is a Maven property reference (e.g.\n${log4j2.version}), omnibump now automatically updates the backing\nproperty to the target version instead of warning and skipping the\npatch entirely. If the caller already su\n[…]\n https://linear.app/chainguard/issue/AUTO-628\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): auto-resolve property references when patching deps (#80)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T12:13:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25c832f3051c8fc5ca29f417907888900c630c68",
          "body": "…ction (#79)\n\nWhat: isSkippableDirectory now includes \"testdata\", \"vendor\", and \"test\",\npreventing hasMavenPom() from scanning those directories during recursive\nPOM detection. Adds TestMavenDetect_SkippedDirectories to assert that a\nvalid pom.xml inside any skipped directory does not trigger Maven \n[…]\n, causing omnibump to fail with\n\"pom.xml not found\" on a valid Go project.\n\nCloses https://linear.app/chainguard/issue/AUTO-619/\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): skip testdata, vendor, and test dirs during POM dete…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-18T13:55:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1251778a4cfe240f21512e0efea7bdff97eb7fb8",
          "body": "…om.xml (#73)\n\nMaven.Detect() now falls back to a recursive directory scan when no root\npom.xml is found, allowing projects like Apache Cassandra (Ant-based, with\nPOMs under .build/) to be identified as Maven projects automatically.\n\nMavenAnalyzer.Analyze() now always delegates to analyzeAllPoms() w\n[…]\ntory, findMavenPoms,\nMaven.Detect() recursive cases, and MavenAnalyzer.Analyze() multi-POM\naggregation (702 total, all passing).\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(java/maven): recursive POM discovery for projects without root p…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-14T13:55:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ba57225cb9f650ec31922a22cee980fbc287597",
          "body": "When fetchFromProxy receives a 404, it now returns ErrModuleVersionNotFound\nrather than ErrProxyRequestFailed. This lets callers use errors.Is to detect\nthat a version simply does not exist on the proxy, as opposed to a transient\nnetwork failure, without changing omnibump update behavior (DetectCoUpdates\ncontinues to warn and continue on any CheckTransitiveRequirements error).",
          "is_bot": false,
          "headline": "fix(golang): distinguish proxy 404 as ErrModuleVersionNotFound (#71)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-07T17:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "106c534838a3ebefe590d279d35aff57f1df3b49",
          "body": "* feat(java/maven): content-based Maven POM detection via IsMavenPom\n\nReplace filename-only detection with XML parsing:\n- Add IsMavenPom() that parses XML and validates the root element is\n  <project> with namespace http://maven.apache.org/POM/4.0.0\n- Thread manifestFile through Language.Detect() an\n[…]\na.go to flatten nested blocks (nestif)\n- Split manifest pre-detection and directory detection into separate if blocks (nestif)\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "feat(java/maven): content-based Maven POM detection via IsMavenPom (#67)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-07T17:09:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3a3e57595be7bf57eebd2eae55f1b0eb2a636e",
          "body": "Some Maven projects use a non-standard manifest filename. Add a\n--manifest flag that lets callers specify the exact path to the\nmanifest file to update, falling back to <dir>/pom.xml when unset.\n\nResolves SUS-596",
          "is_bot": false,
          "headline": "feat(java/maven): add --manifest flag for custom pom.xml path (#66)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-06T13:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d4886c89991ebe81860ff7fc4bbd64fe5a020df",
          "body": "…rom being co-updated (#65)\n\n* fix(golang): prevent independent golang.org/x and gopkg.in packages from being co-updated\n\nTwo layered fixes for the golang.org/x/* family bug where bumping\ngolang.org/x/net pulled every other golang.org/x/* package as a co-update\nat the same target version, causing un\n[…]\n cases and trim verbose comment\n\n* fix: address golangci-lint findings\n\nFlatten else-if to remove extra nesting (nestif complexity 5→3).\nAcknowledge fmt.Fprint return value in test handler (errcheck).",
          "is_bot": false,
          "headline": "fix(golang): prevent independent golang.org/x and gopkg.in packages f…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-05T22:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3186cf086064973ca214cedf67ea6886d8601d2",
          "body": "Both functions are needed by callers (e.g. cve-remediation bot) that want\nto perform pre-creation viability checks without reimplementing the\ndetection logic:\n\n- DetectCoUpdates: runs the full co-update analysis against a go.mod,\n  returning required missing deps and API compat alerts with recommend\n[…]\nd\n  minimum compatible versions.\n- FindMinCompatibleVersion: finds the lowest version of a package above\n  its current version whose go.mod requires a given dependency at or\n  above a minimum version.",
          "is_bot": false,
          "headline": "feat(golang): export DetectCoUpdates and FindMinCompatibleVersion (#64)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:44:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5392beefc43b0aca18747fa1decd47a43a8ecdc9",
          "body": "…set (#63)\n\n* feat(golang): reduce required co-package updates to minimal necessary set\n\n- Filter CheckTransitiveRequirements to only flag direct project deps;\n  indirect deps are resolved automatically by Go's MVS and cannot cause\n  API breakage in the project's own code\n- Add FindVersionGroupPacka\n[…]\nanch where it is used\n- Remove duplicate familyRoot argument from log message\n- Use distinct Reason string for cross-major packages so it doesn't\n  incorrectly say 'both at X' when the versions differ",
          "is_bot": false,
          "headline": "fix(golang): reduce required co-package updates to minimal necessary …",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:16:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96a8f2ef03e7758ea4738fa3354c89a074d2bc8f",
          "body": "…ts (#60)\n\n* fix(golang): warn instead of error on transitive co-update requirements\n\n* fix(lint): remove unused nolint directives and convert checkMissingTransitiveDeps to void\n\n* fix(security): resolve gosec G703/G704/prealloc lint findings\n\n* fix(security): construct proxy URL from struct fields to eliminate G704 taint path\n\n* fix(security): parse proxy path through url.Parse to break G704 taint chain",
          "is_bot": false,
          "headline": "fix(golang): warn instead of error on transitive co-update requiremen…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-22T18:25:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d6ae7c44329db2040d15feba2897e5d7c6df186",
          "body": "…#59)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.18.0 to 2.19.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/6c3c2f2c1c457b00c10c4848d6f5491db3b629df...8\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.18.0 to 2.19.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe28291046b7208e29b7f20821eec2f551d94905",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.2 to 0.5.3.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f3159\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 (#52)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:20:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6e703f2374cf01e5bdd2ce46e57766956a8971b",
          "body": "…#56)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.18.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/v2.16.0...6c3c2f2c1c457b00c10c4848d6f5491db3\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.18.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T00:17:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3a25bae26d8699e66e5b5efdf93966101ab87a1",
          "body": "…y (#57)\n\n* fix(golang): dedup suggested command packages and reduce log verbosity\n\nFixes a bug where the same package appeared twice in the suggested update\ncommand when it existed in both the filtered update set and the transitive\nco-update requirements at different versions. The command builder n\n[…]\nedundant internal-step messages\n(go get, AddRequire, replace) and downgrading per-package skip and analysis\nlogs to Debug level.\n\n* fix(golang): use map[string]struct{} for set type and fix formatting",
          "is_bot": false,
          "headline": "fix(golang): dedup suggested command packages and reduce log verbosit…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-21T19:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29c353c59acecb4db901f884def22ecea3dab834",
          "body": "* fix: handle +incompatible versions and vendor go.sum updates\n\nFixes issues where packages with +incompatible suffix were not resolved correctly,\nand vendor directories failed due to missing go.sum entries.\n\n- Resolve all semantic versions through go list to get canonical forms\n- Handles +incompati\n[…]\nline in indirect_resolver_test.go\n\n* fix: use go 1.25 in test go.mod fixtures\n\n* fix: restore go 1.26 in downgrade test fixture\n\n* fix: extract resolvePackageVersion helper to reduce nestif complexity",
          "is_bot": false,
          "headline": "feat: detect transitive dependency requirements  (#26)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-15T16:46:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c0b14475020d8a3642e6cb83e74c141ce236705",
          "body": "* feat: add PHP language support with Composer build tool\n\nRestructure to match Java pattern where PHP is the language and Composer\nis a build tool underneath it. This allows for future addition of other\nPHP build tools.\n\n- Add pkg/languages/php/ with language detection and build tool interface\n- Ad\n[…]\n package-level documentation\nand Example functions demonstrating the public API for both the\nphp and composer packages.\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add PHP language support with Composer build tool (#50)",
          "author_name": "Thomas Bechtold",
          "author_login": "toabctl",
          "committed_at": "2026-04-14T14:03:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c9785986745c30cb047b291351d72c7e5974c4a",
          "body": "…] (#47)\n\nSigned-off-by: Steve Beattie <steve.beattie@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(workflows): add actionlint and zizmor action linters [SECINT-75…",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-04-07T12:28:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c1997b9c829e3e100ab5ffe81018ea1fab3bbec",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.2 to 0.35.3.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.2...v0.35.3)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.35.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.2 to 0.35.3 (#35)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf8678c0e978cd7a3a166978600c6c8d6870510a",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.0 to 4.1.1.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/ba7bc0a3fef59531c69a25acd34668d6d3fe6f22...cad07c2e89fa2edd6e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 (#39)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ffeb5a6e760f3f3fdbfcd3eca68c9f61e9fa0f1",
          "body": "Bumps [sigs.k8s.io/release-utils](https://github.com/kubernetes-sigs/release-utils) from 0.12.3 to 0.12.4.\n- [Release notes](https://github.com/kubernetes-sigs/release-utils/releases)\n- [Commits](https://github.com/kubernetes-sigs/release-utils/compare/v0.12.3...v0.12.4)\n\n---\nupdated-dependencies:\n-\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigs.k8s.io/release-utils from 0.12.3 to 0.12.4 (#43)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e97c6510110dc859501de949a5a2ed578e76a3",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.32.6 to 4.35.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/0\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.32.6 to 4.35.1 (#45)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a2bd14d17fff9dd99838f4bcb6307439bb6713",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.3.0 to 6.4.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c)\n\n---\nupdated\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#46)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f22d33724321a115f747691421590076327c5d1a",
          "body": "…#44)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.16.1.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594...f\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.16.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:30:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f3487913b86ce427152d1c7eef3819b9a4139d0",
          "body": "…oring (#42)\n\n* fix(golang): warn and skip packages superseded by major version upgrades after tidy\n\nWhen go mod tidy runs after updating a batch of dependencies, packages\nthat migrated to a new major version path (e.g. containerd/v2 replacing\ncontainerd) are legitimately removed from go.mod. Previo\n[…]\nire passes into separate helper functions to reduce\nDoUpdate complexity from 36 to acceptable levels. Remove unused ctx parameter\nfrom addRequirePackage function to satisfy revive and unparam linters.",
          "is_bot": false,
          "headline": "fix(golang): warn and skip missing packages after tidy instead of err…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-01T21:57:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 42,
      "commits_last_year": 133,
      "latest_release_at": "2026-07-27T00:21:30Z",
      "latest_release_tag": "v0.23.1",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 3.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chainguard-dev/omnibump",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chainguard-dev/omnibump",
          "is_deprecated": false,
          "latest_version": "v0.23.1",
          "repository_url": "https://github.com/chainguard-dev/omnibump",
          "versions_count": 51,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-24T08:13:59Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 10,
      "stars": 13,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-05",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-25",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-07-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 10,
        "total_forks": 10
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
        "pkg/languages/golang/testdata/bye/go.mod",
        "pkg/languages/golang/testdata/confd/go.mod",
        "pkg/languages/golang/testdata/hello/go.mod",
        "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
        "pkg/languages/golang/testdata/tidy-compat/go.mod",
        "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
        "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
        "testdata/maven-simple/pom.xml"
      ],
      "largest_source_bytes": 88710,
      "source_files_sampled": 157,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 13
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 50,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/aquasecurity/go-pep440-version",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.1"
        },
        {
          "name": "github.com/chainguard-dev/clog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        },
        {
          "name": "github.com/chainguard-dev/gopom",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250828200639-b1a78ac4b263"
        },
        {
          "name": "github.com/charmbracelet/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ghodss/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/v75",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v75.0.0"
        },
        {
          "name": "github.com/samber/lo",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tidwall/gjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.0"
        },
        {
          "name": "github.com/tidwall/sjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.5"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231006140011-7918f672742d"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.38.0"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.48.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "sigs.k8s.io/release-utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.4"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aquasecurity/go-pep440-version",
            "direct": true,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/clog",
            "direct": true,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/gopom",
            "direct": true,
            "version": "v0.0.0-20250828200639-b1a78ac4b263",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/log",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ghodss/yaml",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v75",
            "direct": true,
            "version": "v75.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/samber/lo",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/gjson",
            "direct": true,
            "version": "v1.19.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/sjson",
            "direct": true,
            "version": "v1.2.5",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20231006140011-7918f672742d",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": true,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": true,
            "version": "v0.48.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/release-utils",
            "direct": true,
            "version": "v0.12.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquasecurity/go-version",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.2.3-0.20250311203215-f60798e515dc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13-0.20250311204145-2c3ea96c31dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/common-nighthawk/go-figure",
            "direct": false,
            "version": "v0.0.0-20210622060536-734e95fb86be",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logfmt/logfmt",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kr/text",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/match",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/pretty",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools/go/packages/packagestest",
            "direct": false,
            "version": "v0.1.1-deprecated",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20231012003039-104605ab7028",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/check.v1",
            "direct": false,
            "version": "v1.0.0-20180628173108-788fd7840127",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 50,
        "direct_count": 18,
        "indirect_count": 32
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 129,
        "open_issues": 3,
        "closed_ratio": 0.4,
        "closed_issues": 2,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "kbsteere",
          "commits": 27,
          "avatar_url": "https://avatars.githubusercontent.com/u/13925027?v=4"
        },
        {
          "type": "User",
          "login": "dnegreira",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/5215383?v=4"
        },
        {
          "type": "User",
          "login": "AdamIsrael",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/125008?v=4"
        },
        {
          "type": "User",
          "login": "justinvreeland",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/3758821?v=4"
        },
        {
          "type": "User",
          "login": "stevebeattie",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/1686002?v=4"
        },
        {
          "type": "User",
          "login": "iainlane",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/321014?v=4"
        },
        {
          "type": "User",
          "login": "toabctl",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/276317?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.31
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "actionlint.yaml",
        "build.yaml",
        "codeql.yaml",
        "go-tests.yaml",
        "release.yaml",
        "verify.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "composer.lock",
        "go.sum",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "3 out of the last 3 releases have a total of 3 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "152 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
        "ran_at": "2026-07-28T03:30:54Z",
        "aggregate_score": 8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T00:21:36Z",
      "oldest_open_prs": [
        {
          "number": 151,
          "created_at": "2026-07-07T16:03:50Z",
          "last_comment_at": "2026-07-22T15:36:22Z",
          "last_comment_author": "kbsteere"
        },
        {
          "number": 165,
          "created_at": "2026-07-23T14:25:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 167,
          "created_at": "2026-07-23T14:25:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 169,
          "created_at": "2026-07-23T14:27:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T08:14:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 112,
          "created_at": "2026-06-11T08:51:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 118,
          "created_at": "2026-06-16T07:33:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 134,
          "created_at": "2026-06-28T15:02:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chainguard-dev/omnibump",
    "host": "github.com",
    "name": "omnibump",
    "owner": "chainguard-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 73,
      "inputs": {
        "security": 84,
        "vitality": 88,
        "community": 38,
        "governance": 71,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 133,
              "human_commit_share": 0.67,
              "days_since_last_push": 1,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "133 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 133
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 42,
              "latest_release_tag": "v0.23.1",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 3.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "42 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 42
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 38,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 27,
            "inputs": {
              "forks": 10,
              "stars": 13,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "10 forks",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 71,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 7,
              "top_contributor_share": 0.31
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 31% of commits",
                "points": 15.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 31
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 129,
              "open_issues": 3,
              "closed_issues": 2,
              "issue_closed_ratio": 0.4,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "129/160 decided PRs merged",
                "points": 30.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 129,
                      "decided": 160
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "followers": 844,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chainguard-dev",
              "public_repos": 116,
              "account_age_days": 1839
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "844 followers of chainguard-dev",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 844,
                      "login": "chainguard-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "116 public repos, account ~5 yr old",
                "points": 23.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 116
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/chainguard-dev/omnibump"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "51 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "cargo",
                "go",
                "gradle",
                "maven"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 84,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "152 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 50 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 50
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 50,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 50,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 79,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 67,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "composer.lock",
                "go.sum",
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.19,
              "toolchain_manifests": [
                "go.mod",
                "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
                "pkg/languages/golang/testdata/bye/go.mod",
                "pkg/languages/golang/testdata/confd/go.mod",
                "pkg/languages/golang/testdata/hello/go.mod",
                "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
                "pkg/languages/golang/testdata/tidy-compat/go.mod",
                "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
                "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
                "testdata/maven-simple/pom.xml"
              ],
              "dependency_bot_commit_share": 0.33
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "19 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 19,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "33 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 33,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 88710,
              "source_files_sampled": 157,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/157 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 157,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T03:31:20.595249Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chainguard-dev/omnibump.svg",
  "full_name": "chainguard-dev/omnibump",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.