Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 07:59 UTC

cycodehq / cycode-cli

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning

PythonMIT★ 99 estrellas⑂ 65 forksdesde jul 2022Ver en GitHub ↗

cycodehq/cycode-cli tiene un índice de salud de 74 sobre 100, lo que lo sitúa en la banda Bueno. Su puntuación más alta es Vitality (91/100) y la más baja, AI Readiness (46/100). Se actualizó por última vez hoy. 2 personas concentran la mayor parte del trabajo reciente.

74
global / 100
Bueno

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

74
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

CycodeOrganización
20 seguidores7 repositorios públicosdesde jul 2019

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
PyPIcycode3.18.0127.867431hace 3 díassecret-scancycodedevopstokensecretsecuritycode

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

91Excelente · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
28.4/36Cadencia de commits — 41/52 semanas con commits
18/18Volumen de commits — 149 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year149
human_commit_share0,61
days_since_last_push0
active_weeks_last_year41
Cómo se puntúa
27/27Publica versiones — 100 versiones publicadas
36/36Recencia de las versiones — última versión hace 3 días
27/27Cadencia de publicación — una versión cada ~8,7 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count100
latest_release_tagv3.18.0
releases_from_tagsno
days_since_latest_release3
mean_days_between_releases8,7

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

67Moderado · 18% del índice global
Cómo se puntúa
32.3/60Estrellas — 99 estrellas
15.1/25Forks — 65 forks
6.5/15Observadores — 16 observadores
Datos de entrada utilizados
forks65
stars99
watchers16
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
68.1/80Descargas mensuales — 127.867 descargas/mes en pypi
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagescycode
dependents
ecosystemspypi
total_downloads
monthly_downloads127.867
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

76Bueno · 24% del índice global
Cómo se puntúa
25.2/54Factor bus — la mitad de los commits recae en 2 contribuyente(s)
12.9/22.5Distribución de commits — el principal contribuyente firma el 43% de los commits
13.5/13.5Amplitud de contribuyentes — 34 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Datos de entrada utilizados
bus_factor2
contributors_sampled34
top_contributor_share0,428
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
34.7/38.3Aceptación de PR — 454/500 PR decididos fusionados
13.5/15OpenSSF Scorecard: Code-Review — Found 21/22 approved changesets -- score normalized to 9
Datos de entrada utilizados
merged_prs454
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs46
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
9.5/25Alcance del propietario — 20 seguidores de cycodehq
18.6/25Trayectoria — 7 repos públicos, cuenta de ~7 años
Datos de entrada utilizados
followers20
owner_typeOrganization
is_verified
owner_logincycodehq
public_repos7
account_age_days2582
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en pypi
35/35Recencia de publicación — última publicación hace 3 días
20/20Historial de versiones — 431 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagescycode
ecosystemspypi
any_deprecatedno
min_days_since_publish3

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

67Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 7 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

65Moderado
Cómo se puntúa
30/30README
0/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://www.cycode.com
10/10Descripción del repositorio
10/10Topics — 7 topics
0/10Wiki
Datos de entrada utilizados
topicscode, sast, sca, secrets, secure, security, cycode
has_wikino
homepagehttps://www.cycode.com
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

66Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — sin datos
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6.8/7.5Code-Review — Found 21/22 approved changesets -- score normalized to 9
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 20 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6,2
Excluidos de la puntuación (sin datos o no aplicable): branch_protection. Los pesos restantes se han renormalizado.
Cómo se puntúa
14.8/35Dependencias directas libres de avisos conocidos — 1 afectados: click 8.1.8 (high 7.2)
25/25Dependencias indirectas libres de avisos conocidos — ninguna dependencia indirecta tiene un aviso conocido
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages50
unassessed_packages0
affected_by_severityhigh 1
direct_affected_packages1
Se cotejó el cierre de dependencias en tiempo de ejecución de pypi:cycode@3.18.0 —lo que arrastra la instalación del paquete publicado—: 50 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

46En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 53 de 61 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,869
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
0/11Verificación estática de tipos
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 25 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 39 de los últimos 100 commits son actualizaciones automáticas de dependencias
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Datos de entrada utilizados
has_nixno
has_tests
lockfilespoetry.lock
has_dockerfile
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0,25
toolchain_manifests
dependency_bot_commit_share0,39
Cómo se puntúa
0/45Código verificable por tipos — Python sin configuración de verificación de tipos
55/55Tamaños de archivo manejables — 0/333 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePython
largest_source_bytes53.141
source_files_sampled333
oversized_source_files0
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_files

Datos clave

99estrellas de GitHub
34contribuidores
149commits en los últimos 12 meses
0días desde el último push
100versiones publicadas
2factor bus
0issues abiertas
PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

Historial de estrellas y forks 0 ★ / 65 ⇿
0Estrellas
65Forks
99Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

013253850637564172022-112024-092026-07
Mayor 3Menor 33Parche 63

Cada punto abarca 4 días.

OpenSSF Scorecard 6.2 / 10
6.2agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 07:58 UTC

10Binary-Artifactsno binaries found in the repo
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
9Code-ReviewFound 21/22 approved changesets -- score normalized to 9
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities20 existing vulnerabilities detected
Dependencias directas 19
RegistroPaqueteRestricción de versiónManifiesto
PyPIclick>=8.1.0,<8.2.0pyproject.toml
PyPIcolorama>=0.4.3,<0.5.0pyproject.toml
PyPIpyyaml>=6.0,<7.0pyproject.toml
PyPImarshmallow>=3.15.0,<4.0.0pyproject.toml
PyPIgitpython>=3.1.50,<3.2.0pyproject.toml
PyPIarrow>=1.0.0,<1.5.0pyproject.toml
PyPIrequests>=2.32.4,<3.0pyproject.toml
PyPIurllib3>=2.4.0,<3.0.0pyproject.toml
PyPIpyjwt>=2.8.0,<3.0pyproject.toml
PyPIrich>=13.9.4, <14pyproject.toml
PyPIpatch-ng1.19.1pyproject.toml
PyPItyper^0.15.3pyproject.toml
PyPItenacity>=9.0.0,<9.1.0pyproject.toml
PyPImcp>=1.28.1,<2.0.0pyproject.toml
PyPIpydantic>=2.11.5,<3.0.0pyproject.toml
PyPIpathvalidate>=3.3.1,<4.0.0pyproject.toml
PyPItomli-w>=1.0.0,<2.0.0pyproject.toml
PyPItomli>=2.0.0,<3.0.0pyproject.toml
PyPIanyio>=4.0.0, <4.13.0pyproject.toml
Todas las dependencias 75

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 19 paquetes directos y 56 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
PyPIanyio4.12.1directa
PyPIarrow1.4.0directa
PyPIclick8.1.8directa
PyPIcolorama0.4.6directa
PyPIgitpython3.1.50directa
PyPImarshmallow3.26.2directa
PyPImcp1.28.1directa
PyPIpatch-ng1.19.1directa
PyPIpathvalidate3.3.1directa
PyPIpydantic2.13.4directa
PyPIpyjwt2.13.0directa
PyPIpyyaml6.0.3directa
PyPIrequests2.32.5directa
PyPIrich13.9.4directa
PyPItenacity9.0.0directa
PyPItomli2.4.1directa
PyPItomli-w1.2.0directa
PyPItyper0.15.4directa
PyPIurllib32.6.3directa
PyPIaltgraph0.17.5indirecta
PyPIannotated-types0.7.0indirecta
PyPIattrs26.1.0indirecta
PyPIcertifi2026.5.20indirecta
PyPIcffi2.0.0indirecta
PyPIcharset-normalizer3.4.7indirecta
PyPIcoverage7.10.7indirecta
PyPIcryptography48.0.0indirecta
PyPIdunamai1.26.1indirecta
PyPIexceptiongroup1.3.1indirecta
PyPIgitdb4.0.12indirecta
PyPIh110.16.0indirecta
PyPIhttpcore1.0.9indirecta
PyPIhttpx0.28.1indirecta
PyPIhttpx-sse0.4.3indirecta
PyPIidna3.18indirecta
PyPIimportlib-metadata8.7.1indirecta
PyPIiniconfig2.1.0indirecta
PyPIjsonschema4.26.0indirecta
PyPIjsonschema-specifications2025.9.1indirecta
PyPImacholib1.16.4indirecta
PyPImarkdown-it-py3.0.0indirecta
PyPImdurl0.1.2indirecta
PyPImock5.2.0indirecta
PyPIpackaging26.2indirecta
PyPIpefile2024.8.26indirecta
PyPIpluggy1.6.0indirecta
PyPIpycparser3.0indirecta
PyPIpydantic-core2.46.4indirecta
PyPIpydantic-settings2.14.1indirecta
PyPIpyfakefs5.10.2indirecta
PyPIpygments2.20.0indirecta
PyPIpyinstaller6.20.0indirecta
PyPIpyinstaller-hooks-contrib2026.5indirecta
PyPIpytest8.4.2indirecta
PyPIpytest-mock3.10.0indirecta
PyPIpython-dateutil2.9.0.post0indirecta
PyPIpython-dotenv1.2.2indirecta
PyPIpython-multipart0.0.30indirecta
PyPIpywin32311indirecta
PyPIpywin32-ctypes0.2.3indirecta
PyPIreferencing0.37.0indirecta
PyPIresponses0.26.1indirecta
PyPIrpds-py0.30.0indirecta
PyPIruff0.15.20indirecta
PyPIsetuptools82.0.1indirecta
PyPIshellingham1.5.4indirecta
PyPIsix1.17.0indirecta
PyPIsmmap5.0.3indirecta
PyPIsse-starlette3.4.4indirecta
PyPIstarlette1.2.1indirecta
PyPItyping-extensions4.15.0indirecta
PyPItyping-inspection0.4.2indirecta
PyPItzdata2026.2indirecta
PyPIuvicorn0.48.0indirecta
PyPIzipp3.23.1indirecta
Avisos de dependencias 1

Instalar pypi:cycode@3.18.0 arrastra 50 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 1 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
click8.1.8directaalta18.3.3

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "code",
        "sast",
        "sca",
        "secrets",
        "secure",
        "security",
        "cycode"
      ],
      "is_fork": false,
      "size_kb": 2775,
      "has_wiki": false,
      "homepage": "https://www.cycode.com",
      "languages": {
        "Python": 1168140,
        "Dockerfile": 1065
      },
      "pushed_at": "2026-07-27T07:36:40Z",
      "created_at": "2022-07-04T16:39:28Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T07:37:13Z",
      "description": "Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://cycode.com",
      "name": "Cycode",
      "type": "Organization",
      "login": "cycodehq",
      "company": null,
      "location": "Israel",
      "followers": 20,
      "avatar_url": "https://avatars.githubusercontent.com/u/52411968?v=4",
      "created_at": "2019-07-01T12:22:48Z",
      "is_verified": null,
      "public_repos": 7,
      "account_age_days": 2582
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.18.0",
          "kind": "minor",
          "published_at": "2026-07-23T09:37:58Z"
        },
        {
          "tag": "v3.17.2",
          "kind": "patch",
          "published_at": "2026-07-13T05:25:03Z"
        },
        {
          "tag": "v3.17.1",
          "kind": "patch",
          "published_at": "2026-07-09T11:47:53Z"
        },
        {
          "tag": "v3.17.0",
          "kind": "minor",
          "published_at": "2026-07-06T08:20:27Z"
        },
        {
          "tag": "v3.16.2",
          "kind": "patch",
          "published_at": "2026-06-17T07:15:40Z"
        },
        {
          "tag": "v3.16.1",
          "kind": "patch",
          "published_at": "2026-06-09T06:09:34Z"
        },
        {
          "tag": "v3.16.0",
          "kind": "minor",
          "published_at": "2026-06-01T17:06:53Z"
        },
        {
          "tag": "v3.15.3",
          "kind": "patch",
          "published_at": "2026-05-25T08:09:06Z"
        },
        {
          "tag": "v3.15.2",
          "kind": "patch",
          "published_at": "2026-05-12T14:08:15Z"
        },
        {
          "tag": "v3.15.1",
          "kind": "patch",
          "published_at": "2026-05-06T06:34:39Z"
        },
        {
          "tag": "v3.15.0",
          "kind": "minor",
          "published_at": "2026-04-29T08:34:40Z"
        },
        {
          "tag": "v3.14.0",
          "kind": "minor",
          "published_at": "2026-04-23T07:56:13Z"
        },
        {
          "tag": "v3.13.0",
          "kind": "minor",
          "published_at": "2026-04-09T15:26:19Z"
        },
        {
          "tag": "v3.12.2",
          "kind": "patch",
          "published_at": "2026-04-02T11:25:56Z"
        },
        {
          "tag": "v3.12.1",
          "kind": "patch",
          "published_at": "2026-03-26T15:55:08Z"
        },
        {
          "tag": "v3.12.0",
          "kind": "minor",
          "published_at": "2026-03-23T11:45:04Z"
        },
        {
          "tag": "v3.11.5",
          "kind": "patch",
          "published_at": "2026-03-19T10:41:02Z"
        },
        {
          "tag": "v3.11.3",
          "kind": "patch",
          "published_at": "2026-03-11T15:51:19Z"
        },
        {
          "tag": "v3.11.2",
          "kind": "patch",
          "published_at": "2026-03-09T13:48:14Z"
        },
        {
          "tag": "v3.11.1",
          "kind": "patch",
          "published_at": "2026-03-03T18:01:28Z"
        },
        {
          "tag": "v3.11.0",
          "kind": "minor",
          "published_at": "2026-03-03T16:04:44Z"
        },
        {
          "tag": "v3.10.3",
          "kind": "patch",
          "published_at": "2026-03-02T11:07:18Z"
        },
        {
          "tag": "v3.10.2",
          "kind": "patch",
          "published_at": "2026-02-23T09:29:08Z"
        },
        {
          "tag": "v3.10.1",
          "kind": "patch",
          "published_at": "2026-02-19T10:40:22Z"
        },
        {
          "tag": "v3.10.0",
          "kind": "minor",
          "published_at": "2026-02-18T10:42:57Z"
        },
        {
          "tag": "v3.9.3",
          "kind": "patch",
          "published_at": "2026-02-12T11:34:12Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-02-04T16:25:47Z"
        },
        {
          "tag": "v3.9.1",
          "kind": "patch",
          "published_at": "2026-02-04T09:31:51Z"
        },
        {
          "tag": "v3.9.0",
          "kind": "minor",
          "published_at": "2026-01-29T16:03:56Z"
        },
        {
          "tag": "v3.8.10",
          "kind": "patch",
          "published_at": "2026-01-26T09:19:45Z"
        },
        {
          "tag": "v3.8.9",
          "kind": "patch",
          "published_at": "2026-01-22T09:35:16Z"
        },
        {
          "tag": "v3.8.8",
          "kind": "patch",
          "published_at": "2026-01-21T13:59:05Z"
        },
        {
          "tag": "v3.8.7",
          "kind": "patch",
          "published_at": "2026-01-16T08:32:13Z"
        },
        {
          "tag": "v3.8.6",
          "kind": "patch",
          "published_at": "2026-01-14T12:13:26Z"
        },
        {
          "tag": "v3.8.5",
          "kind": "patch",
          "published_at": "2026-01-12T14:40:07Z"
        },
        {
          "tag": "v3.8.4",
          "kind": "patch",
          "published_at": "2026-01-09T11:56:19Z"
        },
        {
          "tag": "v3.8.3",
          "kind": "patch",
          "published_at": "2026-01-07T13:35:24Z"
        },
        {
          "tag": "v3.8.2",
          "kind": "patch",
          "published_at": "2026-01-05T11:37:39Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2025-12-19T15:32:22Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2025-12-02T13:24:18Z"
        },
        {
          "tag": "v3.7.1",
          "kind": "patch",
          "published_at": "2025-11-25T14:12:00Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2025-11-20T11:02:09Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2025-10-14T08:36:30Z"
        },
        {
          "tag": "v3.5.2",
          "kind": "patch",
          "published_at": "2025-10-09T15:36:10Z"
        },
        {
          "tag": "v3.5.1",
          "kind": "patch",
          "published_at": "2025-10-07T12:41:51Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2025-09-19T09:51:03Z"
        },
        {
          "tag": "v3.4.3",
          "kind": "patch",
          "published_at": "2025-09-17T10:54:09Z"
        },
        {
          "tag": "v3.4.2",
          "kind": "patch",
          "published_at": "2025-09-10T13:29:06Z"
        },
        {
          "tag": "v3.4.1",
          "kind": "patch",
          "published_at": "2025-09-08T08:52:11Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2025-08-28T16:49:41Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2025-07-17T15:51:13Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2025-06-18T13:49:23Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2025-06-11T15:17:16Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2025-05-23T09:26:09Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2025-05-16T11:38:22Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2025-05-14T15:21:03Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2025-04-30T13:42:27Z"
        },
        {
          "tag": "v2.3.3",
          "kind": "patch",
          "published_at": "2025-04-04T13:17:10Z"
        },
        {
          "tag": "v2.3.2",
          "kind": "patch",
          "published_at": "2025-03-24T11:31:34Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2025-03-05T16:08:14Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2025-02-25T11:21:12Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2024-12-18T15:36:34Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2024-12-12T11:02:22Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2024-12-11T11:06:40Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2024-11-13T14:58:13Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2024-10-01T12:48:45Z"
        },
        {
          "tag": "v1.10.9",
          "kind": "patch",
          "published_at": "2024-09-26T11:50:19Z"
        },
        {
          "tag": "v1.10.8",
          "kind": "patch",
          "published_at": "2024-08-29T15:00:45Z"
        },
        {
          "tag": "v1.10.7",
          "kind": "patch",
          "published_at": "2024-07-25T10:10:56Z"
        },
        {
          "tag": "v1.10.6",
          "kind": "patch",
          "published_at": "2024-07-23T11:15:46Z"
        },
        {
          "tag": "v1.10.5",
          "kind": "patch",
          "published_at": "2024-07-18T13:49:14Z"
        },
        {
          "tag": "v1.10.4",
          "kind": "patch",
          "published_at": "2024-07-18T09:14:22Z"
        },
        {
          "tag": "v1.10.3",
          "kind": "patch",
          "published_at": "2024-07-09T13:35:24Z"
        },
        {
          "tag": "v1.10.2",
          "kind": "patch",
          "published_at": "2024-06-28T11:43:44Z"
        },
        {
          "tag": "v1.10.1",
          "kind": "patch",
          "published_at": "2024-06-24T10:43:00Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2024-05-29T15:35:16Z"
        },
        {
          "tag": "v1.9.5",
          "kind": "patch",
          "published_at": "2024-05-14T08:44:31Z"
        },
        {
          "tag": "v1.9.4",
          "kind": "patch",
          "published_at": "2024-04-15T09:30:20Z"
        },
        {
          "tag": "v1.9.3",
          "kind": "patch",
          "published_at": "2024-04-05T10:27:47Z"
        },
        {
          "tag": "v1.9.2",
          "kind": "patch",
          "published_at": "2024-03-28T14:25:18Z"
        },
        {
          "tag": "v1.9.1",
          "kind": "patch",
          "published_at": "2024-02-28T15:08:35Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2024-02-12T12:27:22Z"
        },
        {
          "tag": "v1.8.2",
          "kind": "patch",
          "published_at": "2024-02-07T13:41:14Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2024-01-25T16:38:12Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2024-01-25T13:12:44Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2024-01-11T10:51:22Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2023-12-13T13:19:01Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2023-12-12T09:51:25Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2023-12-04T14:22:11Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2023-10-10T13:52:32Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2023-10-09T10:23:56Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2023-09-18T13:22:16Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2023-08-07T15:25:39Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2023-07-30T08:04:44Z"
        },
        {
          "tag": "v0.2.5",
          "kind": "patch",
          "published_at": "2023-06-13T12:09:32Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2023-05-22T14:38:06Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2023-03-30T14:07:32Z"
        },
        {
          "tag": "0.2.2",
          "kind": "patch",
          "published_at": "2023-03-16T16:29:24Z"
        },
        {
          "tag": "0.2.1",
          "kind": "patch",
          "published_at": "2023-03-06T13:04:46Z"
        },
        {
          "tag": "0.2.0",
          "kind": "minor",
          "published_at": "2023-03-05T09:29:54Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "349fe1d3bdedf9bbebb1653cb87e5b323be98d4b",
          "body": null,
          "is_bot": false,
          "headline": "CM-68709: Add pip package manager support to SCA local scans (#502)",
          "author_name": "valeriistryhun-dev",
          "author_login": "valeriistryhun-dev",
          "committed_at": "2026-07-27T07:36:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed2f7148b5258e9c754fa160ebc77d46b1a06582",
          "body": "…or (#495)\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68642: stop SCA scan on restore command failure with --stop-on-err…",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-23T07:00:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dea03fbcbeca0406ceaae810e16882b864442ede",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-69233 ai guardrails respect ignores (#499)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-22T12:45:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0eeb0f29ac9fe5354c10275b541317b1f7bb9660",
          "body": "…rdrails scan (#500)\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-65504: Skip synthetic task-notification prompts in Claude Code gua…",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-22T12:44:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d823528f7faa0314eae110d7b48e998c957cd54",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-64462: add GitHub Copilot (VS Code) support to AI guardrails (#498)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-20T07:42:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a57ba409816bfb73666e4001ae891724fb9b4aeb",
          "body": "…… (#497)",
          "is_bot": false,
          "headline": "Revert \"CM-68872: gate secret-scan async (presigned) flow behind CYCO…",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-16T09:24:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "815461f84a4755315110253ce977e920294c5490",
          "body": "…T_SCAN_ASYNC (#496)\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68872: gate secret-scan async (presigned) flow behind CYCODE_SECRE…",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-15T18:17:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8be08edc66d053fc345685f19617c1bcc2949ec5",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68554: Build and sign Windows onedir executable (#494)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-12T13:36:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "49c9e404e247c3f5a00388a80800809ae0cf3736",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68342: sweep all IDEs' session context and dedup reports (#493)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-12T13:32:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1342addaab9ae33c29f989aae0af3e6ab6922630",
          "body": null,
          "is_bot": false,
          "headline": "CM-68462 added support for gradlew (#492)",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-09T11:44:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23158f506dccfb9a30bac58830887b4aac7ff7a2",
          "body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68330: fix hook payload handling on Cursor for Windows (#491)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-08T12:46:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2615e0259676f4c6c456675d32a8ad17d7491204",
          "body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-68232: read a machine-wide AI Guardrails policy path (#490)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-07-07T07:40:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2ce15d4befcbcd16fe0388b036aa2d09ae3f2d46",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump snok/install-poetry from 1.4.1 to 1.4.2 (#469)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T05:50:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7dcb13eb59f9dd577f37f41471f85265e5d772e",
          "body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-67391: Use S3 presigned upload for secret CLI scans (#476)",
          "author_name": "Ilia Shkolyar",
          "author_login": "ilia-cy",
          "committed_at": "2026-07-06T17:44:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a4b4957c9150528110dd0700055cd799e7fc37b4",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump mock from 4.0.3 to 5.2.0 (#485)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:39:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c8a96db15a72649a89b34e0f55948a5554dafe1",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump mcp from 1.27.2 to 1.28.1 (#486)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:35:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e3da7108ebf2c9b684ae8af31e26d494f01b004",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#484)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce210dfe40c15362fe01bfb03e4ad3062bb8a737",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/cache from 5.0.5 to 6.1.0 (#479)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:25:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c6e81cadef2c99da9410154d23f943615bbd795",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/setup-python from 6.2.0 to 6.3.0 (#480)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:17:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a11ea08e4280fc591fa539514bd363ca8a2eaea7",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump ruff from 0.15.15 to 0.15.20 (#487)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:07:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac3b09e4d6fd128e259617194c9fd6a7a18a8034",
          "body": null,
          "is_bot": false,
          "headline": "CM-68185 update workflow cache settings (#489)",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-06T08:10:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f44bc4b0651e4984a4c605d9e19c20e33c7f955",
          "body": null,
          "is_bot": false,
          "headline": "CM-68136 added package cooldown (#483)",
          "author_name": "omer-roth",
          "author_login": "omer-roth",
          "committed_at": "2026-07-05T08:52:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "641747d5803c411a10bad96a7263494c97bc6dd9",
          "body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-67195: Add Bun package manager support to SCA local scans (#478)",
          "author_name": "Arad Traub",
          "author_login": "AradTraub",
          "committed_at": "2026-06-29T13:25:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9f34d7f616de50ddb80fea185cd6e9b4ba46f1b6",
          "body": null,
          "is_bot": false,
          "headline": "CM-67459: Enrich session context payload (#477)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-06-29T10:10:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7f407681db37d8dae59a27a14229cd16e2a10bf",
          "body": "Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-67318: Warn when env vars override configured credentials (#474)",
          "author_name": "Ilia Shkolyar",
          "author_login": "ilia-cy",
          "committed_at": "2026-06-21T12:45:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1c6435ed5ec35355542e11433c7eedfc7353b50c",
          "body": "Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-65436: add SAST fallback ignore-extensions list (#473)",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-06-16T08:44:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d651b3ca6ab71994b989d89b2649b15f68c08988",
          "body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-65100-add-file-support-codex-and-claude (#463)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-06-14T09:48:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "67aab550d276e2f2041d523f2860b011861c08af",
          "body": "Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-64735 - Reduce sync scan latency (#472)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-06-08T12:21:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d53991be25f77090c6f913fd448c92e9d0d92759",
          "body": "…fork) (#470)",
          "is_bot": false,
          "headline": "CM-65507 fire AI Guardrails SessionStart hook on all sources (resume/…",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-06-04T11:37:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46504511ed26208417f6e1ddc099bc98159ced3",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 (#468)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T07:56:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22c1f20f222b4cecb00a54a71e49be4a65fc7b3e",
          "body": null,
          "is_bot": false,
          "headline": "CM-65133 upgrade ruff to 0.15.14 (#462)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-06-03T07:34:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c33b781fc4f929e6e703e5ebbd2f0a1307871f8a",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/upload-artifact from 4.6.2 to 7.0.1 (#449)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T05:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41285c086f755fdcd6ec769065f885ef28339c70",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pyinstaller from 6.19.0 to 6.20.0 (#443)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T05:03:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61e5289ea5e2284057921653be752da215c42592",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump cycodelabs/cimon-action from 0.10.1 to 1.0.1 (#466)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T04:47:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b798456ec7e1699dbb64c4a4061d8c443934b4c",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/build-push-action from 7.1.0 to 7.2.0 (#467)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T04:38:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af3127cb6be77a3d6d8af36dc05ec291e035fbb3",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump svenstaro/upload-release-action from 2.11.4 to 2.11.5 (#428)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-28T13:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39f70a5077b7d1f7164df2b8ff4ace4d8bb896b4",
          "body": "Co-authored-by: omerr-cycode <omer.roth@cycode.com>",
          "is_bot": false,
          "headline": "CM-63882 - Added scanType validation (#452)",
          "author_name": "aaron-butler-cy-int",
          "author_login": "aaron-butler-cy-int",
          "committed_at": "2026-05-27T15:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d152224d199bd2f8f4ddfda6b877d241afbc3bb",
          "body": "Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-62984 add codex cli support (#461)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-05-27T13:29:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "08499d3a888ce071726ea5dc5e13ff1cffa43793",
          "body": "…#459)\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-64678: refactor ai-guardrails to single-file-per-IDE abstraction (…",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-05-25T13:11:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "db56b13b9c37db1d2277a1c41d2a2248aa2cb4bb",
          "body": null,
          "is_bot": false,
          "headline": "CM-64439 updated READ for MCP with certificates (#457)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-05-19T13:26:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0e52810acd8e6f3397c5c840aad9fe4d30bc15f",
          "body": "Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-64214: Fix missing dependency paths in Maven CLI scan (#456)",
          "author_name": "Amit Moskovitz",
          "author_login": "amitmoskovitz",
          "committed_at": "2026-05-18T17:24:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "da8a2ab31c874fd06586d2dffc9a082b23a5e089",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/build-push-action from 7.0.0 to 7.1.0 (#448)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T06:17:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82c263bd744b9288933efe09547ee803295eee74",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump dunamai from 1.26.0 to 1.26.1 (#445)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T06:05:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff91b13678b1cdf84d0520f4210b52ad665ba12f",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump patch-ng from 1.19.0 to 1.19.1 (#444)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T05:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e42ebf645399035aa8fc7b9762a5f05906d3103d",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/cache from 5.0.3 to 5.0.5 (#447)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T05:40:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2199836813d5599e6113a5263fad6983923b10a6",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump cycodelabs/cimon-action from 0.10.0 to 0.10.1 (#450)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-12T14:34:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "050789cfd8ef13e7d5c7123e6d6b8a958e5cedeb",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump gitpython from 3.1.47 to 3.1.50 (#454)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-12T14:22:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c45123c9bc6961f928d6a1ae137beeef0b6b5f57",
          "body": null,
          "is_bot": false,
          "headline": "Update CODEOWNERS (#455)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-05-12T12:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "865aa40b977ec76a6f503323d01f0a9b3501dd2d",
          "body": null,
          "is_bot": false,
          "headline": "CM-62381-add-user-email-for-claude-ide (#451)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-05-06T07:30:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9e0197184e029d6bb94772ce2718ad1c3f82a66",
          "body": null,
          "is_bot": false,
          "headline": "CM-55107 add support for UV package manager for SCA scans (#441)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-05-06T06:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7451e5f10031bfab2150ad00ea436b341a31bcf",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump cycodelabs/cimon-action from 0.9.4 to 0.10.0 (#429)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-28T18:14:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5dc614203d9951c94100c0d4e2a735ecb3255c5",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump gitpython from 3.1.45 to 3.1.47 (#439)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-27T13:04:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e49a742888c5fecac0a41c1a60f61b407ba79a9",
          "body": null,
          "is_bot": false,
          "headline": "CM-63288 cli add error code 2 for scan errors (#440)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-04-27T12:40:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0a093313db7ead8fe6b48832516518395b22dcc",
          "body": "Co-authored-by: Maor Davidzon <56628808+MaorDavidzon@users.noreply.github.com>",
          "is_bot": false,
          "headline": "CM-62381-remove-matcher (#438)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-04-23T07:35:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2c22ba72608e371880c61bb423faa49c4bccd42",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/login-action from 3.7.0 to 4.0.0 (#430)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-20T14:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "980d72223cbf7637f440a95e7aef8480524aae37",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 4.3.1 to 6.0.2 (#426)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-20T12:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa1fe95a7373795435158295d68c67be8cc09754",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#427)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-20T12:46:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4213d72530e24f82bc3543d16990d0be2084289b",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pygments from 2.19.2 to 2.20.0 (#420)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-20T11:09:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5405656e5f55f81135ffb32cfa224f98e04d61fd",
          "body": null,
          "is_bot": false,
          "headline": "CM-62381-add-session-start-hook (#434)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-04-20T10:17:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1f5eb7a57652242c41683ac72b1135dfa98e5b1",
          "body": "Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-62578: Expose Cycode API v4 through CLI commands (#435)",
          "author_name": "Maor Davidzon",
          "author_login": "MaorDavidzon",
          "committed_at": "2026-04-19T07:54:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f89bbe6435becd7bebf017a6fd5bf91450c31b29",
          "body": null,
          "is_bot": false,
          "headline": "CM-61986-add-mcp-and-email-enrichment-from-claude-json (#421)",
          "author_name": "RoniCycode",
          "author_login": "RoniCycode",
          "committed_at": "2026-04-09T11:21:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d77820946c8ee5d21ab122eeed7996f54bc1d43a",
          "body": null,
          "is_bot": false,
          "headline": "CM-62406: handle more pre-push types gracefully (#433)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-04-07T15:15:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c404e4caca288a98d2294dcb7f0d06edfaf41ac1",
          "body": "…… (#432)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-61568: Fix sensitive path skipping content scan and directory hand…",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-04-07T11:22:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5c6876ab231ed744485519826e8bdd47db04f607",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump coverage from 7.2.7 to 7.10.7 (#423)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T15:50:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ac16e5d36fcff092e8e10aac47c9ce1174caa14",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pytest from 7.3.2 to 8.4.2 (#425)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T15:14:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14c71e0888b7ed5035e4db043e7f1c161be678f8",
          "body": "Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-62273: Add compression manifest to v4 presigned upload scans (#431)",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-04-02T11:20:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6cfc436abae0830e6181af57f0e5ec4b7a79bde4",
          "body": "…n (#419)\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-61550: Show upload progress and detect slow connections during sca…",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-03-27T09:31:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cf6379cfeba69e4ac55ad19ea6d14f5b7247f0d9",
          "body": null,
          "is_bot": false,
          "headline": "CM-61547 add stop-on-error flag to stop file collection on errors (#416)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-03-26T15:04:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d95dca1644c49deb19f4a1a664c50cc73f08adf",
          "body": null,
          "is_bot": false,
          "headline": "CM-61587 MCP scan improvements (#418)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-03-26T14:58:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49ec71360d3c032639556788ce5355c96b846d24",
          "body": "Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-61376: Track CLI/IDE activation events (#415)",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-03-23T11:43:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "71f3690fcd214d2845eb1e0a7378e109bd859950",
          "body": null,
          "is_bot": false,
          "headline": "CM-61023: update pinned actions (#414)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-03-18T13:14:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6462beacb666f27678c256800aaea663c3d5952e",
          "body": null,
          "is_bot": false,
          "headline": "CM-61023: fix pinning issue (#413)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-03-18T09:38:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "279cc84dce8cfb698d8c45b0f7e499724c6e4b52",
          "body": "Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CM-60929: Add report mode to ai-guardrails install (#410)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-03-18T09:19:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "364da74d85e9ea7bcb9fae4201d73a99e1793248",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pyjwt from 2.10.1 to 2.12.0 (#412)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-16T08:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf7393234ac766390ea4bb9ac70ba6a46a8ffc4",
          "body": null,
          "is_bot": false,
          "headline": "CM-61023: pin build deps (#411)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-03-16T08:46:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "867055d88d67f7cf817904a0922c945be3cc5185",
          "body": null,
          "is_bot": false,
          "headline": "CM-60869 SCA add restored files cleanup mechanism (#409)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-03-11T15:43:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3906f27961edfab4be36d5c60be0f431c0fc0650",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump patch-ng from 1.18.1 to 1.19.0 (#408)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T13:32:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cd333d078c7b6820facfa8cec771798ddc88fd4",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/download-artifact from 4 to 8 (#399)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T12:00:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b0cd9be0126fa693eebad467433ed1c225b9f51",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/build-push-action from 6 to 7 (#402)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T11:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b551df0f747683f4667e5590dca1d0581e486486",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump responses from 0.23.3 to 0.26.0 (#406)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T11:32:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae28578ae01ca1c64b852fab0411b35eecfd4980",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump dunamai from 1.21.2 to 1.26.0 (#405)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T11:23:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfdea2fce9852199b6bfb036f0fc8921988692ae",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump arrow from 1.3.0 to 1.4.0 (#407)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T11:14:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8c309c70c88635dfb64e1b33a3e366dec8b5163",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pyfakefs from 5.7.4 to 5.10.2 (#403)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T11:04:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d273c905728c87a616c36e46501ebb0b26ed8060",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/setup-python from 4 to 6 (#404)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T10:50:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1dc3599ad630f72412fd21711c4401b77830d456",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/cache from 3 to 5 (#400)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T10:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae926aba8b637b0d6386a4bfecee399c0bdcce83",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/setup-buildx-action from 3 to 4 (#401)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T10:44:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b71a99253c90e58d32cadbea0b291dfe555351b5",
          "body": null,
          "is_bot": false,
          "headline": "CM-60683: update multipart dep and schedule monthly dep updates (#398)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-03-09T10:16:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "058b06673fff380499ba43697590fd8c14c9c86c",
          "body": null,
          "is_bot": false,
          "headline": "CM-60540: remove binaryornot dep (#397)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-03-05T16:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6419aafce60542f606dbcc7c8473ec3de5bbe7ea",
          "body": null,
          "is_bot": false,
          "headline": "CM-60459-Fallback on V4 upload failure (#396)",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-03-03T17:31:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9ce12c3af14610b6896bb27e8be5ace5839b214",
          "body": null,
          "is_bot": false,
          "headline": "CM-60184-Scans using presigned post url (#395)",
          "author_name": "Mateusz Sterczewski",
          "author_login": "mateusz-sterczewski",
          "committed_at": "2026-03-03T14:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "718521abcea69720f4c419c5f4cb3e0c4fb1fff8",
          "body": null,
          "is_bot": false,
          "headline": "CM-59977: SCA maintainability improvements (#393)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-03-02T09:56:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e4450c70e8fa1fdef57019035b169cbafc20306",
          "body": null,
          "is_bot": false,
          "headline": "CM-53930: fix onedir signing issues on mac (#394)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-02-24T09:14:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "457022c99a6e927ae63d1fe0967b2ee9e2464991",
          "body": null,
          "is_bot": false,
          "headline": "CM-53930: improve notarization output (#391)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-02-23T08:36:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51e89619c07aef6151e4130aed46a19188961d8b",
          "body": null,
          "is_bot": false,
          "headline": "CM-59965 add additional logging for SCA verbose mode (#392)",
          "author_name": "omerr-cycode",
          "author_login": "omer-roth",
          "committed_at": "2026-02-23T06:54:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f55dfbedb166168002e4e9e531a135b13de21b28",
          "body": "Signed-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump starlette from 0.48.0 to 0.49.1 (#355)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-19T09:37:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "097980b62a2a207c41734811434c06c8a97a26de",
          "body": null,
          "is_bot": false,
          "headline": "CM 59844: update deps (#390)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-02-19T09:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d956fdb11e5cb72361b4d9a67947d5ca1d43f2a6",
          "body": null,
          "is_bot": false,
          "headline": "CM-59792 read file hook save file path (#389)",
          "author_name": "Ilan Lidovski",
          "author_login": "Ilanlido",
          "committed_at": "2026-02-19T08:03:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fa780d569190c51caa7f43d153b0ca46045c9d7",
          "body": null,
          "is_bot": false,
          "headline": "CM-59691: update build processes and pyinstaller setup (#386)",
          "author_name": "Philip Hayton",
          "author_login": "gotbadger",
          "committed_at": "2026-02-18T10:31:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3ae1da3c6431905602f3d130d6bb8150a5a63d6",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>\nCo-authored-by: Philip Hayton <gotbadger@users.noreply.github.com>",
          "is_bot": false,
          "headline": "CM-59712: add --maven-settings-file to report sbom path command (#385)",
          "author_name": "ronens88",
          "author_login": "ronens88",
          "committed_at": "2026-02-18T10:23:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5922901fd7937d3acb7b4a283fba492a60b21b94",
          "body": null,
          "is_bot": false,
          "headline": "Update Python version requirements in README (#387)",
          "author_name": "Brad Smith",
          "author_login": "bradmsmith",
          "committed_at": "2026-02-18T09:15:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 149,
      "latest_release_at": "2026-07-23T09:37:58Z",
      "latest_release_tag": "v3.18.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 41,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 8.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "cycode",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "secret-scan",
            "cycode",
            "devops",
            "token",
            "secret",
            "security",
            "code",
            "Development Status :: 5 - Production/Stable",
            "Environment :: Console",
            "Natural Language :: English",
            "Operating System :: OS Independent",
            "Programming Language :: Python",
            "Programming Language :: Python :: 3 :: Only",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.14",
            "Programming Language :: Python :: 3.9"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/cycode/",
          "is_deprecated": false,
          "latest_version": "3.18.0",
          "repository_url": "https://github.com/cycodehq/cycode-cli",
          "versions_count": 431,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 127867,
          "first_published_at": "2022-07-12T12:03:34.274340Z",
          "latest_published_at": "2026-07-23T09:39:32.550036Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 65,
      "stars": 99,
      "watchers": 16,
      "fork_history": {
        "days": [
          {
            "date": "2022-11-03",
            "count": 1
          },
          {
            "date": "2022-11-24",
            "count": 1
          },
          {
            "date": "2023-02-03",
            "count": 1
          },
          {
            "date": "2023-06-22",
            "count": 17
          },
          {
            "date": "2023-06-25",
            "count": 5
          },
          {
            "date": "2023-06-26",
            "count": 6
          },
          {
            "date": "2023-06-28",
            "count": 3
          },
          {
            "date": "2023-06-30",
            "count": 1
          },
          {
            "date": "2023-09-25",
            "count": 1
          },
          {
            "date": "2023-10-19",
            "count": 1
          },
          {
            "date": "2024-07-09",
            "count": 1
          },
          {
            "date": "2024-10-10",
            "count": 1
          },
          {
            "date": "2025-02-18",
            "count": 1
          },
          {
            "date": "2025-04-03",
            "count": 1
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-29",
            "count": 1
          },
          {
            "date": "2025-07-14",
            "count": 1
          },
          {
            "date": "2025-08-05",
            "count": 1
          },
          {
            "date": "2025-08-24",
            "count": 1
          },
          {
            "date": "2025-08-25",
            "count": 1
          },
          {
            "date": "2025-08-26",
            "count": 1
          },
          {
            "date": "2025-09-06",
            "count": 1
          },
          {
            "date": "2025-09-09",
            "count": 1
          },
          {
            "date": "2025-11-20",
            "count": 1
          },
          {
            "date": "2025-12-01",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 2
          },
          {
            "date": "2026-01-18",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-03-06",
            "count": 3
          },
          {
            "date": "2026-05-06",
            "count": 1
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-07-24",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 64,
        "total_forks": 65
      },
      "star_history": null,
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 53141,
      "source_files_sampled": 333,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "click",
            "direct": true,
            "version": "8.1.8",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.2,
            "advisory_ids": [
              "PYSEC-2026-2132"
            ],
            "fixed_version": "8.3.3",
            "advisory_count": 1,
            "oldest_advisory_days": 87
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 50,
        "malicious_count": 0,
        "assessed_package": "pypi:cycode@3.18.0",
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "click",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.1.0,<8.2.0"
        },
        {
          "name": "colorama",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.4.3,<0.5.0"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0,<7.0"
        },
        {
          "name": "marshmallow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.15.0,<4.0.0"
        },
        {
          "name": "gitpython",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1.50,<3.2.0"
        },
        {
          "name": "arrow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0.0,<1.5.0"
        },
        {
          "name": "requests",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.32.4,<3.0"
        },
        {
          "name": "urllib3",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.4.0,<3.0.0"
        },
        {
          "name": "pyjwt",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.8.0,<3.0"
        },
        {
          "name": "rich",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.9.4, <14"
        },
        {
          "name": "patch-ng",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "1.19.1"
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.15.3"
        },
        {
          "name": "tenacity",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=9.0.0,<9.1.0"
        },
        {
          "name": "mcp",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.28.1,<2.0.0"
        },
        {
          "name": "pydantic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.11.5,<3.0.0"
        },
        {
          "name": "pathvalidate",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.3.1,<4.0.0"
        },
        {
          "name": "tomli-w",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0.0,<2.0.0"
        },
        {
          "name": "tomli",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0.0,<3.0.0"
        },
        {
          "name": "anyio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.0.0, <4.13.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "anyio",
            "direct": true,
            "version": "4.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "arrow",
            "direct": true,
            "version": "1.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": true,
            "version": "8.1.8",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": true,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "gitpython",
            "direct": true,
            "version": "3.1.50",
            "ecosystem": "pypi"
          },
          {
            "name": "marshmallow",
            "direct": true,
            "version": "3.26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mcp",
            "direct": true,
            "version": "1.28.1",
            "ecosystem": "pypi"
          },
          {
            "name": "patch-ng",
            "direct": true,
            "version": "1.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pathvalidate",
            "direct": true,
            "version": "3.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": true,
            "version": "2.13.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": true,
            "version": "2.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": true,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": true,
            "version": "2.32.5",
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": true,
            "version": "13.9.4",
            "ecosystem": "pypi"
          },
          {
            "name": "tenacity",
            "direct": true,
            "version": "9.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": true,
            "version": "2.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli-w",
            "direct": true,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typer",
            "direct": true,
            "version": "0.15.4",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": true,
            "version": "2.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "altgraph",
            "direct": false,
            "version": "0.17.5",
            "ecosystem": "pypi"
          },
          {
            "name": "annotated-types",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.5.20",
            "ecosystem": "pypi"
          },
          {
            "name": "cffi",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.7",
            "ecosystem": "pypi"
          },
          {
            "name": "coverage",
            "direct": false,
            "version": "7.10.7",
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "48.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "dunamai",
            "direct": false,
            "version": "1.26.1",
            "ecosystem": "pypi"
          },
          {
            "name": "exceptiongroup",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "gitdb",
            "direct": false,
            "version": "4.0.12",
            "ecosystem": "pypi"
          },
          {
            "name": "h11",
            "direct": false,
            "version": "0.16.0",
            "ecosystem": "pypi"
          },
          {
            "name": "httpcore",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "pypi"
          },
          {
            "name": "httpx",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "pypi"
          },
          {
            "name": "httpx-sse",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.18",
            "ecosystem": "pypi"
          },
          {
            "name": "importlib-metadata",
            "direct": false,
            "version": "8.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "4.26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-specifications",
            "direct": false,
            "version": "2025.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "macholib",
            "direct": false,
            "version": "1.16.4",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-it-py",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mdurl",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mock",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pefile",
            "direct": false,
            "version": "2024.8.26",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycparser",
            "direct": false,
            "version": "3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-core",
            "direct": false,
            "version": "2.46.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-settings",
            "direct": false,
            "version": "2.14.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyfakefs",
            "direct": false,
            "version": "5.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyinstaller",
            "direct": false,
            "version": "6.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyinstaller-hooks-contrib",
            "direct": false,
            "version": "2026.5",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-mock",
            "direct": false,
            "version": "3.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dateutil",
            "direct": false,
            "version": "2.9.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "python-multipart",
            "direct": false,
            "version": "0.0.30",
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32",
            "direct": false,
            "version": "311",
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32-ctypes",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "pypi"
          },
          {
            "name": "referencing",
            "direct": false,
            "version": "0.37.0",
            "ecosystem": "pypi"
          },
          {
            "name": "responses",
            "direct": false,
            "version": "0.26.1",
            "ecosystem": "pypi"
          },
          {
            "name": "rpds-py",
            "direct": false,
            "version": "0.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ruff",
            "direct": false,
            "version": "0.15.20",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "82.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "shellingham",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "smmap",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "sse-starlette",
            "direct": false,
            "version": "3.4.4",
            "ecosystem": "pypi"
          },
          {
            "name": "starlette",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspection",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "tzdata",
            "direct": false,
            "version": "2026.2",
            "ecosystem": "pypi"
          },
          {
            "name": "uvicorn",
            "direct": false,
            "version": "0.48.0",
            "ecosystem": "pypi"
          },
          {
            "name": "zipp",
            "direct": false,
            "version": "3.23.1",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 75,
        "direct_count": 19,
        "indirect_count": 56
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 3,
        "merged_prs": 454,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 46
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "MarshalX",
          "commits": 175,
          "avatar_url": "https://avatars.githubusercontent.com/u/15520314?v=4"
        },
        {
          "type": "User",
          "login": "MichalBor",
          "commits": 56,
          "avatar_url": "https://avatars.githubusercontent.com/u/12269096?v=4"
        },
        {
          "type": "User",
          "login": "morsa4406",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/104304449?v=4"
        },
        {
          "type": "User",
          "login": "avishaiamiel",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/93073140?v=4"
        },
        {
          "type": "User",
          "login": "gotbadger",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/699436?v=4"
        },
        {
          "type": "User",
          "login": "omer-roth",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/204220715?v=4"
        },
        {
          "type": "User",
          "login": "Ilanlido",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/105583525?v=4"
        },
        {
          "type": "User",
          "login": "mateusz-sterczewski",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/187307637?v=4"
        },
        {
          "type": "User",
          "login": "naftalicy",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/178474828?v=4"
        },
        {
          "type": "User",
          "login": "RoniCycode",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/142726722?v=4"
        }
      ],
      "contributors_sampled": 34,
      "top_contributor_share": 0.428
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build_executable.yml",
        "docker-image.yml",
        "pre_release.yml",
        "release.yml",
        "ruff.yml",
        "tests.yml",
        "tests_full.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "poetry.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 9,
            "reason": "Found 21/22 approved changesets -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "20 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "349fe1d3bdedf9bbebb1653cb87e5b323be98d4b",
        "ran_at": "2026-07-27T07:58:30Z",
        "aggregate_score": 6.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T07:37:50Z",
      "oldest_open_prs": [
        {
          "number": 446,
          "created_at": "2026-05-01T22:05:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 488,
          "created_at": "2026-07-05T08:55:21Z",
          "last_comment_at": "2026-07-06T17:39:59Z",
          "last_comment_author": "omer-roth"
        },
        {
          "number": 503,
          "created_at": "2026-07-24T22:39:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-27T07:36:40Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cycodehq/cycode-cli",
    "host": "github.com",
    "name": "cycode-cli",
    "owner": "cycodehq"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 74,
      "inputs": {
        "security": 66,
        "vitality": 91,
        "community": 67,
        "governance": 76,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 91,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "commits_last_year": 149,
              "human_commit_share": 0.61,
              "days_since_last_push": 0,
              "active_weeks_last_year": 41
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "41/52 weeks with commits",
                "points": 28.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 41
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "149 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 149
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v3.18.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 8.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 67,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "forks": 65,
              "stars": 99,
              "watchers": 16,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "99 stars",
                "points": 32.3,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 99
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "65 forks",
                "points": 15.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 65
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "16 watchers",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "packages": [
                "cycode"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 127867
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "127,867 downloads/month across pypi",
                "points": 68.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 127867,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 76,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 34,
              "top_contributor_share": 0.428
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 43% of commits",
                "points": 12.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 43
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "34 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 91,
            "inputs": {
              "merged_prs": 454,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 46
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "454/500 decided PRs merged",
                "points": 34.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 454,
                      "decided": 500
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 21/22 approved changesets -- score normalized to 9",
                "points": 13.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "followers": 20,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "cycodehq",
              "public_repos": 7,
              "account_age_days": 2582
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "20 followers of cycodehq",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 20,
                      "login": "cycodehq"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "7 public repos, account ~7 yr old",
                "points": 18.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 7
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "cycode"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "431 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 431
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "code",
                "sast",
                "sca",
                "secrets",
                "secure",
                "security",
                "cycode"
              ],
              "has_wiki": false,
              "homepage": "https://www.cycode.com",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.cycode.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 66,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 21/22 approved changesets -- score normalized to 9",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "20 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the pypi:cycode@3.18.0 runtime dependency closure — what installing the published package pulls in — 50 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "pypi:cycode@3.18.0",
                  "assessed": 50
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 50,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: click 8.1.8 (high 7.2)",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "click 8.1.8 (high 7.2)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 50,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 46,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.869,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "53 of 61 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 53,
                      "sampled": 61
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "poetry.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.25,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.39
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "25 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 25,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "39 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 39,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 53141,
              "source_files_sampled": 333,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/333 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 333,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T07:59:00.102289Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cycodehq/cycode-cli.svg",
  "full_name": "cycodehq/cycode-cli",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPyPI.