Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"icp-brasil",
"digital-signature",
"cryptography",
"timestamp",
"pki",
"certificates",
"x509certificates",
"x509"
],
"is_fork": false,
"size_kb": 55889,
"has_wiki": true,
"homepage": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
"languages": {
"Go": 20616,
"HTML": 517,
"Java": 1853557,
"Shell": 4505
},
"pushed_at": "2026-07-24T07:22:05Z",
"created_at": "2016-11-08T18:23:40Z",
"owner_type": "Organization",
"updated_at": "2026-07-15T21:35:50Z",
"description": "Repositório que contém os componentes para facilitar a implementação de assinatura digital nos padrões da ICP-BRASIL",
"is_archived": false,
"is_disabled": false,
"license_spdx": "LGPL-3.0",
"default_branch": "master",
"license_spdx_raw": "LGPL-3.0",
"primary_language": "Java",
"significant_languages": [
"Java"
]
},
"owner": {
"blog": "https://www.frameworkdemoiselle.gov.br/",
"name": "Demoiselle",
"type": "Organization",
"login": "demoiselle",
"company": null,
"location": "Brazil",
"followers": 28,
"avatar_url": "https://avatars.githubusercontent.com/u/541492?v=4",
"created_at": "2010-12-30T11:49:11Z",
"is_verified": null,
"public_repos": 29,
"account_age_days": 5685
},
"license": {
"state": "standard",
"spdx_id": "LGPL-3.0",
"raw_spdx": "LGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "4.5.0",
"kind": "minor",
"published_at": "2025-11-21T14:01:49Z"
},
{
"tag": "3.0.1",
"kind": "patch",
"published_at": "2017-04-26T18:56:53Z"
},
{
"tag": "3.0.0",
"kind": "major",
"published_at": "2017-04-18T15:05:39Z"
}
],
"recent_commits": [
{
"oid": "89c54a31fd05b8a7a410bb9c5c5e9c0ebe4a9d7c",
"body": "Versão 4.6.1 para o master",
"is_bot": false,
"headline": "Merge pull request #451 from demoiselle/4.6.1",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T20:42:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4348c53e3c33fff5e749186dfc0a690ef49454d0",
"body": "Versão 4.6.1 para ramo 4.6.1",
"is_bot": false,
"headline": "Merge pull request #450 from evandrojr/4.6.1",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T20:40:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "175dcc48d77292ec4ec4da57f55acfe59f6b37f2",
"body": "…vhistory.xml; correct release notes for 4.5.1",
"is_bot": false,
"headline": "fix: update version numbers to 4.6.1 in pom.xml, bookinfo.xml, and re…",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T20:37:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "22a87308af011e3225c2c24746b0a3b1f36b3197",
"body": null,
"is_bot": false,
"headline": "chore: remove VSCode settings file",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T20:34:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e7d14f83c97760f5e010c45f18f8d480112314c",
"body": null,
"is_bot": false,
"headline": "chore: remove obsolete deployment scripts and logs",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T20:33:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a16064549face2e0d0d0527375d9430e363a920",
"body": null,
"is_bot": false,
"headline": "fix: update policy-engine version to 4.6.1 and fix dependencies",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T18:17:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1920632fd96a970b8919bc60ca729a651a0d216b",
"body": null,
"is_bot": false,
"headline": "fix: correct strings.Repeat in publicador.go",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T18:09:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69b4300558426208084a91a28614bbd952c3eec9",
"body": null,
"is_bot": false,
"headline": "build: fix Sonatype Central publication and add Go deploy script",
"author_name": "Evandro Junior",
"author_login": "evandrojr",
"committed_at": "2026-07-15T17:00:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "034652b11754966bfc7d77e1a863775d324a36eb",
"body": null,
"is_bot": false,
"headline": "docs: update TESTING.md, integration tests moved to external project",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-09T20:59:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2437351072993a65cc8d58dc4dbc3733a8a3107d",
"body": null,
"is_bot": false,
"headline": "docs: update README to version 4.6.1",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-09T20:58:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2515312595c9e0178d88a5f7f9c330e5da7dc8e6",
"body": null,
"is_bot": false,
"headline": "release: version 4.6.1, update deploy script and cleanup tests",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-09T19:38:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79a6b338b4f70c93b1146060c3d863e130a43a2f",
"body": "- Bumped log4j-api, log4j-core, and log4j-1.2-api from 2.11.2 to 2.25.4\n- Bumped jackson-databind from 2.0.6 to 2.22.0\n- Bumped xmlsec from 2.0.10 to 2.2.6",
"is_bot": false,
"headline": "chore(security): bump dependencies for vulnerabilities",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-07T11:18:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "deed98e93ac75e6d1f35945e8ba4fd59f4c0d44a",
"body": "…atibility\n\n- Replaced explicit casts to DERTaggedObject, DEROctetString, DLSequence, and DERIA5String with generic ASN1* classes and .getInstance() methods.\n- Fixed ClassCastException in BasicCertificate.getAuthorityKeyIdentifier() and related methods.\n- Updated policy-engine parsing logic (LPA, PolicyInfo, etc.) to use generic ASN1Sequence and ASN1OctetString.\n- Added unit and integration tests (AuthorityKeyIdentifierTest/IT) to verify fixes.\n- Updated version to 4.6.1-SNAPSHOT in all modules.",
"is_bot": false,
"headline": "fix(core,policy): refactor ASN.1 parsing for Bouncy Castle 1.7x+ comp…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-06T17:37:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "534176a576ca386b868eb213c60be002dc0e4219",
"body": null,
"is_bot": false,
"headline": "Release 4.6.0",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-07-03T10:08:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "917c37e7745a0e845bd93788c35e32032bdd946d",
"body": "- Converte classe com método main para um caso de teste JUnit 4 (@Test).\n- Remove blocos de texto (Java 15+) incompatíveis com o -source 8 do projeto.\n- Remove caracteres ocultos/inválidos que causavam falha na compilação.\n- Remove chamada a método getCnpjAR() inexistente em BasicCertificate.",
"is_bot": false,
"headline": "test(core): adapta Resolution211CertificateDataTest para JUnit 4",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-23T13:14:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb68818bc920797d96339e886e726ac8ae1500e7",
"body": "…cateExtra\n\n- Atualiza o metodo isCertificatePJ() para verificar a presenca tanto do OID de CEI (2.16.76.1.3.7) quanto do OID de CNPJ (2.16.76.1.3.3), alinhando a validacao aos padroes da ICP-Brasil e a implementacao em ICPBRSubjectAlternativeNames.",
"is_bot": false,
"headline": "fix: corrige identificacao inconsistente de certificado PJ em Certifi…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-22T15:16:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d353525ee5ffe1ea89cbfa05376d74bafb1d95fe",
"body": "- PolicyUtils.getPolicyByOid(): retorna null com warn para OID nulo/vazio ou nao mapeado\n- XMLChecker.verifyPolicy(): early return null se policyOID for nulo ou\n politica nao reconhecida, evitando NPE e aceitacao de politica incorreta",
"is_bot": false,
"headline": "fix: rejeita OID de politica nao mapeado em vez de aceitar silentemente",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-19T16:10:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2129e3981d6ea19f2555efaf9983041b438f1ac2",
"body": "…ação",
"is_bot": false,
"headline": "fix: torna detecção de AC Raiz leniente apenas em ambiente de homolog…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-19T16:00:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44cfc2b063808a152f7fe05f5f77f2c42b4bc702",
"body": null,
"is_bot": false,
"headline": "fix: melhora detecção de AC Raiz e comparação de Principals no CAManager",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-19T15:33:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "963fede9fd0ad064ba5ca715006d2735fe10a9ed",
"body": "…cação",
"is_bot": false,
"headline": "fix: refatora CAManager para construção robusta de cadeias de certifi…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-19T15:18:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc05dd9ab7f66398e964b24f17239f0dcecbc419",
"body": "…s XAdES",
"is_bot": false,
"headline": "fix: corrige erro de sintaxe e melhora robustez no lookup de elemento…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T23:11:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0a3631372d744d4c485f18fe8d325e6503a8620",
"body": "…orar validação",
"is_bot": false,
"headline": "fix: torna a busca de elementos XAdES flexível a namespaces para melh…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T23:07:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f540b271e1987ecf27ac346ba5734dc70875231",
"body": "…a de carregamento",
"is_bot": false,
"headline": "fix: garante retorno do identificador da política XAdES mesmo em falh…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T23:00:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b0cf713084e455bb99507a9eaedd51c01743405",
"body": "…olitica v2.5\n\nO PolicyUtils estava falhando ao resolver OIDs da v2.5 (.2.5) e caindo no fallback que tambem estava incorreto ou retornando string invalida. Agora o parser OID -> PolicyFactory resolve as politicas da Raiz v12 com seguranca.",
"is_bot": false,
"headline": "fix(policy): corrige NullPointerException no XAdES mapeando OIDs da p…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T19:49:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8ca92964fd8cb47c8e5b7d36523f23812ea79f9",
"body": "Incorpora as variacoes de versoes de politicas PAdES (v1.4) e XAdES (v2.5) na skill e alerta para a necessidade de atualizacao do XMLPoliciesOID, evitando incidentes futuros.",
"is_bot": false,
"headline": "docs(cli): atualiza skill de cadeias com licoes aprendidas",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T19:10:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d40b1736b1726564d779caee8e116410f78f1672",
"body": "…atualizado",
"is_bot": false,
"headline": "chore: adiciona os artefatos fisicos das novas politicas PAdES e BKS …",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T18:50:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4be7ff9d92330a059c7f5255c8871302d626ac4e",
"body": "Baseado no levantamento oficial das raizes, mapeia e adiciona suporte nativo as politicas PAdES v1.3 e v1.4, alem de atualizar o default do PAdESSigner para a versao v1.3 garantindo compatibilidade da RB com Raiz v12.",
"is_bot": false,
"headline": "fix(policy): complementa suporte a PAdES com raizes v12",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T18:50:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "341d52b61cacdab36857700da436e9fc5752b3d0",
"body": "Mapeia as politicas XML v2.5 e PAdES v1.3/v1.4, alinhando os construtores padroes para XAdES (v2.5) de acordo com os ultimos lancamentos da ICP-Brasil. OIDs atualizados em XMLPoliciesOID.",
"is_bot": false,
"headline": "fix(policy): corrige limites de versoes para XAdES e PAdES com raiz v12",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T18:31:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d86811d224636e50f387a6b3104ff40af324e34",
"body": "Atendendo a recomendacao do lider tecnico (Ronald), a validacao estrita que barrava assinaturas incompatíveis com a Raiz v12 foi comentada para não causar breaking changes ou bloqueios em produtos satelites antes do esperado. A prioridade emergencial eh focar na migracao suave dos defaults para v2.4 (ja realizados). Uma arquitetura definitiva para cruzar as raizes homologadas dentro do arquivo .der da politica sera pensada em releases futuras.",
"is_bot": false,
"headline": "fix(policy): suspende trava de seguranca de raiz provisoriamente",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T12:10:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d49f976e03c30fc736fee81f85eeebdc214a71e",
"body": "…v2.4\n\nSubstitui a política AD_RB_CADES_2_3 pela AD_RB_CADES_2_4 no TokenSignatureIT para atestar a interoperabilidade do hardware fisico com a nova Raiz v12 e com as travas do RootCompatValidator.",
"is_bot": false,
"headline": "test: atualiza teste do token para validar fluxo com a nova politica …",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T11:14:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8448e510ebfc2c1781eb20acce26ad762d315fb",
"body": "…rtefatos\n\nEssa skill instrui o agente de IA a seguir um fluxo seguro e validado sempre que solicitado a atualizar cadeias ou politicas, passando pelo descobrimento da LPA, download e testes de compilacao.",
"is_bot": false,
"headline": "feat(cli): adiciona skill para o Gemini automatizar atualizacoes de a…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T10:15:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9afa20852c186df08b7719cb6a7ea56d7828450d",
"body": "O relatorio explica a causa raiz da rejeicao de assinaturas no ITI, esclarece que a automacao de politicas nao falhou, e documenta as modificacoes (Hotfix, Defaults, RootCompatValidator) realizadas no motor Java, alem de orientacoes para os produtos finais.",
"is_bot": false,
"headline": "docs: adiciona relatorio de incidente sobre Raiz v12 e politicas",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T10:10:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3ba71c057e6e0c7618bba99d72420253daf1bd1",
"body": "Mapeia as novas politicas v2.4 e v2.5 do ITI no enum PolicyFactory. Implementa trava de seguranca (RootCompatValidator) que barra assinaturas caso o certificado pertença a uma hierarquia de Raiz v12 mas a politica solicitada seja antiga (< v2.4), impedindo assinaturas invalidas. Atualiza os defaults de CAdES, PAdES e XAdES para as ultimas versoes confiaveis das politicas.",
"is_bot": false,
"headline": "feat(policy): Suporte a Raiz v12 e politicas v2.4/v2.5",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-18T10:07:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "126312b05664ee2d0d8919aa48cf6ac7370f6082",
"body": "Atualiza as dependências do Bouncy Castle nos POMs e nos scripts de automação Go para a versão lts8on-2.73.11, alinhando com as atualizações do Java. Remove referências ao DatatypeConverter deprecado em ICPBrasilOnLineSerproProviderCA.java e atualiza os binários gerados.",
"is_bot": false,
"headline": "chore: atualiza Bouncy Castle para LTS 2.73.11 e ajusta código Java",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T18:52:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cfdcec4ec8d9d9d6800bfdeb407232c63f290fb",
"body": "…tomation\n\nAtualiza dependências do projeto para usar pacotes Bouncy Castle LTS (bc*-lts8on) na versão 2.73.11, garantindo melhor suporte a ECDSA/SHA512. Substitui DatatypeConverter por Base64 para compatibilidade com Java 25. Adiciona script unificado de atualização de artefatos de homologação.",
"is_bot": false,
"headline": "feat: upgrade Bouncy Castle to 2.73.11 and add homologation update au…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T18:50:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4ccc7a2ce2d96b1717b27fc891cda79762a38c3",
"body": "O importador agora suporta a flag '-update-lpa', que baixa o LPA.xml da ICP-Brasil, faz o parse das URLs (incluindo inferência da extensão .der) e as adiciona automaticamente ao politicas.txt, mantendo a lista oficial sempre em dia com o ITI.",
"is_bot": false,
"headline": "feat: adiciona flag -update-lpa para autodescoberta de políticas",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T18:15:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f646f6cdf831b16ee45247f67fc33e3d69d5880b",
"body": "Consolida as rotinas de download de cadeias e políticas de prod/hom em um único projeto modular em automacao-importador/. Resolve erro de parsing de certificados ECC (Raiz v13) adicionando rotina de limpeza PEM com OpenSSL antes da importação do keytool. Remove scripts bash/go esparsos.",
"is_bot": false,
"headline": "refactor: cria importador unificado em Go e remove scripts antigos",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T18:07:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c90790bd19dd1b3011ee6d7350e79392853b7097",
"body": "Atualiza scripts de download de políticas e cadeias para incluir headers de navegador, resolvendo falhas de conexão com os servidores da ICP-Brasil e ITI.",
"is_bot": false,
"headline": "fix: adicionar User-Agent para evitar bloqueios no download de artefatos",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T14:10:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3efffe3d5ff2a92e6fcc3495afa779fb826c492",
"body": "Adiciona script mestre 'atualizar-artefatos-producao.sh' e script auxiliar para download de cadeias. Inclui documentação detalhada sobre o processo de atualização de produção.",
"is_bot": false,
"headline": "feat: automação completa para atualização de cadeias e políticas",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T13:56:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "088ce2649d6be7beca447f5f93f0efc7cee8d856",
"body": "…il 'it'\n\nRenomeia arquivos de teste de integração para *IT.java para serem ignorados pelo surefire. Configura failsafe no parent pom com skipITs=true por padrão. Adiciona perfil 'it' para ativar os testes de integração quando desejado.",
"is_bot": false,
"headline": "feat: isolar testes de integração usando maven-failsafe-plugin e perf…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T13:48:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6dad84386a6f34ac46e5cbaf48ae9951bd2b4dc6",
"body": "- Adiciona 'synchronized' ao CAManager.getCertificateChain para evitar condições de corrida.\n- Implementa try-with-resources nos provedores de cadeias para garantir o fechamento de streams.\n- Resolve erro 'O arquivo já está sendo usado por outro processo' no Windows.",
"is_bot": false,
"headline": "fix: corrige lock de arquivo e concorrência no carregamento de cadeias",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-17T13:38:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3719ed1d45fcc6396a99015e256ae844e9da099b",
"body": "…FX real\n\n- Ajusta getCertificateLevel para usar startsWith ao invés de equals, permitindo identificar corretamente os certificados que possuem sub-políticas anexadas ao OID base (ex: 2.16.76.1.2.201.1 para SE-S).\n- Adiciona PfxIntegrationTest que valida empiricamente a extração do CNPJ (Y1V5MYJT000195) a partir do serialNumber do DN utilizando o certificado de homologação do novo perfil.",
"is_bot": false,
"headline": "fix: Correspondência flexível de OID para sub-políticas e teste com P…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-16T17:31:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b07a9457e5352786db9f6c9f5101979a9c8bf24",
"body": "- Adiciona suporte aos novos perfis de certificados: Selo Eletrônico (SE-S, SE-H) e Aplicações Específicas (AE-S, AE-H).\n- Extração de CNPJ e CPF a partir do OID 2.5.4.5 (serialNumber) no DN para os novos perfis.\n- Extração do CNPJ da AR a partir do OID 2.16.76.1.4.5.1 no SubjectAlternativeName.\n- R\n[…]\nficados mockados.\n- Adiciona TokenIntegrationTest para validação empírica de certificados em hardware token, incluindo verificação de retrocompatibilidade com OIDs extintos (Título Eleitor, RIC, etc).",
"is_bot": false,
"headline": "feat: Suporte à Resolução 211 da ICP-Brasil",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-16T17:20:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af4067fdd1ece526f7c2eb0cf5f7a9d1acbf52ba",
"body": "…ateLevel()\n\n- Corrige getCertificateLevel() que usava startsWith() em OIDs,\n causando colisão entre A2 (2.16.76.1.2.2) e SE-S (2.16.76.1.2.201)\n e entre A1 (2.16.76.1.2.1) e S1-S4 (2.16.76.1.2.101-104)\n- Troca cast de DLSequence para ASN1Sequence (compatível com DER)\n- Remove varASN1InputStream f\n[…]\nE para retornar corporateName de Equipment\n- Adiciona bloco SE ao toString() e mensagens i18n\n- Adiciona ICPBRCertificateSE (nova classe)\n- Adiciona teste de SE com policy OID, renomeia teste enganoso",
"is_bot": false,
"headline": "fix: corrige detecção de Selo Eletrônico e bugs de OID em getCertific…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-15T19:32:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "373b74304aa699a52b5183d178a032737cbfcb93",
"body": null,
"is_bot": false,
"headline": "arquivo removido",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-11T11:24:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "61ce32ac29ea249c27d4fcad16f9c87bc5226694",
"body": null,
"is_bot": false,
"headline": "Executa os testes em todas as versoes java LTS",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-11T11:21:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "990fcf054bec24b95297a1d8c6a73677b1b0bd61",
"body": "Roda os testes do signer-core no Java 8, 11, 17 e 25 para validar a retrocompatibilidade da refatoração.",
"is_bot": false,
"headline": "chore: adiciona script go para automação de testes multi-versão",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-11T11:16:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f30ae7dc93f4bdec1a2d4efcaf610e2188678f3",
"body": "O Java 9+ utiliza o método Provider.configure() que quebrava o build em Java 8. Adicionado método de inicialização via reflection que suporta o Java 9+ e possui fallback compatível com os antigos construtores SunPKCS11 do Java 8.",
"is_bot": false,
"headline": "fix: refatora PKCS11 Provider para suportar Java 8 via Reflection",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-11T11:07:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c414a49e043a916bcf20601df91ea1c72ce826a",
"body": "…1 ICP-Brasil)\n\nMapeia novos OIDs para Selo Eletrônico (SE-S, SE-H) e CNPJ da AR.\n\nPrioriza extração de CPF e CNPJ pelo campo serialNumber no DN do certificado.\n\nGarante retrocompatibilidade mantendo extração via SubjectAlternativeNames (SAN) para perfis legados.\n\nRemove fallback depreciado que extraía dados fatiando o Common Name (CN).\n\nAdiciona BasicCertificateTest validando extrações de CPF e CNPJ nos novos padrões.",
"is_bot": false,
"headline": "feat: adiciona suporte aos novos perfis de certificados (Resolução 21…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-11T11:00:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2231c334383cce5c9e1e9ce439f67a94e0e4e21c",
"body": "…iciona testes",
"is_bot": false,
"headline": "fix: corrige parsing de PolicyInfo para lidar com revocationDate e ad…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-06-01T14:44:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "10a8dccc6c477620f3e136b1c47bbfdd6b00b9f2",
"body": "A partir do xmlsec 2.3.x, Canonicalizer.canonicalizeSubtree(Node) que\nretornava byte[] foi removida. A nova assinatura é\ncanonicalizeSubtree(Node, OutputStream) que retorna void.\n\nArquivos corrigidos (8 chamadas no total):\n- XMLSigner.java (2 chamadas)\n- XMLChecker.java (3 chamadas)\n- XMLSignedAttri\n[…]\nByteArrayOutputStream();\n c14n.canonicalizeSubtree(node, baos);\n byte[] result = baos.toByteArray();\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: adapta canonicalizeSubtree para API do xmlsec 2.3.x",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-29T18:21:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9c5eb6e2917f22ac1b4485a5dd8ae4d17b72d47a",
"body": "- ASN1Object: substitui System.out.println por logger (SLF4J)\n- PolicyIssuerName: substitui System.out.println por logger (SLF4J)\n- PolicyInfo: corrige condição que usava 'secondObject' (índice 1)\n em vez de 'revocationObject' (índice 3) para detectar revocationDate\n- policy-impl-xades: atualiza xmlsec 2.0.10 → 2.3.5 (fix de segurança,\n resolve Dependabot PR #397 do upstream demoiselle/signer)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: corrige bugs e atualiza xmlsec para 2.3.5",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-29T17:59:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f7016af5000d3be05b15f231d70d8598f5068bb0",
"body": "Em Java 25+, entradas OtherName no SAN podem ter mais de 2 elementos,\nfazendo list.size() != 2 lançar exceção e abortar todo o loop.\nResultado: mapa 'extras' vazio, getCNPJ() retorna null (NPE nos chamadores).\n\nCorreção:\n- Muda condição para < 2 (tolera listas com 2+ elementos)\n- Remove throw, usa continue para pular entrada inválida\n- Muda logger.error para logger.info (não é erro crítico)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: corrige parsing de SubjectAlternativeNames com mais de 2 elementos",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-28T12:19:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b43814e217c6263d6a9d8cd4a9182de57086e044",
"body": "…externos\n\n- Versão 3.0.1 → 3.10.1 (build, reporting, perfil aggregated)\n- Substitui failOnError=false por <doclint>none</doclint> (causa raiz dos erros)\n- Adiciona detectJavaApiLink=false e detectOfflineLinks=false para evitar\n falhas de redirecionamento HTTP nos links externos (Oracle, BouncyCastle)\n- Remove links externos que causavam 'Unexpected redirection' errors\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(javadoc): atualiza plugin 3.10.1, doclint=none, desabilita links …",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-26T16:13:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "751c3b6a40bb9172b322afe17c0421acee15e65c",
"body": "… failOnError\\n\\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: maven-javadoc-plugin — add BouncyCastle javadoc link and disable…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-26T13:33:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2882ff9b746131472efd1e695c8dfc0f1b09e623",
"body": "BouncyCastle 1.80 passou a retornar DLTaggedObject e DLSequence\nao invés de DERTaggedObject e DERSequence ao parsear arquivos DER.\n\nAs verificações 'instanceof DERTaggedObject' e 'instanceof DERSequence'\nfalhavam silenciosamente, fazendo com que signerAndVeriferRules ficasse\nnull em CommonRules.pars\n[…]\nence por ASN1Sequence\n- Atualizados casts e imports correspondentes\n- ASN1Object.getDERSequence() e getDEREnumerated() atualizados\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: corrige parsing de política ASN.1 com BouncyCastle 1.80",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-25T20:50:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f9639a6b5da2d82bd2500b2fb392a50f9c567a6b",
"body": "4.5.1",
"is_bot": false,
"headline": "Merge pull request #442 from demoiselle/4.5.1",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-05-21T18:08:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "001bc864fecbb46e84eabac218cf56825681ee94",
"body": "4.5.1",
"is_bot": false,
"headline": "Merge pull request #441 from evandrojr/4.5.1",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-05-21T18:06:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "332d152220012373c69bbc796fc9092cc8d1c82d",
"body": null,
"is_bot": false,
"headline": "Atualiza a versão para 4.6.0-SNAPSHOT em arquivos de documentação",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-20T14:13:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cee764b6150481343e999fb77ede912364e08971",
"body": null,
"is_bot": false,
"headline": "4.6.0-SNAPSHOT",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-20T13:59:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ec76b3a21aed44075fada7681e6a80fe8a84d03",
"body": null,
"is_bot": false,
"headline": "Remove versão SNAPSHOT e define versão estável 4.5.1 no pom.xml",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-20T13:50:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24b0cbb2137562eeba20298fc89540f56b4a5f80",
"body": null,
"is_bot": false,
"headline": "Merge branch '4.5.1' into 4.6.0-com-4.5.1",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-20T13:49:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb381c8fd6802bdd4947444050fb4ddf88420717",
"body": "…erar-versao.sh",
"is_bot": false,
"headline": "Atualiza versão para 4.5.1 em todos os arquivos pom.xml e no script g…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-18T14:26:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d6637283ae54c08384d0d08aa95c6c578f0a33b0",
"body": null,
"is_bot": false,
"headline": "Atualiza versão para 4.5.1 em arquivos de documentação e pom.xml",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-18T14:17:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63956df148a0ea65d2903a781e249c9f46ee4515",
"body": "Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Adiciona release notes 4.5.1 e atualiza README",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-15T13:55:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4e5e2d661457a5b0b9c3808a6b8fe8850621234c",
"body": "…o HTTPS\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Cache SSLContext ICP-Brasil para evitar reconstrução a cada requisiçã…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-15T13:48:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "919105653d96039eea7632145bf755141a2c0b00",
"body": "Ao fazer fallback de HTTP para HTTPS, a JVM rejeitava certificados\ndos servidores do governo (ex: politicas.icpbrasil.gov.br) por não\nter os CAs da ICP-Brasil no truststore padrão.\n\nA solução carrega os CAs disponíveis via ProviderCAFactory (ServiceLoader)\ne constrói um SSLContext confiável para a conexão HTTPS. Um ThreadLocal\nprevine recursão infinita quando providers online também usam Downloads.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Corrige erro PKIX em conexões HTTPS usando cadeia ICP-Brasil",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-15T13:45:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0ce0ead8fe30b4226181a3522bbe48d5468c88b7",
"body": "…o de versão",
"is_bot": false,
"headline": "Adiciona script gerar-versao.sh para automatizar o processo de criaçã…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-15T13:32:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "03697916b2f90bceb4ec9b224b9ecb89e3343a2e",
"body": "…HOT em todos os arquivos pom.xml",
"is_bot": false,
"headline": "Aumento timeout download cadeias e Atualiza a versão para 4.5.1-SNAPS…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-15T13:31:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93e49913eb033933cd2e40d0bd4e48c3c64dfa8c",
"body": "Tika 2.9.3 chama UnsynchronizedByteArrayInputStream.builder() que foi\nintroduzido no commons-io 2.12.0. Atualiza todas as declaracoes:\n- bom/pom.xml: 2.11.0 -> 2.15.1\n- policy-impl-pades/pom.xml: 2.8.0 -> 2.15.1\n- policy-impl-xades/pom.xml: 2.6 -> 2.15.1\n- signer-xmldsig/pom.xml: 2.6 -> 2.15.1\n- signer-examples/pom.xml: 2.8.0 -> 2.15.1\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: atualiza commons-io de versoes antigas para 2.15.1",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T20:48:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "21ec1faa922b9062fa9fb26568487d2cdd6502a8",
"body": "…ado não é encontrada",
"is_bot": false,
"headline": "Loga informação do fornecedor e da cadeia quando a cadeia do certific…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T20:27:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "515ca3265edccd1318f30fd4e08901c37a54cfae",
"body": "…1.80\n\nBouncyCastle 1.80 retorna DLTaggedObject em vez de DERTaggedObject ao\nler sequencias via ASN1InputStream. Os casts para DERTaggedObject lancavam\nClassCastException silenciosa no CertificateExtra, deixando o mapa extras\nvazio. Como resultado, isCertificatePF()/isCertificatePJ() retornavam fals\n[…]\nt (superclasse), ASN1OctetString e ASN1String\nem vez das classes DER* concretas, tornando o parsing robusto para\nDL*, DER* e BER*.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: corrige parsing de OtherName do SAN compativel com BouncyCastle …",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T19:49:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a1bee215294bfb789bc3bc0cd8660a3fc98a6c09",
"body": null,
"is_bot": false,
"headline": "sMerge branch 'master' of github.com:evandrojr/signer",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T12:09:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7d757dc483801128ba7ee483229fe1a95433411",
"body": "…ado não é encontrada",
"is_bot": false,
"headline": "Loga informação do fornecedor e da cadeia quando a cadeia do certific…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T12:09:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8dda5e127c6120d862ac62e3faa5b99c81c1a85",
"body": "…SignaturePolicy (campo OPTIONAL ETSI)",
"is_bot": false,
"headline": "fix: trata NPE quando signerAndVeriferRules é null em CAdESChecker e …",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-14T11:25:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce9112fb32f9fa24f0807ac2a92849da0ceab837",
"body": "…ampo OPTIONAL ETSI)",
"is_bot": false,
"headline": "fix: trata NPE quando signingCertTrustCondition é null na política (c…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-13T14:18:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cfe581c53d5a26aa455713185d22990643688400",
"body": "… envelopSignature",
"is_bot": false,
"headline": "fix: restaura declarações de attributeFactory e unsignedAttributes em…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-13T14:09:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79ac0972baf7827d60c85ca6c4eaaa60e52528df",
"body": "… OPTIONAL ETSI)",
"is_bot": false,
"headline": "fix: trata NPE quando signerAndVeriferRules é null na política (campo…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-13T13:59:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0d048fee4b84ff3043ef79c86cf5f0cf869d215",
"body": "…o OPTIONAL ETSI)",
"is_bot": false,
"headline": "fix: trata NPE quando algorithmConstraintSet é null na política (camp…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-13T13:51:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6eb9cf2e87662478a7ae24380a6be6582212fc4d",
"body": "PDFs do Gov.br com assinatura ML-DSA-44 mas certificado com chave RSA\ncausavam InvalidKeyException nao capturada que propagava como\nSignerException sem adicionar o SignatureInformations ao resultado.\n\nSolucao:\n- Adiciona catch(CMSSignerDigestMismatchException) e catch(CMSException)\n no bloco intern\n[…]\ne ficou inalcancavel\n- Mismatch de algoritmo/chave agora marca a assinatura como invalida\n com mensagem clara, sem lancar excecao\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: trata CMSException no verify para mismatch algoritmo/chave (ML-DSA)",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-12T20:12:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fce36bf3b5d73ec5f8c3a436277d61b416403ce6",
"body": "Evita que Maven resolva 1.80.0.redhat-00001 (fork Red Hat) via\nrange [1.80,1.81) declarada pelo bcmail-jdk18on:1.80. A versão redhat\nnão tem o fix de verificação ML-DSA presente no 1.80 padrão.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: pina bcpkix/bcprov/bcutil 1.80 explicitamente no BOM",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-12T19:56:04Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4679ffbe5d4ce84dbfadb76714986116942febce",
"body": "BC 1.79 tinha bug na camada JCA que causava:\n InvalidKeyException: unknown public key passed to ML-DSA\nao verificar assinaturas pós-quânticas ML-DSA de documentos externos\n(ex: PDFs assinados pelo Gov.br). Corrigido na 1.80.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: atualiza BouncyCastle 1.79 → 1.80 para corrigir verificação ML-DSA",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-12T19:49:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4ccc6e55c549f025b52a5d057976649e2f4e9f92",
"body": "feat: suporte ML-DSA-44/65/87 (FIPS 204) - algoritmos pos-quanticos",
"is_bot": false,
"headline": "Merge pull request #2 from iasegura/copilot-suporte-ML-DSA-44",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-05-12T19:22:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5eef48e377b50022cf3f09f15c07a40ac8f8ab51",
"body": "…-ML-DSA-44",
"is_bot": false,
"headline": "Merge branch '4.5.1-Novo-algoritmo-pos-quantico' into copilot-suporte…",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-05-12T19:15:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d96f9c493539c4291a50c13001596006c4d92ec",
"body": "- Registra OIDs ML-DSA-44/65/87 em AlgorithmNames, SignerAlgorithmEnum e AsymmetricAlgorithmEnum\n- Corrige cast RSAKey em CAdESSigner para suportar chaves EC e pos-quanticas\n- Corrige NPE em CAdESChecker para algoritmos desconhecidos\n- Atualiza Bouncy Castle de 1.62 (jdk15on) para 1.79 (jdk18on)\n- A\n[…]\ntarget de 1.7 para 1.8\n- Corrige API BC: getObject() -> getBaseObject() (5 arquivos)\n- Corrige SunPKCS11 para Java 9+ (9 arquivos)\n- Adiciona testes unitarios e de integracao (sign/verify) para ML-DSA",
"is_bot": false,
"headline": "feat: suporte ML-DSA-44/65/87 (FIPS 204) - algoritmos pos-quanticos",
"author_name": "Gabriel Almeida Gonçalves",
"author_login": "gabriel4567",
"committed_at": "2026-05-11T16:39:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba649c645b8582ae22923cc3b71cc9a7581015f2",
"body": "O método fixAliases() acessava o campo privado KeyStore.keyStoreSpi\nvia reflexão para corrigir o bug 6672015 (aliases duplicados no SunMSCAPI).\nEsse bug foi resolvido desde a build 101 do Java 1.8 (bug 6483657).\n\nNo Java 9+, field.setAccessible(true) em campos de módulos fechados lança\nInaccessibleObjectException sem add-opens. Como o workaround é desnecessário\npara qualquer Java >= 1.8.0_101, o corpo do método foi removido.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: remove reflexão em MSKeyStoreLoader incompatível com Java 9+",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-08T16:59:45Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ea02108222f856a77ad8b74de9677a08d95ebeb1",
"body": "Os construtores SunPKCS11(InputStream) e SunPKCS11(String) foram\nremovidos no Java 9. Substitui por Provider.configure() que é a\nAPI pública oficial desde o Java 9.\n\nProblemas corrigidos:\n- NoSuchMethodException ao tentar instanciar SunPKCS11 via reflexão\n causava NullPointerException em ex.getCaus\n[…]\no removida: login feito via AuthProvider.login() (API pública)\n- Verificação null-safe para ex.getCause() em todos os catch blocks\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: compatibilidade SunPKCS11 com Java 9+",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-05-07T19:51:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ae88c273f2aeba4a9050979ab3e0f7a4f664d066",
"body": "…nível\n\n- Adiciona método CRLValidator.validate(X509Certificate, Date) que verifica se o certificado estava revogado ANTES de uma data específica\n- Modifica CAdESChecker para extrair timestamp antes da validação CRL\n- Usa data do timestamp (quando disponível) ao invés da data atual para validação de\n[…]\nrtificado era válido no momento da assinatura)\n- Atualiza BOM para versão 4.5.1-SNAPSHOT\n\nIssue: Assinaturas com timestamp válido mas certificado revogado posteriormente devem ser consideradas válidas",
"is_bot": false,
"headline": "Valida revogação de certificado usando data do timestamp quando dispo…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-02-11T13:16:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4cff39e87371de38253873f71aa8f9f6bd0f67fd",
"body": "- Teste CAdESSigningCertificateV2Test.java\n- Verifica presença do atributo signing-certificate-v2 (OID 1.2.840.113549.1.9.16.2.47)\n- Valida estrutura do atributo em assinaturas SHA-256\n- Documenta validação completa feita por CAdESChecker\n- Inclui keystore de teste para execução\n\nTestes: 2 passed, 0 failed, 0 skipped\nBuild: SUCCESS",
"is_bot": false,
"headline": "Adiciona teste unitário para validação RFC 5035",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-02-11T11:47:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c8d8cb0d7f67665dd560bd3598a32d47b18ed14",
"body": "- Adiciona validação de hash do certificado nos atributos assinados\n- Previne substituição de certificado (ataque man-in-the-middle)\n- Integrado à arquitetura de políticas ICP-Brasil\n- Suporte a SHA-256/384/512 (v2) e SHA-1 (v1 legado)\n- Estabelece padrão para validação semântica de outros atributos\n[…]\ncas\n- Métodos: validateMandatedAttributeContent, validateSigningCertificateV2/V1\n- Mensagens: error.rfc5035.* e warn.rfc2634.* (pt_BR e en_US)\n- Conformidade: ETSI EN 319 102-1 v1.4.1 clausula 5.2.8.1",
"is_bot": false,
"headline": "Implementa validação RFC 5035 (signing-certificate-v2)",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-02-10T19:34:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bded984f87f1c2aa7099ce8b3fbcb396a17c4463",
"body": "Atualizar versao para 4.5.1-SNAPSHOT em todos os arquivos pom.xml",
"is_bot": false,
"headline": "Tenta HTTP primeiro, depois HTTPS sem verificacao de certificado",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2026-01-29T14:10:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e0fbac1c1ce4cf4e3181cb186f9a4e82062e22eb",
"body": null,
"is_bot": false,
"headline": "Delete gerar-versao.sh",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-01-23T14:18:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82d2faff2ce662efa07ba5c6a455330111c02dfd",
"body": null,
"is_bot": false,
"headline": "Delete Todo-4.5.0.txt",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-01-23T14:17:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a48898879ead5ac8f8db5947ca7d64c6c34f37ba",
"body": "Incorporação versão 4.5.0 ao master",
"is_bot": false,
"headline": "Merge pull request #438 from demoiselle/4.5.0-SNAPSHOT",
"author_name": "Evandro Magalhães Leite Júnior",
"author_login": "evandrojr",
"committed_at": "2026-01-23T14:14:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e79734ae965b52c8523c689cd0e29b1b3788bc92",
"body": null,
"is_bot": false,
"headline": "Update documentation to version 4.5.0",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T17:15:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0514bd639afa6a88366ec1bae81199f640874ef1",
"body": "…o pom.xml",
"is_bot": false,
"headline": "Adicionar Evandro Magalhães Leite Júnior à lista de desenvolvedores n…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T15:46:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77967dba26c13ce2b5a169b9b43eb652a6238ecb",
"body": "… for 4.5.0 release",
"is_bot": false,
"headline": "Add GPG signing plugin and fix Maven Central deployment configuration…",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T14:54:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "38871eeb239d46087bc817103c0a78f684c28433",
"body": null,
"is_bot": false,
"headline": "Fix Maven Central repository configuration for release deployment",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T14:47:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3a2b38d7838e7077b3d8a697e2a968595a623037",
"body": null,
"is_bot": false,
"headline": "Fix merge conflict in pom.xml",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T14:04:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ca9e099e11f7374cdc5c1e7f4e15239a3681335",
"body": null,
"is_bot": false,
"headline": "Merge: resolve conflict and set version to 4.5.0",
"author_name": "Evandro Jr",
"author_login": "evandrojr",
"committed_at": "2025-11-21T14:02:48Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 3,
"commits_last_year": 113,
"latest_release_at": "2025-11-21T14:01:49Z",
"latest_release_tag": "4.5.0",
"releases_from_tags": true,
"days_since_last_push": 1,
"active_weeks_last_year": 20,
"days_since_latest_release": 245,
"mean_days_between_releases": 1569.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "org.demoiselle.signer:signer-core",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-core",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 10,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:55:52Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:chain-iti",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/chain-iti",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 6,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:55:43Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:signer-timestamp",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-timestamp",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 10,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:59:32Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-cryptography",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 10,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:55:51Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:policy-engine",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/policy-engine",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 45,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T18:30:31Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:signer-xmldsig",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/signer-xmldsig",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 4,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:59:33Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"exists": true,
"license": "GNU Lesser General Public License, Version 3",
"keywords": [],
"ecosystem": "maven",
"matches_repo": true,
"registry_url": "https://central.sonatype.com/artifact/org.demoiselle.signer/chain-icp-brasil",
"is_deprecated": false,
"latest_version": "4.6.1",
"repository_url": "https://github.com/demoiselle/signer",
"versions_count": 45,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-15T14:55:48Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
}
]
},
"popularity": {
"forks": 80,
"stars": 172,
"watchers": 30,
"fork_history": {
"days": [
{
"date": "2017-01-27",
"count": 1
},
{
"date": "2017-10-03",
"count": 1
},
{
"date": "2017-10-11",
"count": 1
},
{
"date": "2017-10-23",
"count": 1
},
{
"date": "2017-11-10",
"count": 1
},
{
"date": "2018-01-09",
"count": 1
},
{
"date": "2018-02-05",
"count": 1
},
{
"date": "2018-04-27",
"count": 1
},
{
"date": "2018-08-08",
"count": 2
},
{
"date": "2018-09-04",
"count": 1
},
{
"date": "2018-10-09",
"count": 1
},
{
"date": "2018-11-01",
"count": 1
},
{
"date": "2018-11-02",
"count": 1
},
{
"date": "2019-02-14",
"count": 1
},
{
"date": "2019-03-26",
"count": 1
},
{
"date": "2019-03-29",
"count": 2
},
{
"date": "2019-06-05",
"count": 1
},
{
"date": "2019-06-06",
"count": 1
},
{
"date": "2019-07-11",
"count": 1
},
{
"date": "2019-08-03",
"count": 1
},
{
"date": "2019-08-08",
"count": 1
},
{
"date": "2019-11-11",
"count": 1
},
{
"date": "2020-03-29",
"count": 1
},
{
"date": "2020-05-12",
"count": 1
},
{
"date": "2020-05-26",
"count": 1
},
{
"date": "2020-06-22",
"count": 1
},
{
"date": "2020-06-25",
"count": 1
},
{
"date": "2020-08-25",
"count": 1
},
{
"date": "2020-08-26",
"count": 1
},
{
"date": "2020-09-11",
"count": 1
},
{
"date": "2020-11-10",
"count": 1
},
{
"date": "2020-12-31",
"count": 1
},
{
"date": "2021-01-18",
"count": 1
},
{
"date": "2021-03-06",
"count": 1
},
{
"date": "2021-05-27",
"count": 1
},
{
"date": "2021-06-02",
"count": 1
},
{
"date": "2021-07-07",
"count": 1
},
{
"date": "2021-08-16",
"count": 1
},
{
"date": "2021-08-19",
"count": 1
},
{
"date": "2021-08-24",
"count": 1
},
{
"date": "2021-08-30",
"count": 1
},
{
"date": "2021-10-04",
"count": 1
},
{
"date": "2021-10-09",
"count": 1
},
{
"date": "2021-11-16",
"count": 1
},
{
"date": "2021-12-20",
"count": 1
},
{
"date": "2022-02-17",
"count": 1
},
{
"date": "2022-03-15",
"count": 1
},
{
"date": "2022-03-16",
"count": 2
},
{
"date": "2022-03-29",
"count": 1
},
{
"date": "2022-05-30",
"count": 1
},
{
"date": "2022-09-30",
"count": 1
},
{
"date": "2022-11-16",
"count": 1
},
{
"date": "2023-04-26",
"count": 1
},
{
"date": "2023-06-16",
"count": 1
},
{
"date": "2023-08-29",
"count": 1
},
{
"date": "2023-10-17",
"count": 1
},
{
"date": "2023-10-20",
"count": 1
},
{
"date": "2023-11-03",
"count": 1
},
{
"date": "2024-02-08",
"count": 1
},
{
"date": "2024-02-26",
"count": 1
},
{
"date": "2024-06-11",
"count": 1
},
{
"date": "2024-07-30",
"count": 1
},
{
"date": "2024-08-15",
"count": 1
},
{
"date": "2024-11-07",
"count": 1
},
{
"date": "2024-11-18",
"count": 1
},
{
"date": "2025-04-04",
"count": 1
},
{
"date": "2025-04-06",
"count": 1
},
{
"date": "2025-06-03",
"count": 1
},
{
"date": "2025-06-10",
"count": 1
},
{
"date": "2025-06-20",
"count": 1
},
{
"date": "2025-07-15",
"count": 1
},
{
"date": "2025-07-30",
"count": 1
},
{
"date": "2025-08-12",
"count": 1
},
{
"date": "2026-05-11",
"count": 1
}
],
"complete": true,
"collected": 77,
"total_forks": 80
},
"star_history": null,
"open_issues_and_prs": 46
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"automacao-importador/go.mod",
"bom/pom.xml",
"chain-icp-brasil-homolog/go.mod",
"chain-icp-brasil-homolog/pom.xml",
"chain-icp-brasil/pom.xml",
"chain-iti-homolog/pom.xml",
"chain-iti/pom.xml",
"chain-serpro-neosigner/pom.xml",
"core/pom.xml",
"cryptography/pom.xml",
"documentation/reference/pom.xml",
"parent/pom.xml",
"policy-engine/pom.xml",
"policy-impl-cades/pom.xml",
"policy-impl-pades/pom.xml",
"policy-impl-xades/pom.xml",
"pom.xml",
"signer-examples/pom.xml",
"signer-xmldsig/pom.xml",
"timestamp/pom.xml"
],
"largest_source_bytes": 208648,
"source_files_sampled": 370,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"automacao-importador/go.mod",
"bom/pom.xml",
"chain-icp-brasil-homolog/go.mod",
"chain-icp-brasil-homolog/pom.xml",
"chain-icp-brasil/pom.xml",
"chain-iti-homolog/pom.xml",
"chain-iti/pom.xml",
"chain-serpro-neosigner/pom.xml",
"core/pom.xml",
"cryptography/pom.xml",
"parent/pom.xml",
"policy-engine/pom.xml",
"policy-impl-cades/pom.xml",
"policy-impl-pades/pom.xml",
"policy-impl-xades/pom.xml",
"pom.xml",
"signer-examples/pom.xml",
"signer-xmldsig/pom.xml",
"timestamp/pom.xml"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 9,
"malicious_count": 0,
"assessed_package": "maven:org.demoiselle.signer:signer-core@4.6.1",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"maven"
],
"dependencies": [
{
"name": "golang.org/x/net",
"manifest": "automacao-importador/go.mod",
"ecosystem": "go",
"version_constraint": "v0.17.0"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil-homolog",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:policy-engine",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:policy-impl-xades",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:policy-impl-pades",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:signer-timestamp",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:chain-serpro-neosigner",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.demoiselle.signer:chain-iti",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "${demoiselle.signer.version}"
},
{
"name": "org.apache.logging.log4j:log4j-api",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.apache.logging.log4j:log4j-core",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.apache.logging.log4j:log4j-1.2-api",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.slf4j:slf4j-log4j12",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "1.7.32"
},
{
"name": "org.bouncycastle:bcmail-lts8on",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.73.11"
},
{
"name": "org.bouncycastle:bcpkix-lts8on",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.73.11"
},
{
"name": "org.bouncycastle:bcprov-lts8on",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.73.11"
},
{
"name": "org.bouncycastle:bcutil-lts8on",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.73.11"
},
{
"name": "commons-io:commons-io",
"manifest": "bom/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.15.1"
},
{
"name": "golang.org/x/net",
"manifest": "chain-icp-brasil-homolog/go.mod",
"ecosystem": "go",
"version_constraint": "v0.42.0"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "chain-icp-brasil-homolog/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "chain-icp-brasil/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "chain-iti-homolog/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil-homolog",
"manifest": "chain-iti-homolog/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "chain-iti/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"manifest": "chain-iti/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:chain-serpro-neosigner",
"manifest": "chain-iti/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "chain-serpro-neosigner/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"manifest": "chain-serpro-neosigner/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.apache.logging.log4j:log4j-api",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.apache.logging.log4j:log4j-core",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.apache.logging.log4j:log4j-1.2-api",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.slf4j:slf4j-log4j12",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "1.7.32"
},
{
"name": "com.sun.xml.bind:jaxb-core",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.3.0.1"
},
{
"name": "javax.xml.bind:jaxb-api",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.3.1"
},
{
"name": "com.sun.xml.bind:jaxb-impl",
"manifest": "core/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.3.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "cryptography/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:bom",
"manifest": "parent/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.apache.logging.log4j:log4j-1.2-api",
"manifest": "parent/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.25.4"
},
{
"name": "org.slf4j:slf4j-log4j12",
"manifest": "parent/pom.xml",
"ecosystem": "maven",
"version_constraint": "1.7.32"
},
{
"name": "org.bouncycastle:bcmail-lts8on",
"manifest": "parent/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.73.11"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "policy-engine/pom.xml",
"ecosystem": "maven",
"version_constraint": "${project.version}"
},
{
"name": "commons-io:commons-io",
"manifest": "policy-engine/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.15.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "policy-impl-cades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"manifest": "policy-impl-cades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:policy-engine",
"manifest": "policy-impl-cades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-timestamp",
"manifest": "policy-impl-cades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "policy-impl-pades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"manifest": "policy-impl-pades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:policy-engine",
"manifest": "policy-impl-pades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"manifest": "policy-impl-pades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.apache.santuario:xmlsec",
"manifest": "policy-impl-xades/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.3.5"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"manifest": "policy-impl-xades/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "commons-io:commons-io",
"manifest": "policy-impl-xades/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.15.1"
},
{
"name": "org.demoiselle.signer:core",
"manifest": "signer-examples/pom.xml",
"ecosystem": "maven",
"version_constraint": "3.7.1"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"manifest": "signer-examples/pom.xml",
"ecosystem": "maven",
"version_constraint": "3.7.1"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"manifest": "signer-examples/pom.xml",
"ecosystem": "maven",
"version_constraint": "3.7.1"
},
{
"name": "commons-io:commons-io",
"manifest": "signer-examples/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.15.1"
},
{
"name": "org.apache.santuario:xmlsec",
"manifest": "signer-xmldsig/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.2.6"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "signer-xmldsig/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "commons-io:commons-io",
"manifest": "signer-xmldsig/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.15.1"
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"manifest": "timestamp/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "org.demoiselle.signer:signer-core",
"manifest": "timestamp/pom.xml",
"ecosystem": "maven",
"version_constraint": "4.6.1"
},
{
"name": "com.mashape.unirest:unirest-java",
"manifest": "timestamp/pom.xml",
"ecosystem": "maven",
"version_constraint": "1.4.9"
},
{
"name": "com.fasterxml.jackson.core:jackson-databind",
"manifest": "timestamp/pom.xml",
"ecosystem": "maven",
"version_constraint": "2.22.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.17.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "com.fasterxml.jackson.core:jackson-databind",
"direct": true,
"version": "2.22.0",
"ecosystem": "maven"
},
{
"name": "com.mashape.unirest:unirest-java",
"direct": true,
"version": "1.4.9",
"ecosystem": "maven"
},
{
"name": "com.sun.xml.bind:jaxb-core",
"direct": true,
"version": "2.3.0.1",
"ecosystem": "maven"
},
{
"name": "com.sun.xml.bind:jaxb-impl",
"direct": true,
"version": "2.3.1",
"ecosystem": "maven"
},
{
"name": "commons-io:commons-io",
"direct": true,
"version": "2.15.1",
"ecosystem": "maven"
},
{
"name": "javax.xml.bind:jaxb-api",
"direct": true,
"version": "2.3.1",
"ecosystem": "maven"
},
{
"name": "org.apache.logging.log4j:log4j-1.2-api",
"direct": true,
"version": "2.25.4",
"ecosystem": "maven"
},
{
"name": "org.apache.logging.log4j:log4j-api",
"direct": true,
"version": "2.25.4",
"ecosystem": "maven"
},
{
"name": "org.apache.logging.log4j:log4j-core",
"direct": true,
"version": "2.25.4",
"ecosystem": "maven"
},
{
"name": "org.apache.santuario:xmlsec",
"direct": true,
"version": "2.2.6",
"ecosystem": "maven"
},
{
"name": "org.apache.santuario:xmlsec",
"direct": true,
"version": "2.3.5",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcmail-lts8on",
"direct": true,
"version": "2.73.11",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcpkix-lts8on",
"direct": true,
"version": "2.73.11",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcprov-lts8on",
"direct": true,
"version": "2.73.11",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcutil-lts8on",
"direct": true,
"version": "2.73.11",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:bom",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"direct": true,
"version": "3.7.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:chain-icp-brasil-homolog",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:chain-iti",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:chain-serpro-neosigner",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:core",
"direct": true,
"version": "3.7.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:policy-engine",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"direct": true,
"version": "3.7.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:policy-impl-cades",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:policy-impl-pades",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:policy-impl-xades",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:signer-core",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:signer-cryptography",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.demoiselle.signer:signer-timestamp",
"direct": true,
"version": "4.6.1",
"ecosystem": "maven"
},
{
"name": "org.slf4j:slf4j-log4j12",
"direct": true,
"version": "1.7.32",
"ecosystem": "maven"
},
{
"name": "br.gov.frameworkdemoiselle.documentation:demoiselle-docbook-xslt",
"direct": false,
"version": "2.0.2",
"ecosystem": "maven"
},
{
"name": "br.gov.frameworkdemoiselle.documentation:demoiselle-jdocbook-style",
"direct": false,
"version": "2.0.2",
"ecosystem": "maven"
},
{
"name": "commons-codec:commons-codec",
"direct": false,
"version": "1.10",
"ecosystem": "maven"
},
{
"name": "commons-codec:commons-codec",
"direct": false,
"version": "1.14",
"ecosystem": "maven"
},
{
"name": "junit:junit",
"direct": false,
"version": "4.13.1",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-assembly-plugin",
"direct": false,
"version": "2.6",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-compiler-plugin",
"direct": false,
"version": null,
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-compiler-plugin",
"direct": false,
"version": "3.5.1",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-deploy-plugin",
"direct": false,
"version": "1.0",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-failsafe-plugin",
"direct": false,
"version": "2.22.2",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-gpg-plugin",
"direct": false,
"version": "3.0.1",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-jar-plugin",
"direct": false,
"version": "3.0.2",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-javadoc-plugin",
"direct": false,
"version": "3.10.1",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-scm-plugin",
"direct": false,
"version": "1.4",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-source-plugin",
"direct": false,
"version": "2.2.1",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.wagon:wagon-ssh",
"direct": false,
"version": "1.0",
"ecosystem": "maven"
},
{
"name": "org.apache.pdfbox:pdfbox",
"direct": false,
"version": "2.0.24",
"ecosystem": "maven"
},
{
"name": "org.jboss.maven.plugins:maven-jdocbook-plugin",
"direct": false,
"version": "2.3.5",
"ecosystem": "maven"
},
{
"name": "org.jboss.seam:seam-docbook-xslt",
"direct": false,
"version": "1.1.0",
"ecosystem": "maven"
},
{
"name": "org.jboss.seam:seam-jdocbook-style",
"direct": false,
"version": "1.1.0",
"ecosystem": "maven"
},
{
"name": "org.jboss.weld:weld-docbook-xslt",
"direct": false,
"version": "1.1.1-Beta5",
"ecosystem": "maven"
},
{
"name": "org.jboss:jbossorg-jdocbook-style",
"direct": false,
"version": "1.1.1",
"ecosystem": "maven"
},
{
"name": "org.junit.jupiter:junit-jupiter",
"direct": false,
"version": "5.10.2",
"ecosystem": "maven"
},
{
"name": "org.sonatype.central:central-publishing-maven-plugin",
"direct": false,
"version": "0.6.0",
"ecosystem": "maven"
}
],
"collected": true,
"truncated": false,
"total_count": 57,
"direct_count": 33,
"indirect_count": 24
}
},
"maintainership": {
"issues": {
"open_prs": 6,
"merged_prs": 33,
"open_issues": 40,
"closed_ratio": 0.9,
"closed_issues": 362,
"closed_unmerged_prs": 11
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "esaito",
"commits": 591,
"avatar_url": "https://avatars.githubusercontent.com/u/1101956?v=4"
},
{
"type": "User",
"login": "juliancesar",
"commits": 127,
"avatar_url": "https://avatars.githubusercontent.com/u/4247825?v=4"
},
{
"type": "User",
"login": "evandrojr",
"commits": 123,
"avatar_url": "https://avatars.githubusercontent.com/u/939608?v=4"
},
{
"type": "User",
"login": "FabianoK",
"commits": 14,
"avatar_url": "https://avatars.githubusercontent.com/u/4664271?v=4"
},
{
"type": "User",
"login": "kyriosdata",
"commits": 13,
"avatar_url": "https://avatars.githubusercontent.com/u/1735792?v=4"
},
{
"type": "User",
"login": "eduardomg",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/1227746?v=4"
},
{
"type": "User",
"login": "FabianoSerpro",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/197613080?v=4"
},
{
"type": "User",
"login": "fabiomdj",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/69532695?v=4"
},
{
"type": "User",
"login": "laubstein",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/457100?v=4"
},
{
"type": "User",
"login": "botelhojp",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/1793654?v=4"
}
],
"contributors_sampled": 20,
"top_contributor_share": 0.649
},
"quality_signals": {
"has_ci": false,
"has_tests": true,
"ci_workflows": [],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 7,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 0,
"reason": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/2 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 6 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "16 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "89c54a31fd05b8a7a410bb9c5c5e9c0ebe4a9d7c",
"ran_at": "2026-07-25T10:35:29Z",
"aggregate_score": 3.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T07:22:03Z",
"oldest_open_prs": [
{
"number": 444,
"created_at": "2026-07-03T04:07:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 445,
"created_at": "2026-07-04T05:20:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 446,
"created_at": "2026-07-04T05:20:24Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 447,
"created_at": "2026-07-04T05:20:28Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 452,
"created_at": "2026-07-15T20:44:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 453,
"created_at": "2026-07-24T07:22:02Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-15T20:42:29Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 86,
"created_at": "2017-07-02T23:50:51Z",
"last_comment_at": "2019-11-24T13:23:46Z",
"last_comment_author": "joserenecampa"
},
{
"number": 89,
"created_at": "2017-07-20T14:20:39Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 106,
"created_at": "2017-11-09T17:01:24Z",
"last_comment_at": "2018-03-20T11:46:37Z",
"last_comment_author": "alissonns"
},
{
"number": 113,
"created_at": "2017-11-23T12:56:13Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 114,
"created_at": "2017-11-23T12:57:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 138,
"created_at": "2018-03-13T12:34:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 223,
"created_at": "2019-08-14T21:46:17Z",
"last_comment_at": "2024-01-11T13:50:29Z",
"last_comment_author": "alexandre-mbm"
},
{
"number": 230,
"created_at": "2019-11-25T18:05:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 255,
"created_at": "2020-06-29T14:30:02Z",
"last_comment_at": "2020-06-29T20:28:59Z",
"last_comment_author": "esaito"
},
{
"number": 266,
"created_at": "2020-09-04T19:39:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 304,
"created_at": "2021-07-25T09:07:50Z",
"last_comment_at": "2024-12-28T19:07:29Z",
"last_comment_author": "denydias"
},
{
"number": 322,
"created_at": "2021-11-04T13:34:24Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 336,
"created_at": "2022-03-29T21:29:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 343,
"created_at": "2022-05-08T21:09:23Z",
"last_comment_at": "2022-05-13T15:01:18Z",
"last_comment_author": "HelloWar75"
},
{
"number": 345,
"created_at": "2022-05-30T13:09:14Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 360,
"created_at": "2022-12-30T17:04:32Z",
"last_comment_at": "2023-02-15T10:01:29Z",
"last_comment_author": "leanmaster"
},
{
"number": 369,
"created_at": "2023-04-19T14:07:55Z",
"last_comment_at": "2024-10-18T12:46:33Z",
"last_comment_author": "williamargenton"
},
{
"number": 377,
"created_at": "2023-06-21T12:49:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 382,
"created_at": "2023-08-07T13:48:47Z",
"last_comment_at": "2023-08-11T20:56:28Z",
"last_comment_author": "esaito"
},
{
"number": 383,
"created_at": "2023-08-18T11:13:22Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/demoiselle/signer",
"host": "github.com",
"name": "signer",
"owner": "demoiselle"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"security": 49,
"vitality": 64,
"community": 55,
"governance": 66,
"engineering": 58
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 64,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 113,
"human_commit_share": 1,
"days_since_last_push": 1,
"active_weeks_last_year": 20
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "20/52 weeks with commits",
"points": 13.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 20
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "113 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 113
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "at_risk",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 42,
"inputs": {
"releases_count": 3,
"latest_release_tag": "4.5.0",
"releases_from_tags": true,
"days_since_latest_release": 245,
"mean_days_between_releases": 1569.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "3 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 3
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 245 days ago",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "release_recency",
"params": {
"days": 245
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1569.5 days",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1569.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 9,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 9 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 9
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 55,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"forks": 80,
"stars": 172,
"watchers": 30,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "172 stars",
"points": 36.2,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 172
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "80 forks",
"points": 15.8,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 80
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "30 watchers",
"points": 8.1,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 30
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (LGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "LGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 66,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 20,
"top_contributor_share": 0.649
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 65% of commits",
"points": 7.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 65
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "20 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 20
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 6 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"merged_prs": 33,
"open_issues": 40,
"closed_issues": 362,
"issue_closed_ratio": 0.9,
"closed_unmerged_prs": 11
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "90% of issues closed",
"points": 42.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 90
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "33/44 decided PRs merged",
"points": 28.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 33,
"decided": 44
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/2 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"followers": 28,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "demoiselle",
"public_repos": 29,
"account_age_days": 5685
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "28 followers of demoiselle",
"points": 10.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 28,
"login": "demoiselle"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "29 public repos, account ~15 yr old",
"points": 22.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 29
}
},
{
"code": "account_age_years",
"params": {
"years": 15
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"org.demoiselle.signer:signer-core",
"org.demoiselle.signer:chain-iti",
"org.demoiselle.signer:signer-timestamp",
"org.demoiselle.signer:signer-cryptography",
"org.demoiselle.signer:policy-engine",
"org.demoiselle.signer:signer-xmldsig",
"org.demoiselle.signer:chain-icp-brasil"
],
"ecosystems": "maven",
"any_deprecated": false,
"min_days_since_publish": 9
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "7 package(s) on maven",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 7,
"ecosystems": "maven"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 9 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 9
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "45 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 45
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 58,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 30,
"inputs": {
"has_ci": false,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"icp-brasil",
"digital-signature",
"cryptography",
"timestamp",
"pki",
"certificates",
"x509certificates",
"x509"
],
"has_wiki": true,
"homepage": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.frameworkdemoiselle.gov.br/v3/signer/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "8 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 8
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 49,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 36,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 13,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 5,
"scorecard_aggregate": 3.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 5.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "0 out of 2 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/2 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 6 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "16 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the maven:org.demoiselle.signer:signer-core@4.6.1 runtime dependency closure — what installing the published package pulls in — 9 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "maven:org.demoiselle.signer:signer-core@4.6.1",
"assessed": 9
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 9,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 9,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 7
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 62,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.74,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "74 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 39.5,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 74,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 73,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.16,
"toolchain_manifests": [
"automacao-importador/go.mod",
"bom/pom.xml",
"chain-icp-brasil-homolog/go.mod",
"chain-icp-brasil-homolog/pom.xml",
"chain-icp-brasil/pom.xml",
"chain-iti-homolog/pom.xml",
"chain-iti/pom.xml",
"chain-serpro-neosigner/pom.xml",
"core/pom.xml",
"cryptography/pom.xml",
"documentation/reference/pom.xml",
"parent/pom.xml",
"policy-engine/pom.xml",
"policy-impl-cades/pom.xml",
"policy-impl-pades/pom.xml",
"policy-impl-xades/pom.xml",
"pom.xml",
"signer-examples/pom.xml",
"signer-xmldsig/pom.xml",
"timestamp/pom.xml"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "automacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "automacao-importador/go.mod, bom/pom.xml, chain-icp-brasil-homolog/go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Java (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Java"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "16 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 16,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Java",
"largest_source_bytes": 208648,
"source_files_sampled": 370,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Java (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Java"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/370 source files over 60KB",
"points": 54.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 370,
"oversized": 1
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch maven package 'org.demoiselle.signer:signer-examples' from its registry"
],
"report_type": "repository",
"generated_at": "2026-07-25T10:35:51.571881Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/demoiselle/signer.svg",
"full_name": "demoiselle/signer",
"license_state": "standard",
"license_spdx": "LGPL-3.0"
}