Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"dependencies",
"git",
"git-commands",
"package-management"
],
"is_fork": false,
"size_kb": 1478,
"has_wiki": true,
"homepage": "https://git-pkgs.dev",
"languages": {
"Go": 1129565,
"Shell": 3140
},
"pushed_at": "2026-07-31T16:20:56Z",
"created_at": "2026-01-15T15:41:01Z",
"owner_type": "Organization",
"updated_at": "2026-08-01T19:54:48Z",
"description": " About A git subcommand for analyzing package/dependency usage in git repositories over time",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://git-pkgs.dev/",
"name": "git-pkgs",
"type": "Organization",
"login": "git-pkgs",
"company": null,
"location": null,
"followers": 42,
"avatar_url": "https://avatars.githubusercontent.com/u/254671775?v=4",
"created_at": "2026-01-13T11:51:00Z",
"is_verified": null,
"public_repos": 47,
"account_age_days": 200
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.18.2",
"kind": "patch",
"published_at": "2026-07-27T11:33:19Z"
},
{
"tag": "v0.18.1",
"kind": "patch",
"published_at": "2026-07-23T11:25:40Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2026-07-21T13:40:17Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2026-06-29T14:03:55Z"
},
{
"tag": "v0.16.2",
"kind": "patch",
"published_at": "2026-05-25T14:25:32Z"
},
{
"tag": "v0.16.1",
"kind": "patch",
"published_at": "2026-05-22T19:42:24Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-05-09T12:23:39Z"
},
{
"tag": "v0.15.4",
"kind": "patch",
"published_at": "2026-05-02T17:41:05Z"
},
{
"tag": "v0.15.3",
"kind": "patch",
"published_at": "2026-04-13T07:57:38Z"
},
{
"tag": "v0.15.2",
"kind": "patch",
"published_at": "2026-03-29T19:13:46Z"
},
{
"tag": "v0.15.1",
"kind": "patch",
"published_at": "2026-03-05T18:36:36Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-02-27T10:26:26Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-02-16T11:47:46Z"
},
{
"tag": "v0.13.2",
"kind": "patch",
"published_at": "2026-02-10T11:42:06Z"
},
{
"tag": "v0.13.1",
"kind": "patch",
"published_at": "2026-02-09T11:41:13Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-02-07T12:01:57Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-02-06T13:06:42Z"
},
{
"tag": "v0.11.6",
"kind": "patch",
"published_at": "2026-02-05T16:49:23Z"
},
{
"tag": "v0.11.5",
"kind": "patch",
"published_at": "2026-02-05T12:28:54Z"
},
{
"tag": "v0.11.4",
"kind": "patch",
"published_at": "2026-01-31T21:28:25Z"
},
{
"tag": "v0.11.3",
"kind": "patch",
"published_at": "2026-01-31T07:19:26Z"
},
{
"tag": "v0.11.2",
"kind": "patch",
"published_at": "2026-01-30T20:29:04Z"
},
{
"tag": "v0.11.1",
"kind": "patch",
"published_at": "2026-01-29T15:08:12Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-01-28T06:43:40Z"
},
{
"tag": "v0.10.7",
"kind": "patch",
"published_at": "2026-01-27T23:14:39Z"
},
{
"tag": "v0.10.6",
"kind": "patch",
"published_at": "2026-01-26T21:24:14Z"
},
{
"tag": "v0.10.5",
"kind": "patch",
"published_at": "2026-01-26T16:03:10Z"
},
{
"tag": "v0.10.4",
"kind": "patch",
"published_at": "2026-01-25T12:30:58Z"
},
{
"tag": "v0.10.3",
"kind": "patch",
"published_at": "2026-01-24T07:27:44Z"
},
{
"tag": "v0.10.2",
"kind": "patch",
"published_at": "2026-01-23T11:37:15Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-01-23T11:12:31Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-01-22T18:13:24Z"
},
{
"tag": "v0.9.3",
"kind": "patch",
"published_at": "2026-01-21T22:52:13Z"
},
{
"tag": "v0.9.2",
"kind": "patch",
"published_at": "2026-01-18T21:49:18Z"
},
{
"tag": "v0.9.1",
"kind": "patch",
"published_at": "2026-01-18T13:50:22Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-01-16T10:02:02Z"
}
],
"recent_commits": [
{
"oid": "08bf43497d7706f8c4e754b551f541d0df12bb37",
"body": null,
"is_bot": false,
"headline": "Fix vulnerability ref resolution (#300)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-31T16:20:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "277fe1e04a29d52341145fcc03ea5e258c0a0104",
"body": "* Add --kind flag to diff for filtering by manifest/lockfile\n\nAdds a --kind filter to git-pkgs diff that restricts output to entries\nfrom either manifest files or lockfiles, and exposes manifest_kind on\neach entry in the JSON output.\n\nCloses #298\n\n* Filter --kind before computing diff, accept mixed \n[…]\nle\nrows into one bucket, so the reported manifest_kind is always correct\nand a lockfile-only bump can't be masked by a sibling manifest row.\n\nAlso lowercases the flag value so --kind Lockfile matches.",
"is_bot": false,
"headline": "Add --kind flag to diff for filtering by manifest/lockfile (#301)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-31T15:56:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "584bca5eccd6b535a16f88f6b6d790842434cb54",
"body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.54.0 to 1.55.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.54.0...v1.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n depende\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump modernc.org/sqlite from 1.54.0 to 1.55.0 (#297)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-31T08:32:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "115e7e6fda572646e2db6bc4a6e1b412f3a44c36",
"body": "Bumps [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) from 5.9.0 to 5.9.1.\n- [Release notes](https://github.com/go-git/go-billy/releases)\n- [Commits](https://github.com/go-git/go-billy/compare/v5.9.0...v5.9.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-git/go-bil\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/go-git/go-billy/v5 from 5.9.0 to 5.9.1 (#296)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-31T08:31:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99a2f7a4796fe8fbcacad8324bab5a7509eba542",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 7.0.0 to 7.0.1 (#295)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-30T16:14:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d07a00bace682d7eda71738e172d7a0ad7fb0b3",
"body": null,
"is_bot": false,
"headline": "Bump git-pkgs enrichment, manifests, registries (#293)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-27T11:29:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "81417cbe9a37e4acb894d2108ba7505e87f40fb4",
"body": "…ns/setup-go-7.0.0\n\nBump actions/setup-go from 6.5.0 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #292 from git-pkgs/dependabot/github_actions/actio…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T15:47:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f7a303a10459301dcd73a1548448db634404290",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356fb5720e22ba16...b7ad1dad31e06c5925ef5d2fc7ad053ef454303e)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/setup-go from 6.5.0 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-23T12:53:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ccd584a00627f1e42febfdbc26b80034bfad754b",
"body": "Use version metadata in SBOMs",
"is_bot": false,
"headline": "Merge pull request #288 from git-pkgs/fix/sbom-version-metadata",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T11:16:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eba43c66971ea99a9ad864043ce431d10a30dd81",
"body": "…tion\n\nResolve direct versions for license checks",
"is_bot": false,
"headline": "Merge pull request #289 from git-pkgs/fix/license-multiversion-resolu…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T11:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "13b9fb3e67c4d17b5e452a0e37f7dcde645cc6e8",
"body": "Bump dependencies before v0.18.1",
"is_bot": false,
"headline": "Merge pull request #291 from git-pkgs/chore/release-dependency-updates",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T10:54:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "385ee46047776479b39371c6ac1c5f0865c742ea",
"body": null,
"is_bot": false,
"headline": "Bump dependencies before patch release",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T10:46:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e6d56ee8d21b448f7c2a93c2281907e1d726104",
"body": "Handle withdrawn versions in dependency checks",
"is_bot": false,
"headline": "Merge pull request #290 from git-pkgs/fix/yanked-retracted-versions",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T10:39:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "635285a140d8d3f80f02ef51b4794356be834d15",
"body": null,
"is_bot": false,
"headline": "Handle withdrawn package versions",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-23T10:30:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fea374589b21d5f43e40025664bcf629ca15a70",
"body": null,
"is_bot": false,
"headline": "Resolve direct versions for license checks",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-22T19:28:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "284c1034dfe55f9521794f7835fc38b63a946ccd",
"body": null,
"is_bot": false,
"headline": "Keep SBOM components without PURLs",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-22T19:18:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d600d5d527d742172f0f9eefadc5319459b0b72",
"body": null,
"is_bot": false,
"headline": "Use version metadata in SBOMs",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-22T19:03:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "88dbdb14fe04ec04c7072499cca88dc9bdece184",
"body": "* Use installed version licenses for policies\n\n* Warn when version license lookup fails",
"is_bot": false,
"headline": "Use installed version licenses for policies (#284)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-22T18:37:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "36745b49d99fa18264579d6caa3e8f0bccfd8104",
"body": "github.com/git-pkgs/enrichment v0.5.0 -> v0.6.1\ngithub.com/git-pkgs/purl v0.1.14 -> v0.1.15\ngithub.com/git-pkgs/vers v0.2.6 -> v0.3.0\ngithub.com/git-pkgs/vulns v0.1.6 -> v0.2.1\ngithub.com/mattn/go-isatty v0.0.22 -> v0.0.23\nmodernc.org/sqlite v1.53.0 -> v1.54.0",
"is_bot": false,
"headline": "Bump dependencies before release (#282)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-21T13:34:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f0effae7474c135ce9bd782c53f5d1efedb4f5e",
"body": "* Add provenance metadata command\n\n* fix provenance unsupported status output\n\n* fix: use registry provenance APIs\n\n* fix: distinguish npm attestations\n\n* fix: filter attested provenance results",
"is_bot": false,
"headline": "Add provenance metadata command (#244)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-20T13:31:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a373dafbdeeb5feaadcf16fb33557891f909db6",
"body": "* feat: support configured ecosystem filters\n\n* fix ecosystem config filtering in db query paths\n\n* fix ignored ecosystem init test\n\n* fix ecosystem filter follow-ups\n\n* fix: filter historical queries by ecosystem config\n\n* fix: filter bisect culprit changes\n\n* fix: expand ecosystem aliases for SQL filters",
"is_bot": false,
"headline": "Add configurable ecosystem allow/deny filters (#262)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-20T13:20:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53acfbffb019353cd3fdf79da6aad768b2f8d1db",
"body": "* fix: handle unsupported OSV ecosystems\n\n* fix: align OSV ecosystem queries\n\n* fix: preserve Maven OSV package names",
"is_bot": false,
"headline": "fix: handle unsupported OSV ecosystems (#277)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-20T11:34:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83783ae2dafabc6b2bb93973cc57076e512b5076",
"body": "Bumps [github.com/git-pkgs/sbom](https://github.com/git-pkgs/sbom) from 0.1.2 to 0.1.3.\n- [Commits](https://github.com/git-pkgs/sbom/compare/v0.1.2...v0.1.3)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/sbom\n dependency-version: 0.1.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/sbom from 0.1.2 to 0.1.3 (#280)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-16T13:46:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "72a8b842ba0885ef2d9c1fe3316949a892f83f95",
"body": "Bumps [github.com/git-pkgs/enrichment](https://github.com/git-pkgs/enrichment) from 0.4.1 to 0.5.0.\n- [Commits](https://github.com/git-pkgs/enrichment/compare/v0.4.1...v0.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/enrichment\n dependency-version: 0.5.0\n dependency-type: \n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/enrichment from 0.4.1 to 0.5.0 (#278)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-16T13:45:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a970a7a24804de1d9164dba8650069c32576659c",
"body": "Bumps [github.com/git-pkgs/purl](https://github.com/git-pkgs/purl) from 0.1.13 to 0.1.14.\n- [Commits](https://github.com/git-pkgs/purl/compare/v0.1.13...v0.1.14)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/purl\n dependency-version: 0.1.14\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/purl from 0.1.13 to 0.1.14 (#279)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-16T13:45:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b14403c6817380cb9ad2e9c8d2149271eea78ff",
"body": "* feat: cache registry integrity lookups\n\n# Conflicts:\n#\tdocs/internals.md\n#\tinternal/database/queries.go\n\n* fix: preserve partial version metadata\n\n* fix: separate version cache freshness\n\n# Conflicts:\n#\tdocs/internals.md\n#\tinternal/database/queries.go",
"is_bot": false,
"headline": "feat: cache registry integrity lookups (#274)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-15T12:40:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eba05e37a6637f5f8fbd8a1bb9235cbd93d48520",
"body": "* feat: support offline license metadata cache\n\n* test: isolate license cache database path\n\n* fix: handle incomplete offline cache entries",
"is_bot": false,
"headline": "Add offline license metadata caching support (#273)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-13T22:34:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea95e7fff26ee829026e883f97aa58d2556e20df",
"body": "* Use SARIF module for vulns output\n\n* Use SARIF constructors for schema defaults\n\n* Address review feedback\n\n- Use build version for SARIF tool.driver.version instead of hardcoded 1.0.0\n- Build run/driver locally and assign to report.Runs at the end\n- Fix inverted test failure messages for constructor default checks\n- go mod tidy to drop stale sarif v0.1.0 sum entries",
"is_bot": false,
"headline": "Use SARIF module for vulns output (#271)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-07-13T22:08:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "193c850d87052dfce6bcfb3f64acf6c21a86324a",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.54.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.54.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.55.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump golang.org/x/net from 0.54.0 to 0.55.0 (#270)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T15:17:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7193a0fbe55ba4260f98b914352216259f02454d",
"body": "Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.51.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n dependency-version: 0.52.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#269)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T15:06:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31a7a86169177877442b8de94a69b9368edf8f7a",
"body": "Bumps [github.com/git-pkgs/manifests](https://github.com/git-pkgs/manifests) from 0.5.1 to 0.6.0.\n- [Commits](https://github.com/git-pkgs/manifests/compare/v0.5.1...v0.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/manifests\n dependency-version: 0.6.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/manifests from 0.5.1 to 0.6.0 (#267)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T14:53:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6805bef1b365cb006261ac1a72a61f7b8451379c",
"body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89...f06c13\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#268)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T13:15:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "400dca35cc14ad285f9931fe8b827e82a61363f7",
"body": "Bumps [github.com/git-pkgs/managers](https://github.com/git-pkgs/managers) from 0.10.0 to 0.10.1.\n- [Commits](https://github.com/git-pkgs/managers/compare/v0.10.0...v0.10.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/managers\n dependency-version: 0.10.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/managers from 0.10.0 to 0.10.1 (#266)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T13:14:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c77a83b938960e2a4f5f3d12571878009cd28fab",
"body": "* fix schema sql index output\n\n* fix schema index row error handling",
"is_bot": false,
"headline": "Fix schema SQL index output (#265)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-07-08T12:14:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b0b698b69a0817af3bfe5006ec75330b68b4d55",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump actions/setup-go from 6.4.0 to 6.5.0 (#264)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-02T15:13:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a30ca52d22625c54937d412e73305fb20ae6c71c",
"body": "* fix: reject unsupported output formats\n\n* fix: clean up format validation\n\n---------\n\nCo-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: reject unsupported output formats (#251)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-07-01T16:13:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80b4b46c22859321ac22d893ead6f854e3be9506",
"body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: preserve json output for empty results (#257)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-07-01T16:05:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ad00120421d6f3359110b0ba5367cb9a4519019",
"body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: preserve where context line numbers (#263)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-07-01T16:00:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1072fd6dc6c566b86167d518f224f86c455c7262",
"body": "* Add replace command for dependency redirects\n\n* refactor replace command to use managers library",
"is_bot": false,
"headline": "Add replace command for dependency redirects (#236)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-30T18:48:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dcad319db70e86241f365873b1bf7eb0da4b10e4",
"body": null,
"is_bot": false,
"headline": "Bump git-pkgs and third-party dependencies (#255)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-29T13:48:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4df5ba17f129c9baaaa477d0259da173ee49db1",
"body": null,
"is_bot": false,
"headline": "docs: explain bare column usage in first_added CTE (#253)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-29T09:29:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd00b9ae2882972d1ecc3039f531ce0a941d1f3a",
"body": "* fix: preserve json output for empty results\n\n* fix: cover remaining empty json outputs\n\n---------\n\nCo-authored-by: sanmaxdev <144138089+sanmaxdev@users.noreply.github.com>\nCo-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: preserve json output for empty results (#248)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-06-29T08:55:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b0e5272996d83ff4ddcd26c524535872b6406da",
"body": null,
"is_bot": false,
"headline": "refactor: optimize first_added sqlite query (#252)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-28T17:39:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff56085cef274413a3366fea265d71cbddbd819a",
"body": "* fix: group SearchDependencies CTEs by ecosystem\n\n* test: add regression tests for #241; fix added_in to use earliest commit SHA",
"is_bot": false,
"headline": "fix: group SearchDependencies CTEs by ecosystem (#250)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-28T10:36:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "552e9061c258ef0f5b032115c7b0a5e91cbb5ba4",
"body": "Bump enrichment to v0.4.0 (which brings ecosystems-go v0.2.0) and route\nall enrichment client construction through a single helper that applies\nGIT_PKGS_ECOSYSTEMS_FROM, GIT_PKGS_ECOSYSTEMS_API_KEY and\nGIT_PKGS_ECOSYSTEMS_BATCH_SIZE. BulkLookup failures now include a hint\npointing at those variables when no identity is configured.\n\nFixes #231",
"is_bot": false,
"headline": "Add ecosyste.ms identity options and friendlier lookup errors (#245)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-28T06:55:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04f5ad05ffafef512bd7ee06e0dc5f0b3f5e2035",
"body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: avoid partial package matches in where (#246)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-06-28T06:37:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76063f70c0a5522cbbc54bc2c5de053dec0ce18a",
"body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: include all schema tables in info counts (#247)",
"author_name": "Sangeeth Thilakarathna",
"author_login": "sanmaxdev",
"committed_at": "2026-06-28T06:33:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f21cd00f627ad02e9d4b4ab088aca3e5d683bf9f",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.3 to 7.0.0 (#249)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-25T13:05:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea8f727740d34d2e3efa960d64a26f38528e58e1",
"body": "…#240)",
"is_bot": false,
"headline": "Fix urls command using version ranges and wrong name from db lookup (…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-21T17:12:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "693e53e0d2f73fa0d9cbdeb1c0536fd0814c5bdb",
"body": null,
"is_bot": false,
"headline": "Add JSON help output (#237)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-21T17:11:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "633d3022d2ab01e8695547bfd691b11fae76a3f3",
"body": null,
"is_bot": false,
"headline": "Recover from panics in library goroutines (#235)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-21T17:07:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2429ac352f44ceb4af9354ccfa7c70b1d5bc47b0",
"body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.51.0 to 1.52.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.51.0...v1.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n depende\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump modernc.org/sqlite from 1.51.0 to 1.52.0 (#238)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-19T07:50:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1282e92200a839c1c2d8e91a3dba2de7f7b928f3",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.2 to 6.0.3 (#232)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-11T14:03:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "88af619bd0ea554316313014200014af08d36d05",
"body": null,
"is_bot": false,
"headline": "Add ecosystem matching mode for dependency diff (#230)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-08T08:48:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "faaab47a137400dec04e2bf8b9c465b05a7dc873",
"body": null,
"is_bot": false,
"headline": "Add notes import command (#229)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-08T08:41:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c98db00eeeea8200372b2b249293a6dda87db441",
"body": null,
"is_bot": false,
"headline": "Add maintenance health scores (#221)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-08T08:41:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76bb7b1dbae4c36b3a366d24c1644c31f4e07289",
"body": null,
"is_bot": false,
"headline": "Add license drift detection (#220)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-06T09:53:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5c511c783d114e0ad0d60d8419b0fd2b3e954691",
"body": null,
"is_bot": false,
"headline": "Treat Maven manifest versions as resolved (#226)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-05T14:22:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9549f0c37f06ca30e2b1c1e76541c4a8c6c0cf7a",
"body": "* Add dependency maintainer data\n\n* Preserve maintainer entries per dependency\n\n* Cache maintainer data\n\n* Adjust maintainer lookup timeout\n\n* Use enrichment bulk lookup for maintainers",
"is_bot": false,
"headline": "Add dependency maintainer data command (#215)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-05T14:03:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb317b49036f24f18c9e2080c4893446df7ddde3",
"body": "Bumps [github.com/git-pkgs/manifests](https://github.com/git-pkgs/manifests) from 0.4.3 to 0.5.0.\n- [Commits](https://github.com/git-pkgs/manifests/compare/v0.4.3...v0.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/manifests\n dependency-version: 0.5.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/manifests from 0.4.3 to 0.5.0 (#227)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-05T08:38:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "660616307f02ee0ccc98b9435764466927456e89",
"body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.50.1 to 1.51.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.50.1...v1.51.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n depende\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump modernc.org/sqlite from 1.50.1 to 1.51.0 (#228)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-05T08:38:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7174987be4e9f81de20d6068b4e4c0df536b27b7",
"body": "Replaces 17 inline \"git-pkgs/\" + version concatenations with a single\npackage-level userAgent variable populated in init() once version has\nresolved. New callers reach for cmd.userAgent instead of reconstructing\nthe string, keeping the UA format in one place.",
"is_bot": false,
"headline": "Centralize user agent string in cmd.userAgent (#225)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-03T11:30:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "36a60722d935a6d8b5da27e73ae1efb2e42150d4",
"body": "Two call sites in cmd/urls.go and cmd/deprecated.go passed a nil client\nto the registries package, falling back to the library default User-Agent\nof \"registries\". Pass a client configured with the same\n\"git-pkgs/<version>\" UA used by every other outbound call.",
"is_bot": false,
"headline": "Set git-pkgs user agent on registries calls (#224)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-06-03T11:06:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d116b5f686d1423cd3a387900247bc8a0b4510fc",
"body": "* Add exclude bots filtering\n\n* Fix exclude-bots diff replay matching\n\n* Drop exclude-bots support from diff\n\n* Remove unused bot author helper",
"is_bot": false,
"headline": "Add --exclude-bots filtering (#211)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-02T06:42:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a7da0007ce54e56e657a89f2cc381e5ca8547e8",
"body": "* Add dependency funding info\n\n* Clarify unresolved funding metadata output\n\n* Cache funding package metadata\n\n* Adjust funding timeout and schema version\n\n* Use enrichment funding links",
"is_bot": false,
"headline": "Add dependency funding info command (#214)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-06-02T06:35:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4f93b15b40f0c4c244946750152b85116a88138",
"body": "* Add deprecated dependency warnings\n\n* Address deprecated command review feedback\n\n* Cache deprecated version metadata\n\n* Adjust deprecated registry lookup timeout",
"is_bot": false,
"headline": "Add deprecated dependency warnings (#213)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-05-31T07:53:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "49bdd97788bf596a3a0e93615bb54961eacb1f9c",
"body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.1 to 7.2.2.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8...5daf1e\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 (#219)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-28T14:40:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b9235b4ee67a477800e0392fc8601c06468c0686",
"body": "* Add dependency freshness metrics\n\n* Report freshness metadata lookup failures\n\n* Fix freshness timeout and empty JSON output",
"is_bot": false,
"headline": "Add dependency freshness metrics (#212)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-05-28T14:04:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "564e354df041e29295703bedff90d272f3e9ee96",
"body": null,
"is_bot": false,
"headline": "Add diff summary stat mode (#216)",
"author_name": "Abhinav Gautam",
"author_login": "abhinavgautam01",
"committed_at": "2026-05-28T13:36:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2abff90627586d87c83c8a1867419500c6b5c691",
"body": "PR #166 added scope to each output line but the sort comparator still\nonly considered name and version. When a lockfile lists the same\npackage and version under more than one scope (e.g. Pipfile.lock\ndefault + develop), those entries compared equal and sort.Slice ordered\nthem however the parser emitted them, producing spurious diff hunks.\n\nFixes #217",
"is_bot": false,
"headline": "Sort diff-driver output by scope as final tiebreaker (#218)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-28T13:36:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef45ca2ce7a511eddc2b4b0f19a5a79ca7cdf5b7",
"body": "* fix(list): emit [] instead of null for empty JSON list results\n\nWhen GetDependenciesWithDB returns a nil slice, json.Encode emits `null`.\nDownstream consumers expecting a JSON array fail schema validation.\nCoalesce to empty slice before encoding.\n\nFixes #207.\n\n* test: add unit test for outputListJSON nil-to-[] conversion",
"is_bot": false,
"headline": "fix(list): emit [] instead of null for empty JSON list results (#208)",
"author_name": "Karry",
"author_login": "Karry2019web",
"committed_at": "2026-05-27T06:21:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8117f7985914ad767ff26909268918db1acf5abb",
"body": "The post-commit hook fired once per commit during a rebase, so a\n100-commit rebase ran reindex 100 times. The hook now bails when\n$GIT_DIR/rebase-merge or rebase-apply exists, and a new post-rewrite\nhook reindexes once when the rebase finishes ($1 = rebase, so\nper-commit amend calls inside the rebase are ignored).\n\nHooks installed by older versions are detected by their #!/bin/sh\nheader and overwritten on the next `hooks --install` or `init`.\n\nFixes #209",
"is_bot": false,
"headline": "Skip reindex during rebase and add post-rewrite hook (#210)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-27T06:20:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79854c47522a2a2be8c0c5e7a10e554deb87e1fd",
"body": "* feat: minimize progress updates to a single line\n\nInstead of printing every line, if we have a TTY, replace it instead.\n\nSigned-off-by: Mike Fiedler <miketheman@gmail.com>\n\n* Extract progress reporting into internal/progress package\n\nWraps the io.Writer in a Reporter that detects whether it is a t\n[…]\ntection now inspects the actual output writer\nrather than always checking os.Stdout.\n\n---------\n\nSigned-off-by: Mike Fiedler <miketheman@gmail.com>\nCo-authored-by: Andrew Nesbitt <andrewnez@gmail.com>",
"is_bot": false,
"headline": "Minimize indexer progress updates to a single line on a TTY",
"author_name": "Mike Fiedler",
"author_login": "miketheman",
"committed_at": "2026-05-25T14:18:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a6bfec65fd8b191edc36768fcee78fe4143b101f",
"body": null,
"is_bot": false,
"headline": "Bump github.com/go-git/go-git/v5 to v5.19.1 (#206)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-25T13:34:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a49b6b5f57a150f093d964dc5cdb27409414478",
"body": null,
"is_bot": false,
"headline": "Bump github.com/git-pkgs/managers to v0.9.0 (#205)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-25T13:34:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c92f2c1f04992c0f9ebad3bb046d8d1e1843829f",
"body": null,
"is_bot": false,
"headline": "Bump git-pkgs deps for v0.16.1 (#204)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-22T18:51:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dcb58e54d1ee85e7f9183978443d7cb46b19321",
"body": "Path exclusions only filter where goconst issues are reported, not which files contribute to the occurrence count, so a string used once in production code and twice in tests still gets flagged. The `ignore-tests` setting makes goconst skip test files entirely.",
"is_bot": false,
"headline": "Set goconst to ignore test files (#203)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-22T11:18:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ac11fe2bb705ce0e20d00ee8b10bdcca176746e",
"body": "Bumps [github.com/git-pkgs/sbom](https://github.com/git-pkgs/sbom) from 0.1.1 to 0.1.2.\n- [Commits](https://github.com/git-pkgs/sbom/compare/v0.1.1...v0.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/sbom\n dependency-version: 0.1.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/sbom from 0.1.1 to 0.1.2 (#202)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-22T03:02:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3104e84fa6ece62757bca63c1564eb74ef2783d8",
"body": "Bumps [github.com/git-pkgs/vers](https://github.com/git-pkgs/vers) from 0.2.5 to 0.2.6.\n- [Commits](https://github.com/git-pkgs/vers/compare/v0.2.5...v0.2.6)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/vers\n dependency-version: 0.2.6\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/git-pkgs/vers from 0.2.5 to 0.2.6 (#201)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-22T03:02:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1bb2c77bbc6d83dd1fa1d3358c89cf1c3aba4a51",
"body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.50.0 to 1.50.1.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.50.0...v1.50.1)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n depende\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump modernc.org/sqlite from 1.50.0 to 1.50.1 (#200)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-22T03:01:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "64927d154bf1cdab96150767cd2b0b519c22d5d6",
"body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003...6f9f17788090df1f26\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#199)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-15T13:40:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "33f5ba586d1f767bff27ef291aa727d8e225d839",
"body": "Version.Integrity is now populated for pub, julia and nuget, so the\nintegrity command can verify lockfile hashes for those ecosystems\nwhere it previously had nothing to compare against.",
"is_bot": false,
"headline": "Bump git-pkgs/registries to v0.6.0 (#198)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-13T05:44:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85f49073e99bce1087786b24c279c0db29b93bf9",
"body": null,
"is_bot": false,
"headline": "Bump go-git to v5.19.0 and go-billy to v5.9.0 (#197)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T12:11:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0edfa260d7d8a75b0755b957af67251e118597c0",
"body": null,
"is_bot": false,
"headline": "Update diff-driver README example to include scope",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T11:53:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d2731ebf2dd867ce80e59d85aabc7a77124a9f7c",
"body": "The diff driver now outputs scope (dev, runtime, optional) alongside\nname and version so scope changes are visible in git diff. The analyzer\ntracks PreviousDependencyType on scope-only changes, and show displays\nthem as \"package 1.0.0 (dev -> runtime)\" instead of the misleading\n\"package 1.0.0 -> 1.0.0\".\n\nBumps schema to v9 with a previous_dependency_type column.\n\nRelated to #164",
"is_bot": false,
"headline": "Include dependency type in diff driver and show output (#166)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T11:45:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "970917fb1802072c08c7da7fef947728593de33a",
"body": "go-git's ResolveRevision does not implement reflog (@{n}), :/regex,\ndate refs, and can fail on hashes in some storage layouts. Shell out\nto git rev-parse --verify as a fallback so show/tree/bisect/branch\naccept the full gitrevisions(7) grammar.\n\nReported in #166.",
"is_bot": false,
"headline": "Fall back to git rev-parse when go-git cannot resolve a revision (#193)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T11:45:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7cfaa99d59b02e3d098786cc7da9dcce3136e868",
"body": "* Enable commondir resolution so go-git can read refs and objects from linked worktrees\n\n* Build commondir wrapping ourselves to avoid go-git v5 fd leak on Windows",
"is_bot": false,
"headline": "Read refs and objects from linked worktrees (#196)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T11:44:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "08425d366ef58b39bb64a683fe8850ba5a8b8d28",
"body": "go-git's PlainOpen chroots its billy filesystem to .git, so absolute\npaths in objects/info/alternates can't be followed and borrowed\nobjects are invisible. Repos created with clone --shared or\n--reference would fail to resolve any SHA in the borrowed history\nwith \"reference not found\".\n\nReopen the storage with AlternatesFS rooted at the volume root so\ngo-git can follow alternates. PlainOpenOptions doesn't expose this\nso the storage has to be rebuilt by hand after discovery.\n\nReported in #166.",
"is_bot": false,
"headline": "Read alternate object stores when opening a repository (#194)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-09T10:44:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f187c2f46794915363795abe0dd1e6dd77c184d2",
"body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.1.0 to 7.2.1.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/e24998b8b67b290c2fa8b7c14fcfa7de2c5c9b8c...1a8083\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#191)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-07T13:10:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a5843fd4db2959d3a848b02986dc517c809123d2",
"body": "Bumps [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) from 0.0.21 to 0.0.22.\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.21...v0.0.22)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/mattn/go-isatty\n dependency-version: 0.0.22\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 (#192)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-07T13:06:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3eb8925554c436b89946f413e24a1f80edce864f",
"body": null,
"is_bot": false,
"headline": "Bump git-pkgs deps to latest patch releases",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-02T17:28:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a969d90226c970f4fcc9e3b2164694a143b405c8",
"body": "…utput (#189)\n\nChangelog text fetched from upstream repos, OSV summary/details fields,\nparsed dependency names from lockfiles, and git commit metadata all\nreach the terminal with C0 control bytes intact, allowing ANSI/OSC\nsequence injection (cursor movement, screen clearing, OSC 8 hyperlinks,\nclipboard writes on terminals that honour OSC 52).\n\nAdds a Sanitize helper in cmd/output.go that strips control characters\nother than tab and newline, applied at each cited output site.",
"is_bot": false,
"headline": "Strip control characters from externally sourced strings before TTY o…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-02T17:27:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b1a2167272a2eee907638767abad23281ba38d5",
"body": "searchFileForPackage used os.Open with an absolute path, which follows\nsymlinks. A symlink named like a manifest file could point outside the\nrepository and leak file contents. Uses os.Root scoped to the working\ndirectory so the kernel rejects any path that resolves outside the repo.",
"is_bot": false,
"headline": "Prevent where command from following symlinks out of repo (#188)",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-05-02T17:27:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2280f740eb66fb06c5502bb6e8ccbf45880eb31a",
"body": "…easer/goreleaser-action-7.1.0\n\nBump goreleaser/goreleaser-action from 7.0.0 to 7.1.0",
"is_bot": false,
"headline": "Merge pull request #184 from git-pkgs/dependabot/github_actions/gorel…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-04-30T16:54:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9218bf47ace1b1b7b58a3fa977e7b0ce382f35c7",
"body": "…m/go-git/go-git/v5-5.18.0\n\nBump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0",
"is_bot": false,
"headline": "Merge pull request #185 from git-pkgs/dependabot/go_modules/github.co…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-04-30T16:53:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1830953d9d901e7d2b26f6132ec5786c00388d8d",
"body": "…rg/sqlite-1.49.1\n\nBump modernc.org/sqlite from 1.48.2 to 1.49.1",
"is_bot": false,
"headline": "Merge pull request #186 from git-pkgs/dependabot/go_modules/modernc.o…",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-04-30T16:53:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc24f9d24536000e236838f3e50a4f42dc3d7bcc",
"body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.48.2 to 1.49.1.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.48.2...v1.49.1)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n dependency-version: 1.49.1\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump modernc.org/sqlite from 1.48.2 to 1.49.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T12:57:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85b954d74adaf8d1592d58cac48b4aadc96fba9d",
"body": "Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.2 to 5.18.0.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.17.2...v5.18.0)\n\n---\n\n[…]\n-name: github.com/go-git/go-git/v5\n dependency-version: 5.18.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T12:57:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46904086328428d5285726777f26ed6273c2776a",
"body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.0.0 to 7.1.0.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...e24998\n[…]\n-name: goreleaser/goreleaser-action\n dependency-version: 7.1.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump goreleaser/goreleaser-action from 7.0.0 to 7.1.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T12:56:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46aaf1e63899915b6f81cd9d4eb0c3f66d3ee658",
"body": "sbom: emit via github.com/git-pkgs/sbom",
"is_bot": false,
"headline": "Merge pull request #183 from git-pkgs/sbom-module",
"author_name": "Andrew Nesbitt",
"author_login": "andrew",
"committed_at": "2026-04-28T14:12:21Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 36,
"commits_last_year": 392,
"latest_release_at": "2026-07-27T11:33:19Z",
"latest_release_tag": "v0.18.2",
"releases_from_tags": false,
"days_since_last_push": 1,
"active_weeks_last_year": 28,
"days_since_latest_release": 5,
"mean_days_between_releases": 13.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/git-pkgs/git-pkgs",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/git-pkgs/git-pkgs",
"is_deprecated": false,
"latest_version": "v0.18.2",
"repository_url": "https://github.com/git-pkgs/git-pkgs",
"versions_count": 36,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-27T11:29:29Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 10,
"stars": 177,
"watchers": 4,
"fork_history": {
"days": [
{
"date": "2026-01-18",
"count": 1
},
{
"date": "2026-01-24",
"count": 1
},
{
"date": "2026-01-28",
"count": 1
},
{
"date": "2026-01-31",
"count": 1
},
{
"date": "2026-02-05",
"count": 1
},
{
"date": "2026-02-24",
"count": 1
},
{
"date": "2026-03-03",
"count": 1
},
{
"date": "2026-05-26",
"count": 1
},
{
"date": "2026-05-27",
"count": 1
},
{
"date": "2026-06-24",
"count": 1
}
],
"complete": true,
"collected": 10,
"total_forks": 10
},
"star_history": null,
"open_issues_and_prs": 9
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": true,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 85124,
"source_files_sampled": 136,
"oversized_source_files": 2,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 25
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 260,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/git-pkgs/changelog",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.3"
},
{
"name": "github.com/git-pkgs/enrichment",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.4"
},
{
"name": "github.com/git-pkgs/gitignore",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "github.com/git-pkgs/managers",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.10.1"
},
{
"name": "github.com/git-pkgs/manifests",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.1"
},
{
"name": "github.com/git-pkgs/purl",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.15"
},
{
"name": "github.com/git-pkgs/registries",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.4"
},
{
"name": "github.com/git-pkgs/resolve",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.2"
},
{
"name": "github.com/git-pkgs/sarif",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1"
},
{
"name": "github.com/git-pkgs/sbom",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.3"
},
{
"name": "github.com/git-pkgs/spdx",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.4"
},
{
"name": "github.com/git-pkgs/vers",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/git-pkgs/vulns",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.1"
},
{
"name": "github.com/go-git/go-billy/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.9.1"
},
{
"name": "github.com/go-git/go-git/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.19.1"
},
{
"name": "github.com/mattn/go-isatty",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.23"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "github.com/spf13/pflag",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.10"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.55.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/git-pkgs/changelog",
"direct": true,
"version": "v0.1.3",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/enrichment",
"direct": true,
"version": "v0.6.4",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/gitignore",
"direct": true,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/managers",
"direct": true,
"version": "v0.10.1",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/manifests",
"direct": true,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/purl",
"direct": true,
"version": "v0.1.15",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/registries",
"direct": true,
"version": "v0.6.4",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/resolve",
"direct": true,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/sarif",
"direct": true,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/sbom",
"direct": true,
"version": "v0.1.3",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/spdx",
"direct": true,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/vers",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/vulns",
"direct": true,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/go-git/go-billy/v5",
"direct": true,
"version": "v5.9.1",
"ecosystem": "go"
},
{
"name": "github.com/go-git/go-git/v5",
"direct": true,
"version": "v5.19.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": true,
"version": "v0.0.23",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": true,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "modernc.org/sqlite",
"direct": true,
"version": "v1.55.0",
"ecosystem": "go"
},
{
"name": "4d63.com/gocheckcompilerdirectives",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "4d63.com/gochecknoglobals",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "codeberg.org/chavacava/garif",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "codeberg.org/polyfloyd/go-errorlint",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "dario.cat/mergo",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "dev.gaijin.team/go/exhaustruct/v4",
"direct": false,
"version": "v4.0.0",
"ecosystem": "go"
},
{
"name": "dev.gaijin.team/go/golib",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/4meepo/tagalign",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/abirdcfly/dupword",
"direct": false,
"version": "v0.1.7",
"ecosystem": "go"
},
{
"name": "github.com/adminbenni/iota-mixing",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/alecthomas/chroma/v2",
"direct": false,
"version": "v2.23.1",
"ecosystem": "go"
},
{
"name": "github.com/alecthomas/go-check-sumtype",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/alexkohler/nakedret/v2",
"direct": false,
"version": "v2.0.6",
"ecosystem": "go"
},
{
"name": "github.com/alexkohler/prealloc",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/alfatraining/structtag",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/alingse/asasalint",
"direct": false,
"version": "v0.0.11",
"ecosystem": "go"
},
{
"name": "github.com/alingse/nilnesserr",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/alwxsin/noinlineerr",
"direct": false,
"version": "v1.0.5",
"ecosystem": "go"
},
{
"name": "github.com/antonboom/errname",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/antonboom/nilnil",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/antonboom/testifylint",
"direct": false,
"version": "v1.6.4",
"ecosystem": "go"
},
{
"name": "github.com/apapsch/go-jsonmerge/v2",
"direct": false,
"version": "v2.0.0",
"ecosystem": "go"
},
{
"name": "github.com/ashanbrown/forbidigo/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/ashanbrown/makezero/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bazelbuild/buildtools",
"direct": false,
"version": "v0.0.0-20260716142318-04cf7de1434f",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bkielbasa/cyclop",
"direct": false,
"version": "v1.2.3",
"ecosystem": "go"
},
{
"name": "github.com/blizzy78/varnamelen",
"direct": false,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/bombsimon/wsl/v4",
"direct": false,
"version": "v4.7.0",
"ecosystem": "go"
},
{
"name": "github.com/bombsimon/wsl/v5",
"direct": false,
"version": "v5.6.0",
"ecosystem": "go"
},
{
"name": "github.com/breml/bidichk",
"direct": false,
"version": "v0.3.3",
"ecosystem": "go"
},
{
"name": "github.com/breml/errchkjson",
"direct": false,
"version": "v0.4.1",
"ecosystem": "go"
},
{
"name": "github.com/burntsushi/toml",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/butuzov/ireturn",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/butuzov/mirror",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/catenacyber/perfsprint",
"direct": false,
"version": "v0.10.1",
"ecosystem": "go"
},
{
"name": "github.com/ccojocar/zxcvbn-go",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/charithe/durationcheck",
"direct": false,
"version": "v0.0.11",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.2.3-0.20250311203215-f60798e515dc",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.10.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.13-0.20250311204145-2c3ea96c31dd",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/ckaznocha/intrange",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.6.4",
"ecosystem": "go"
},
{
"name": "github.com/cpuguy83/go-md2man/v2",
"direct": false,
"version": "v2.0.7",
"ecosystem": "go"
},
{
"name": "github.com/curioswitch/go-reassign",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/cyphar/filepath-securejoin",
"direct": false,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/daixiang0/gci",
"direct": false,
"version": "v0.13.7",
"ecosystem": "go"
},
{
"name": "github.com/dave/dst",
"direct": false,
"version": "v0.27.3",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/denis-tingaikin/go-header",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/djarvur/go-err113",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/dlclark/regexp2",
"direct": false,
"version": "v1.11.5",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/ecosyste-ms/ecosystems-go",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/emirpasic/gods",
"direct": false,
"version": "v1.18.1",
"ecosystem": "go"
},
{
"name": "github.com/ettle/strcase",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/fatih/color",
"direct": false,
"version": "v1.18.0",
"ecosystem": "go"
},
{
"name": "github.com/fatih/structtag",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/firefart/nonamedreturns",
"direct": false,
"version": "v1.0.6",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/fzipp/gocyclo",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/ghostiam/protogetter",
"direct": false,
"version": "v0.3.20",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/packageurl-go",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/git-pkgs/pom",
"direct": false,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "github.com/github/go-spdx/v2",
"direct": false,
"version": "v2.7.0",
"ecosystem": "go"
},
{
"name": "github.com/go-critic/go-critic",
"direct": false,
"version": "v0.14.3",
"ecosystem": "go"
},
{
"name": "github.com/go-git/gcfg",
"direct": false,
"version": "v1.5.1-0.20230307220236-3a3c6141e376",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/astcast",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/astcopy",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/astequal",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/astfmt",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/astp",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/strparse",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-toolsmith/typep",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/go-xmlfmt/xmlfmt",
"direct": false,
"version": "v1.1.3",
"ecosystem": "go"
},
{
"name": "github.com/gobwas/glob",
"direct": false,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/godoc-lint/godoc-lint",
"direct": false,
"version": "v0.11.2",
"ecosystem": "go"
},
{
"name": "github.com/gofrs/flock",
"direct": false,
"version": "v0.13.0",
"ecosystem": "go"
},
{
"name": "github.com/golang/groupcache",
"direct": false,
"version": "v0.0.0-20241129210726-2c02b8208cf8",
"ecosystem": "go"
},
{
"name": "github.com/golang/protobuf",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/golangci/asciicheck",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/golangci/dupl",
"direct": false,
"version": "v0.0.0-20250308024227-f665c8d69b32",
"ecosystem": "go"
},
{
"name": "github.com/golangci/go-printf-func-name",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/golangci/gofmt",
"direct": false,
"version": "v0.0.0-20250106114630-d62b90e6713d",
"ecosystem": "go"
},
{
"name": "github.com/golangci/golangci-lint/v2",
"direct": false,
"version": "v2.10.1",
"ecosystem": "go"
},
{
"name": "github.com/golangci/golines",
"direct": false,
"version": "v0.15.0",
"ecosystem": "go"
},
{
"name": "github.com/golangci/misspell",
"direct": false,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/golangci/plugin-module-register",
"direct": false,
"version": "v0.1.2",
"ecosystem": "go"
},
{
"name": "github.com/golangci/revgrep",
"direct": false,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/golangci/swaggoswag",
"direct": false,
"version": "v0.0.0-20250504205917-77f2aca3143e",
"ecosystem": "go"
},
{
"name": "github.com/golangci/unconvert",
"direct": false,
"version": "v0.0.0-20250410112200-a129a6e6413e",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/gordonklaus/ineffassign",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/gostaticanalysis/analysisutil",
"direct": false,
"version": "v0.7.1",
"ecosystem": "go"
},
{
"name": "github.com/gostaticanalysis/comment",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/gostaticanalysis/forcetypeassert",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/gostaticanalysis/nilerr",
"direct": false,
"version": "v0.1.2",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-immutable-radix/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-version",
"direct": false,
"version": "v1.8.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru/v2",
"direct": false,
"version": "v2.0.7",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/hcl",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/hexops/gotextdiff",
"direct": false,
"version": "v1.0.3",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/jbenet/go-context",
"direct": false,
"version": "v0.0.0-20150711004518-d14ea06fba99",
"ecosystem": "go"
},
{
"name": "github.com/jgautheron/goconst",
"direct": false,
"version": "v1.8.2",
"ecosystem": "go"
},
{
"name": "github.com/jingyugao/rowserrcheck",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/jjti/go-spancheck",
"direct": false,
"version": "v0.6.5",
"ecosystem": "go"
},
{
"name": "github.com/julz/importas",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/karamaru-alpha/copyloopvar",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/kevinburke/ssh_config",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/kisielk/errcheck",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/kkhaike/contextcheck",
"direct": false,
"version": "v1.1.6",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/cpuid/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/kulti/thelper",
"direct": false,
"version": "v0.7.1",
"ecosystem": "go"
},
{
"name": "github.com/kunwardeep/paralleltest",
"direct": false,
"version": "v1.0.15",
"ecosystem": "go"
},
{
"name": "github.com/lasiar/canonicalheader",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/ldez/exptostd",
"direct": false,
"version": "v0.4.5",
"ecosystem": "go"
},
{
"name": "github.com/ldez/gomoddirectives",
"direct": false,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/ldez/grignotin",
"direct": false,
"version": "v0.10.1",
"ecosystem": "go"
},
{
"name": "github.com/ldez/structtags",
"direct": false,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/ldez/tagliatelle",
"direct": false,
"version": "v0.7.2",
"ecosystem": "go"
},
{
"name": "github.com/ldez/usetesting",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/leonklingele/grouper",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/macabu/inamedparam",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/magiconair/properties",
"direct": false,
"version": "v1.8.6",
"ecosystem": "go"
},
{
"name": "github.com/manuelarte/embeddedstructfieldcheck",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/manuelarte/funcorder",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/maratori/testableexamples",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/maratori/testpackage",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/semver/v3",
"direct": false,
"version": "v3.4.0",
"ecosystem": "go"
},
{
"name": "github.com/matoous/godox",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-colorable",
"direct": false,
"version": "v0.1.14",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.16",
"ecosystem": "go"
},
{
"name": "github.com/matttproud/golang_protobuf_extensions",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mgechev/revive",
"direct": false,
"version": "v1.14.0",
"ecosystem": "go"
},
{
"name": "github.com/microsoft/go-winio",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/mirrexone/unqueryvet",
"direct": false,
"version": "v1.5.3",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/go-homedir",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/mapstructure",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/moricho/tparallel",
"direct": false,
"version": "v0.3.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/nakabonne/nestif",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/ncruces/go-strftime",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/nishanths/exhaustive",
"direct": false,
"version": "v0.12.0",
"ecosystem": "go"
},
{
"name": "github.com/nishanths/predeclared",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/nunnatsa/ginkgolinter",
"direct": false,
"version": "v0.23.0",
"ecosystem": "go"
},
{
"name": "github.com/oapi-codegen/nullable",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/oapi-codegen/runtime",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/openpeedeep/depguard/v2",
"direct": false,
"version": "v2.2.1",
"ecosystem": "go"
},
{
"name": "github.com/package-url/packageurl-go",
"direct": false,
"version": "v0.1.6",
"ecosystem": "go"
},
{
"name": "github.com/pandatix/go-cvss",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml",
"direct": false,
"version": "v1.9.5",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": false,
"version": "v2.2.4",
"ecosystem": "go"
},
{
"name": "github.com/pjbgf/sha1cd",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.12.1",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.32.1",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.7.3",
"ecosystem": "go"
},
{
"name": "github.com/protonmail/go-crypto",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/quasilyte/go-ruleguard",
"direct": false,
"version": "v0.4.5",
"ecosystem": "go"
},
{
"name": "github.com/quasilyte/go-ruleguard/dsl",
"direct": false,
"version": "v0.3.23",
"ecosystem": "go"
},
{
"name": "github.com/quasilyte/gogrep",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/quasilyte/regex/syntax",
"direct": false,
"version": "v0.0.0-20210819130434-b3f0c404a727",
"ecosystem": "go"
},
{
"name": "github.com/quasilyte/stdinfo",
"direct": false,
"version": "v0.0.0-20220114132959-f7386bf02567",
"ecosystem": "go"
},
{
"name": "github.com/raeperd/recvcheck",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/remyoudompheng/bigfft",
"direct": false,
"version": "v0.0.0-20230129092748-24d4a6f8daec",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.14.1",
"ecosystem": "go"
},
{
"name": "github.com/russross/blackfriday/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/ryancurrah/gomodguard",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/ryanrolds/sqlclosecheck",
"direct": false,
"version": "v0.5.1",
"ecosystem": "go"
},
{
"name": "github.com/sanposhiho/wastedassign/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"direct": false,
"version": "v6.0.2",
"ecosystem": "go"
},
{
"name": "github.com/sashamelentyev/interfacebloat",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/sashamelentyev/usestdlibvars",
"direct": false,
"version": "v1.29.0",
"ecosystem": "go"
},
{
"name": "github.com/securego/gosec/v2",
"direct": false,
"version": "v2.23.0",
"ecosystem": "go"
},
{
"name": "github.com/sergi/go-diff",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/sirupsen/logrus",
"direct": false,
"version": "v1.9.4",
"ecosystem": "go"
},
{
"name": "github.com/sivchari/containedctx",
"direct": false,
"version": "v1.0.3",
"ecosystem": "go"
},
{
"name": "github.com/skeema/knownhosts",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/sonatard/noctx",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/sourcegraph/go-diff",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/afero",
"direct": false,
"version": "v1.15.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/jwalterweatherman",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/viper",
"direct": false,
"version": "v1.12.0",
"ecosystem": "go"
},
{
"name": "github.com/ssgreg/nlreturn/v2",
"direct": false,
"version": "v2.2.1",
"ecosystem": "go"
},
{
"name": "github.com/stbenjam/no-sprintf-host-port",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/objx",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": false,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "github.com/subosito/gotenv",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/tetafro/godot",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/timakin/bodyclose",
"direct": false,
"version": "v0.0.0-20241222091800-1db5c5ca4d67",
"ecosystem": "go"
},
{
"name": "github.com/timonwong/loggercheck",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/tomarrell/wrapcheck/v2",
"direct": false,
"version": "v2.12.0",
"ecosystem": "go"
},
{
"name": "github.com/tommy-muehle/go-mnd/v2",
"direct": false,
"version": "v2.5.1",
"ecosystem": "go"
},
{
"name": "github.com/ultraware/funlen",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/ultraware/whitespace",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/uudashr/gocognit",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/uudashr/iface",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/xanzy/ssh-agent",
"direct": false,
"version": "v0.3.3",
"ecosystem": "go"
},
{
"name": "github.com/xen0n/gosmopolitan",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "github.com/yagipy/maintidx",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/yeya24/promlinter",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/ykadowak/zerologlint",
"direct": false,
"version": "v0.1.5",
"ecosystem": "go"
},
{
"name": "gitlab.com/bosi/decorder",
"direct": false,
"version": "v0.4.2",
"ecosystem": "go"
},
{
"name": "go-simpler.org/musttag",
"direct": false,
"version": "v0.14.0",
"ecosystem": "go"
},
{
"name": "go-simpler.org/sloglint",
"direct": false,
"version": "v0.11.1",
"ecosystem": "go"
},
{
"name": "go.augendre.info/arangolint",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "go.augendre.info/fatcontext",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/multierr",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/zap",
"direct": false,
"version": "v1.27.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp/typeparams",
"direct": false,
"version": "v0.0.0-20260209203927-2842357ff358",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": false,
"version": "v0.37.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.56.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.46.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.39.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/tools",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": false,
"version": "v1.36.8",
"ecosystem": "go"
},
{
"name": "gopkg.in/ini.v1",
"direct": false,
"version": "v1.67.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/warnings.v0",
"direct": false,
"version": "v0.1.2",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v2",
"direct": false,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "honnef.co/go/tools",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "modernc.org/libc",
"direct": false,
"version": "v1.74.3",
"ecosystem": "go"
},
{
"name": "modernc.org/mathutil",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "modernc.org/memory",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "mvdan.cc/gofumpt",
"direct": false,
"version": "v0.9.2",
"ecosystem": "go"
},
{
"name": "mvdan.cc/unparam",
"direct": false,
"version": "v0.0.0-20251027182757-5beb8c8f8f15",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 260,
"direct_count": 20,
"indirect_count": 240
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 212,
"open_issues": 9,
"closed_ratio": 0.892,
"closed_issues": 74,
"closed_unmerged_prs": 5
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "andrew",
"commits": 297,
"avatar_url": "https://avatars.githubusercontent.com/u/1060?v=4"
},
{
"type": "User",
"login": "abhinavgautam01",
"commits": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/183635986?v=4"
},
{
"type": "User",
"login": "bryceberger",
"commits": 8,
"avatar_url": "https://avatars.githubusercontent.com/u/9222441?v=4"
},
{
"type": "User",
"login": "sanmaxdev",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/46221775?v=4"
},
{
"type": "User",
"login": "miketheman",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/529516?v=4"
},
{
"type": "User",
"login": "bnjmnt4n",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/813865?v=4"
},
{
"type": "User",
"login": "Karry2019web",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/51736839?v=4"
}
],
"contributors_sampled": 7,
"top_contributor_share": 0.874
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 3,
"reason": "Found 5/15 approved changesets -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 24 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 8,
"reason": "SAST tool is not run on all commits -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "08bf43497d7706f8c4e754b551f541d0df12bb37",
"ran_at": "2026-08-02T05:11:46Z",
"aggregate_score": 6.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-31T16:28:18Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-31T16:20:56Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 112,
"created_at": "2026-02-16T09:10:18Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 113,
"created_at": "2026-02-16T09:10:26Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 114,
"created_at": "2026-02-16T09:10:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 115,
"created_at": "2026-02-16T09:10:49Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 116,
"created_at": "2026-02-16T09:11:09Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 133,
"created_at": "2026-02-26T12:55:12Z",
"last_comment_at": "2026-06-20T07:52:07Z",
"last_comment_author": "abhinavgautam01"
},
{
"number": 164,
"created_at": "2026-03-09T18:50:44Z",
"last_comment_at": "2026-05-27T14:20:37Z",
"last_comment_author": "benknoble"
},
{
"number": 261,
"created_at": "2026-06-30T07:42:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 294,
"created_at": "2026-07-30T12:35:59Z",
"last_comment_at": "2026-07-30T12:57:28Z",
"last_comment_author": "andrew"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/git-pkgs/git-pkgs",
"host": "github.com",
"name": "git-pkgs",
"owner": "git-pkgs"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 75 is calibrated to 89 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 75,
"calibrated": 89,
"calibration": "2026-08-02"
}
}
],
"value": 89,
"inputs": {
"security": 72,
"vitality": 86,
"community": 65,
"governance": 64,
"calibration": "2026-08-02",
"engineering": 90,
"ai_readiness": 72,
"weighted_overall_raw": 75
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 86,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"commits_last_year": 392,
"human_commit_share": 0.72,
"days_since_last_push": 1,
"active_weeks_last_year": 28
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "28/52 weeks with commits",
"points": 19.4,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 28
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "392 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 392
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 36,
"latest_release_tag": "v0.18.2",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 13.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "36 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 36
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~13.3 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 13.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 2,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 2 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 2
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 65,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "weak",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"forks": 10,
"stars": 177,
"watchers": 4,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "177 stars",
"points": 36.4,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 177
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "10 forks",
"points": 8,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 10
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "4 watchers",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 4
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 64,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 31,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 7,
"top_contributor_share": 0.874
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 87% of commits",
"points": 2.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 87
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "7 contributors",
"points": 9.5,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 7
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 24 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 82,
"inputs": {
"merged_prs": 212,
"open_issues": 9,
"closed_issues": 74,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 0.892,
"closed_unmerged_prs": 5,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "89% of issues closed",
"points": 37.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 89
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "212/217 decided PRs merged",
"points": 29.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 212,
"decided": 217
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 5/15 approved changesets -- score normalized to 3",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"followers": 42,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "git-pkgs",
"public_repos": 47,
"account_age_days": 200
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "42 followers of git-pkgs",
"points": 11.7,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 42,
"login": "git-pkgs"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "47 public repos, account ~0 yr old",
"points": 13.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 47
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/git-pkgs/git-pkgs"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "36 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 36
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 90,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "exceptional",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"dependencies",
"git",
"git-commands",
"package-management"
],
"has_wiki": true,
"homepage": "https://git-pkgs.dev",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://git-pkgs.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "4 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 4
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 72,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 5/15 approved changesets -- score normalized to 3",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 24 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 8",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 260 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 260
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 260,
"unassessed_packages": 0,
"affected_by_severity": "unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 260,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 19
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 72,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.889,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "64 of 72 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 64,
"sampled": 72
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": true,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.28
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "devcontainer, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "devcontainer, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "28 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 28,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 85124,
"source_files_sampled": 136,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/136 source files over 60KB",
"points": 54.2,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 136,
"oversized": 2
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"library",
"cli"
],
"scores": {
"cli": 4,
"library": 6
},
"primary": "library",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:go",
"weight": 6
},
{
"tier": "dependencies",
"label": "cli",
"source": "dep:github.com/spf13/cobra",
"weight": 4
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-08-02T05:12:05.579334Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/git-pkgs/git-pkgs.svg",
"full_name": "git-pkgs/git-pkgs",
"license_state": "standard",
"license_spdx": "MIT"
}