Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 2.3.1 · 2026-08-02 05:12 UTC

git-pkgs / git-pkgs

About A git subcommand for analyzing package/dependency usage in git repositories over time

GoMIT★ 177 estrellas⑂ 10 forksdesde ene 2026Ver en GitHub ↗
TipoBibliotecaHerramienta de línea de comandoscómo se determina

git-pkgs/git-pkgs tiene un índice de salud de 89 sobre 100, lo que lo sitúa en la banda Excelente. Su puntuación más alta es Engineering Quality (90/100) y la más baja, Sustainability & Governance (64/100). Se actualizó por última vez hace 1 día. Una sola persona concentra la mayor parte del trabajo reciente.

89
global / 100
Excelente

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala estandarizada de 1 a 100. El resultado global parte de su media ponderada, calibrada contra la distribución del registro público para que las bandas tengan significado percentil; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe un límite «En riesgo» de 34.

89
Excepcional93-100El nivel más alto del registro (≈ el 5% superior); cumple prácticamente todos los criterios evaluados
Excelente80-92Sólido en todos los frentes; carencias menores
Bueno65-79Saludable; carencias limitadas y manejables
Moderado50-64Aceptable con carencias notables; se recomienda revisión
Débil35-49Debilidades sustanciales en varias áreas
En riesgo20-34Debilidades significativas; su adopción exige cautela
Crítico1-19Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

El resultado global ponderado 75 se calibra a 89 en la escala publicada del índice (calibración del registro 2026-08-02).

Titularidad

git-pkgsOrganización
42 seguidores47 repositorios públicosdesde ene 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/git-pkgs/git-pkgsv0.18.2-36hace 5 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

86Excelente · 21% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 1 días
19.4/36Cadencia de commits — 28/52 semanas con commits
18/18Volumen de commits — 392 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year392
human_commit_share0,72
days_since_last_push1
active_weeks_last_year28
Cómo se puntúa
27/27Publica versiones — 36 versiones publicadas
36/36Recencia de las versiones — última versión hace 5 días
27/27Cadencia de publicación — una versión cada ~13,3 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count36
latest_release_tagv0.18.2
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases13,3

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

65Bueno · 17% del índice global
Cómo se puntúa
36.4/60Estrellas — 177 estrellas
8/25Forks — 10 forks
2.7/15Observadores — 4 observadores
Datos de entrada utilizados
forks10
stars177
watchers4
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
readme_badges
has_contributing
has_issue_templateno
has_code_of_conduct
readme_badge_services
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

64Moderado · 23% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
2.8/22.5Distribución de commits — el principal contribuyente firma el 87% de los commits
9.5/13.5Amplitud de contribuyentes — 7 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 24 contributing companies or organizations
Datos de entrada utilizados
bus_factor1
contributors_sampled7
top_contributor_share0,874
Cómo se puntúa
37.5/42Resolución de issues — 89% de issues cerradas
29.3/30Aceptación de PR — 212/217 PR decididos fusionados
0/13Newcomer PR acceptance — ningún PR de un contribuyente primerizo decidido en 30 d
4.5/15OpenSSF Scorecard: Code-Review — Found 5/15 approved changesets -- score normalized to 3
Datos de entrada utilizados
merged_prs212
open_issues9
closed_issues74
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0,892
closed_unmerged_prs5
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluidos de la puntuación (sin datos o no aplicable): newcomer_pr_acceptance. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
11.7/25Alcance del propietario — 42 seguidores de git-pkgs
13.3/25Trayectoria — 47 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers42
owner_typeOrganization
is_verified
owner_logingit-pkgs
public_repos47
account_age_days200
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 36 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/git-pkgs/git-pkgs
ecosystemsgo
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

90Excelente · 19% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 2 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yml
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 24 out of 24 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno

Documentación

100Excepcional
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://git-pkgs.dev
10/10Descripción del repositorio
10/10Topics — 4 topics
10/10Wiki
Datos de entrada utilizados
topicsdependencies, git, git-commands, package-management
has_wiki
homepagehttps://git-pkgs.dev
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

72Bueno · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 24 out of 24 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
2.2/7.5Code-Review — Found 5/15 approved changesets -- score normalized to 3
2.5/2.5Contributors — project has 24 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
4/5SAST — SAST tool is not run on all commits -- score normalized to 8
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate6,5
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages260
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos, Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejaron 260 dependencias resueltas con OSV. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Tiene un peso deliberadamente pequeño (4%): las herramientas para agentes son una señal real de mantenimiento, pero un repositorio sin ninguna puede alcanzar igualmente 100/100.

72Bueno · 4% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 64 de 72 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,889
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
12.6/18Arranque con un solo comando — go.mod (convención del toolchain, sin ejecutor de tareas)
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yml
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — devcontainer, lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
8/8Mantenimiento automatizado — 28 de los últimos 100 commits son actualizaciones automáticas de dependencias
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfileno
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0,28
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.2/55Tamaños de archivo manejables — 2/136 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes85.124
source_files_sampled136
oversized_source_files2

Datos clave

177estrellas de GitHub
7contribuidores
392commits en los últimos 12 meses
1días desde el último push
36versiones publicadas
1factor bus
9issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

Historial de estrellas y forks 0 ★ / 10 ⇿
0Estrellas
10Forks
31Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

02468101012026-012026-042026-06
Mayor 0Menor 7Parche 24
OpenSSF Scorecard 6.5 / 10
6.5agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-08-02 05:11 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests24 out of 24 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
3Code-ReviewFound 5/15 approved changesets -- score normalized to 3
10Contributorsproject has 24 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
8SASTSAST tool is not run on all commits -- score normalized to 8
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Dependencias directas 20
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/git-pkgs/changelogv0.1.3go.mod
Gogithub.com/git-pkgs/enrichmentv0.6.4go.mod
Gogithub.com/git-pkgs/gitignorev1.2.0go.mod
Gogithub.com/git-pkgs/managersv0.10.1go.mod
Gogithub.com/git-pkgs/manifestsv0.6.1go.mod
Gogithub.com/git-pkgs/purlv0.1.15go.mod
Gogithub.com/git-pkgs/registriesv0.6.4go.mod
Gogithub.com/git-pkgs/resolvev0.2.2go.mod
Gogithub.com/git-pkgs/sarifv0.1.1go.mod
Gogithub.com/git-pkgs/sbomv0.1.3go.mod
Gogithub.com/git-pkgs/spdxv0.1.4go.mod
Gogithub.com/git-pkgs/versv0.3.0go.mod
Gogithub.com/git-pkgs/vulnsv0.2.1go.mod
Gogithub.com/go-git/go-billy/v5v5.9.1go.mod
Gogithub.com/go-git/go-git/v5v5.19.1go.mod
Gogithub.com/mattn/go-isattyv0.0.23go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.10go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.55.0go.mod
Todas las dependencias 260

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 20 paquetes directos y 240 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Gogithub.com/git-pkgs/changelogv0.1.3directa
Gogithub.com/git-pkgs/enrichmentv0.6.4directa
Gogithub.com/git-pkgs/gitignorev1.2.0directa
Gogithub.com/git-pkgs/managersv0.10.1directa
Gogithub.com/git-pkgs/manifestsv0.6.1directa
Gogithub.com/git-pkgs/purlv0.1.15directa
Gogithub.com/git-pkgs/registriesv0.6.4directa
Gogithub.com/git-pkgs/resolvev0.2.2directa
Gogithub.com/git-pkgs/sarifv0.1.1directa
Gogithub.com/git-pkgs/sbomv0.1.3directa
Gogithub.com/git-pkgs/spdxv0.1.4directa
Gogithub.com/git-pkgs/versv0.3.0directa
Gogithub.com/git-pkgs/vulnsv0.2.1directa
Gogithub.com/go-git/go-billy/v5v5.9.1directa
Gogithub.com/go-git/go-git/v5v5.19.1directa
Gogithub.com/mattn/go-isattyv0.0.23directa
Gogithub.com/spf13/cobrav1.10.2directa
Gogithub.com/spf13/pflagv1.0.10directa
Gogopkg.in/yaml.v3v3.0.1directa
Gomodernc.org/sqlitev1.55.0directa
Go4d63.com/gocheckcompilerdirectivesv1.3.0indirecta
Go4d63.com/gochecknoglobalsv0.2.2indirecta
Gocodeberg.org/chavacava/garifv0.2.0indirecta
Gocodeberg.org/polyfloyd/go-errorlintv1.9.0indirecta
Godario.cat/mergov1.0.2indirecta
Godev.gaijin.team/go/exhaustruct/v4v4.0.0indirecta
Godev.gaijin.team/go/golibv0.6.0indirecta
Gogithub.com/4meepo/tagalignv1.4.3indirecta
Gogithub.com/abirdcfly/dupwordv0.1.7indirecta
Gogithub.com/adminbenni/iota-mixingv1.0.0indirecta
Gogithub.com/alecthomas/chroma/v2v2.23.1indirecta
Gogithub.com/alecthomas/go-check-sumtypev0.3.1indirecta
Gogithub.com/alexkohler/nakedret/v2v2.0.6indirecta
Gogithub.com/alexkohler/preallocv1.0.2indirecta
Gogithub.com/alfatraining/structtagv1.0.0indirecta
Gogithub.com/alingse/asasalintv0.0.11indirecta
Gogithub.com/alingse/nilnesserrv0.2.0indirecta
Gogithub.com/alwxsin/noinlineerrv1.0.5indirecta
Gogithub.com/antonboom/errnamev1.1.1indirecta
Gogithub.com/antonboom/nilnilv1.1.1indirecta
Gogithub.com/antonboom/testifylintv1.6.4indirecta
Gogithub.com/apapsch/go-jsonmerge/v2v2.0.0indirecta
Gogithub.com/ashanbrown/forbidigo/v2v2.3.0indirecta
Gogithub.com/ashanbrown/makezero/v2v2.1.0indirecta
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1indirecta
Gogithub.com/bazelbuild/buildtoolsv0.0.0-20260716142318-04cf7de1434findirecta
Gogithub.com/beorn7/perksv1.0.1indirecta
Gogithub.com/bkielbasa/cyclopv1.2.3indirecta
Gogithub.com/blizzy78/varnamelenv0.8.0indirecta
Gogithub.com/bombsimon/wsl/v4v4.7.0indirecta
Gogithub.com/bombsimon/wsl/v5v5.6.0indirecta
Gogithub.com/breml/bidichkv0.3.3indirecta
Gogithub.com/breml/errchkjsonv0.4.1indirecta
Gogithub.com/burntsushi/tomlv1.6.0indirecta
Gogithub.com/butuzov/ireturnv0.4.0indirecta
Gogithub.com/butuzov/mirrorv1.3.0indirecta
Gogithub.com/catenacyber/perfsprintv0.10.1indirecta
Gogithub.com/ccojocar/zxcvbn-gov1.0.4indirecta
Gogithub.com/cespare/xxhash/v2v2.3.0indirecta
Gogithub.com/charithe/durationcheckv0.0.11indirecta
Gogithub.com/charmbracelet/colorprofilev0.2.3-0.20250311203215-f60798e515dcindirecta
Gogithub.com/charmbracelet/lipglossv1.1.0indirecta
Gogithub.com/charmbracelet/x/ansiv0.10.1indirecta
Gogithub.com/charmbracelet/x/cellbufv0.0.13-0.20250311204145-2c3ea96c31ddindirecta
Gogithub.com/charmbracelet/x/termv0.2.1indirecta
Gogithub.com/ckaznocha/intrangev0.3.1indirecta
Gogithub.com/cloudflare/circlv1.6.4indirecta
Gogithub.com/cpuguy83/go-md2man/v2v2.0.7indirecta
Gogithub.com/curioswitch/go-reassignv0.3.0indirecta
Gogithub.com/cyphar/filepath-securejoinv0.6.1indirecta
Gogithub.com/daixiang0/gciv0.13.7indirecta
Gogithub.com/dave/dstv0.27.3indirecta
Gogithub.com/davecgh/go-spewv1.1.1indirecta
Gogithub.com/denis-tingaikin/go-headerv0.5.0indirecta
Gogithub.com/djarvur/go-err113v0.1.1indirecta
Gogithub.com/dlclark/regexp2v1.11.5indirecta
Gogithub.com/dustin/go-humanizev1.0.1indirecta
Gogithub.com/ecosyste-ms/ecosystems-gov0.4.0indirecta
Gogithub.com/emirpasic/godsv1.18.1indirecta
Gogithub.com/ettle/strcasev0.2.0indirecta
Gogithub.com/fatih/colorv1.18.0indirecta
Gogithub.com/fatih/structtagv1.2.0indirecta
Gogithub.com/firefart/nonamedreturnsv1.0.6indirecta
Gogithub.com/fsnotify/fsnotifyv1.5.4indirecta
Gogithub.com/fzipp/gocyclov0.6.0indirecta
Gogithub.com/ghostiam/protogetterv0.3.20indirecta
Gogithub.com/git-pkgs/packageurl-gov0.3.1indirecta
Gogithub.com/git-pkgs/pomv0.1.5indirecta
Gogithub.com/github/go-spdx/v2v2.7.0indirecta
Gogithub.com/go-critic/go-criticv0.14.3indirecta
Gogithub.com/go-git/gcfgv1.5.1-0.20230307220236-3a3c6141e376indirecta
Gogithub.com/go-toolsmith/astcastv1.1.0indirecta
Gogithub.com/go-toolsmith/astcopyv1.1.0indirecta
Gogithub.com/go-toolsmith/astequalv1.2.0indirecta
Gogithub.com/go-toolsmith/astfmtv1.1.0indirecta
Gogithub.com/go-toolsmith/astpv1.1.0indirecta
Gogithub.com/go-toolsmith/strparsev1.1.0indirecta
Gogithub.com/go-toolsmith/typepv1.1.0indirecta
Gogithub.com/go-viper/mapstructure/v2v2.5.0indirecta
Gogithub.com/go-xmlfmt/xmlfmtv1.1.3indirecta
Gogithub.com/gobwas/globv0.2.3indirecta
Gogithub.com/godoc-lint/godoc-lintv0.11.2indirecta
Gogithub.com/gofrs/flockv0.13.0indirecta
Gogithub.com/golang/groupcachev0.0.0-20241129210726-2c02b8208cf8indirecta
Gogithub.com/golang/protobufv1.5.4indirecta
Gogithub.com/golangci/asciicheckv0.5.0indirecta
Gogithub.com/golangci/duplv0.0.0-20250308024227-f665c8d69b32indirecta
Gogithub.com/golangci/go-printf-func-namev0.1.1indirecta
Gogithub.com/golangci/gofmtv0.0.0-20250106114630-d62b90e6713dindirecta
Gogithub.com/golangci/golangci-lint/v2v2.10.1indirecta
Gogithub.com/golangci/golinesv0.15.0indirecta
Gogithub.com/golangci/misspellv0.8.0indirecta
Gogithub.com/golangci/plugin-module-registerv0.1.2indirecta
Gogithub.com/golangci/revgrepv0.8.0indirecta
Gogithub.com/golangci/swaggoswagv0.0.0-20250504205917-77f2aca3143eindirecta
Gogithub.com/golangci/unconvertv0.0.0-20250410112200-a129a6e6413eindirecta
Gogithub.com/google/go-cmpv0.7.0indirecta
Gogithub.com/google/uuidv1.6.0indirecta
Gogithub.com/gordonklaus/ineffassignv0.2.0indirecta
Gogithub.com/gostaticanalysis/analysisutilv0.7.1indirecta
Gogithub.com/gostaticanalysis/commentv1.5.0indirecta
Gogithub.com/gostaticanalysis/forcetypeassertv0.2.0indirecta
Gogithub.com/gostaticanalysis/nilerrv0.1.2indirecta
Gogithub.com/hashicorp/go-immutable-radix/v2v2.1.0indirecta
Gogithub.com/hashicorp/go-versionv1.8.0indirecta
Gogithub.com/hashicorp/golang-lru/v2v2.0.7indirecta
Gogithub.com/hashicorp/hclv1.0.0indirecta
Gogithub.com/hexops/gotextdiffv1.0.3indirecta
Gogithub.com/inconshreveable/mousetrapv1.1.0indirecta
Gogithub.com/jbenet/go-contextv0.0.0-20150711004518-d14ea06fba99indirecta
Gogithub.com/jgautheron/goconstv1.8.2indirecta
Gogithub.com/jingyugao/rowserrcheckv1.1.1indirecta
Gogithub.com/jjti/go-spancheckv0.6.5indirecta
Gogithub.com/julz/importasv0.2.0indirecta
Gogithub.com/karamaru-alpha/copyloopvarv1.2.2indirecta
Gogithub.com/kevinburke/ssh_configv1.5.0indirecta
Gogithub.com/kisielk/errcheckv1.9.0indirecta
Gogithub.com/kkhaike/contextcheckv1.1.6indirecta
Gogithub.com/klauspost/cpuid/v2v2.3.0indirecta
Gogithub.com/kulti/thelperv0.7.1indirecta
Gogithub.com/kunwardeep/paralleltestv1.0.15indirecta
Gogithub.com/lasiar/canonicalheaderv1.1.2indirecta
Gogithub.com/ldez/exptostdv0.4.5indirecta
Gogithub.com/ldez/gomoddirectivesv0.8.0indirecta
Gogithub.com/ldez/grignotinv0.10.1indirecta
Gogithub.com/ldez/structtagsv0.6.1indirecta
Gogithub.com/ldez/tagliatellev0.7.2indirecta
Gogithub.com/ldez/usetestingv0.5.0indirecta
Gogithub.com/leonklingele/grouperv1.1.2indirecta
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0indirecta
Gogithub.com/macabu/inamedparamv0.2.0indirecta
Gogithub.com/magiconair/propertiesv1.8.6indirecta
Gogithub.com/manuelarte/embeddedstructfieldcheckv0.4.0indirecta
Gogithub.com/manuelarte/funcorderv0.5.0indirecta
Gogithub.com/maratori/testableexamplesv1.0.1indirecta
Gogithub.com/maratori/testpackagev1.1.2indirecta
Gogithub.com/masterminds/semver/v3v3.4.0indirecta
Gogithub.com/matoous/godoxv1.1.0indirecta
Gogithub.com/mattn/go-colorablev0.1.14indirecta
Gogithub.com/mattn/go-runewidthv0.0.16indirecta
Gogithub.com/matttproud/golang_protobuf_extensionsv1.0.1indirecta
Gogithub.com/mgechev/revivev1.14.0indirecta
Gogithub.com/microsoft/go-winiov0.6.2indirecta
Gogithub.com/mirrexone/unqueryvetv1.5.3indirecta
Gogithub.com/mitchellh/go-homedirv1.1.0indirecta
Gogithub.com/mitchellh/mapstructurev1.5.0indirecta
Gogithub.com/moricho/tparallelv0.3.2indirecta
Gogithub.com/muesli/termenvv0.16.0indirecta
Gogithub.com/nakabonne/nestifv0.3.1indirecta
Gogithub.com/ncruces/go-strftimev1.0.0indirecta
Gogithub.com/nishanths/exhaustivev0.12.0indirecta
Gogithub.com/nishanths/predeclaredv0.2.2indirecta
Gogithub.com/nunnatsa/ginkgolinterv0.23.0indirecta
Gogithub.com/oapi-codegen/nullablev1.1.0indirecta
Gogithub.com/oapi-codegen/runtimev1.6.0indirecta
Gogithub.com/openpeedeep/depguard/v2v2.2.1indirecta
Gogithub.com/package-url/packageurl-gov0.1.6indirecta
Gogithub.com/pandatix/go-cvssv0.6.2indirecta
Gogithub.com/pelletier/go-tomlv1.9.5indirecta
Gogithub.com/pelletier/go-toml/v2v2.2.4indirecta
Gogithub.com/pjbgf/sha1cdv0.6.0indirecta
Gogithub.com/pmezard/go-difflibv1.0.0indirecta
Gogithub.com/prometheus/client_golangv1.12.1indirecta
Gogithub.com/prometheus/client_modelv0.2.0indirecta
Gogithub.com/prometheus/commonv0.32.1indirecta
Gogithub.com/prometheus/procfsv0.7.3indirecta
Gogithub.com/protonmail/go-cryptov1.3.0indirecta
Gogithub.com/quasilyte/go-ruleguardv0.4.5indirecta
Gogithub.com/quasilyte/go-ruleguard/dslv0.3.23indirecta
Gogithub.com/quasilyte/gogrepv0.5.0indirecta
Gogithub.com/quasilyte/regex/syntaxv0.0.0-20210819130434-b3f0c404a727indirecta
Gogithub.com/quasilyte/stdinfov0.0.0-20220114132959-f7386bf02567indirecta
Gogithub.com/raeperd/recvcheckv0.2.0indirecta
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirecta
Gogithub.com/rivo/unisegv0.4.7indirecta
Gogithub.com/rogpeppe/go-internalv1.14.1indirecta
Gogithub.com/russross/blackfriday/v2v2.1.0indirecta
Gogithub.com/ryancurrah/gomodguardv1.4.1indirecta
Gogithub.com/ryanrolds/sqlclosecheckv0.5.1indirecta
Gogithub.com/sanposhiho/wastedassign/v2v2.1.0indirecta
Gogithub.com/santhosh-tekuri/jsonschema/v6v6.0.2indirecta
Gogithub.com/sashamelentyev/interfacebloatv1.1.0indirecta
Gogithub.com/sashamelentyev/usestdlibvarsv1.29.0indirecta
Gogithub.com/securego/gosec/v2v2.23.0indirecta
Gogithub.com/sergi/go-diffv1.4.0indirecta
Gogithub.com/sirupsen/logrusv1.9.4indirecta
Gogithub.com/sivchari/containedctxv1.0.3indirecta
Gogithub.com/skeema/knownhostsv1.3.2indirecta
Gogithub.com/sonatard/noctxv0.4.0indirecta
Gogithub.com/sourcegraph/go-diffv0.7.0indirecta
Gogithub.com/spf13/aferov1.15.0indirecta
Gogithub.com/spf13/castv1.5.0indirecta
Gogithub.com/spf13/jwalterweathermanv1.1.0indirecta
Gogithub.com/spf13/viperv1.12.0indirecta
Gogithub.com/ssgreg/nlreturn/v2v2.2.1indirecta
Gogithub.com/stbenjam/no-sprintf-host-portv0.3.1indirecta
Gogithub.com/stretchr/objxv0.5.2indirecta
Gogithub.com/stretchr/testifyv1.11.1indirecta
Gogithub.com/subosito/gotenvv1.4.1indirecta
Gogithub.com/tetafro/godotv1.5.4indirecta
Gogithub.com/timakin/bodyclosev0.0.0-20241222091800-1db5c5ca4d67indirecta
Gogithub.com/timonwong/loggercheckv0.11.0indirecta
Gogithub.com/tomarrell/wrapcheck/v2v2.12.0indirecta
Gogithub.com/tommy-muehle/go-mnd/v2v2.5.1indirecta
Gogithub.com/ultraware/funlenv0.2.0indirecta
Gogithub.com/ultraware/whitespacev0.2.0indirecta
Gogithub.com/uudashr/gocognitv1.2.0indirecta
Gogithub.com/uudashr/ifacev1.4.1indirecta
Gogithub.com/xanzy/ssh-agentv0.3.3indirecta
Gogithub.com/xen0n/gosmopolitanv1.3.0indirecta
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41eindirecta
Gogithub.com/yagipy/maintidxv1.0.0indirecta
Gogithub.com/yeya24/promlinterv0.3.0indirecta
Gogithub.com/ykadowak/zerologlintv0.1.5indirecta
Gogitlab.com/bosi/decorderv0.4.2indirecta
Gogo-simpler.org/musttagv0.14.0indirecta
Gogo-simpler.org/sloglintv0.11.1indirecta
Gogo.augendre.info/arangolintv0.4.0indirecta
Gogo.augendre.info/fatcontextv0.9.0indirecta
Gogo.uber.org/multierrv1.10.0indirecta
Gogo.uber.org/zapv1.27.0indirecta
Gogo.yaml.in/yaml/v3v3.0.4indirecta
Gogolang.org/x/cryptov0.53.0indirecta
Gogolang.org/x/exp/typeparamsv0.0.0-20260209203927-2842357ff358indirecta
Gogolang.org/x/modv0.37.0indirecta
Gogolang.org/x/netv0.56.0indirecta
Gogolang.org/x/syncv0.21.0indirecta
Gogolang.org/x/sysv0.46.0indirecta
Gogolang.org/x/textv0.39.0indirecta
Gogolang.org/x/toolsv0.47.0indirecta
Gogoogle.golang.org/protobufv1.36.8indirecta
Gogopkg.in/ini.v1v1.67.0indirecta
Gogopkg.in/warnings.v0v0.1.2indirecta
Gogopkg.in/yaml.v2v2.4.0indirecta
Gohonnef.co/go/toolsv0.7.0indirecta
Gomodernc.org/libcv1.74.3indirecta
Gomodernc.org/mathutilv1.7.1indirecta
Gomodernc.org/memoryv1.11.0indirecta
Gomvdan.cc/gofumptv0.9.2indirecta
Gomvdan.cc/unparamv0.0.0-20251027182757-5beb8c8f8f15indirecta
Avisos de dependencias 1

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 260 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 1 tienen avisos conocidos, de los cuales 0 son directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
golang.org/x/cryptov0.53.0indirectadesconocida1

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "dependencies",
        "git",
        "git-commands",
        "package-management"
      ],
      "is_fork": false,
      "size_kb": 1478,
      "has_wiki": true,
      "homepage": "https://git-pkgs.dev",
      "languages": {
        "Go": 1129565,
        "Shell": 3140
      },
      "pushed_at": "2026-07-31T16:20:56Z",
      "created_at": "2026-01-15T15:41:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-08-01T19:54:48Z",
      "description": " About  A git subcommand for analyzing package/dependency usage in git repositories over time",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://git-pkgs.dev/",
      "name": "git-pkgs",
      "type": "Organization",
      "login": "git-pkgs",
      "company": null,
      "location": null,
      "followers": 42,
      "avatar_url": "https://avatars.githubusercontent.com/u/254671775?v=4",
      "created_at": "2026-01-13T11:51:00Z",
      "is_verified": null,
      "public_repos": 47,
      "account_age_days": 200
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-07-27T11:33:19Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-07-23T11:25:40Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-21T13:40:17Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-29T14:03:55Z"
        },
        {
          "tag": "v0.16.2",
          "kind": "patch",
          "published_at": "2026-05-25T14:25:32Z"
        },
        {
          "tag": "v0.16.1",
          "kind": "patch",
          "published_at": "2026-05-22T19:42:24Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-05-09T12:23:39Z"
        },
        {
          "tag": "v0.15.4",
          "kind": "patch",
          "published_at": "2026-05-02T17:41:05Z"
        },
        {
          "tag": "v0.15.3",
          "kind": "patch",
          "published_at": "2026-04-13T07:57:38Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2026-03-29T19:13:46Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-03-05T18:36:36Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-02-27T10:26:26Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-02-16T11:47:46Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-02-10T11:42:06Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-02-09T11:41:13Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-02-07T12:01:57Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-02-06T13:06:42Z"
        },
        {
          "tag": "v0.11.6",
          "kind": "patch",
          "published_at": "2026-02-05T16:49:23Z"
        },
        {
          "tag": "v0.11.5",
          "kind": "patch",
          "published_at": "2026-02-05T12:28:54Z"
        },
        {
          "tag": "v0.11.4",
          "kind": "patch",
          "published_at": "2026-01-31T21:28:25Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-01-31T07:19:26Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2026-01-30T20:29:04Z"
        },
        {
          "tag": "v0.11.1",
          "kind": "patch",
          "published_at": "2026-01-29T15:08:12Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-01-28T06:43:40Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-01-27T23:14:39Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-01-26T21:24:14Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-01-26T16:03:10Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-01-25T12:30:58Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-01-24T07:27:44Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-01-23T11:37:15Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-01-23T11:12:31Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-01-22T18:13:24Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-01-21T22:52:13Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-01-18T21:49:18Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-01-18T13:50:22Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-01-16T10:02:02Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "08bf43497d7706f8c4e754b551f541d0df12bb37",
          "body": null,
          "is_bot": false,
          "headline": "Fix vulnerability ref resolution (#300)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-31T16:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "277fe1e04a29d52341145fcc03ea5e258c0a0104",
          "body": "* Add --kind flag to diff for filtering by manifest/lockfile\n\nAdds a --kind filter to git-pkgs diff that restricts output to entries\nfrom either manifest files or lockfiles, and exposes manifest_kind on\neach entry in the JSON output.\n\nCloses #298\n\n* Filter --kind before computing diff, accept mixed \n[…]\nle\nrows into one bucket, so the reported manifest_kind is always correct\nand a lockfile-only bump can't be masked by a sibling manifest row.\n\nAlso lowercases the flag value so --kind Lockfile matches.",
          "is_bot": false,
          "headline": "Add --kind flag to diff for filtering by manifest/lockfile (#301)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-31T15:56:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "584bca5eccd6b535a16f88f6b6d790842434cb54",
          "body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.54.0 to 1.55.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.54.0...v1.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n  depende\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump modernc.org/sqlite from 1.54.0 to 1.55.0 (#297)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-31T08:32:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "115e7e6fda572646e2db6bc4a6e1b412f3a44c36",
          "body": "Bumps [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) from 5.9.0 to 5.9.1.\n- [Release notes](https://github.com/go-git/go-billy/releases)\n- [Commits](https://github.com/go-git/go-billy/compare/v5.9.0...v5.9.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-git/go-bil\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-git/go-billy/v5 from 5.9.0 to 5.9.1 (#296)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-31T08:31:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99a2f7a4796fe8fbcacad8324bab5a7509eba542",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 7.0.0 to 7.0.1 (#295)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-30T16:14:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d07a00bace682d7eda71738e172d7a0ad7fb0b3",
          "body": null,
          "is_bot": false,
          "headline": "Bump git-pkgs enrichment, manifests, registries (#293)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-27T11:29:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81417cbe9a37e4acb894d2108ba7505e87f40fb4",
          "body": "…ns/setup-go-7.0.0\n\nBump actions/setup-go from 6.5.0 to 7.0.0",
          "is_bot": false,
          "headline": "Merge pull request #292 from git-pkgs/dependabot/github_actions/actio…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T15:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f7a303a10459301dcd73a1548448db634404290",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356fb5720e22ba16...b7ad1dad31e06c5925ef5d2fc7ad053ef454303e)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/setup-go from 6.5.0 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T12:53:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccd584a00627f1e42febfdbc26b80034bfad754b",
          "body": "Use version metadata in SBOMs",
          "is_bot": false,
          "headline": "Merge pull request #288 from git-pkgs/fix/sbom-version-metadata",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T11:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eba43c66971ea99a9ad864043ce431d10a30dd81",
          "body": "…tion\n\nResolve direct versions for license checks",
          "is_bot": false,
          "headline": "Merge pull request #289 from git-pkgs/fix/license-multiversion-resolu…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T11:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13b9fb3e67c4d17b5e452a0e37f7dcde645cc6e8",
          "body": "Bump dependencies before v0.18.1",
          "is_bot": false,
          "headline": "Merge pull request #291 from git-pkgs/chore/release-dependency-updates",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T10:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "385ee46047776479b39371c6ac1c5f0865c742ea",
          "body": null,
          "is_bot": false,
          "headline": "Bump dependencies before patch release",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T10:46:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e6d56ee8d21b448f7c2a93c2281907e1d726104",
          "body": "Handle withdrawn versions in dependency checks",
          "is_bot": false,
          "headline": "Merge pull request #290 from git-pkgs/fix/yanked-retracted-versions",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T10:39:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "635285a140d8d3f80f02ef51b4794356be834d15",
          "body": null,
          "is_bot": false,
          "headline": "Handle withdrawn package versions",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-23T10:30:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fea374589b21d5f43e40025664bcf629ca15a70",
          "body": null,
          "is_bot": false,
          "headline": "Resolve direct versions for license checks",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-22T19:28:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "284c1034dfe55f9521794f7835fc38b63a946ccd",
          "body": null,
          "is_bot": false,
          "headline": "Keep SBOM components without PURLs",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-22T19:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d600d5d527d742172f0f9eefadc5319459b0b72",
          "body": null,
          "is_bot": false,
          "headline": "Use version metadata in SBOMs",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-22T19:03:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88dbdb14fe04ec04c7072499cca88dc9bdece184",
          "body": "* Use installed version licenses for policies\n\n* Warn when version license lookup fails",
          "is_bot": false,
          "headline": "Use installed version licenses for policies (#284)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-22T18:37:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36745b49d99fa18264579d6caa3e8f0bccfd8104",
          "body": "github.com/git-pkgs/enrichment  v0.5.0  -> v0.6.1\ngithub.com/git-pkgs/purl        v0.1.14 -> v0.1.15\ngithub.com/git-pkgs/vers        v0.2.6  -> v0.3.0\ngithub.com/git-pkgs/vulns       v0.1.6  -> v0.2.1\ngithub.com/mattn/go-isatty      v0.0.22 -> v0.0.23\nmodernc.org/sqlite              v1.53.0 -> v1.54.0",
          "is_bot": false,
          "headline": "Bump dependencies before release (#282)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-21T13:34:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f0effae7474c135ce9bd782c53f5d1efedb4f5e",
          "body": "* Add provenance metadata command\n\n* fix provenance unsupported status output\n\n* fix: use registry provenance APIs\n\n* fix: distinguish npm attestations\n\n* fix: filter attested provenance results",
          "is_bot": false,
          "headline": "Add provenance metadata command (#244)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-20T13:31:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a373dafbdeeb5feaadcf16fb33557891f909db6",
          "body": "* feat: support configured ecosystem filters\n\n* fix ecosystem config filtering in db query paths\n\n* fix ignored ecosystem init test\n\n* fix ecosystem filter follow-ups\n\n* fix: filter historical queries by ecosystem config\n\n* fix: filter bisect culprit changes\n\n* fix: expand ecosystem aliases for SQL filters",
          "is_bot": false,
          "headline": "Add configurable ecosystem allow/deny filters (#262)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-20T13:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53acfbffb019353cd3fdf79da6aad768b2f8d1db",
          "body": "* fix: handle unsupported OSV ecosystems\n\n* fix: align OSV ecosystem queries\n\n* fix: preserve Maven OSV package names",
          "is_bot": false,
          "headline": "fix: handle unsupported OSV ecosystems (#277)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-20T11:34:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83783ae2dafabc6b2bb93973cc57076e512b5076",
          "body": "Bumps [github.com/git-pkgs/sbom](https://github.com/git-pkgs/sbom) from 0.1.2 to 0.1.3.\n- [Commits](https://github.com/git-pkgs/sbom/compare/v0.1.2...v0.1.3)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/sbom\n  dependency-version: 0.1.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/sbom from 0.1.2 to 0.1.3 (#280)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T13:46:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72a8b842ba0885ef2d9c1fe3316949a892f83f95",
          "body": "Bumps [github.com/git-pkgs/enrichment](https://github.com/git-pkgs/enrichment) from 0.4.1 to 0.5.0.\n- [Commits](https://github.com/git-pkgs/enrichment/compare/v0.4.1...v0.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/enrichment\n  dependency-version: 0.5.0\n  dependency-type: \n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/enrichment from 0.4.1 to 0.5.0 (#278)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T13:45:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a970a7a24804de1d9164dba8650069c32576659c",
          "body": "Bumps [github.com/git-pkgs/purl](https://github.com/git-pkgs/purl) from 0.1.13 to 0.1.14.\n- [Commits](https://github.com/git-pkgs/purl/compare/v0.1.13...v0.1.14)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/purl\n  dependency-version: 0.1.14\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/purl from 0.1.13 to 0.1.14 (#279)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T13:45:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b14403c6817380cb9ad2e9c8d2149271eea78ff",
          "body": "* feat: cache registry integrity lookups\n\n# Conflicts:\n#\tdocs/internals.md\n#\tinternal/database/queries.go\n\n* fix: preserve partial version metadata\n\n* fix: separate version cache freshness\n\n# Conflicts:\n#\tdocs/internals.md\n#\tinternal/database/queries.go",
          "is_bot": false,
          "headline": "feat: cache registry integrity lookups (#274)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-15T12:40:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eba05e37a6637f5f8fbd8a1bb9235cbd93d48520",
          "body": "* feat: support offline license metadata cache\n\n* test: isolate license cache database path\n\n* fix: handle incomplete offline cache entries",
          "is_bot": false,
          "headline": "Add offline license metadata caching support (#273)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-13T22:34:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea95e7fff26ee829026e883f97aa58d2556e20df",
          "body": "* Use SARIF module for vulns output\n\n* Use SARIF constructors for schema defaults\n\n* Address review feedback\n\n- Use build version for SARIF tool.driver.version instead of hardcoded 1.0.0\n- Build run/driver locally and assign to report.Runs at the end\n- Fix inverted test failure messages for constructor default checks\n- go mod tidy to drop stale sarif v0.1.0 sum entries",
          "is_bot": false,
          "headline": "Use SARIF module for vulns output (#271)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-07-13T22:08:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "193c850d87052dfce6bcfb3f64acf6c21a86324a",
          "body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.54.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.54.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n  dependency-version: 0.55.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump golang.org/x/net from 0.54.0 to 0.55.0 (#270)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T15:17:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7193a0fbe55ba4260f98b914352216259f02454d",
          "body": "Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.51.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n  dependency-version: 0.52.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#269)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T15:06:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31a7a86169177877442b8de94a69b9368edf8f7a",
          "body": "Bumps [github.com/git-pkgs/manifests](https://github.com/git-pkgs/manifests) from 0.5.1 to 0.6.0.\n- [Commits](https://github.com/git-pkgs/manifests/compare/v0.5.1...v0.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/manifests\n  dependency-version: 0.6.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/manifests from 0.5.1 to 0.6.0 (#267)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T14:53:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6805bef1b365cb006261ac1a72a61f7b8451379c",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89...f06c13\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#268)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T13:15:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "400dca35cc14ad285f9931fe8b827e82a61363f7",
          "body": "Bumps [github.com/git-pkgs/managers](https://github.com/git-pkgs/managers) from 0.10.0 to 0.10.1.\n- [Commits](https://github.com/git-pkgs/managers/compare/v0.10.0...v0.10.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/managers\n  dependency-version: 0.10.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/managers from 0.10.0 to 0.10.1 (#266)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T13:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c77a83b938960e2a4f5f3d12571878009cd28fab",
          "body": "* fix schema sql index output\n\n* fix schema index row error handling",
          "is_bot": false,
          "headline": "Fix schema SQL index output (#265)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-07-08T12:14:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b0b698b69a0817af3bfe5006ec75330b68b4d55",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/setup-go from 6.4.0 to 6.5.0 (#264)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-02T15:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a30ca52d22625c54937d412e73305fb20ae6c71c",
          "body": "* fix: reject unsupported output formats\n\n* fix: clean up format validation\n\n---------\n\nCo-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: reject unsupported output formats (#251)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-07-01T16:13:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80b4b46c22859321ac22d893ead6f854e3be9506",
          "body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: preserve json output for empty results (#257)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-07-01T16:05:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ad00120421d6f3359110b0ba5367cb9a4519019",
          "body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: preserve where context line numbers (#263)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-07-01T16:00:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1072fd6dc6c566b86167d518f224f86c455c7262",
          "body": "* Add replace command for dependency redirects\n\n* refactor replace command to use managers library",
          "is_bot": false,
          "headline": "Add replace command for dependency redirects (#236)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-30T18:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcad319db70e86241f365873b1bf7eb0da4b10e4",
          "body": null,
          "is_bot": false,
          "headline": "Bump git-pkgs and third-party dependencies (#255)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-29T13:48:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4df5ba17f129c9baaaa477d0259da173ee49db1",
          "body": null,
          "is_bot": false,
          "headline": "docs: explain bare column usage in first_added CTE (#253)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-29T09:29:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd00b9ae2882972d1ecc3039f531ce0a941d1f3a",
          "body": "* fix: preserve json output for empty results\n\n* fix: cover remaining empty json outputs\n\n---------\n\nCo-authored-by: sanmaxdev <144138089+sanmaxdev@users.noreply.github.com>\nCo-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: preserve json output for empty results (#248)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-06-29T08:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b0e5272996d83ff4ddcd26c524535872b6406da",
          "body": null,
          "is_bot": false,
          "headline": "refactor: optimize first_added sqlite query (#252)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-28T17:39:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff56085cef274413a3366fea265d71cbddbd819a",
          "body": "* fix: group SearchDependencies CTEs by ecosystem\n\n* test: add regression tests for #241; fix added_in to use earliest commit SHA",
          "is_bot": false,
          "headline": "fix: group SearchDependencies CTEs by ecosystem (#250)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-28T10:36:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "552e9061c258ef0f5b032115c7b0a5e91cbb5ba4",
          "body": "Bump enrichment to v0.4.0 (which brings ecosystems-go v0.2.0) and route\nall enrichment client construction through a single helper that applies\nGIT_PKGS_ECOSYSTEMS_FROM, GIT_PKGS_ECOSYSTEMS_API_KEY and\nGIT_PKGS_ECOSYSTEMS_BATCH_SIZE. BulkLookup failures now include a hint\npointing at those variables when no identity is configured.\n\nFixes #231",
          "is_bot": false,
          "headline": "Add ecosyste.ms identity options and friendlier lookup errors (#245)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-28T06:55:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04f5ad05ffafef512bd7ee06e0dc5f0b3f5e2035",
          "body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: avoid partial package matches in where (#246)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-06-28T06:37:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76063f70c0a5522cbbc54bc2c5de053dec0ce18a",
          "body": "Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: include all schema tables in info counts (#247)",
          "author_name": "Sangeeth Thilakarathna",
          "author_login": "sanmaxdev",
          "committed_at": "2026-06-28T06:33:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f21cd00f627ad02e9d4b4ab088aca3e5d683bf9f",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 6.0.3 to 7.0.0 (#249)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-25T13:05:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea8f727740d34d2e3efa960d64a26f38528e58e1",
          "body": "…#240)",
          "is_bot": false,
          "headline": "Fix urls command using version ranges and wrong name from db lookup (…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-21T17:12:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "693e53e0d2f73fa0d9cbdeb1c0536fd0814c5bdb",
          "body": null,
          "is_bot": false,
          "headline": "Add JSON help output (#237)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-21T17:11:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "633d3022d2ab01e8695547bfd691b11fae76a3f3",
          "body": null,
          "is_bot": false,
          "headline": "Recover from panics in library goroutines (#235)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-21T17:07:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2429ac352f44ceb4af9354ccfa7c70b1d5bc47b0",
          "body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.51.0 to 1.52.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.51.0...v1.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n  depende\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump modernc.org/sqlite from 1.51.0 to 1.52.0 (#238)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-19T07:50:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1282e92200a839c1c2d8e91a3dba2de7f7b928f3",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 6.0.2 to 6.0.3 (#232)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-11T14:03:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88af619bd0ea554316313014200014af08d36d05",
          "body": null,
          "is_bot": false,
          "headline": "Add ecosystem matching mode for dependency diff (#230)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-08T08:48:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "faaab47a137400dec04e2bf8b9c465b05a7dc873",
          "body": null,
          "is_bot": false,
          "headline": "Add notes import command (#229)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-08T08:41:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c98db00eeeea8200372b2b249293a6dda87db441",
          "body": null,
          "is_bot": false,
          "headline": "Add maintenance health scores (#221)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-08T08:41:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76bb7b1dbae4c36b3a366d24c1644c31f4e07289",
          "body": null,
          "is_bot": false,
          "headline": "Add license drift detection (#220)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-06T09:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c511c783d114e0ad0d60d8419b0fd2b3e954691",
          "body": null,
          "is_bot": false,
          "headline": "Treat Maven manifest versions as resolved (#226)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-05T14:22:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9549f0c37f06ca30e2b1c1e76541c4a8c6c0cf7a",
          "body": "* Add dependency maintainer data\n\n* Preserve maintainer entries per dependency\n\n* Cache maintainer data\n\n* Adjust maintainer lookup timeout\n\n* Use enrichment bulk lookup for maintainers",
          "is_bot": false,
          "headline": "Add dependency maintainer data command (#215)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-05T14:03:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb317b49036f24f18c9e2080c4893446df7ddde3",
          "body": "Bumps [github.com/git-pkgs/manifests](https://github.com/git-pkgs/manifests) from 0.4.3 to 0.5.0.\n- [Commits](https://github.com/git-pkgs/manifests/compare/v0.4.3...v0.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/manifests\n  dependency-version: 0.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/manifests from 0.4.3 to 0.5.0 (#227)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-05T08:38:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "660616307f02ee0ccc98b9435764466927456e89",
          "body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.50.1 to 1.51.0.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.50.1...v1.51.0)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n  depende\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump modernc.org/sqlite from 1.50.1 to 1.51.0 (#228)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-05T08:38:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7174987be4e9f81de20d6068b4e4c0df536b27b7",
          "body": "Replaces 17 inline \"git-pkgs/\" + version concatenations with a single\npackage-level userAgent variable populated in init() once version has\nresolved. New callers reach for cmd.userAgent instead of reconstructing\nthe string, keeping the UA format in one place.",
          "is_bot": false,
          "headline": "Centralize user agent string in cmd.userAgent (#225)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-03T11:30:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36a60722d935a6d8b5da27e73ae1efb2e42150d4",
          "body": "Two call sites in cmd/urls.go and cmd/deprecated.go passed a nil client\nto the registries package, falling back to the library default User-Agent\nof \"registries\". Pass a client configured with the same\n\"git-pkgs/<version>\" UA used by every other outbound call.",
          "is_bot": false,
          "headline": "Set git-pkgs user agent on registries calls (#224)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-06-03T11:06:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d116b5f686d1423cd3a387900247bc8a0b4510fc",
          "body": "* Add exclude bots filtering\n\n* Fix exclude-bots diff replay matching\n\n* Drop exclude-bots support from diff\n\n* Remove unused bot author helper",
          "is_bot": false,
          "headline": "Add --exclude-bots filtering (#211)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-02T06:42:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a7da0007ce54e56e657a89f2cc381e5ca8547e8",
          "body": "* Add dependency funding info\n\n* Clarify unresolved funding metadata output\n\n* Cache funding package metadata\n\n* Adjust funding timeout and schema version\n\n* Use enrichment funding links",
          "is_bot": false,
          "headline": "Add dependency funding info command (#214)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-06-02T06:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4f93b15b40f0c4c244946750152b85116a88138",
          "body": "* Add deprecated dependency warnings\n\n* Address deprecated command review feedback\n\n* Cache deprecated version metadata\n\n* Adjust deprecated registry lookup timeout",
          "is_bot": false,
          "headline": "Add deprecated dependency warnings (#213)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-05-31T07:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49bdd97788bf596a3a0e93615bb54961eacb1f9c",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.1 to 7.2.2.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8...5daf1e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 (#219)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-28T14:40:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9235b4ee67a477800e0392fc8601c06468c0686",
          "body": "* Add dependency freshness metrics\n\n* Report freshness metadata lookup failures\n\n* Fix freshness timeout and empty JSON output",
          "is_bot": false,
          "headline": "Add dependency freshness metrics (#212)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-05-28T14:04:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "564e354df041e29295703bedff90d272f3e9ee96",
          "body": null,
          "is_bot": false,
          "headline": "Add diff summary stat mode (#216)",
          "author_name": "Abhinav Gautam",
          "author_login": "abhinavgautam01",
          "committed_at": "2026-05-28T13:36:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2abff90627586d87c83c8a1867419500c6b5c691",
          "body": "PR #166 added scope to each output line but the sort comparator still\nonly considered name and version. When a lockfile lists the same\npackage and version under more than one scope (e.g. Pipfile.lock\ndefault + develop), those entries compared equal and sort.Slice ordered\nthem however the parser emitted them, producing spurious diff hunks.\n\nFixes #217",
          "is_bot": false,
          "headline": "Sort diff-driver output by scope as final tiebreaker (#218)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-28T13:36:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef45ca2ce7a511eddc2b4b0f19a5a79ca7cdf5b7",
          "body": "* fix(list): emit [] instead of null for empty JSON list results\n\nWhen GetDependenciesWithDB returns a nil slice, json.Encode emits `null`.\nDownstream consumers expecting a JSON array fail schema validation.\nCoalesce to empty slice before encoding.\n\nFixes #207.\n\n* test: add unit test for outputListJSON nil-to-[] conversion",
          "is_bot": false,
          "headline": "fix(list): emit [] instead of null for empty JSON list results (#208)",
          "author_name": "Karry",
          "author_login": "Karry2019web",
          "committed_at": "2026-05-27T06:21:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8117f7985914ad767ff26909268918db1acf5abb",
          "body": "The post-commit hook fired once per commit during a rebase, so a\n100-commit rebase ran reindex 100 times. The hook now bails when\n$GIT_DIR/rebase-merge or rebase-apply exists, and a new post-rewrite\nhook reindexes once when the rebase finishes ($1 = rebase, so\nper-commit amend calls inside the rebase are ignored).\n\nHooks installed by older versions are detected by their #!/bin/sh\nheader and overwritten on the next `hooks --install` or `init`.\n\nFixes #209",
          "is_bot": false,
          "headline": "Skip reindex during rebase and add post-rewrite hook (#210)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-27T06:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79854c47522a2a2be8c0c5e7a10e554deb87e1fd",
          "body": "* feat: minimize progress updates to a single line\n\nInstead of printing every line, if we have a TTY, replace it instead.\n\nSigned-off-by: Mike Fiedler <miketheman@gmail.com>\n\n* Extract progress reporting into internal/progress package\n\nWraps the io.Writer in a Reporter that detects whether it is a t\n[…]\ntection now inspects the actual output writer\nrather than always checking os.Stdout.\n\n---------\n\nSigned-off-by: Mike Fiedler <miketheman@gmail.com>\nCo-authored-by: Andrew Nesbitt <andrewnez@gmail.com>",
          "is_bot": false,
          "headline": "Minimize indexer progress updates to a single line on a TTY",
          "author_name": "Mike Fiedler",
          "author_login": "miketheman",
          "committed_at": "2026-05-25T14:18:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6bfec65fd8b191edc36768fcee78fe4143b101f",
          "body": null,
          "is_bot": false,
          "headline": "Bump github.com/go-git/go-git/v5 to v5.19.1 (#206)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-25T13:34:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a49b6b5f57a150f093d964dc5cdb27409414478",
          "body": null,
          "is_bot": false,
          "headline": "Bump github.com/git-pkgs/managers to v0.9.0 (#205)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-25T13:34:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c92f2c1f04992c0f9ebad3bb046d8d1e1843829f",
          "body": null,
          "is_bot": false,
          "headline": "Bump git-pkgs deps for v0.16.1 (#204)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-22T18:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dcb58e54d1ee85e7f9183978443d7cb46b19321",
          "body": "Path exclusions only filter where goconst issues are reported, not which files contribute to the occurrence count, so a string used once in production code and twice in tests still gets flagged. The `ignore-tests` setting makes goconst skip test files entirely.",
          "is_bot": false,
          "headline": "Set goconst to ignore test files (#203)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-22T11:18:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ac11fe2bb705ce0e20d00ee8b10bdcca176746e",
          "body": "Bumps [github.com/git-pkgs/sbom](https://github.com/git-pkgs/sbom) from 0.1.1 to 0.1.2.\n- [Commits](https://github.com/git-pkgs/sbom/compare/v0.1.1...v0.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/sbom\n  dependency-version: 0.1.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/sbom from 0.1.1 to 0.1.2 (#202)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-22T03:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3104e84fa6ece62757bca63c1564eb74ef2783d8",
          "body": "Bumps [github.com/git-pkgs/vers](https://github.com/git-pkgs/vers) from 0.2.5 to 0.2.6.\n- [Commits](https://github.com/git-pkgs/vers/compare/v0.2.5...v0.2.6)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/git-pkgs/vers\n  dependency-version: 0.2.6\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/git-pkgs/vers from 0.2.5 to 0.2.6 (#201)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-22T03:02:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bb2c77bbc6d83dd1fa1d3358c89cf1c3aba4a51",
          "body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.50.0 to 1.50.1.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.50.0...v1.50.1)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n  depende\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump modernc.org/sqlite from 1.50.0 to 1.50.1 (#200)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-22T03:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "64927d154bf1cdab96150767cd2b0b519c22d5d6",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003...6f9f17788090df1f26\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#199)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-15T13:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33f5ba586d1f767bff27ef291aa727d8e225d839",
          "body": "Version.Integrity is now populated for pub, julia and nuget, so the\nintegrity command can verify lockfile hashes for those ecosystems\nwhere it previously had nothing to compare against.",
          "is_bot": false,
          "headline": "Bump git-pkgs/registries to v0.6.0 (#198)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-13T05:44:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85f49073e99bce1087786b24c279c0db29b93bf9",
          "body": null,
          "is_bot": false,
          "headline": "Bump go-git to v5.19.0 and go-billy to v5.9.0 (#197)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T12:11:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0edfa260d7d8a75b0755b957af67251e118597c0",
          "body": null,
          "is_bot": false,
          "headline": "Update diff-driver README example to include scope",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T11:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2731ebf2dd867ce80e59d85aabc7a77124a9f7c",
          "body": "The diff driver now outputs scope (dev, runtime, optional) alongside\nname and version so scope changes are visible in git diff. The analyzer\ntracks PreviousDependencyType on scope-only changes, and show displays\nthem as \"package 1.0.0 (dev -> runtime)\" instead of the misleading\n\"package 1.0.0 -> 1.0.0\".\n\nBumps schema to v9 with a previous_dependency_type column.\n\nRelated to #164",
          "is_bot": false,
          "headline": "Include dependency type in diff driver and show output (#166)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T11:45:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "970917fb1802072c08c7da7fef947728593de33a",
          "body": "go-git's ResolveRevision does not implement reflog (@{n}), :/regex,\ndate refs, and can fail on hashes in some storage layouts. Shell out\nto git rev-parse --verify as a fallback so show/tree/bisect/branch\naccept the full gitrevisions(7) grammar.\n\nReported in #166.",
          "is_bot": false,
          "headline": "Fall back to git rev-parse when go-git cannot resolve a revision (#193)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T11:45:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cfaa99d59b02e3d098786cc7da9dcce3136e868",
          "body": "* Enable commondir resolution so go-git can read refs and objects from linked worktrees\n\n* Build commondir wrapping ourselves to avoid go-git v5 fd leak on Windows",
          "is_bot": false,
          "headline": "Read refs and objects from linked worktrees (#196)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T11:44:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08425d366ef58b39bb64a683fe8850ba5a8b8d28",
          "body": "go-git's PlainOpen chroots its billy filesystem to .git, so absolute\npaths in objects/info/alternates can't be followed and borrowed\nobjects are invisible. Repos created with clone --shared or\n--reference would fail to resolve any SHA in the borrowed history\nwith \"reference not found\".\n\nReopen the storage with AlternatesFS rooted at the volume root so\ngo-git can follow alternates. PlainOpenOptions doesn't expose this\nso the storage has to be rebuilt by hand after discovery.\n\nReported in #166.",
          "is_bot": false,
          "headline": "Read alternate object stores when opening a repository (#194)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-09T10:44:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f187c2f46794915363795abe0dd1e6dd77c184d2",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.1.0 to 7.2.1.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/e24998b8b67b290c2fa8b7c14fcfa7de2c5c9b8c...1a8083\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#191)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T13:10:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5843fd4db2959d3a848b02986dc517c809123d2",
          "body": "Bumps [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) from 0.0.21 to 0.0.22.\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.21...v0.0.22)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/mattn/go-isatty\n  dependency-version: 0.0.22\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 (#192)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T13:06:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3eb8925554c436b89946f413e24a1f80edce864f",
          "body": null,
          "is_bot": false,
          "headline": "Bump git-pkgs deps to latest patch releases",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-02T17:28:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a969d90226c970f4fcc9e3b2164694a143b405c8",
          "body": "…utput (#189)\n\nChangelog text fetched from upstream repos, OSV summary/details fields,\nparsed dependency names from lockfiles, and git commit metadata all\nreach the terminal with C0 control bytes intact, allowing ANSI/OSC\nsequence injection (cursor movement, screen clearing, OSC 8 hyperlinks,\nclipboard writes on terminals that honour OSC 52).\n\nAdds a Sanitize helper in cmd/output.go that strips control characters\nother than tab and newline, applied at each cited output site.",
          "is_bot": false,
          "headline": "Strip control characters from externally sourced strings before TTY o…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-02T17:27:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b1a2167272a2eee907638767abad23281ba38d5",
          "body": "searchFileForPackage used os.Open with an absolute path, which follows\nsymlinks. A symlink named like a manifest file could point outside the\nrepository and leak file contents. Uses os.Root scoped to the working\ndirectory so the kernel rejects any path that resolves outside the repo.",
          "is_bot": false,
          "headline": "Prevent where command from following symlinks out of repo (#188)",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-05-02T17:27:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2280f740eb66fb06c5502bb6e8ccbf45880eb31a",
          "body": "…easer/goreleaser-action-7.1.0\n\nBump goreleaser/goreleaser-action from 7.0.0 to 7.1.0",
          "is_bot": false,
          "headline": "Merge pull request #184 from git-pkgs/dependabot/github_actions/gorel…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-04-30T16:54:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9218bf47ace1b1b7b58a3fa977e7b0ce382f35c7",
          "body": "…m/go-git/go-git/v5-5.18.0\n\nBump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0",
          "is_bot": false,
          "headline": "Merge pull request #185 from git-pkgs/dependabot/go_modules/github.co…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-04-30T16:53:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1830953d9d901e7d2b26f6132ec5786c00388d8d",
          "body": "…rg/sqlite-1.49.1\n\nBump modernc.org/sqlite from 1.48.2 to 1.49.1",
          "is_bot": false,
          "headline": "Merge pull request #186 from git-pkgs/dependabot/go_modules/modernc.o…",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-04-30T16:53:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc24f9d24536000e236838f3e50a4f42dc3d7bcc",
          "body": "Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.48.2 to 1.49.1.\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.48.2...v1.49.1)\n\n---\nupdated-dependencies:\n- dependency-name: modernc.org/sqlite\n  dependency-version: 1.49.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump modernc.org/sqlite from 1.48.2 to 1.49.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-30T12:57:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85b954d74adaf8d1592d58cac48b4aadc96fba9d",
          "body": "Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.2 to 5.18.0.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.17.2...v5.18.0)\n\n---\n\n[…]\n-name: github.com/go-git/go-git/v5\n  dependency-version: 5.18.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-30T12:57:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46904086328428d5285726777f26ed6273c2776a",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.0.0 to 7.1.0.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...e24998\n[…]\n-name: goreleaser/goreleaser-action\n  dependency-version: 7.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump goreleaser/goreleaser-action from 7.0.0 to 7.1.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-30T12:56:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46aaf1e63899915b6f81cd9d4eb0c3f66d3ee658",
          "body": "sbom: emit via github.com/git-pkgs/sbom",
          "is_bot": false,
          "headline": "Merge pull request #183 from git-pkgs/sbom-module",
          "author_name": "Andrew Nesbitt",
          "author_login": "andrew",
          "committed_at": "2026-04-28T14:12:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 36,
      "commits_last_year": 392,
      "latest_release_at": "2026-07-27T11:33:19Z",
      "latest_release_tag": "v0.18.2",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 28,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 13.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/git-pkgs/git-pkgs",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/git-pkgs/git-pkgs",
          "is_deprecated": false,
          "latest_version": "v0.18.2",
          "repository_url": "https://github.com/git-pkgs/git-pkgs",
          "versions_count": 36,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T11:29:29Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 10,
      "stars": 177,
      "watchers": 4,
      "fork_history": {
        "days": [
          {
            "date": "2026-01-18",
            "count": 1
          },
          {
            "date": "2026-01-24",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-01-31",
            "count": 1
          },
          {
            "date": "2026-02-05",
            "count": 1
          },
          {
            "date": "2026-02-24",
            "count": 1
          },
          {
            "date": "2026-03-03",
            "count": 1
          },
          {
            "date": "2026-05-26",
            "count": 1
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-06-24",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 10,
        "total_forks": 10
      },
      "star_history": null,
      "open_issues_and_prs": 9
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 85124,
      "source_files_sampled": 136,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 25
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 260,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/git-pkgs/changelog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.3"
        },
        {
          "name": "github.com/git-pkgs/enrichment",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.4"
        },
        {
          "name": "github.com/git-pkgs/gitignore",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/git-pkgs/managers",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.10.1"
        },
        {
          "name": "github.com/git-pkgs/manifests",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.1"
        },
        {
          "name": "github.com/git-pkgs/purl",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.15"
        },
        {
          "name": "github.com/git-pkgs/registries",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.4"
        },
        {
          "name": "github.com/git-pkgs/resolve",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.2"
        },
        {
          "name": "github.com/git-pkgs/sarif",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.1"
        },
        {
          "name": "github.com/git-pkgs/sbom",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.3"
        },
        {
          "name": "github.com/git-pkgs/spdx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/git-pkgs/vers",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "github.com/git-pkgs/vulns",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.1"
        },
        {
          "name": "github.com/go-git/go-billy/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.1"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.19.1"
        },
        {
          "name": "github.com/mattn/go-isatty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.23"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.10"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.55.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/git-pkgs/changelog",
            "direct": true,
            "version": "v0.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/enrichment",
            "direct": true,
            "version": "v0.6.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/gitignore",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/managers",
            "direct": true,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/manifests",
            "direct": true,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/purl",
            "direct": true,
            "version": "v0.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/registries",
            "direct": true,
            "version": "v0.6.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/resolve",
            "direct": true,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/sarif",
            "direct": true,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/sbom",
            "direct": true,
            "version": "v0.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/spdx",
            "direct": true,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/vers",
            "direct": true,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/vulns",
            "direct": true,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-billy/v5",
            "direct": true,
            "version": "v5.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-git/v5",
            "direct": true,
            "version": "v5.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": true,
            "version": "v0.0.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": true,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.55.0",
            "ecosystem": "go"
          },
          {
            "name": "4d63.com/gocheckcompilerdirectives",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "4d63.com/gochecknoglobals",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "codeberg.org/chavacava/garif",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "codeberg.org/polyfloyd/go-errorlint",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "dev.gaijin.team/go/exhaustruct/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "dev.gaijin.team/go/golib",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/4meepo/tagalign",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/abirdcfly/dupword",
            "direct": false,
            "version": "v0.1.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/adminbenni/iota-mixing",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecthomas/chroma/v2",
            "direct": false,
            "version": "v2.23.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecthomas/go-check-sumtype",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alexkohler/nakedret/v2",
            "direct": false,
            "version": "v2.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alexkohler/prealloc",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alfatraining/structtag",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alingse/asasalint",
            "direct": false,
            "version": "v0.0.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alingse/nilnesserr",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alwxsin/noinlineerr",
            "direct": false,
            "version": "v1.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antonboom/errname",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antonboom/nilnil",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antonboom/testifylint",
            "direct": false,
            "version": "v1.6.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apapsch/go-jsonmerge/v2",
            "direct": false,
            "version": "v2.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ashanbrown/forbidigo/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ashanbrown/makezero/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bazelbuild/buildtools",
            "direct": false,
            "version": "v0.0.0-20260716142318-04cf7de1434f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bkielbasa/cyclop",
            "direct": false,
            "version": "v1.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blizzy78/varnamelen",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bombsimon/wsl/v4",
            "direct": false,
            "version": "v4.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bombsimon/wsl/v5",
            "direct": false,
            "version": "v5.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/breml/bidichk",
            "direct": false,
            "version": "v0.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/breml/errchkjson",
            "direct": false,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/butuzov/ireturn",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/butuzov/mirror",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/catenacyber/perfsprint",
            "direct": false,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ccojocar/zxcvbn-go",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charithe/durationcheck",
            "direct": false,
            "version": "v0.0.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.2.3-0.20250311203215-f60798e515dc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13-0.20250311204145-2c3ea96c31dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ckaznocha/intrange",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.6.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cpuguy83/go-md2man/v2",
            "direct": false,
            "version": "v2.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/curioswitch/go-reassign",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cyphar/filepath-securejoin",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/daixiang0/gci",
            "direct": false,
            "version": "v0.13.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dave/dst",
            "direct": false,
            "version": "v0.27.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/denis-tingaikin/go-header",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/djarvur/go-err113",
            "direct": false,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2",
            "direct": false,
            "version": "v1.11.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ecosyste-ms/ecosystems-go",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emirpasic/gods",
            "direct": false,
            "version": "v1.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ettle/strcase",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/color",
            "direct": false,
            "version": "v1.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/structtag",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/firefart/nonamedreturns",
            "direct": false,
            "version": "v1.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": false,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fzipp/gocyclo",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ghostiam/protogetter",
            "direct": false,
            "version": "v0.3.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/packageurl-go",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/git-pkgs/pom",
            "direct": false,
            "version": "v0.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/github/go-spdx/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-critic/go-critic",
            "direct": false,
            "version": "v0.14.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/gcfg",
            "direct": false,
            "version": "v1.5.1-0.20230307220236-3a3c6141e376",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/astcast",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/astcopy",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/astequal",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/astfmt",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/astp",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/strparse",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-toolsmith/typep",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-xmlfmt/xmlfmt",
            "direct": false,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": false,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/godoc-lint/godoc-lint",
            "direct": false,
            "version": "v0.11.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gofrs/flock",
            "direct": false,
            "version": "v0.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/groupcache",
            "direct": false,
            "version": "v0.0.0-20241129210726-2c02b8208cf8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/protobuf",
            "direct": false,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/asciicheck",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/dupl",
            "direct": false,
            "version": "v0.0.0-20250308024227-f665c8d69b32",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/go-printf-func-name",
            "direct": false,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/gofmt",
            "direct": false,
            "version": "v0.0.0-20250106114630-d62b90e6713d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/golangci-lint/v2",
            "direct": false,
            "version": "v2.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/golines",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/misspell",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/plugin-module-register",
            "direct": false,
            "version": "v0.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/revgrep",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/swaggoswag",
            "direct": false,
            "version": "v0.0.0-20250504205917-77f2aca3143e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golangci/unconvert",
            "direct": false,
            "version": "v0.0.0-20250410112200-a129a6e6413e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gordonklaus/ineffassign",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gostaticanalysis/analysisutil",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gostaticanalysis/comment",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gostaticanalysis/forcetypeassert",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gostaticanalysis/nilerr",
            "direct": false,
            "version": "v0.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-immutable-radix/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-version",
            "direct": false,
            "version": "v1.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru/v2",
            "direct": false,
            "version": "v2.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/hcl",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hexops/gotextdiff",
            "direct": false,
            "version": "v1.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jbenet/go-context",
            "direct": false,
            "version": "v0.0.0-20150711004518-d14ea06fba99",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jgautheron/goconst",
            "direct": false,
            "version": "v1.8.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jingyugao/rowserrcheck",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jjti/go-spancheck",
            "direct": false,
            "version": "v0.6.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/julz/importas",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/karamaru-alpha/copyloopvar",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kevinburke/ssh_config",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kisielk/errcheck",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kkhaike/contextcheck",
            "direct": false,
            "version": "v1.1.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/cpuid/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kulti/thelper",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kunwardeep/paralleltest",
            "direct": false,
            "version": "v1.0.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lasiar/canonicalheader",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/exptostd",
            "direct": false,
            "version": "v0.4.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/gomoddirectives",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/grignotin",
            "direct": false,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/structtags",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/tagliatelle",
            "direct": false,
            "version": "v0.7.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ldez/usetesting",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/leonklingele/grouper",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/macabu/inamedparam",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.8.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/manuelarte/embeddedstructfieldcheck",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/manuelarte/funcorder",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/maratori/testableexamples",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/maratori/testpackage",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/semver/v3",
            "direct": false,
            "version": "v3.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/matoous/godox",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": false,
            "version": "v0.1.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/matttproud/golang_protobuf_extensions",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgechev/revive",
            "direct": false,
            "version": "v1.14.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mirrexone/unqueryvet",
            "direct": false,
            "version": "v1.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-homedir",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moricho/tparallel",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nakabonne/nestif",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nishanths/exhaustive",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nishanths/predeclared",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nunnatsa/ginkgolinter",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oapi-codegen/nullable",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oapi-codegen/runtime",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openpeedeep/depguard/v2",
            "direct": false,
            "version": "v2.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/package-url/packageurl-go",
            "direct": false,
            "version": "v0.1.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pandatix/go-cvss",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml",
            "direct": false,
            "version": "v1.9.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pjbgf/sha1cd",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.12.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.32.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.7.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/protonmail/go-crypto",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quasilyte/go-ruleguard",
            "direct": false,
            "version": "v0.4.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quasilyte/go-ruleguard/dsl",
            "direct": false,
            "version": "v0.3.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quasilyte/gogrep",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quasilyte/regex/syntax",
            "direct": false,
            "version": "v0.0.0-20210819130434-b3f0c404a727",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quasilyte/stdinfo",
            "direct": false,
            "version": "v0.0.0-20220114132959-f7386bf02567",
            "ecosystem": "go"
          },
          {
            "name": "github.com/raeperd/recvcheck",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rogpeppe/go-internal",
            "direct": false,
            "version": "v1.14.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/russross/blackfriday/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ryancurrah/gomodguard",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ryanrolds/sqlclosecheck",
            "direct": false,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sanposhiho/wastedassign/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/santhosh-tekuri/jsonschema/v6",
            "direct": false,
            "version": "v6.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sashamelentyev/interfacebloat",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sashamelentyev/usestdlibvars",
            "direct": false,
            "version": "v1.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/securego/gosec/v2",
            "direct": false,
            "version": "v2.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sergi/go-diff",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.9.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sivchari/containedctx",
            "direct": false,
            "version": "v1.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/skeema/knownhosts",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sonatard/noctx",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/go-diff",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/jwalterweatherman",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ssgreg/nlreturn/v2",
            "direct": false,
            "version": "v2.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stbenjam/no-sprintf-host-port",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/objx",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": false,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tetafro/godot",
            "direct": false,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/timakin/bodyclose",
            "direct": false,
            "version": "v0.0.0-20241222091800-1db5c5ca4d67",
            "ecosystem": "go"
          },
          {
            "name": "github.com/timonwong/loggercheck",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tomarrell/wrapcheck/v2",
            "direct": false,
            "version": "v2.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tommy-muehle/go-mnd/v2",
            "direct": false,
            "version": "v2.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ultraware/funlen",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ultraware/whitespace",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uudashr/gocognit",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uudashr/iface",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xanzy/ssh-agent",
            "direct": false,
            "version": "v0.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xen0n/gosmopolitan",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yagipy/maintidx",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yeya24/promlinter",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ykadowak/zerologlint",
            "direct": false,
            "version": "v0.1.5",
            "ecosystem": "go"
          },
          {
            "name": "gitlab.com/bosi/decorder",
            "direct": false,
            "version": "v0.4.2",
            "ecosystem": "go"
          },
          {
            "name": "go-simpler.org/musttag",
            "direct": false,
            "version": "v0.14.0",
            "ecosystem": "go"
          },
          {
            "name": "go-simpler.org/sloglint",
            "direct": false,
            "version": "v0.11.1",
            "ecosystem": "go"
          },
          {
            "name": "go.augendre.info/arangolint",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "go.augendre.info/fatcontext",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": false,
            "version": "v1.27.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp/typeparams",
            "direct": false,
            "version": "v0.0.0-20260209203927-2842357ff358",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.39.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": false,
            "version": "v1.36.8",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/ini.v1",
            "direct": false,
            "version": "v1.67.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/warnings.v0",
            "direct": false,
            "version": "v0.1.2",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "honnef.co/go/tools",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.74.3",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "mvdan.cc/gofumpt",
            "direct": false,
            "version": "v0.9.2",
            "ecosystem": "go"
          },
          {
            "name": "mvdan.cc/unparam",
            "direct": false,
            "version": "v0.0.0-20251027182757-5beb8c8f8f15",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 260,
        "direct_count": 20,
        "indirect_count": 240
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 212,
        "open_issues": 9,
        "closed_ratio": 0.892,
        "closed_issues": 74,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "andrew",
          "commits": 297,
          "avatar_url": "https://avatars.githubusercontent.com/u/1060?v=4"
        },
        {
          "type": "User",
          "login": "abhinavgautam01",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/183635986?v=4"
        },
        {
          "type": "User",
          "login": "bryceberger",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/9222441?v=4"
        },
        {
          "type": "User",
          "login": "sanmaxdev",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/46221775?v=4"
        },
        {
          "type": "User",
          "login": "miketheman",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/529516?v=4"
        },
        {
          "type": "User",
          "login": "bnjmnt4n",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/813865?v=4"
        },
        {
          "type": "User",
          "login": "Karry2019web",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/51736839?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.874
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 3,
            "reason": "Found 5/15 approved changesets -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 24 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 8,
            "reason": "SAST tool is not run on all commits -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "08bf43497d7706f8c4e754b551f541d0df12bb37",
        "ran_at": "2026-08-02T05:11:46Z",
        "aggregate_score": 6.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-31T16:28:18Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-31T16:20:56Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 112,
          "created_at": "2026-02-16T09:10:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 113,
          "created_at": "2026-02-16T09:10:26Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 114,
          "created_at": "2026-02-16T09:10:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 115,
          "created_at": "2026-02-16T09:10:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 116,
          "created_at": "2026-02-16T09:11:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 133,
          "created_at": "2026-02-26T12:55:12Z",
          "last_comment_at": "2026-06-20T07:52:07Z",
          "last_comment_author": "abhinavgautam01"
        },
        {
          "number": 164,
          "created_at": "2026-03-09T18:50:44Z",
          "last_comment_at": "2026-05-27T14:20:37Z",
          "last_comment_author": "benknoble"
        },
        {
          "number": 261,
          "created_at": "2026-06-30T07:42:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 294,
          "created_at": "2026-07-30T12:35:59Z",
          "last_comment_at": "2026-07-30T12:57:28Z",
          "last_comment_author": "andrew"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/git-pkgs/git-pkgs",
    "host": "github.com",
    "name": "git-pkgs",
    "owner": "git-pkgs"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": "The weighted overall 75 is calibrated to 89 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 75,
            "calibrated": 89,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 89,
      "inputs": {
        "security": 72,
        "vitality": 86,
        "community": 65,
        "governance": 64,
        "calibration": "2026-08-02",
        "engineering": 90,
        "ai_readiness": 72,
        "weighted_overall_raw": 75
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 86,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "commits_last_year": 392,
              "human_commit_share": 0.72,
              "days_since_last_push": 1,
              "active_weeks_last_year": 28
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "28/52 weeks with commits",
                "points": 19.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 28
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "392 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 392
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 36,
              "latest_release_tag": "v0.18.2",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 13.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "36 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 36
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~13.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 13.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 2,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 2 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 65,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "weak",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 10,
              "stars": 177,
              "watchers": 4,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "177 stars",
                "points": 36.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 177
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "10 forks",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "4 watchers",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 64,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 31,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.874
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 87% of commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 87
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 24 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 82,
            "inputs": {
              "merged_prs": 212,
              "open_issues": 9,
              "closed_issues": 74,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.892,
              "closed_unmerged_prs": 5,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "89% of issues closed",
                "points": 37.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "212/217 decided PRs merged",
                "points": 29.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 212,
                      "decided": 217
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 5/15 approved changesets -- score normalized to 3",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "followers": 42,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "git-pkgs",
              "public_repos": 47,
              "account_age_days": 200
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "42 followers of git-pkgs",
                "points": 11.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 42,
                      "login": "git-pkgs"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "47 public repos, account ~0 yr old",
                "points": 13.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 47
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/git-pkgs/git-pkgs"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "36 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 36
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "exceptional",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "dependencies",
                "git",
                "git-commands",
                "package-management"
              ],
              "has_wiki": true,
              "homepage": "https://git-pkgs.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://git-pkgs.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 72,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 6.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 5/15 approved changesets -- score normalized to 3",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 24 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 260 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 260
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 260,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 260,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 19
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 72,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.889,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "64 of 72 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 64,
                      "sampled": 72
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.28
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "28 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 28,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 85124,
              "source_files_sampled": 136,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/136 source files over 60KB",
                "points": 54.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 136,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "library",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:github.com/spf13/cobra",
          "weight": 4
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-02T05:12:05.579334Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/git-pkgs/git-pkgs.svg",
  "full_name": "git-pkgs/git-pkgs",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v2.3.1, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.