Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 67019,
"has_wiki": true,
"homepage": null,
"languages": {
"CSS": 1831266,
"PHP": 13264523,
"GLSL": 2468,
"HTML": 853937,
"Hack": 388,
"Shell": 398,
"JavaScript": 3123685
},
"pushed_at": "2026-07-24T07:15:20Z",
"created_at": "2014-06-09T04:51:56Z",
"owner_type": "Organization",
"updated_at": "2026-07-24T07:16:49Z",
"description": "그누보드5 (영카트 포함) 공개형 Git",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "master",
"license_spdx_raw": "NOASSERTION",
"primary_language": "PHP",
"significant_languages": [
"PHP",
"JavaScript"
]
},
"owner": {
"blog": "gnuboard.com",
"name": "kagla",
"type": "Organization",
"login": "gnuboard",
"company": null,
"location": "Corea",
"followers": 34,
"avatar_url": "https://avatars.githubusercontent.com/u/1716400?v=4",
"created_at": "2012-05-08T10:00:38Z",
"is_verified": null,
"public_repos": 62,
"account_age_days": 5190
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v5.6.34",
"kind": "patch",
"published_at": "2026-07-24T07:30:53Z"
},
{
"tag": "v5.6.33",
"kind": "patch",
"published_at": "2026-07-24T03:56:04Z"
},
{
"tag": "v5.6.32",
"kind": "patch",
"published_at": "2026-07-14T03:32:29Z"
},
{
"tag": "v5.6.31",
"kind": "patch",
"published_at": "2026-06-26T11:03:25Z"
},
{
"tag": "v5.6.30",
"kind": "patch",
"published_at": "2026-06-16T05:14:21Z"
},
{
"tag": "v5.6.29",
"kind": "patch",
"published_at": "2026-06-16T05:13:42Z"
},
{
"tag": "v5.6.28",
"kind": "patch",
"published_at": "2026-06-01T03:51:26Z"
},
{
"tag": "v5.6.27",
"kind": "patch",
"published_at": "2026-06-01T03:42:58Z"
},
{
"tag": "v5.6.26",
"kind": "patch",
"published_at": "2026-04-16T05:06:19Z"
},
{
"tag": "v5.6.25",
"kind": "patch",
"published_at": "2026-04-06T04:00:43Z"
},
{
"tag": "v5.6.23",
"kind": "patch",
"published_at": "2025-09-22T02:22:15Z"
},
{
"tag": "v5.6.22",
"kind": "patch",
"published_at": "2025-09-22T02:23:14Z"
},
{
"tag": "v5.6.21",
"kind": "patch",
"published_at": "2025-09-08T01:10:44Z"
},
{
"tag": "v5.6.17",
"kind": "patch",
"published_at": "2025-09-02T09:46:02Z"
},
{
"tag": "v5.6.16",
"kind": "patch",
"published_at": "2025-09-01T03:20:09Z"
},
{
"tag": "v5.6.15",
"kind": "patch",
"published_at": "2025-07-31T11:58:38Z"
},
{
"tag": "v5.6.14",
"kind": "patch",
"published_at": "2025-06-12T08:51:05Z"
},
{
"tag": "v5.6.13",
"kind": "patch",
"published_at": "2025-05-15T07:32:26Z"
},
{
"tag": "v5.6.12",
"kind": "patch",
"published_at": "2025-04-15T07:47:48Z"
},
{
"tag": "v5.6.11",
"kind": "patch",
"published_at": "2025-04-15T03:46:13Z"
},
{
"tag": "v5.6.10",
"kind": "patch",
"published_at": "2025-02-04T02:42:11Z"
},
{
"tag": "v5.6.9",
"kind": "patch",
"published_at": "2025-02-04T02:41:32Z"
},
{
"tag": "v5.6.8",
"kind": "patch",
"published_at": "2025-02-04T02:40:55Z"
},
{
"tag": "v5.6.7",
"kind": "patch",
"published_at": "2025-02-04T02:39:24Z"
},
{
"tag": "v5.6.6",
"kind": "patch",
"published_at": "2024-09-24T07:40:17Z"
},
{
"tag": "v5.6.5",
"kind": "patch",
"published_at": "2024-09-04T11:13:06Z"
},
{
"tag": "v5.6.4",
"kind": "patch",
"published_at": "2024-07-03T05:46:14Z"
},
{
"tag": "v5.5.17",
"kind": "patch",
"published_at": "2024-06-07T06:05:24Z"
},
{
"tag": "v5.6.3",
"kind": "patch",
"published_at": "2024-06-07T06:06:22Z"
},
{
"tag": "v5.5.16",
"kind": "patch",
"published_at": "2024-04-17T09:46:05Z"
},
{
"tag": "v5.6.2",
"kind": "patch",
"published_at": "2024-04-17T09:35:25Z"
},
{
"tag": "v5.6.1",
"kind": "patch",
"published_at": "2024-04-11T03:42:43Z"
},
{
"tag": "v5.5.15",
"kind": "patch",
"published_at": "2024-04-11T03:41:34Z"
},
{
"tag": "v5.6",
"kind": "other",
"published_at": "2024-04-03T03:58:26Z"
},
{
"tag": "v5.5.14",
"kind": "patch",
"published_at": "2024-04-03T01:27:42Z"
},
{
"tag": "v5.5.13",
"kind": "patch",
"published_at": "2024-02-19T01:22:52Z"
},
{
"tag": "v5.5.12",
"kind": "patch",
"published_at": "2024-01-25T08:12:04Z"
},
{
"tag": "v5.5.11",
"kind": "patch",
"published_at": "2024-01-02T08:34:02Z"
},
{
"tag": "v5.5.10",
"kind": "patch",
"published_at": "2023-11-10T05:37:32Z"
},
{
"tag": "v5.5.9",
"kind": "patch",
"published_at": "2023-10-19T02:59:25Z"
},
{
"tag": "v5.5.8.3.4",
"kind": "other",
"published_at": "2023-08-17T05:54:36Z"
},
{
"tag": "v5.5.8.3.3",
"kind": "other",
"published_at": "2023-08-16T07:06:35Z"
},
{
"tag": "v5.5.8.3.2",
"kind": "other",
"published_at": "2023-07-17T03:20:24Z"
},
{
"tag": "v5.5.8.3.1",
"kind": "other",
"published_at": "2023-06-19T09:12:34Z"
},
{
"tag": "v5.5.8.3",
"kind": "other",
"published_at": "2023-04-17T06:35:36Z"
},
{
"tag": "v5.5.8.2.9",
"kind": "other",
"published_at": "2023-04-13T11:31:10Z"
},
{
"tag": "v5.5.8.2.8",
"kind": "other",
"published_at": "2023-03-23T06:33:35Z"
},
{
"tag": "v5.5.8.2.7",
"kind": "other",
"published_at": "2023-01-25T08:28:10Z"
},
{
"tag": "v5.5.8.2.6",
"kind": "other",
"published_at": "2023-01-13T07:44:14Z"
},
{
"tag": "v5.5.8.2.5",
"kind": "other",
"published_at": "2022-12-08T07:41:31Z"
},
{
"tag": "v5.5.8.2.4",
"kind": "other",
"published_at": "2022-11-22T02:43:05Z"
},
{
"tag": "v5.5.8.2.3",
"kind": "other",
"published_at": "2022-10-17T02:13:33Z"
},
{
"tag": "v5.5.8.2.2",
"kind": "other",
"published_at": "2022-10-04T06:32:02Z"
},
{
"tag": "v5.5.8.2.1",
"kind": "other",
"published_at": "2022-09-13T02:02:53Z"
},
{
"tag": "v5.5.8.2",
"kind": "other",
"published_at": "2022-07-26T05:19:28Z"
},
{
"tag": "v5.5.8.1.2",
"kind": "other",
"published_at": "2022-07-01T01:08:19Z"
},
{
"tag": "v5.5.8.1.1",
"kind": "other",
"published_at": "2022-06-23T07:47:49Z"
},
{
"tag": "v5.5.8.1",
"kind": "other",
"published_at": "2022-06-20T06:56:42Z"
},
{
"tag": "v5.5.8",
"kind": "patch",
"published_at": "2022-06-13T11:27:43Z"
},
{
"tag": "v5.5.7.5",
"kind": "other",
"published_at": "2022-05-30T05:25:51Z"
},
{
"tag": "v5.5.7.4",
"kind": "other",
"published_at": "2022-05-24T08:19:28Z"
},
{
"tag": "v5.5.7.3",
"kind": "other",
"published_at": "2022-05-24T08:15:10Z"
},
{
"tag": "v5.5.7.2",
"kind": "other",
"published_at": "2022-05-03T03:17:41Z"
},
{
"tag": "v5.5.7.1",
"kind": "other",
"published_at": "2022-04-28T08:21:23Z"
},
{
"tag": "v5.5.7",
"kind": "patch",
"published_at": "2022-04-25T06:16:19Z"
},
{
"tag": "v5.5.6",
"kind": "patch",
"published_at": "2022-04-18T07:59:35Z"
},
{
"tag": "v5.5.5",
"kind": "patch",
"published_at": "2022-04-07T07:11:28Z"
},
{
"tag": "v5.5.4",
"kind": "patch",
"published_at": "2022-03-21T04:32:39Z"
},
{
"tag": "v5.5.3.1",
"kind": "other",
"published_at": "2022-03-07T00:43:31Z"
},
{
"tag": "v5.5.3",
"kind": "patch",
"published_at": "2022-03-04T02:24:57Z"
},
{
"tag": "v5.5.2",
"kind": "patch",
"published_at": "2022-02-22T03:12:12Z"
},
{
"tag": "v5.5.1",
"kind": "patch",
"published_at": "2022-02-15T09:30:28Z"
},
{
"tag": "v5.5.1-beta",
"kind": "prerelease",
"published_at": "2022-01-19T06:50:45Z"
},
{
"tag": "v5.4.22",
"kind": "patch",
"published_at": "2022-01-17T05:57:07Z"
},
{
"tag": "v5.4.21",
"kind": "patch",
"published_at": "2022-01-10T04:34:56Z"
},
{
"tag": "v5.4.20",
"kind": "patch",
"published_at": "2021-12-22T02:27:42Z"
},
{
"tag": "v5.4.19",
"kind": "patch",
"published_at": "2021-12-09T01:57:57Z"
},
{
"tag": "v5.4.18",
"kind": "patch",
"published_at": "2021-10-25T04:21:56Z"
},
{
"tag": "v5.4.17",
"kind": "patch",
"published_at": "2021-10-18T03:22:43Z"
},
{
"tag": "v5.5.0.2-beta",
"kind": "other",
"published_at": "2021-10-12T04:43:31Z"
},
{
"tag": "v5.5.0.1-beta",
"kind": "other",
"published_at": "2021-10-06T03:07:25Z"
},
{
"tag": "v5.5.0-beta",
"kind": "prerelease",
"published_at": "2021-10-01T04:23:38Z"
},
{
"tag": "v5.4.16",
"kind": "patch",
"published_at": "2021-09-23T05:32:44Z"
},
{
"tag": "v5.4.15.1",
"kind": "other",
"published_at": "2021-08-19T13:45:52Z"
},
{
"tag": "v5.4.15",
"kind": "patch",
"published_at": "2021-08-18T08:10:48Z"
},
{
"tag": "v5.4.14",
"kind": "patch",
"published_at": "2021-08-10T02:33:03Z"
},
{
"tag": "v5.4.13.1",
"kind": "other",
"published_at": "2021-07-27T05:33:08Z"
},
{
"tag": "v5.4.13",
"kind": "patch",
"published_at": "2021-07-27T00:59:26Z"
},
{
"tag": "v5.4.12",
"kind": "patch",
"published_at": "2021-07-20T01:30:38Z"
},
{
"tag": "v5.4.11",
"kind": "patch",
"published_at": "2021-07-19T03:01:08Z"
},
{
"tag": "v5.4.10",
"kind": "patch",
"published_at": "2021-07-01T03:00:52Z"
},
{
"tag": "v5.4.9",
"kind": "patch",
"published_at": "2021-06-24T06:59:07Z"
},
{
"tag": "v5.4.8",
"kind": "patch",
"published_at": "2021-06-18T05:03:39Z"
},
{
"tag": "v5.4.7",
"kind": "patch",
"published_at": "2021-06-18T01:44:37Z"
},
{
"tag": "5.4.6",
"kind": "patch",
"published_at": "2021-06-17T05:27:29Z"
},
{
"tag": "5.0.17",
"kind": "patch",
"published_at": "2014-09-16T01:34:13Z"
},
{
"tag": "5.0.14",
"kind": "patch",
"published_at": "2014-08-19T06:18:19Z"
}
],
"recent_commits": [
{
"oid": "0b6f081f765ac1af204d53c6a2b17a1b25a71502",
"body": null,
"is_bot": false,
"headline": "버전 5.6.34 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T07:14:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "adbd9c3accf7df38c31fe274a90b4f2aec32dbd4",
"body": "- 부분취소 합계로 전액 환불되고 주문도 취소된 거래는 일치 상태로 판정\n- 현황 목록 필터·KG 대사·관리자 알림에 동일 기준 적용\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "KG이니시스 PRO 현황 부분취소 전액환불 종결 판정 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T07:11:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8fcbd2a9b1eb7df79ee3d72f49c96a790bb6a78c",
"body": "- 부분취소 이력이 있는 주문은 잔여 금액을 부분취소로 처리해 전체취소 지원\n- 부분취소로 전액 환불된 주문과 KG에서 이미 취소된 주문은 주문 취소만 진행\n- PG 승인취소 미선택 시 차단하지 않고 주문만 취소하며 처리 내용을 이력에 기록\n- 남은 품목 취소로 주문 전체가 취소되는 경우에도 PG 취소 여부 확인창 표시\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "INIpay PRO 주문 전체취소 흐름 개선",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T07:11:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f8c06a26cbac77175183af0e0078b1b5080a2bdc",
"body": "- 팝업에서 admin.js와 토큰키를 로드해 처리 요청이 검증을 통과하도록 수정\n- 금액 입력 유효성 검사의 필드명 오타 수정\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "관리자 부분취소 팝업 처리 오류 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T07:11:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1fd5ec46ae1695186cc4ffe8bfd63abfba975067",
"body": "- 안내 문구의 로컬 표현을 영카트로 통일\n- PG와 영카트 주문이 모두 취소 상태로 일치하면 조치 불필요 문구 출력\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "KG이니시스 PRO 현황 안내 문구 정비",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T06:25:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cbd70fbe18829c5d61b0b0dabbd593a1085170b0",
"body": "- 전체취소 전에 KG 거래상태를 조회해 이미 취소된 거래이면 주문 취소만 진행\n- 조회 결과와 처리 사유를 결제 현황 이력에 기록\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "KG이니시스 상점관리자에서 먼저 취소한 INIpay PRO 주문의 전체취소 허용",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T06:25:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "bc07b8383e6a2c058030cf0779533564aa9ed4d0",
"body": "- 주문서/개인결제 결제 시작 시 이메일 형식을 확인해 잘못된 경우 안내 후 중단\n- 결제창 요청에서는 확인된 이메일만 선택 항목으로 전달해 결제가 막히지 않게 처리\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "KG이니시스 INIpay PRO 주문자 이메일 확인 후 전달",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T06:25:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "23c60a8ba11b0e5860ceace92762b492396b7b32",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "SMS 아이코드 신청 링크 최신 경로로 교체",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T05:28:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "abb777016dce1c6c1dac2f6f9db8e960e6036e13",
"body": "- 전자결제/본인확인/SMS 신청 링크를 sir.kr 최신 경로로 교체\n- 신용카드 전자결제에 나이스페이먼츠 추가(4개 1열 배치, 카드 폭 조정)\n- 나이스페이먼츠 신청 버튼 이미지 추가\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "부가서비스 신청 링크 최신화 및 나이스페이먼츠 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T05:19:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e45bd1d9e12351a662e3263ed301018b9ac412aa",
"body": null,
"is_bot": false,
"headline": "버전 5.6.33 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-24T01:04:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "acdbcfd8baa93bc6f4cd33feff4ed4efeffbfa82",
"body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "KG이니시스 INIpay PRO 결제 연동 및 결제 처리 현황 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-23T08:03:16Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1f48f6bd804b3243f13f97e2a16f394101912ef9",
"body": null,
"is_bot": false,
"headline": "버전 5.6.32 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-14T02:35:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "87d86d317e1f639ef4c6c59870e9960d844a621e",
"body": null,
"is_bot": false,
"headline": "소셜 로그인 앱 등록 링크 최신화",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T08:55:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7fa554f396d04018b92011567f6e17c9c7aaeecd",
"body": null,
"is_bot": false,
"headline": "XSS 취약점 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:38:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bc322c9d660da32a922b6777c4dfca46c772fa4",
"body": "- register_form_update.php에서 mb_1~mb_10을 다른 회원필드(mb_name 등)와\n 동일하게 clean_xss_tags 처리하여 저장하도록 보완\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "회원 여분필드 저장 시 입력값 정제 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:36:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "43fba4407d19c5072e13be55543efda6128110aa",
"body": null,
"is_bot": false,
"headline": "[KVE-2025-1533] 미결제내역 임시주문 데이터 출력 시 이스케이프 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:36:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d7fa045699aa4923ece21477869051a795d1b86",
"body": "- 상품이벤트/개인결제복사/SMS 번호·그룹·폼·업로드/방문로그 삭제 등\n POST 기반 상태변경 처리에 check_request_origin() 적용 (스킨 수정 불필요)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "관리자 상태변경 엔드포인트에 요청 출처 검증 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:20:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "82ee3ef438b9ddcce92c3d3e9df3c1a9319bd440",
"body": null,
"is_bot": false,
"headline": "[KVE-1525] SMS 번호·이모티콘 이동 처리 권한 속성 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:20:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4049c6c164cc664ffcc4d9c3eac0894bca9ae058",
"body": null,
"is_bot": false,
"headline": "[KVE-1524] 주문 상태변경 관리자 엔드포인트에 메뉴 권한 검증 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-13T07:15:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f80ed3946fa631ef76cba8cf5ef876cb392cc4ac",
"body": null,
"is_bot": false,
"headline": "Fix monthly visit date range end date",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-07-01T08:41:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7d5f265244ea869582d2f8d372eac14c2cef16b",
"body": "- get_write() 진입 시 wr_id를 정수로 캐스팅하여 SQL 조건에 비정상 값이 전달되지 않도록 보완\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[KVE-2026-1233]취약점- 게시글 조회 시 wr_id 정수 처리 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-30T02:05:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e0a42d8f46c30495daa829b2d05356120ed14b1a",
"body": null,
"is_bot": false,
"headline": "버전 5.6.31 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-26T10:50:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c6787ec1f412e5482a0f4f6aadfe62190ea3ef2",
"body": null,
"is_bot": false,
"headline": "상품 스킨 디렉토리 검증 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-26T10:40:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d419f430a9ff49e5ce72b0e655c8d216b004901a",
"body": "- shop/ajax.orderdatasave.php에 check_request_origin() 적용하여\n 외부 사이트발 자동 요청에 의한 임시 주문 데이터 교체 차단\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[KVE-20206-1176]XSS 취약점 - 결제 전 주문 임시데이터 저장 요청 출처 검증 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-24T07:10:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1a5661a995f86067bf9a1c13ce23a16dc1630dda",
"body": "- vi_referer 디코딩 후 title 속성에 출력할 때 따옴표를 이스케이프하도록 보완\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "접속자검색 접속경로 출력 시 속성값 이스케이프 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-23T00:52:40Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8a5767dc7007e72fc2a92bebac60481cb3daa9da",
"body": "- member_list·index·couponzonelist·inorderlist·personalpaylist의\n 정렬 컬럼/방향 값을 허용 목록으로 제한하여 ORDER BY 절에 임의 값 삽입 차단\n- 기존 다른 목록 파일과 동일한 in_array 화이트리스트 패턴 적용\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[KVE-2026-1176]취약점수정 - 관리자 목록 정렬 파라미터 화이트리스트 적용 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-23T00:48:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "935ea84c7c20f6e8b9bf26fceb9853d522231d5a",
"body": "- 쿠폰/희망배송일/검색어/계정/결제 콜백 등 입력값을 SQL 컨텍스트에 맞게 재처리\n- dt_data·PG 응답 등 비-GPC 값과 소셜 provider 입력 정제 보완\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[KVE-2026-1122]취약점 수정 - 주문·관리자·결제·소셜 등 사용자 입력 처리 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-23T00:36:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1cade844fb4f0ea2f519bdb15df1e231ff82de96",
"body": null,
"is_bot": false,
"headline": "chore: allow CRLF in PHP whitespace checks",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-22T08:30:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dfca17a599ca1bd89871e6e1886d855e4f399e51",
"body": null,
"is_bot": false,
"headline": "버전 5.6.30 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-16T03:33:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ed691136dc19c8dd18f9ec4ef07e2abcc977cb9",
"body": null,
"is_bot": false,
"headline": "나이스페이 가상계좌 취소금액 보정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-16T03:26:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cdda8320817022e69ea62945f552b5cf50637d7b",
"body": null,
"is_bot": false,
"headline": "Fix register form member defaults",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-16T03:26:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5374fb5f7447f43760fc532545702285d07098ac",
"body": null,
"is_bot": false,
"headline": "NHN KCP 본인확인 v2 설정 안내 보완",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-16T03:17:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "16a8dca6f738acdaa644aa857335d0e236e7f3f9",
"body": null,
"is_bot": false,
"headline": "버전 5.6.29 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-09T02:34:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b00fc18275d1bdc5070ea0694b2370db8d444da0",
"body": null,
"is_bot": false,
"headline": "Merge branch 'master' into tmp_install",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-09T02:27:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c6ff731f6bdb7fdc187e9c8b806bfa5296b06da",
"body": null,
"is_bot": false,
"headline": "관리권한 부여 목록에서 최고관리자 전용 메뉴 제외",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-09T02:26:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77835010dff8095a332f03539ecba50e1a932ccf",
"body": null,
"is_bot": false,
"headline": "메일 테스트 발송 안내 개선",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-09T02:26:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33416852fc1511c93472086b12824c8a931c487e",
"body": "가상계좌(4100) 채번 시 od_app_no가 빈 AuthCode로 남아\n입금통보 매칭(od_app_no = VbankNum)이 실패하던 문제 수정\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "나이스페이 가상계좌 채번 시 od_app_no 누락 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-09T01:34:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3a4612420c847096797cfbadde29afcf1f29865d",
"body": null,
"is_bot": false,
"headline": "Improve installer validation and error handling",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-08T02:09:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a55f1457dd828920adfc087e23b30094f6dc842",
"body": "html_process 의 접속자 처리에서 count 조회 결과 접근을 empty() 로\n보정. 쿼리 실패 등 비정상 상황에서 빈 배열/undefined 키 접근으로\nPHP 8.0+ 경고가 나는 경우를 예방. 동작 변화 없음.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "현재접속자 처리 시 카운트 접근 null 보정 (PHP 8 호환)",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-05T07:32:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "76d83c2bae7dee59ebd8267fd7e29f8e10a3b848",
"body": "게시판 설정의 bo_sort_field 가 허용 목록 검증 없이 저장·사용되어\n목록 조회 ORDER BY 절에 임의 표현식이 들어갈 수 있던 문제 수정.\n정렬값은 따옴표로 감싸지 않아 escape 로 막히지 않으므로,\n게시판 관리 권한 계정이 저장한 값이 비로그인 목록 조회에서\n실행될 수 있었음.\n\nget_board_sort_fields() 의 허용 목록(관리자 드롭다운과 동일)으로\n저장(adm/board_form_update.php)과 사용(bbs/list.php) 양쪽을 검증.\n허용 목록 외 값은 기본 정렬로 무력화하여 이미 저장된 값도 차단.\nfunction_exists 가드로 부분 패치 환경 대비.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "게시판 정렬 필드 화이트리스트 검증 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-05T07:20:58Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "afd8b35423e06de6aa3a93365a2f9a5b6980c1f2",
"body": "member_update.php 가 get_token()(HMAC) 으로 발급한 토큰을\nmember_update_run.php 가 check_admin_token()(세션) 으로 검증해\n항상 불일치 → 오류 HTML 반환으로 AJAX JSON 파싱이 실패하던 문제 수정.\n\nsms_admin 의 다른 _run 들과 동일하게 검증측(check_admin_token)은\n유지하고, 실행 시 ajax.token.php 로 세션 토큰을 발급받아 본 요청에\n사용하도록 변경. check_admin_token 의 1회용 소거 특성상 재실행에도\n견고함.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "SMS 회원정보 업데이트 토큰 방식 불일치 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-02T08:22:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e7c89675b622b22a6066eebe83a689ddce954d6e",
"body": "내장함수에 null 이 전달되어 PHP 8.1+ 에서 경고가 발생하던 것을\nisset 삼항 / 문자열 캐스팅으로 보정.\n\n- adm/member_form.php: number_format(mb_point), substr(mb_id) 2곳,\n substr(mp_register_day) — null/미정의 시 0 또는 빈 문자열 처리\n- plugin/htmlpurifier/extend.video.php: strstr 인자 (string) 캐스팅\n\n표시·동작 변화 없음. PHP 5.2~8.3 호환 유지(?? 미사용).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "회원관리/비디오 필터 null 인자 보정 (PHP 8.1 호환)",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-02T07:55:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "10c6c18857efe701995fb651000038a92ecc574e",
"body": null,
"is_bot": false,
"headline": "Fix JavaScript alert string escaping",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-01T10:26:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e002199d5f20afcb80546210f63c718cd9e2c2e",
"body": null,
"is_bot": false,
"headline": "버전 5.6.28 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-01T03:40:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7dde02d3962ce6627eeff694db1cb4727aa5bd4d",
"body": "기본값 있는 $strDate 뒤에 기본값 없는 $nCount 가 선언되어 PHP 8.0+\n에서 경고가 발생하던 것을 $nCount=0 기본값 부여로 해소.\n\n- plugin/sms5/sms5.lib.php: Add(), Add2()\n- lib/icode.lms.lib.php: Add() (LMS 부모 클래스 동일 패턴)\n\nLMS 분기 호출부는 $strDate, $nCount 를 항상 함께 전달하므로\n동작 변화 없음. PHP 5.2~8.3 호환 유지.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "SMS 모듈 Add/Add2 매개변수 기본값 보정 (PHP 8 호환)",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-06-01T01:02:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "31871ee3e61c2f93fa134c0b9aba335f00e14d6a",
"body": "- adm/shop_admin/orderform.php: 주문상세 hidden 의 od_hp 출력에\n get_text() 적용 (인접한 od_name 과 동일 처리, 누락분 보완)\n- bbs/member_cert_refresh_update.php: 본인확인 갱신 후 이동 URL 에\n check_url_host() 적용\n- plugin/social/includes/functions.php: 소셜 로그인/연동 후 이동\n URL 2곳에 동일하게 check_url_host() 적용\n\nlogin_check.php 등 기존 코드와 동일한 호스트 검증 패턴으로,\n같은 도메인/상대경로 복귀는 그대로 동작하고 타 도메인 이동만 차단.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 주문자 휴대폰 출력 인코딩 및 리다이렉트 URL 호스트 검증",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T09:16:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ff9a7534edac66e8bc5248a5c01f8f18b070aed9",
"body": null,
"is_bot": false,
"headline": "Restore data htaccess on admin and write upload",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T07:22:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9869be59702566a8a1048019f3a36ae454ecf606",
"body": "토스페이먼츠 결제 요청 폼의 customerName hidden 필드에 주문자명\n($od_name)이 인코딩 없이 출력되던 것을 get_text() 적용으로 정리.\n직전 주문 필드 인코딩 처리와 동일한 맥락의 마무리.\n\nhidden value 의 엔티티는 결제 SDK 가 값을 읽을 때 브라우저가\n디코딩하므로 토스로 전달되는 구매자명에는 영향 없음.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 토스 결제창 customerName 출력 시 get_text 인코딩 적용",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T06:30:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1fa4467cd1a4cefb81e6e6a74da9a5333d91e345",
"body": "영카트 주문자명/받는분/입금자명(od_name, od_b_name, od_deposit_name)\n이 일부 출력 지점에서 인코딩 없이 노출되어, 저장된 값이 HTML/속성\n컨텍스트에서 그대로 렌더링되던 문제 수정. 다음 출력에 get_text() 적용:\n\n- adm/shop_admin/orderform.php, sale1today.php (관리자 주문 화면)\n- shop/orderinquiryview.php (PC/모바일/테마 주문조회)\n- shop/{inicis,kcp,lg,nicepay,toss}/taxsave_form.php \n[…]\nl.php, ordermail.mail.php (주문 메일)\n\n비회원 주문 시 입력값이 관리자 화면에서 실행될 수 있는 경로를 차단.\n폼 value 의 엔티티는 브라우저 제출 시 디코딩되므로 PG 전송값 및\n정상 표시에는 영향 없음.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 주문 관련 필드 출력 시 get_text 인코딩 적용",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T06:25:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3e75ccea65a37e863c00bf3a79cdca1a1d3d17f9",
"body": null,
"is_bot": false,
"headline": "NHN KCP 휴대폰 본인확인(api_v2) 버전 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T06:14:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be9f50f96b231ced700e012a28a9119f001bb879",
"body": null,
"is_bot": false,
"headline": "Fix RSS warnings for invalid board requests",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-29T01:33:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c217cb41b95ba1f9c72f40869e31e6def0f207c",
"body": null,
"is_bot": false,
"headline": "Restore alert newline handling",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-28T06:23:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fc1c3bc27e4ee58e84d3ebfd5feb86b83852fc5",
"body": null,
"is_bot": false,
"headline": "버전 5.6.27 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-27T03:35:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d707c5abac72a95473df9bdf9bf7a5b3b5244e45",
"body": ".gitignore 에는 이미 data/ 가 등록되어 있으나 data/.htaccess\n한 파일이 이전부터 트래킹되고 있어 배포본에 함께 포함되던 문제 정리.\n디스크 파일은 그대로 두고 인덱스에서만 제거.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "data/ 디렉터리 git 추적 제외 (.htaccess 인덱스 제거)",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-27T02:28:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "eeea46cb699b4226bfe5ee2ba9aa810c2063a478",
"body": "KCP 가이드 개정으로 가상계좌 발급 정상 응답이 0000 에서 V000 으로\n변경되어, 기존 코드가 발급 성공을 실패로 인식하던 문제를 수정.\n결제 hub 의 res_cd 비교 두 곳에서 V000 을 0000 과 동등하게 처리.\n\n가상계좌 입금 완료 처리는 Webhook 입금통보가 담당하므로 본 변경과\n무관. 취소/현금영수증/본인인증 경로는 V000 응답 대상이 아니므로\n0000 단독 비교 유지.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "NHN KCP 가상계좌 발급 응답 코드 V000 허용",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T11:55:56Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "669cce70118981d0bd7519c18c104fea672212d6",
"body": "카카오 우편번호 서비스의 oncomplete 콜백이 userSelectedType\n으로 'R'(도로명) 또는 'J'(지번)을 반환하는데, 서버 측 정규식이\n'N|R' 만 허용해 지번 선택 시 빈 문자열로 저장되던 문제를 수정.\nN 은 print_address() 의 도로명 표기 분기를 위한 레거시 값으로\n호환을 위해 유지.\n\n적용 위치: 회원가입(bbs/register_form_update.php), PC/모바일\n주문(shop/, mobile/shop/ orderformupdate.php), 관리자 미완료\n주문(adm/shop_admin/inorderformupdate.php) 의 7곳.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "주소 jibeon 값 화이트리스트에 'J' 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T11:46:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ee8b57eb1368bc8933a0bfa04421a3dcc99cf54d",
"body": "dt_pg 값이 'toss' 또는 'nicepay' 인 건이 default 분기로 빠져\n일괄 'KCP' 로 잘못 표시되던 문제 수정.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "미완료 주문 목록 PG 표시에 토스페이먼츠/NICEPAY 케이스 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T11:40:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c927925a0532ef80ca56b7c63b78f9b61fb250cd",
"body": null,
"is_bot": false,
"headline": "Fix PHP 5.2 compatibility issues",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T09:34:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d914a7843d7212e84586d1f7678287d281373ad3",
"body": null,
"is_bot": false,
"headline": "Fix PHP legacy array syntax",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T08:10:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c04591e24a849bfa79f998357414530b8764d9ea",
"body": null,
"is_bot": false,
"headline": "NHN_KCP 가상계좌 테스트 url 변경",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T07:34:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6fbbe6ad2b784c5bdd99677c79650fb7e1ac4c7",
"body": "lib/common.lib.php 에 csv_safe_cell() 헬퍼 추가 (function_exists\n가드 포함). 셀 값이 = + - @ TAB CR 로 시작하면 작은따옴표를 prefix\n하여 스프레드시트가 수식으로 해석하지 못하도록 변환.\n\n다음 출력 지점에서 사용자 입력 컬럼에 적용:\n- adm/shop_admin/orderprintresult.php (CSV + XLS 두 분기)\n- adm/shop_admin/orderdeliveryexcel.php\n- adm/member_list_exel_export.php\n- adm\n[…]\nin/num_book_file_download.php\n\n호출부는 function_exists('csv_safe_cell') ? ... : 원본 폴백 형태로\n감싸서 lib 미업데이트 환경에서도 fatal error 없이 동작하도록 함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 엑셀/CSV 다운로드 출력값 안전 처리",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T07:30:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c00c6000634b1c8cc42c8b548337c6ac54418ca",
"body": "이전 커밋(e53689ac3)의 미수금 처리 방식은 사용자에게 결제 금액과\n다른 청구가 발생해 혼란/분쟁을 유발할 수 있어, 동시 주문 race 로\n포인트 잔액이 부족하면 결제 자체를 취소하는 방식으로 변경.\n\n- PG 결제가 진행된 경우 (\\$tno 존재): cancel_pg.inc.php 로 환불 요청\n- 장바구니 복구: 기존 line 839 동일 패턴 (od_id = tmp_cart_id, ct_status = '쇼핑')\n- 주문 삭제: g5_shop_order_table 에서 od_id 제거\n- 사용자에게 die 로 명확한 오류 메시지 표시\n\nlock timeout 케이스도 동일하게 결제 취소 처리 (보수적).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0882 race condition 잔액 부족 시 결제 취소 처리로 변경",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T07:10:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "56b1958d373e5dca1c47405a8c398536155f619e",
"body": "shop/orderformupdate.php / mobile/shop/orderformupdate.php 의 포인트\n검증과 차감 사이에 TOCTOU race 가 존재하여, 동일 회원이 여러 세션으로\n동시에 주문 제출 시 같은 포인트 잔액을 반복 검증 통과 → 다중 차감으로\nmb_point 가 음수가 되는 double spend 가 가능했음.\n\ninsert_point() 의 기존 named lock 은 (mb_id, rel_table, rel_id, rel_action)\n조합 키 기반이라 서로 다른 od_id 주문 간에는 lock 이\n[…]\n분은 od_receipt_point\n 보정 + od_misu(미수금) 으로 반영하여 매장 손실 방지.\n\nMyISAM 정책상 트랜잭션 금지이므로 named lock 으로 직렬화하는 방식이\n가장 적합. 데스크톱·모바일 동일 패턴 적용.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0882 주문 포인트 차감 Race Condition (Double Spend) 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T06:52:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6b2f9e094c9834ee0fd4456f2be3333b47ea7f3d",
"body": "KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.\n\n- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)\n- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)\n → 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에\n 검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.\n sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 \n[…]\nwr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용\n 되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식\n 삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T06:32:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a781b4aef39e297c4f86ce3ab70b4f8d756ddb7c",
"body": null,
"is_bot": false,
"headline": "[KVE-2026-0876] 모바일 상품 리스트 sort 파라미터 Blind SQL Injection 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T06:27:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8be4476f56ea333fe1c1eb23fb98ff869bf450d1",
"body": null,
"is_bot": false,
"headline": "[KVE-2026-0869] 인스톨러 관리자 입력값 SQL Injection 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T05:22:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59d0b3c19ccc0b5cc6c344a72ba897cf77176456",
"body": "shop/kcp/pp_cli_hub_lib.php, shop/kcp/pp_ax_hub_lib.php 의\nmf_do_tx() Windows 분기가 사용자 입력이 포함된 KCP CLI 인자를\n큰따옴표로 감싼 단일 문자열로 만들어 mf_exec() 첫 인자로 전달했고,\nmf_exec() 는 첫 인자를 escape 없이 exec() 에 넘겨 Windows cmd.exe\n메타문자(`\"`, `&` 등)로 인증 없는 OS 명령 실행이 가능했음.\n\nLinux 분기와 동일하게 실행 파일 경로와 콤마 구분 인자 문자열을\n분리하여 mf_exec($bin_exe, $args) 형태로 호출하도록 변경.\nmf_exec() 의 foreach 가 두 번째 이후 인자에 escapeshellarg() 를\n자동 적용하여 cmd.exe 메타문자가 안전하게 wrapping 됨.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0859 KCP CLI Windows 환경 명령 인젝션(RCE) 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:35:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f4f8c57a74d743fd3cf0ca4f02fcd8658d2b824e",
"body": "- adm/qa_config_update.php / adm/contentformupdate.php :\n qa_include_head/tail, co_include_head/tail 가 super 가드 없이 변경 가능해\n 하위 관리자가 임의 PHP 경로를 include 시킬 수 있던 LFI 위험을\n board_form_update.php 와 동일한 패턴(super 외에는 기존 값 유지)으로 차단.\n\n- adm/member_form_update.php / adm/member_list_update.php :\n 신규 회원 생성·일괄\n[…]\n adm/sendmail_test.php :\n 상태 변경 동작에 check_admin_token() 누락으로 발생하던 CSRF 위험을\n 토큰 검증 추가로 차단. sendmail_test 폼에는 hidden token 필드 추가.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 관리자 영역 권한 검증 누락 및 CSRF 토큰 누락 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:35:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d5619707bcaffc967081989830a371a2520691e5",
"body": "install/install_db.php 의 g5_shop_prefix 가 dbconfig.php 의\ndefine('G5_SHOP_TABLE_PREFIX','...') 문자열에 작은따옴표 escape 없이\n삽입되어, 설치 전 노출된 인스톨러를 통해 임의 PHP 코드 주입 후 RCE\n가능하던 문제를 수정. table_prefix·admin_id 와 동일하게 [^0-9a-z_]+\n정규식 검증을 추가하여 영문자·숫자·언더스코어만 허용하도록 함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security] 인스톨러 g5_shop_prefix PHP 코드 인젝션(RCE) 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:34:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9e7465319bcdd09258c1c7bb80c679befd2a50ce",
"body": "view_comment.skin.php 8종(skin/, mobile/skin/, theme/basic/ 하위 basic·\ngallery)에서 댓글 수정($w == 'cu') 시 \\$c_wr_content 가 textarea 내부에\n이스케이프 없이 출력되어 </textarea> 페이로드로 탈출 가능하던 문제를\nget_text() 적용으로 일괄 수정. 게시글 본문 수정(bbs/write.php) 과\n동일한 escape 패턴을 댓글 수정에도 적용함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0822 댓글 수정 textarea wr_content 미이스케이프 Stored XSS 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:32:43Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f1f2150c67e497e7cef3c5547196d45d90c2274f",
"body": "bbs/move_update.php 가 원본 게시판 기준 $is_admin 만 검사하고 사용자\n입력 chk_bo_table[] 의 대상 게시판에 대해서는 존재 여부만 확인하던\n문제를 수정. 게시판 관리자(board)·그룹 관리자(group) 권한일 경우\n대상 게시판의 bo_admin 또는 그룹의 gr_admin 이 본인인지 재검증하고,\n일치하지 않으면 해당 대상 게시판 처리를 건너뛰도록 함. super 관리자는\n기존 동작 유지.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0795 게시물 이동/복사 시 대상 게시판 권한 검증 누락 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:32:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3de722d3df9ef3945dd78a9121a18e7f24f707a7",
"body": "bbs/alert.php, bbs/alert_close.php 가 alert(\"$msg\") 형태로 메시지를\nJS 문자열 컨텍스트에 직접 삽입하던 부분을 수정. lib/common.lib.php 에\nPHP 5.2 호환 폴백을 갖춘 get_js_safe_string() 헬퍼를 추가하고,\n호출부에는 function_exists 가드를 걸어 부분 패치 환경에서도 안전하게\n폴백되도록 함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0787 alert() JavaScript 이스케이프 누락 Stored XSS 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:31:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7119b4f61289a32024193b3346d7f5d04078b52c",
"body": "XenoPostToForm::makeInputArray() 에서 POST 값·배열 인덱스는 이스케이프\n되지만 최상위 POST 키 이름이 name 속성에 그대로 삽입되던 문제를 수정.\n재귀 진입 시점에 htmlspecialchars() 로 키를 이스케이프하여 모든 깊이에서\n안전하도록 함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0711 PG 리턴 처리 POST 키 이름 Reflected XSS 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:30:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "efaefbbd0eb3334aba16ef729bac62cb82aeed83",
"body": "MySQL GET_LOCK 으로 동일 회원·동일 쿠폰 다운로드 요청을 직렬화하여,\n동시 요청 시 is_coupon_downloaded() 체크를 중복 통과해 쿠폰이 중복\n발급되는 문제를 방지함.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0687 쇼핑몰 쿠폰 다운로드 TOCTOU Race Condition 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:30:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b12bf551ec2ec2dc69399aa3b83e4c785d941bdb",
"body": null,
"is_bot": false,
"headline": "[security]XSS 취약점 및 token 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-05-26T03:29:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65a419e9cdf1b86c231d57ec0904960f9932f8ec",
"body": null,
"is_bot": false,
"headline": "버전 5.6.26 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T04:38:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f32ecd3e62de4eb1bdcd3dedac484baed98290d",
"body": "수신설정 섹션이 폼에 표시되지 않는 경우(cf_use_promotion 미사용, 휴대폰 미사용,\n아이코드 미사용 등) _default 변수가 undefined 상태가 되어 비교 시 항상 \"변경됨\"으로\n판단되던 문제를 해결. _default 변수를 명시적으로 초기화하고, 폼에 없는 항목은\n기존 DB 값을 유지하도록 수정.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "회원정보 수정 시 약관변경내역 로그가 매번 쌓이는 버그 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T04:01:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b5d218d4461c1ed5c7c3f933ac850f4bb324339a",
"body": null,
"is_bot": false,
"headline": "인증서 교체로 인한 (구)엘지모듈 토스 결제 안되는 문제 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:46:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2e7dbc5ed8833e0168ad506f7855055cd461075",
"body": null,
"is_bot": false,
"headline": "[security]그누보드5 XSS, SQL Injection 취약점 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:46:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c38de4c94b64b72c0c2d5c3195e8eabc65cdadef",
"body": "- bbs/write_update.php, bbs/qawrite_update.php: 업로드 블랙리스트에 shtml|shtm 추가\n- install/install_db.php, data/.htaccess: FilesMatch 정규식에 [Ss]? 추가하여 .shtml 차단\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0701 .shtml 확장자 필터 누락으로 인한 RCE 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:39:31Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7d8a6606420e904785d76785f1b2f2299fcb31ba",
"body": "rand() 대신 CSPRNG 기반 get_random_token_string() 사용\n- mb_nonce: 128비트 CSPRNG 토큰으로 시드 브루트포스 차단\n- change_password: CSPRNG 기반 10자리 hex로 변경\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0693 비밀번호 재설정 토큰 예측 가능 취약점 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:39:12Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5875e8b86bea5cfb9d7562b3914e89642e4359f6",
"body": "skin_dir 파라미터에 디렉토리 트래버설 검증이 없어\n임의 경로의 PHP 파일을 include할 수 있는 취약점을\nclean_relative_paths()로 경로 조작 문자열 제거하여 수정\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0690 설문조사 결과 페이지 Local File Inclusion 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:38:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "68a5b9c25a58a6dbc4369aaacae27ffa2bdc8cf2",
"body": "$_SERVER['REQUEST_URI']를 JavaScript 문자열에 이스케이프 없이\n출력하여 URL을 통한 Reflected XSS가 가능한 취약점을\njson_encode()로 안전하게 이스케이프 처리\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0689 SNS 공유 스킨 Reflected XSS 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:38:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2dff49914bdcf54d54f0e76aa9dfb9d195b35ba1",
"body": null,
"is_bot": false,
"headline": "[security]KVE-2026-0710 그누보드5 SQL Injection 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:35:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "51518e45e483888bf4e8ce524cebadad9f2f30b4",
"body": null,
"is_bot": false,
"headline": "[security]KVE-2026-0709 그누보드5 SQL Injection 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:31:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7883ff65dc130f22ab1dca2c11656311ced3154a",
"body": null,
"is_bot": false,
"headline": "check_token 함수 쓰는곳 없지만 요청사항으로 인해 타임스탬프 추가 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:30:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a2608754bd5fa6bd4875a5da5bb5614e8ee6f6f1",
"body": "case 'h' 직접입력 항목에 bg_no, mb_id, bk_no 키 누락으로 257행에서 Warning 발생\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[fix]SMS 직접입력 발송 시 PHP 8.x Undefined array key 경고 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:24:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "758bb67b7b5fb01047ed0f156b3e2567650be039",
"body": "popup.php에서 mylink 진입 시 Referer 검증 및 세션 토큰 설정\nfunctions.php에서 social_user_profile_replace() 호출 전 세션 토큰 검증\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0685 소셜 로그인 계정 연결 CSRF 방어",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:23:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0037f72cce7f3645731adda34595c38b973c3c72",
"body": null,
"is_bot": false,
"headline": "[security]KVE-2026-0678 사용자 영역 CSRF 방어 추가",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:23:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df940f8168b0f3e8b66b40a0c8fd93d215d807fd",
"body": "비회원 폼메일 발송 시 From 헤더를 관리자 이메일로 고정하고 사용자 입력은 Reply-To로 설정\nformmail_send.php에 세션 기반 발송 횟수 제한 추가 (직접 POST 우회 방지)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0676 폼메일 발신자 위장 및 Rate Limit 우회 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T03:18:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "614b040960c0c63898cb752514d2722967d0cbd5",
"body": "register_email_update.php에 로그인 검증·소유권 강제·ckey HMAC 검증·SQL 이스케이프 추가\nmember_cert_refresh_update.php에 로그인 검증 및 소유권 강제 추가 (연관 IDOR 선제 조치)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "[security]KVE-2026-0673 비인증 이메일 변경을 통한 계정 탈취 취약점 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:55:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "dccb50d8a3d031fcc49853b544fa3464516eff6d",
"body": null,
"is_bot": false,
"headline": "[security]회원 ID/이메일 열거 공격 차단",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:54:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5331aa8be5884facf5e65dece1aaf350d73a8b52",
"body": "sql_query()의 에러 처리가 die()로 SQL 쿼리 전문, MySQL 에러 메시지,\n스크립트 파일 경로를 사용자에게 그대로 노출하고 있었음. 기본값\nG5_DISPLAY_SQL_ERROR=false 덕분에 일반 호출에서는 트리거되지 않으나,\n일부 admin 파일이 명시적으로 sql_query(\\$sql, true)로 호출하여\n관리자에게 raw SQL을 노출했고, SQLi 공격 시도 중 발생한 에러로 DB\n구조(테이블/컬럼명)가 학습되어 정밀 공격에 활용될 수 있었음.\n\n조치:\n- 서버 로그(error_log)에는 항상 상세 \n[…]\n다.\" 만 표시\n- mysqli/mysql 폴백 분기 둘 다 동일하게 적용\n\n변경:\n- lib/common.lib.php:1932 (mysqli 분기)\n- lib/common.lib.php:1942 (mysql 분기, 레거시 PHP 5.x 폴백)\n\nPHP 5.2.17 호환 유지 (htmlspecialchars + ENT_QUOTES 모두 PHP 4.0+).",
"is_bot": false,
"headline": "[security]sql_query() 에러 노출 시 SQL/스키마 정보 차단",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:48:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "79f915988bdbec27aa0279689961eb8756be6b8b",
"body": "shop/personalpayformupdate.php와 lib/shop.lib.php의 ss_personalpay_hash\n검증이 loose 비교(==/!=)를 사용하여 PHP type juggling 잠재적 우회 가능성이\n있었음. md5 결과 중 \"0e...\" 형식 hash는 PHP의 loose 비교에서 0e 지수\n표기법으로 해석되어 다른 \"0e...\" 해시와 동등 판정될 수 있음\n(소위 magic hash collision 패턴).\n\n실제 익스플로잇 가능성은 낮지만 (md5 출력은 32자 hex 문자열이고 PHP의\n문자열 vs\n[…]\nepth 차원에서 strict 비교로 변경.\n\nmobile/shop/personalpayformupdate.php는 이미 strict 비교를 사용 중이라\ncore 두 곳만 동일한 패턴으로 정렬.\n\n- shop/personalpayformupdate.php:35: != / != → !== / !==\n- lib/shop.lib.php:2333: == → ===",
"is_bot": false,
"headline": "[security]개인결제 hash 검증을 strict 비교(===)로 강화",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:46:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3cfe8b6b84fd05d9a3b82c81fcb2383bd97a1f39",
"body": null,
"is_bot": false,
"headline": "[security]현금영수증 발급 페이지 IDOR 취약점 수정",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:43:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31ef78e916593a9cb4007a6f6518456ce02ad7e1",
"body": "strstr()은 일치하는 부분 문자열 전체를 반환하므로 존재 여부만 체크할\n때는 메모리 할당이 낭비됨. strpos()는 위치(int) 또는 false만 반환하여\n메모리 할당 없이 더 빠르게 동일 동작 수행.\n\n적용 파일 (19개, 약 25곳):\n- lib/common.lib.php: wr_option html1/html2/secret 검사 3곳\n- lib/shop.lib.php: de_taxsave_types 검사 2곳\n- lib/latest.lib.php: wr_option secret 검사 1곳\n- lib/thumbnail.\n[…]\nstrpos($a, $b) === false\n\n제외:\n- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)\n- strstr() 반환값을 실제로 사용하는 케이스 (예: lib/common.lib.php:4135\n if( \\$freg = strstr(\\$ori_params, '#') ), extend/gif2mp4.extend.php)",
"is_bot": false,
"headline": "[perf]strstr() 불린 검사를 strpos() !== false 로 교체",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:29:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a612e69d3efef9e9e74196574e97e507ce15aca9",
"body": "for ($i=0; $i<count(\\$arr); $i++) 패턴은 매 반복마다 count()를 호출하여\n불필요한 CPU 오버헤드를 발생시킴. 루프 전에 한 번만 count()를 계산하여\n변수에 저장하는 고전적인 최적화.\n\n적용 파일 (19개, 41곳):\n- lib/common.lib.php (8)\n- common.php (2)\n- lib/shop.lib.php (5)\n- lib/naverpay.lib.php (1)\n- lib/thumbnail.lib.php (2)\n- bbs/list.php (1), bbs/search.php (4\n[…]\n로 변경 (strstr 최적화의 일부)\n\n제외:\n- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)\n- lib/PHPExcel/ (서드파티 라이브러리)\n- adm/ 및 shop/mail/ (관리자/드문 경로, 별도 후속 작업 여지)\n- 주석 처리된 코드 (bbs/delete.php:127, bbs/delete_all.php:143)",
"is_bot": false,
"headline": "[perf]for 루프 조건의 count() 호출을 루프 밖으로 추출 (핵심 파일)",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:26:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29e55de1fa7da0e8821b2db8082697509a3f147d",
"body": "기존 구현은 일반 텍스트 게시글(URL/이메일이 전혀 없는 대부분의 경우)\n에서도 3개의 preg_replace를 항상 호출하여, 모든 게시글 본문 렌더링\n마다 불필요한 regex 컴파일/스캔 오버헤드가 발생.\n\n개선:\n1. Fast bailout: ://, www., @, &, ' 가 하나도 없으면 즉시 반환하여\n forward/reverse str_replace와 3개의 preg_replace를 모두 생략.\n2. 조건부 regex 실행: 각 regex 호출 전에 해당 패턴이 실제로 존재하는지\n strpos로 먼저 확인. \n[…]\n 동작. 페이지에 수십~수백 개 게시글을 표시하는\n목록/검색 페이지에서 누적 효과가 큼.\n\n의미론적 동등성 유지: 각 marker가 없으면 해당 regex가 원래도 no-op였으므로\n조건부 실행은 결과에 영향 없음. Fast path는 모든 marker가 없을 때만\n동작하므로 str_replace의 부작용(& entity 디코딩 등)도 발생할 여지가 없음.",
"is_bot": false,
"headline": "[perf]url_auto_link() 다중 regex 호출 조건부 실행으로 최적화",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:25:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4db6e7751f55249e8bbf3e0d689c6347ceee3b4",
"body": "기존 구현은 preg_split(\"//u\")로 입력 문자열의 모든 문자를 PHP 배열로\n분해한 뒤 count/array_slice/join 3단계로 처리하여, 짧은 문자열이든\n긴 문자열이든 항상 문자 수만큼 배열 원소를 할당하고 regex를 호출함.\n\n게시글 목록의 제목/내용 표시 등 페이지당 수십~수백 회 호출되는\n핫패스에서 불필요한 오버헤드를 발생시킴.\n\n개선:\n1. 바이트 길이 빠른 경로: strlen(str) <= len이면 UTF-8 특성상 문자 수도\n 보장되므로 즉시 반환. ASCII/짧은 제목은 mb_strlen 호출 없이 종료.\n2. mbstring 확장 사용: mb_strlen + mb_substr로 배열 생성 없이 상수\n 메모리로 길이 체크/절단 처리.\n3. preg_split 기반 기존 로직은 mbstring 미설치 환경 폴백으로 유지.\n\n의미론적 동등성 유지 (잘라낸 결과와 suffix 부착 조건 모두 동일).",
"is_bot": false,
"headline": "[perf]cut_str() 메모리 사용량과 CPU 오버헤드 감소",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:25:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47a3790c57a64f670460b4bece12e3a4004d32f1",
"body": "게시판 목록 페이지에서 발생하던 N+1 쿼리 패턴 2건을 제거:\n\n1. 공지 처리 루프 (line 94~120):\n 기존에는 bo_notice의 각 wr_id마다 sql_fetch를 따로 호출하여 공지가 N개면\n N개의 쿼리가 발생. 유효한 wr_id를 정수화하여 수집한 뒤 단일 IN 쿼리로\n 일괄 조회하고, id 기반 해시맵으로 원래 순서대로 처리.\n\n2. 검색 결과 2차 조회 (line 199~200):\n DISTINCT wr_parent 쿼리로 ID만 받은 뒤, 각 행마다 sql_fetch를 호출하여\n 검색 \n[…]\n + 5 notice fetch = 26 쿼리\n 개선: 1 DISTINCT + 1 IN(search) + 1 IN(notice) = 3 쿼리\n\n부수 효과:\n- 삭제된 공지/부모글에 대한 에러 처리 개선\n (기존은 empty row를 get_list에 넘겨 잠재적 오류, 개선판은 자동 스킵)\n- wr_id 정수화로 SQL injection 방지 계층 추가",
"is_bot": false,
"headline": "[perf]bbs/list.php N+1 쿼리 2건을 IN 쿼리로 배치 조회로 전환",
"author_name": "thisgun",
"author_login": "thisgun",
"committed_at": "2026-04-16T02:23:24Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 97,
"commits_last_year": 165,
"latest_release_at": "2026-07-24T07:30:53Z",
"latest_release_tag": "v5.6.34",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 26,
"days_since_latest_release": 0,
"mean_days_between_releases": 12.1
},
"community": {
"has_readme": false,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 268,
"stars": 343,
"watchers": 40,
"fork_history": {
"days": [
{
"date": "2014-06-09",
"count": 1
},
{
"date": "2014-06-10",
"count": 2
},
{
"date": "2014-06-12",
"count": 1
},
{
"date": "2014-07-28",
"count": 1
},
{
"date": "2014-08-12",
"count": 1
},
{
"date": "2014-12-03",
"count": 1
},
{
"date": "2014-12-23",
"count": 1
},
{
"date": "2014-12-29",
"count": 1
},
{
"date": "2015-01-24",
"count": 1
},
{
"date": "2015-05-24",
"count": 1
},
{
"date": "2015-07-02",
"count": 1
},
{
"date": "2015-07-03",
"count": 1
},
{
"date": "2015-07-18",
"count": 1
},
{
"date": "2015-07-20",
"count": 1
},
{
"date": "2015-10-02",
"count": 1
},
{
"date": "2015-10-14",
"count": 1
},
{
"date": "2015-11-13",
"count": 1
},
{
"date": "2015-11-25",
"count": 1
},
{
"date": "2016-01-05",
"count": 1
},
{
"date": "2016-01-21",
"count": 1
},
{
"date": "2016-02-18",
"count": 1
},
{
"date": "2016-02-21",
"count": 1
},
{
"date": "2016-03-07",
"count": 1
},
{
"date": "2016-03-16",
"count": 1
},
{
"date": "2016-05-09",
"count": 1
},
{
"date": "2016-05-10",
"count": 1
},
{
"date": "2016-05-12",
"count": 1
},
{
"date": "2016-05-13",
"count": 1
},
{
"date": "2016-05-17",
"count": 1
},
{
"date": "2016-06-24",
"count": 1
},
{
"date": "2016-08-01",
"count": 1
},
{
"date": "2016-09-06",
"count": 1
},
{
"date": "2016-09-09",
"count": 1
},
{
"date": "2016-11-06",
"count": 1
},
{
"date": "2017-01-13",
"count": 1
},
{
"date": "2017-02-26",
"count": 1
},
{
"date": "2017-03-23",
"count": 1
},
{
"date": "2017-04-02",
"count": 1
},
{
"date": "2017-04-19",
"count": 1
},
{
"date": "2017-05-11",
"count": 1
},
{
"date": "2017-05-15",
"count": 1
},
{
"date": "2017-06-21",
"count": 1
},
{
"date": "2017-09-28",
"count": 1
},
{
"date": "2018-01-04",
"count": 1
},
{
"date": "2018-01-05",
"count": 1
},
{
"date": "2018-01-19",
"count": 1
},
{
"date": "2018-02-05",
"count": 1
},
{
"date": "2018-03-05",
"count": 1
},
{
"date": "2018-03-27",
"count": 1
},
{
"date": "2018-04-17",
"count": 1
},
{
"date": "2018-05-11",
"count": 1
},
{
"date": "2018-05-30",
"count": 1
},
{
"date": "2018-06-19",
"count": 1
},
{
"date": "2018-08-23",
"count": 1
},
{
"date": "2018-09-09",
"count": 1
},
{
"date": "2018-09-15",
"count": 1
},
{
"date": "2018-10-22",
"count": 1
},
{
"date": "2018-10-30",
"count": 1
},
{
"date": "2018-11-05",
"count": 1
},
{
"date": "2018-11-08",
"count": 1
},
{
"date": "2018-11-19",
"count": 1
},
{
"date": "2019-01-18",
"count": 1
},
{
"date": "2019-01-24",
"count": 2
},
{
"date": "2019-02-17",
"count": 1
},
{
"date": "2019-02-20",
"count": 1
},
{
"date": "2019-03-17",
"count": 1
},
{
"date": "2019-03-21",
"count": 1
},
{
"date": "2019-06-22",
"count": 1
},
{
"date": "2019-07-01",
"count": 1
},
{
"date": "2019-07-08",
"count": 1
},
{
"date": "2019-07-10",
"count": 1
},
{
"date": "2019-08-24",
"count": 1
},
{
"date": "2019-08-27",
"count": 1
},
{
"date": "2019-08-30",
"count": 1
},
{
"date": "2019-09-04",
"count": 1
},
{
"date": "2019-09-26",
"count": 1
},
{
"date": "2019-10-16",
"count": 1
},
{
"date": "2019-10-31",
"count": 1
},
{
"date": "2019-12-27",
"count": 1
},
{
"date": "2020-01-06",
"count": 1
},
{
"date": "2020-01-14",
"count": 1
},
{
"date": "2020-01-20",
"count": 1
},
{
"date": "2020-01-23",
"count": 1
},
{
"date": "2020-01-28",
"count": 1
},
{
"date": "2020-03-02",
"count": 1
},
{
"date": "2020-03-08",
"count": 1
},
{
"date": "2020-04-06",
"count": 2
},
{
"date": "2020-05-11",
"count": 1
},
{
"date": "2020-06-02",
"count": 1
},
{
"date": "2020-07-05",
"count": 1
},
{
"date": "2020-08-06",
"count": 1
},
{
"date": "2020-08-25",
"count": 1
},
{
"date": "2020-10-28",
"count": 1
},
{
"date": "2020-10-30",
"count": 1
},
{
"date": "2020-11-03",
"count": 1
},
{
"date": "2020-11-18",
"count": 1
},
{
"date": "2020-11-19",
"count": 1
},
{
"date": "2020-12-07",
"count": 1
},
{
"date": "2020-12-14",
"count": 1
},
{
"date": "2021-01-17",
"count": 1
},
{
"date": "2021-01-18",
"count": 1
},
{
"date": "2021-01-22",
"count": 1
},
{
"date": "2021-01-23",
"count": 1
},
{
"date": "2021-02-05",
"count": 1
},
{
"date": "2021-05-08",
"count": 1
},
{
"date": "2021-05-17",
"count": 1
},
{
"date": "2021-05-20",
"count": 1
},
{
"date": "2021-06-18",
"count": 1
},
{
"date": "2021-06-20",
"count": 1
},
{
"date": "2021-06-22",
"count": 2
},
{
"date": "2021-07-12",
"count": 1
},
{
"date": "2021-07-20",
"count": 1
},
{
"date": "2021-08-03",
"count": 1
},
{
"date": "2021-08-06",
"count": 1
},
{
"date": "2021-08-12",
"count": 1
},
{
"date": "2021-08-16",
"count": 1
},
{
"date": "2021-08-20",
"count": 1
},
{
"date": "2021-09-07",
"count": 1
},
{
"date": "2021-10-21",
"count": 1
},
{
"date": "2021-10-31",
"count": 1
},
{
"date": "2021-11-19",
"count": 1
},
{
"date": "2021-11-20",
"count": 1
},
{
"date": "2021-12-01",
"count": 1
},
{
"date": "2021-12-21",
"count": 1
},
{
"date": "2022-01-03",
"count": 1
},
{
"date": "2022-01-14",
"count": 1
},
{
"date": "2022-01-17",
"count": 1
},
{
"date": "2022-01-19",
"count": 1
},
{
"date": "2022-01-21",
"count": 1
},
{
"date": "2022-02-05",
"count": 1
},
{
"date": "2022-02-23",
"count": 1
},
{
"date": "2022-03-13",
"count": 1
},
{
"date": "2022-03-19",
"count": 1
},
{
"date": "2022-03-30",
"count": 1
},
{
"date": "2022-04-07",
"count": 1
},
{
"date": "2022-04-18",
"count": 1
},
{
"date": "2022-04-24",
"count": 1
},
{
"date": "2022-05-10",
"count": 1
},
{
"date": "2022-05-21",
"count": 2
},
{
"date": "2022-05-24",
"count": 1
},
{
"date": "2022-06-03",
"count": 1
},
{
"date": "2022-06-28",
"count": 1
},
{
"date": "2022-06-29",
"count": 1
},
{
"date": "2022-07-07",
"count": 1
},
{
"date": "2022-07-10",
"count": 1
},
{
"date": "2022-07-13",
"count": 1
},
{
"date": "2022-08-01",
"count": 1
},
{
"date": "2022-09-10",
"count": 1
},
{
"date": "2022-09-14",
"count": 1
},
{
"date": "2022-09-23",
"count": 1
},
{
"date": "2022-09-24",
"count": 1
},
{
"date": "2022-09-27",
"count": 1
},
{
"date": "2022-10-09",
"count": 1
},
{
"date": "2022-11-18",
"count": 1
},
{
"date": "2022-11-21",
"count": 1
},
{
"date": "2022-12-13",
"count": 1
},
{
"date": "2022-12-15",
"count": 1
},
{
"date": "2022-12-27",
"count": 1
},
{
"date": "2023-01-09",
"count": 1
},
{
"date": "2023-01-16",
"count": 1
},
{
"date": "2023-01-17",
"count": 1
},
{
"date": "2023-02-15",
"count": 1
},
{
"date": "2023-03-06",
"count": 1
},
{
"date": "2023-04-07",
"count": 1
},
{
"date": "2023-04-21",
"count": 1
},
{
"date": "2023-04-26",
"count": 1
},
{
"date": "2023-05-02",
"count": 1
},
{
"date": "2023-05-09",
"count": 1
},
{
"date": "2023-06-11",
"count": 1
},
{
"date": "2023-06-13",
"count": 1
},
{
"date": "2023-06-30",
"count": 1
},
{
"date": "2023-07-03",
"count": 1
},
{
"date": "2023-07-04",
"count": 1
},
{
"date": "2023-07-22",
"count": 1
},
{
"date": "2023-07-26",
"count": 1
},
{
"date": "2023-07-30",
"count": 1
},
{
"date": "2023-08-03",
"count": 1
},
{
"date": "2023-08-11",
"count": 1
},
{
"date": "2023-08-23",
"count": 1
},
{
"date": "2023-09-15",
"count": 1
},
{
"date": "2023-10-23",
"count": 1
},
{
"date": "2023-11-08",
"count": 1
},
{
"date": "2023-11-13",
"count": 1
},
{
"date": "2023-11-15",
"count": 1
},
{
"date": "2023-11-18",
"count": 1
},
{
"date": "2023-12-03",
"count": 1
},
{
"date": "2023-12-23",
"count": 1
},
{
"date": "2023-12-30",
"count": 1
},
{
"date": "2024-01-17",
"count": 3
},
{
"date": "2024-01-30",
"count": 1
},
{
"date": "2024-02-27",
"count": 1
},
{
"date": "2024-02-29",
"count": 1
},
{
"date": "2024-04-11",
"count": 1
},
{
"date": "2024-04-18",
"count": 1
},
{
"date": "2024-04-23",
"count": 1
},
{
"date": "2024-05-07",
"count": 1
},
{
"date": "2024-05-27",
"count": 1
},
{
"date": "2024-05-29",
"count": 1
},
{
"date": "2024-06-04",
"count": 1
},
{
"date": "2024-06-05",
"count": 1
},
{
"date": "2024-06-12",
"count": 1
},
{
"date": "2024-06-28",
"count": 1
},
{
"date": "2024-07-04",
"count": 1
},
{
"date": "2024-07-08",
"count": 1
},
{
"date": "2024-07-11",
"count": 2
},
{
"date": "2024-07-23",
"count": 1
},
{
"date": "2024-08-18",
"count": 1
},
{
"date": "2024-08-28",
"count": 1
},
{
"date": "2024-09-04",
"count": 1
},
{
"date": "2024-10-04",
"count": 1
},
{
"date": "2024-10-28",
"count": 1
},
{
"date": "2024-10-30",
"count": 1
},
{
"date": "2025-01-27",
"count": 1
},
{
"date": "2025-01-31",
"count": 1
},
{
"date": "2025-02-03",
"count": 1
},
{
"date": "2025-02-25",
"count": 1
},
{
"date": "2025-03-01",
"count": 1
},
{
"date": "2025-03-08",
"count": 1
},
{
"date": "2025-03-13",
"count": 1
},
{
"date": "2025-03-18",
"count": 1
},
{
"date": "2025-03-20",
"count": 1
},
{
"date": "2025-03-31",
"count": 1
},
{
"date": "2025-04-21",
"count": 1
},
{
"date": "2025-04-28",
"count": 2
},
{
"date": "2025-05-09",
"count": 1
},
{
"date": "2025-05-16",
"count": 1
},
{
"date": "2025-05-31",
"count": 1
},
{
"date": "2025-06-14",
"count": 1
},
{
"date": "2025-07-03",
"count": 1
},
{
"date": "2025-09-06",
"count": 1
},
{
"date": "2025-09-22",
"count": 1
},
{
"date": "2025-09-28",
"count": 1
},
{
"date": "2025-09-30",
"count": 1
},
{
"date": "2025-10-06",
"count": 1
},
{
"date": "2025-11-04",
"count": 1
},
{
"date": "2026-01-16",
"count": 1
},
{
"date": "2026-02-06",
"count": 1
},
{
"date": "2026-03-07",
"count": 1
},
{
"date": "2026-04-21",
"count": 1
},
{
"date": "2026-04-22",
"count": 2
},
{
"date": "2026-04-24",
"count": 1
},
{
"date": "2026-05-12",
"count": 1
},
{
"date": "2026-05-22",
"count": 1
},
{
"date": "2026-06-07",
"count": 1
},
{
"date": "2026-06-11",
"count": 1
},
{
"date": "2026-06-16",
"count": 1
},
{
"date": "2026-07-11",
"count": 1
}
],
"complete": true,
"collected": 257,
"total_forks": 268
},
"star_history": null,
"open_issues_and_prs": 17
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 758100,
"source_files_sampled": 1723,
"oversized_source_files": 38,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [],
"advisories": {
"error": "No resolved dependencies to assess",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [],
"collected": true,
"truncated": false,
"total_count": 0,
"direct_count": 0,
"indirect_count": 0
}
},
"maintainership": {
"issues": {
"open_prs": 9,
"merged_prs": 100,
"open_issues": 8,
"closed_ratio": 0.953,
"closed_issues": 163,
"closed_unmerged_prs": 98
},
"bus_factor": 2,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "chicpro",
"commits": 3586,
"avatar_url": "https://avatars.githubusercontent.com/u/2696233?v=4"
},
{
"type": "User",
"login": "whitedot",
"commits": 3065,
"avatar_url": "https://avatars.githubusercontent.com/u/1720041?v=4"
},
{
"type": "User",
"login": "thisgun",
"commits": 1614,
"avatar_url": "https://avatars.githubusercontent.com/u/4393429?v=4"
},
{
"type": "User",
"login": "kagla",
"commits": 1186,
"avatar_url": "https://avatars.githubusercontent.com/u/99459574?v=4"
},
{
"type": "User",
"login": "projectSylas",
"commits": 109,
"avatar_url": "https://avatars.githubusercontent.com/u/68883321?v=4"
},
{
"type": "User",
"login": "seeoya",
"commits": 62,
"avatar_url": "https://avatars.githubusercontent.com/u/54855563?v=4"
},
{
"type": "User",
"login": "sora90224",
"commits": 60,
"avatar_url": "https://avatars.githubusercontent.com/u/10395803?v=4"
},
{
"type": "User",
"login": "kkigomi",
"commits": 32,
"avatar_url": "https://avatars.githubusercontent.com/u/112419763?v=4"
},
{
"type": "User",
"login": "kitrio",
"commits": 30,
"avatar_url": "https://avatars.githubusercontent.com/u/7542987?v=4"
},
{
"type": "User",
"login": "minsupkr",
"commits": 26,
"avatar_url": "https://avatars.githubusercontent.com/u/7390511?v=4"
}
],
"contributors_sampled": 24,
"top_contributor_share": 0.364
},
"quality_signals": {
"has_ci": false,
"has_tests": false,
"ci_workflows": [],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 0,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 9,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "0b6f081f765ac1af204d53c6a2b17a1b25a71502",
"ran_at": "2026-07-24T16:53:21Z",
"aggregate_score": 3.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T07:15:22Z",
"oldest_open_prs": [
{
"number": 182,
"created_at": "2022-04-29T09:18:38Z",
"last_comment_at": "2022-08-03T06:20:05Z",
"last_comment_author": "kitrio"
},
{
"number": 192,
"created_at": "2022-06-03T01:36:17Z",
"last_comment_at": "2023-12-18T09:32:04Z",
"last_comment_author": "thisgun"
},
{
"number": 195,
"created_at": "2022-07-26T08:04:24Z",
"last_comment_at": "2023-12-18T09:32:18Z",
"last_comment_author": "thisgun"
},
{
"number": 197,
"created_at": "2022-08-02T09:34:32Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 260,
"created_at": "2023-07-26T04:50:43Z",
"last_comment_at": "2023-12-18T07:00:24Z",
"last_comment_author": "thisgun"
},
{
"number": 275,
"created_at": "2023-08-17T01:50:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 276,
"created_at": "2023-08-17T01:50:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 277,
"created_at": "2023-08-17T01:51:10Z",
"last_comment_at": "2024-01-02T02:48:45Z",
"last_comment_author": "thisgun"
},
{
"number": 302,
"created_at": "2024-01-30T07:33:13Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-04-06T03:20:42Z",
"ci_last_conclusion": null,
"oldest_open_issues": [
{
"number": 196,
"created_at": "2022-07-26T08:04:30Z",
"last_comment_at": "2024-01-02T01:59:49Z",
"last_comment_author": "thisgun"
},
{
"number": 226,
"created_at": "2023-03-06T11:15:13Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 227,
"created_at": "2023-04-04T11:18:04Z",
"last_comment_at": "2023-05-11T02:04:43Z",
"last_comment_author": "thisgun"
},
{
"number": 228,
"created_at": "2023-04-04T11:38:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 269,
"created_at": "2023-08-12T01:44:21Z",
"last_comment_at": "2023-12-18T01:37:35Z",
"last_comment_author": "thisgun"
},
{
"number": 272,
"created_at": "2023-08-13T21:19:44Z",
"last_comment_at": "2023-12-18T01:37:14Z",
"last_comment_author": "thisgun"
},
{
"number": 274,
"created_at": "2023-08-17T01:45:32Z",
"last_comment_at": "2023-09-15T16:39:14Z",
"last_comment_author": "smaker"
},
{
"number": 294,
"created_at": "2023-12-02T22:21:36Z",
"last_comment_at": "2023-12-18T01:39:20Z",
"last_comment_author": "thisgun"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/gnuboard/gnuboard5",
"host": "github.com",
"name": "gnuboard5",
"owner": "gnuboard"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"security": 34,
"vitality": 85,
"community": 46,
"governance": 63,
"engineering": 9
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 85,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"commits_last_year": 165,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 26
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "26/52 weeks with commits",
"points": 18,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 26
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "165 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 165
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 97,
"latest_release_tag": "v5.6.34",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 12.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "97 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 97
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~12.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 12.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 46,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "good",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"forks": 268,
"stars": 343,
"watchers": 40,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "343 stars",
"points": 41.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 343
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "268 forks",
"points": 20.2,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 268
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "40 watchers",
"points": 8.8,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 40
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"has_readme": false,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 63,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 24,
"top_contributor_share": 0.364
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 36% of commits",
"points": 14.3,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 36
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "24 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 24
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"merged_prs": 100,
"open_issues": 8,
"closed_issues": 163,
"issue_closed_ratio": 0.953,
"closed_unmerged_prs": 98
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "95% of issues closed",
"points": 44.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 95
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "100/198 decided PRs merged",
"points": 19.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 100,
"decided": 198
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"followers": 34,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "gnuboard",
"public_repos": 62,
"account_age_days": 5190
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "34 followers of gnuboard",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 34,
"login": "gnuboard"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "62 public repos, account ~14 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 62
}
},
{
"code": "account_age_years",
"params": {
"years": 14
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "critical",
"name": "Engineering Quality",
"value": 9,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "critical",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"has_ci": false,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "critical",
"name": "Documentation",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": false,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 34,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"ci_tests",
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 34,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 12,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 6,
"scorecard_aggregate": 3.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 5
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "critical",
"name": "AI Readiness",
"value": 28,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 30,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.56,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "56 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 29.9,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 56,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "critical",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 11,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.5,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "50 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 50,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"primary_language": "PHP",
"largest_source_bytes": 758100,
"source_files_sampled": 1723,
"oversized_source_files": 38
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "PHP without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "PHP"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "38/1723 source files over 60KB",
"points": 53.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 1723,
"oversized": 38
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-24T16:53:38.457993Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gnuboard/gnuboard5.svg",
"full_name": "gnuboard/gnuboard5",
"license_state": "custom",
"license_spdx": null
}