Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-24 22:51 UTC

kubenexis / knxvault

A cloud-native, Kubernetes-native secrets management platform for secure storage, encryption, PKI, and dynamic secrets.

GoApache-2.0★ 2 estrellas⑂ 1 forkdesde jun 2026Ver en GitHub ↗

kubenexis/knxvault tiene un índice de salud de 46 sobre 100, lo que lo sitúa en la banda En riesgo. Su puntuación más alta es Engineering Quality (78/100) y la más baja, Sustainability & Governance (24/100). Se actualizó por última vez hace 5 días. Una sola persona concentra la mayor parte del trabajo reciente.

46
global / 100
En riesgo

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

46
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

kubenexisCuenta personal
0 seguidores1 repositorio públicodesde jun 2026

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/kubenexis/knxvaultv0.5.1-1hace 6 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

64Moderado · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 5 días
2.1/36Cadencia de commits — 3/52 semanas con commits
18/18Volumen de commits — 187 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year187
human_commit_share1
days_since_last_push5
active_weeks_last_year3
Cómo se puntúa
27/27Publica versiones — 1 versiones publicadas
36/36Recencia de las versiones — última versión hace 6 días
12.6/27Cadencia de publicación — cadencia desconocida (una sola versión)
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count1
latest_release_tagv0.5.1
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

24Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 1 forks
0/15Observadores — 2 observadores
Datos de entrada utilizados
forks1
stars2
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

24Crítico · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
0/25Alcance del propietario — 0 seguidores de kubenexis
2.3/25Trayectoria — 1 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers0
owner_typeUser
is_verified
owner_loginkubenexis
public_repos1
account_age_days24
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 6 días
4/20Historial de versiones — 1 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/kubenexis/knxvault
ecosystemsgo
any_deprecatedno
min_days_since_publish6

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

78Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 1 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yml
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

36En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3,6
Excluidos de la puntuación (sin datos o no aplicable): ci_tests. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

68Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yml
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — Dockerfile, lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
55/55Tamaños de archivo manejables — 0/560 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes31.575
source_files_sampled560
oversized_source_files0
Cómo se puntúa
40/40Esquema de API (OpenAPI/GraphQL/proto) — api/openapi.yaml
0/20Servidor MCP
40/40Ejemplos ejecutables — examples, recipes, samples
Datos de entrada utilizados
example_dirsexamples, recipes, samples
has_mcp_signalno
api_schema_filesapi/openapi.yaml

Datos clave

2estrellas de GitHub
1contribuidores
187commits en los últimos 12 meses
5días desde el último push
1versiones publicadas
1factor bus
0issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 3.6 / 10
3.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-24 22:51 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
6Vulnerabilities4 existing vulnerabilities detected
Dependencias directas 23
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/gin-gonic/ginv1.12.0go.mod
Gogithub.com/go-playground/validator/v10v10.30.3go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/jackc/pgx/v5v5.10.0go.mod
Gogithub.com/lni/dragonboat/v3v3.3.8go.mod
Gogithub.com/prometheus/client_golangv1.23.2go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/viperv1.21.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelginv0.69.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogolang.org/x/cryptov0.53.0go.mod
Gogoogle.golang.org/grpcv1.82.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gok8s.io/apiv0.34.1go.mod
Gok8s.io/apimachineryv0.34.1go.mod
Gok8s.io/client-gov0.34.1go.mod
Gomodernc.org/sqlitev1.53.0go.mod
Gosigs.k8s.io/controller-runtimev0.22.4go.mod
Gosigs.k8s.io/secrets-store-csi-driverv1.6.0go.mod
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2401,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1708248,
        "Java": 613,
        "Rust": 333,
        "Shell": 44035,
        "Python": 279,
        "Makefile": 22390,
        "Dockerfile": 2396,
        "TypeScript": 264
      },
      "pushed_at": "2026-07-19T04:11:51Z",
      "created_at": "2026-06-30T08:55:34Z",
      "owner_type": "User",
      "updated_at": "2026-07-17T16:50:41Z",
      "description": "A cloud-native, Kubernetes-native secrets management platform for secure storage, encryption, PKI, and dynamic secrets.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "kubenexis",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/298201111?v=4",
      "created_at": "2026-06-30T08:51:08Z",
      "is_verified": null,
      "public_repos": 1,
      "account_age_days": 24
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-07-18T19:33:54Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e49904c5470d0d77d26d1f8bc375295d9cb7a56b",
          "body": "Remove knxvault-cli from the distroless Dockerfile. The CLI remains a\nhost-only admin tool via make build-cli and CI artifact upload. Mark\nW86-21 complete and realign image/docs catalog.",
          "is_bot": false,
          "headline": "fix(packaging): keep knxvault-cli off the server container image",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f40fe12be20624ef4383c40da70db2958557da08",
          "body": "Map post-W85 re-audit Critical/High/Medium residuals to backlog IDs\nW86-01…W86-22 (plus Low L01–L04), with audit mapping report and\nsecurity-model pointer. Engine packs W78–W85 remain closed.",
          "is_bot": false,
          "headline": "docs(security): add W86 full-audit findings to security backlog",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:43:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f28b373caeb6118b8b61bee1a241de6ad5adc61",
          "body": "Use the cobra version flag so the quality job fails if either binary\nis missing or non-runnable after build-cli.",
          "is_bot": false,
          "headline": "ci: smoke-check knxvault and knxvault-cli with -v",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:25:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aaabc6864bc1d5a1b825fb0492ab3fa2fd9a5670",
          "body": "Include knxvault-cli in the distroless server image, smoke-check host\nbinaries after make build-cli, and upload knxvault + knxvault-cli as\nworkflow artifacts so CI always produces the CLI.",
          "is_bot": false,
          "headline": "ci: build and publish knxvault-cli in Actions and image",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:25:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77c70e98898cd0792be14df38116405f613b021c",
          "body": "No Critical/High/Medium remaining; summarize W81–W85 remediation series.",
          "is_bot": false,
          "headline": "docs(audit): cycle-5 final HOLD re-audit after W85",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:11:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56b242b4057bd62607f1f355ab1e6d1be0e36e1a",
          "body": "Reserve cubbyhole, wrapping, database/ssh creds, transit keys, and\nsys/internal so secrets/* ACLs cannot bypass wrap/cubby isolation.",
          "is_bot": false,
          "headline": "fix(security): W85 deny KVv2 access to internal engine paths",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T16:06:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d82ab48e47b141565217a870f042d8cdbda62ab9",
          "body": "Bound OCSP request body; hold wrap GC under mutex. Document cycle-3\nHOLD (no Critical/High/Medium remaining).",
          "is_bot": false,
          "headline": "fix(security): W84 cycle-3 hygiene after HOLD audit",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c1bb8b499b0667fd85f62bb7876e157b31f80dc",
          "body": null,
          "is_bot": false,
          "headline": "docs(security): note W83 cycle-2 remediation in security model",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:56:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51e8de8e517864e8f560976cc9c971a7d3a394e9",
          "body": "Deny bare GRANT role membership and dangerous pg_* roles; make wrapping\nmeta CAS/cluster-first for single-use HA; ImportCA rejects non-RSA keys.",
          "is_bot": false,
          "headline": "fix(security): W83 cycle-2 residual High/Medium pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:53:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc546745fb7704fd49a304a42ff215b5def73d85",
          "body": "Normalize managed SQL (comments/whitespace) and deny ROLE/IN ROLE\nmembership forms; reject ImportCA RSA keys below 2048 bits.",
          "is_bot": false,
          "headline": "fix(security): W82 cycle-1 residual Medium pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:46:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf81e2def26268869a0decbb92c1df39bf0d053d",
          "body": "Intermediate pathLenZero, unseal min /16, TokenReview audiences,\nlab-only master-as-unseal, RSA 2048 floor, mount-scoped vault sign,\n90d default max leaf TTL, operator Secret ownership, webhook TLS\nmanifests, HTTPS edge defaults, SQL denylist, and tests/docs.",
          "is_bot": false,
          "headline": "fix(security): W81 High/Medium residual audit pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:38:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1949a294a5384f55fad8faf879f9bb9753190e36",
          "body": "Close post-W79 High/Medium findings: Cloudflare SafeHTTP, managed SQL\nGRANT ALL/IN ROLE deny, production disables coarse PKI write, operator\nSecrets least-priv, unseal CIDR max breadth, shared exposure HA replay,\ndoctor lab-profile warn, and base NetworkPolicy egress hardening.",
          "is_bot": false,
          "headline": "fix(security): W80 High/Medium residual audit pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:17:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08028ecee0067c28a1b28e4ce1440c8e5ce0e74e",
          "body": "Use calmer Election/Heartbeat RTT for Dragonboat under CI load, wait for\nquorum and real leadership, propose via current leader with retries, fix\nfailover to stop the actual leader, quiet dragonboat logs, retry port\nbind, and run integration tests serially with a 5m timeout.",
          "is_bot": false,
          "headline": "test(integration): harden flaky multi-node Raft suite",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T15:03:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3be9390ff5c77553e06ddf75814b70fe1cb34a2",
          "body": "Disable env proxy on SafeHTTP clients; expand SSRF blocks (CGNAT/metadata);\nrequire OIDC audience and HTTPS JWKS; ban managed SQL privilege attrs;\nreject world-open unseal CIDRs; remove cluster Secret read from operator\nRBAC; fine-grained PKI permission checks with legacy pki fallback; drop\nAppRole legacy unsalted hashes; force client EKU on issue-client-cert.\nAdd unit tests and audit docs.",
          "is_bot": false,
          "headline": "fix(security): W79 residual audit pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T14:50:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2513f1e394ae32892a8f92e43ea34ccfa221f1a5",
          "body": "CreateRoot accepts optional allowed_domains for the auto role; add\nPUT /pki/roles/:name and CLI flags. Integration/e2e set domains when\nissuing. E2E harness always rebuilds bins so flags stay current.",
          "is_bot": false,
          "headline": "fix(test): restore PKI issue after W78 deny-default roles",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T14:17:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "871eff5afe256f73ca2b10e40f46204ee352ed24",
          "body": "Close High/Medium audit findings: CSR email/URI SAN deny, LDAP MaxExpiresAt,\nACME SSRF under SkipTLS, secure default PKI role, ban sql_strict=false,\noperator namespaced Secrets RBAC, production unseal CIDRs, OIDC issuer/JWKS\nSSRF, audit-forward SafeHTTPClient, PKI KeyUsage EKU, CSI fileName basename,\nImportCA key match, AppRole salted hash, unseal constant-time compare, SSH\nleast-privilege defaults. Add unit tests and security docs.",
          "is_bot": false,
          "headline": "fix(security): W78 full audit remediation pack",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T14:06:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e2ee9d3eefd8cd8af4ea238c10b3824499747bb",
          "body": "Run make quality plus integration/SBOM on PR and main, then build\nserver/operator images, Trivy-scan them, and push validated tags to\nghcr.io/<owner>/knxvault{,-operator} on main and v* releases.",
          "is_bot": false,
          "headline": "ci: add GitHub Actions quality gate and GHCR publish",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T13:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "690e1760fe0b4631309c56c3b9161c5a1161fef6",
          "body": "Default server and operator refs to GHCR (ghcr.io/kubenexis/knxvault and\nknxvault-operator), with IMAGE_ORG override for forks. Align K8s manifests\nand ops docs with the same image form.",
          "is_bot": false,
          "headline": "feat(container): name images as ghcr.io/kubenexis/<repository>",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T13:23:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e65a8b79a329ef14ad82fd5a0719ff6d2e92a7e2",
          "body": "After build, resolve short tags or docker.io/library/* before save so\ncontainer-export does not fail when nerdctl only records the FQ name.",
          "is_bot": false,
          "headline": "fix(make): harden container image detect/export for nerdctl",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T12:40:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8628b361235d5cdf9c9174c41edb7dfda05615d",
          "body": "With .ONESHELL, only the first recipe line honors @. Prefix recursive\n$(MAKE) invocations with @ so users see \"Quality gate passed.\" (and\nstage logs) instead of raw printf/make statements.\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "fix(make): silence recipe echo under .ONESHELL for quality/all",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T12:26:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9859d1d913e9e800f5f805f94c29e2a48647dbd",
          "body": "W77 cert login is fail-closed (stored roles only). Seed e2e-client role\nso TestE2ECertLoginHTTP matches production mapping behavior.\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "test(integration): register persisted role for cert login e2e",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T12:22:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d98a0f8c1bf43b35287b973f1fc60fc383355595",
          "body": "Cycle A: cert login fail-closed (stored roles only); KV soft-delete marks\nlatest destroyed; token Issue/Create set MaxExpiresAt.\nCycle B: seal guard on OCSP and login; listener TLS path jail; skip\nexposure auto-actions while sealed.\nCycle C: single-segment glob *; docs/audit report; unit tests.\nAlso\n[…]\nand W76 residual pack (Incr lockout, ACME dial SSRF, exposure\nprefixes, multi-node master-key guard, Shamir share hardening).\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "fix(security): W77 three-cycle audit remediations",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T12:15:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc1d32400a82ff3a651db31bbf275f3ab8066adb",
          "body": "…eases)\n\nCycle 1: fail-closed unseal CIDRs; seal-aware JobRunner; webhook SSRF via\nSafeHTTPClient and startup URL validation.\nCycle 2: path-safe tenant lease IDs (ns.id); DB/SSH renew/revoke tenant checks;\nempty-ns fail-closed for lease access.\nCycle 3: cert login blocks privileged CN synthetic policies; docs and audit\nreport; unit tests for new guards. Quality coverage gates remain ≥80%/70%.\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "fix(security): W76 three-cycle remediation (seal jobs, SSRF, tenant l…",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T12:02:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d7f547fbe892563943a86f478f13579d21d151a",
          "body": "go.mod requires go >= 1.26.5; container builds failed when ENV forced\ngo1.26.4. Align Dockerfile, operator Dockerfile, and install docs.\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "fix(docker): pin builder GOTOOLCHAIN to go1.26.5",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T11:19:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dedff1245dfbffc1944fd54cdf35c8e6db771287",
          "body": "- Record Kubenexis Systems Private Limited as project sponsor (SPONSORS.md)\n- Use \"Copyright Kubenexis Systems Private Limited.\" in SPDX headers\n- Add best-effort unit tests for previously untested packages with real logic\n- Fix metrics default (MetricsDedicatedOnly) so /metrics stays on API by default\n- Point e2e binary/GOCACHE at build/ to avoid filling host /tmp\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "chore: sponsor file, copyright holder, tests, and integration fixes",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T11:04:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f49fbf20facca28e229e2c5cc7e39afac02b0ccc",
          "body": "Align with CNCF Charter §11 IP policy: outbound code under Apache-2.0,\ndocumentation under CC-BY-4.0. Add LICENSE texts, NOTICE, REUSE.toml,\nfile-level SPDX headers, DCO, OpenAPI license metadata, and CI gates\nfor SPDX headers (make license-headers-check).\n\nSigned-off-by: build01 <build01@csj-build-01.engineering.kubenexis.local>",
          "is_bot": false,
          "headline": "chore(license): CNCF dual license Apache-2.0 code and CC-BY-4.0 docs",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T10:27:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739f9c0e12f02e5fc13cf9fcd24a3573dfd1ec3e",
          "body": "Ship production kustomize/NetPol, metrics plane split, unseal CIDR\nallowlist, doctor --profile production, soft-tenant lease IDs with\nADR-0011 single-trust-domain stance, aes-kek auto-unseal, and ACME\negress samples. Include W74 audit hardening (LDAP, wrap/transit/cubbyhole,\nidentity) and Go 1.26.5 quality-gate toolchain pins.",
          "is_bot": false,
          "headline": "feat(security): W74 remediations and W75 CIS hardening (P0–P3)",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T10:20:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "417ad637b666c2da512d193654fa560ccbf4fe9c",
          "body": "Ship M-PRODSEC-1 A1 (lab/production security profile fail-closed), M-LEASE-1\nunified renew/revoke/tidy with token cascade, M-WRAP-1 cubbyhole and response\nwrapping, M-TRANSIT-1 encryption-as-a-service, M-IDENT-1 entity/group/alias,\nW70 native LDAP (IdP→OIDC preferred), and M-SYNC-1 secret sync matrix docs.\n\nIncludes unit tests, recipes, architecture/API/ops docs, and backlog updates.",
          "is_bot": false,
          "headline": "feat: production security profile, transit, wrap, leases, identity, LDAP",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T09:37:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c5cf44e4268f77c425a45134c9dd86ff1314953",
          "body": "Add design for provider registry, webhook v1, multi-solver CRDs, and\noptional in-tree Route53/RFC2136. Define milestone M-DNS01-1 and backlog\nW61-01–W61-18; link from ACME design and support matrix.",
          "is_bot": false,
          "headline": "docs: M-DNS01-1 plan for cert-manager-class DNS-01 webhooks",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:39:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a9c3a2373b9a89e930b8dd7289f46c69e67981f",
          "body": "quality runs fmt, vet, lint, docs-lint, gosec, licenses, scan, test, and\ntest-coverage. all depends on quality then integration, binaries, and sbom.",
          "is_bot": false,
          "headline": "build: add make quality pre-merge gate",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:35:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e7564704b890ec6eabb1256e22a9f303cfff3e5",
          "body": null,
          "is_bot": false,
          "headline": "docs: note container-export rebuilds images before save",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de2b0fdbc1e5733b8e9a80d47e138e04a018e259",
          "body": "Export targets rebuild images first so make clean container-export-all\nworks. Clearer error if image inspect still fails after build.",
          "is_bot": false,
          "headline": "fix(make): container-export depends on container-build",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:33:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1648e90e5cc74bc6b4450b588655c3010341e43a",
          "body": null,
          "is_bot": false,
          "headline": "docs: document IMAGE_TAG version-commit in air-gap export section",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:23:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e78d832683f5a541ee9b31aa1c513a9b99d0b70",
          "body": "Use IMAGE_TAG=$(VERSION)-$(COMMIT) for knxvault and operator images and\nair-gap archives under build/images/. Also tag VERSION-only aliases and\nwrite build-info-*.txt for inventory.",
          "is_bot": false,
          "headline": "build: include git commit in image tags and export tarball names",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T05:23:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18159567209c3f754cd7b084196edb8c9cc60b34",
          "body": "Update Makefile, version package, Dockerfiles, deployment image tags,\nconfig defaults/tests, and documentation references.",
          "is_bot": false,
          "headline": "chore: bump version to 0.5.1",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:55:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a1f595509a2d7ead1c295444e00f481940c5372",
          "body": "Binaries → build/bin/, air-gap image tarballs → build/images/, SBOM and\ncoverage profiles under build/. Update scripts, docs, clean, and gitignore.",
          "is_bot": false,
          "headline": "build: put all artifacts under build/",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:53:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5dc71b1ec7ba122cbe557209629a30a2db7d4f4c",
          "body": null,
          "is_bot": false,
          "headline": "docs: document container-export-all in quick reference",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a898d414cd941f6d4fec73dd7125fadd7a08071",
          "body": "Add container-export, k8s-operator-export, and container-export-all\nwriting dist/images/*.tar via docker/nerdctl save. Document load steps\nfor standalone and Kubernetes offline deploys.",
          "is_bot": false,
          "headline": "feat(make): export container images as air-gap tarballs",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:49:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3d845baedc2a9645b17828d5c0dc4bfe54058a4",
          "body": "…r-build\n\nPrefer container-build, k8s-operator-build, container-build-all. Keep\ndocker-build* as deprecated aliases. Update docs accordingly.",
          "is_bot": false,
          "headline": "refactor(make): rename image targets to container-build / k8s-operato…",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:44:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26d09236f9fcc4b2103c4b125d54254f357168c9",
          "body": "Prefer docker, then rootless nerdctl, then sudo nerdctl when rootless\ncontainerd is down. Document DOCKER= override for containerd hosts.",
          "is_bot": false,
          "headline": "fix(make): auto-select working docker/nerdctl for image builds",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "860a4e1fb380b470aa55fc596de49893a9c6ca13",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix kv get redaction context in k8s CLI Day-2 guide",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:19:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d74c8923f9e5df2ab92857b019ba4fbb9d285b5b",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt knxvault-cli acme command",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:18:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2aefb06d847422200aba818a2c106ce7def0eb92",
          "body": "Implement host-side ACME automation shared with the operator engine:\nfile account/cert state, profile YAML, HTTP-01 webroot/listen, DNS-01\nwiring, renew helpers, knxvault-cli acme (register/issue/renew/status/\ndoctor/agent). Add examples, systemd units, ADR-0010, vaultstore stub.\nUpdate Day-0/Day-2, CLI, matrix, HLD, and backlog W60. Coverage gate\nsplits operator (≥80%) and acme (≥70%).",
          "is_bot": false,
          "headline": "feat(acme): M-ACME-1 unified Let's Encrypt CLI for standalone and K8s",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:10:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82a136ef669f18e21a30bb1655d1652be7570bee",
          "body": "Add design for ACME/LE on Kubernetes and standalone with knxvault-cli\nacme commands; define milestone M-ACME-1 and backlog W60-01–W60-17;\nlink multi-issuer ACME design and support matrix.",
          "is_bot": false,
          "headline": "docs: design M-ACME-1 unified Let's Encrypt automation",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T04:03:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13e50cc2fc5068ea4572137d7fb0307156b8bcb8",
          "body": "Add build-and-deploy-images.md (image catalog, K8s vs standalone matrix,\nnerdctl standalone steps, air-gap save/load). Add Dockerfile.operator and\nmake docker-build-operator / docker-build-all. Cross-link from install,\nDay-0 guides, and README.",
          "is_bot": false,
          "headline": "docs: build/deploy image guide for containerd and Kubernetes",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:51:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b0dd6eeb7da4421f66d88ac453d2b9ffe9d1bcb",
          "body": "Add a single coherent K8s story centered on knxvault-cli (port-forward or\nService URL, unseal, doctor, KV/PKI, Day-2). Link from runbook, day2,\nstandalone guide, install Option 3, CLI reference, and README.",
          "is_bot": false,
          "headline": "docs: Kubernetes host-CLI Day-0/Day-2 guide",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d66d6ad322eb9444fcc634f42cad94c06eac0c4b",
          "body": "Handle line-wrapped \"AS IS\", detect contributor-name BSD-3 clause,\ncheck BSD-3 before BSD-2, and add a module override for go-difflib.",
          "is_bot": false,
          "headline": "fix(licenses): recognize go-difflib BSD-3-Clause LICENSE text",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:44:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c83317c626c051efbd2937df631a759420eedd1",
          "body": "Add a single coherent runbook for non-Kubernetes installs: distroless\nserver, published API port, host knxvault-cli (no container discovery),\nRaft unseal, smoke, acceptance, and Day-2 ops. Link from install, K8s\nrunbook, day2, CLI reference, and README.",
          "is_bot": false,
          "headline": "docs: standalone distroless + host CLI Day-0/Day-2 guide",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:43:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e10cd85e042a422beea5cd1f1d50d48f50b5350e",
          "body": "Check Body.Close errors, omit redundant RoundTripper type, compare ECDSA\nkeys via Equal instead of deprecated D field.",
          "is_bot": false,
          "headline": "fix: clear acme errcheck and staticcheck lint findings",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:36:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f78b42a3a4d29c1b45fa8b92ee43d4f9131eafa",
          "body": "Use #nosec G402 (gosec does not honor //nolint:gosec) on lab-only\nInsecureSkipVerify paths gated by SkipTLSVerify.",
          "is_bot": false,
          "headline": "fix: silence gosec G402 for opt-in ACME SkipTLSVerify",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b91318e77c79188f0805d2644e8f3015e4ae55d",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt vaultiface auth.go after dead helper removal",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:25:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "873aeeaa01a788afb4b48147f02ff373bc64135d",
          "body": "Remove dead OpenSSL-era helpers and empty branches; use type conversion for\ncluster issuer specs; drop deprecated Result.Requeue assertion.",
          "is_bot": false,
          "headline": "fix: clear golangci-lint unused/gosimple/staticcheck findings",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:23:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a81234d7162911f12c84d2dd3cf2959a569291a5",
          "body": "Ship knxvault exclusively as multi-stage → gcr.io/distroless/static-debian13:nonroot.\nPKI issuance is always in-process Go crypto/x509; delete openssl wrapper/backend,\nstartup openssl probes, breaker metric/alert, and related config knobs (reject if set).",
          "is_bot": false,
          "headline": "feat: distroless debian13 only; remove OpenSSL CLI PKI backend",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-17T03:16:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4408db44d83635cf9d4b796e8f82392009724a82",
          "body": "Capture the full PQ readiness discussion: current blocks, dual planes,\ngenerations, Harbor non-participation, way forward, decisions, and open\nquestions under docs/pq/design-and-architecture-discussion.md.",
          "is_bot": false,
          "headline": "docs(pq): add design and architecture discussion narrative",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T09:39:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f70dbfc6cf15532b74f7e147b0a72b2b437cefc4",
          "body": null,
          "is_bot": false,
          "headline": "docs: link operator runbook to PQ readiness section",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T09:38:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24eb5100fd416113088404a74c12811c9db4580a",
          "body": "Add docs/pq with current crypto state, roadmap, dual crypto planes,\ncrypto generations (g1/g2/g3), and standalone PQ-* backlog. Link from\ndocs index, security model, main backlog, and operator runbook.",
          "is_bot": false,
          "headline": "docs(pq): post-quantum readiness section, dual-plane design, PQ backlog",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T09:37:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b82373cc7ac52bda00fe1cbc21d44d1e1b376220",
          "body": null,
          "is_bot": false,
          "headline": "docs: point indexes at Day-0 + Day-2 operator runbook wording",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:49:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99758719805d87a92a5cf5ac4b1c8166e51a5d5c",
          "body": "Restructure operator-runbook.md so Day-0 is a complete path (plan, keys,\ninstall, unseal, RBAC bootstrap, operator CA/cert, first KV, acceptance)\nand Day-2 covers post-acceptance operations. Update index links.",
          "is_bot": false,
          "headline": "docs: expand operator runbook with full Day-0 and Day-2 structure",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:49:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e1a7b9eb80bb1ed857d85e42523de17f3ffea2c",
          "body": "Single narrative covering what knxvault is, master/unseal custody,\nK8s install, seal/unseal, certs and CSI, day-2, troubleshooting, and\nlinks for deeper reading. Indexed from README, day2, install, and\ngetting-started.",
          "is_bot": false,
          "headline": "docs: end-to-end operator runbook for smart administrators",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:48:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58fa12a1f64f0fc3a53b9543a3c1467867980fb5",
          "body": null,
          "is_bot": false,
          "headline": "docs: replace smartedge.local with example.local in lab E2E host name",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:38:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37332dc1fd462542b9f0353e8bf52428baee9ff7",
          "body": "Add e2e-and-lab-tests.md as the canonical map (unit → integration →\nlab multi-share 53/53). Align testing, seal recipe, operator security,\nMT-33, install/config, CLI, day2, and index docs with current harness\nand lab flows; mark lab-e2e-test01 as historical.",
          "is_bot": false,
          "headline": "docs: comprehensive E2E / multi-share test documentation",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:38:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73745a52bf008373e8d03f9f20b775aacac0d306",
          "body": "… plane\n\nExercise Shamir ops flow on e2e-test01: offline split (scripts/shamir-split),\nKNXVAULT_UNSEAL_THRESHOLD=2, submit shares only (no full-key open path),\nre-seal ceremony with alternate share pair, then full suite.\n\nLab result: SUMMARY|PASS=53 FAIL=0 (2026-07-16). Docs updated.",
          "is_bot": false,
          "headline": "test(e2e): lab multi-share unseal — start sealed, t-of-n shares, data…",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:32:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e3b8845c65002900e29c9cc2c2f2dc27ab6ee24",
          "body": "Fix local daemon and lab full E2E after W50-03/W52 start-sealed:\n- e2e harness unseals with master-key fallback after /ready\n- lab-full-e2e.sh POSTs /sys/unseal before operator/checks; W53 share-split probes\n- w53_e2e_test.go: Shamir multi-share HTTP, tenant PKI, cert login\n\nDocs: lab-full-e2e 44/44 PASS (2026-07-16), testing.md, seal recipe, W53 audit.",
          "is_bot": false,
          "headline": "test(e2e): unseal after start; W53 multi-share/tenant/cert; lab 44/44",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:27:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eac59e98995229f65e268636292dbfb005e4657a",
          "body": "… login, shared rate/lockout\n\nDeliver the five deferred residual items from the full security audit:\n\n- Tenant isolation for DB/SSH/PKI via scopeResourceName when KNXVAULT_TENANT_MODE\n- Shamir GF(2^8) multi-share unseal (SubmitShare, generate-unseal-shares, threshold)\n- AppRole encrypted Raft blob a\n[…]\nrt login (CN/SAN → role policies)\n- Valkey-backed SharedLockoutTracker and SharedRateLimiter with local fallback\n\nDocs: security-model, configuration, seal recipe, API reference, OpenAPI, backlog W53.",
          "is_bot": false,
          "headline": "feat(security): W53 residual multi-tenant, Shamir, AppRole Raft, cert…",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3976b7c763c1fe3a6fd2cdd5c8d5d418711ecf",
          "body": "Critical: seal.state cannot auto-unseal without key. High: PKI\nallowed_domains required (default deny, explicit *); SignCSR/Issue use\npersisted roles with default * role per CA; path-scoped vaultcompat sign\n(no coarse pki write); rate limit on by default; CSI/SDK HTTPS for\nnon-loopback. Medium: IP SANs need *; leaf TTL 72h; agent explicit\npolicies; OCSP rate limit; k8s insecure needs lab flag; sidecar example\nscoped token. Coverage gate 81.8%. Docs + W52 backlog.",
          "is_bot": false,
          "headline": "fix(security): W52 remediate full security audit findings",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:10:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cd074fc10705eaa27e53664df79fd434b9aef95",
          "body": "ParseTTL rejects non-positive/huge values; admin CreateToken clamps to\n30d; backup create validates JSON; HTTP-01 tokens and webhook mount\npaths reject path tricks; lockout map bounded under stuffing. Coverage\ngate 81.8%. Docs: formal-3cycle-tech-review report.",
          "is_bot": false,
          "headline": "fix: 3-cycle technical review — TTL, backup, HTTP-01, lockout bounds",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T08:02:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cceb3cc1954dabe15572f7aa4f495942cca091b7",
          "body": "CSR SignCSR enforces role AllowedDomains/MaxTTL; RequireKVAccess and\nrelated paths fail closed; ACME directory static SSRF checks; ESO path\ntraversal rejected; client cert fingerprint is SHA-256; agent path\nrejects ..; audit redact expanded. Coverage gate 81.5%. Formal report\ndocs/audit/formal-5cycle-security-auditor-2026-07-16.md + W51 backlog.",
          "is_bot": false,
          "headline": "fix(security): 5-cycle security auditor pass (PKI + Go)",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T07:48:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b959f9276f87e7a4ee4f844fd7b487562ddbf93",
          "body": "PKI-focused Golang security auditor skill for code review and formal\naudits: threat modeling, PKI lifecycle checklist, Go secure-coding\nchecklist, KNXVault hotspots, and structured finding format.",
          "is_bot": false,
          "headline": "docs(skills): add knxvault-security-auditor persona",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T07:44:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ded8b78baa746d9f0a652a6e83c00c3122bdf25c",
          "body": "Ten review→remediate→test→document cycles. Restores make test-coverage\nto 81.4% (was 74%). Fixes include: metrics bearer length-safe compare,\npathauth fail-closed, SealGuard exact /sys/unseal, KV list prefix\ntraversal, ACME nil solvers + LE skipTLS, PublicLEHost suffix match,\nsafe HTTP transport clone, audit forward Details deep-copy, lockout\nsingle primary key, DEK memzero on ReencryptDEK. Formal audit report\nand testing/security-model doc updates.",
          "is_bot": false,
          "headline": "fix(security): 10-cycle bugfix, coverage gate ≥80%, docs",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T07:42:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44c4091f9124d72c8ca7d5ba2657257cc73e3f31",
          "body": "ACME account keys load/store via PrivateKeySecretRef; DEK memzero on\nSeal/Open; RBAC sync fail-closed; trusted proxies + identity lockout;\nmetrics bearer auth; multi-node Raft mTLS gate; rate-limit bucket\neviction; managed SQL allow-list; CSI socket 0700/0660; exposure HMAC\ntimestamp; OpenAPI vault-compat paths; 72h root token TTL; bounded\naudit forwarder queue/metrics; unseal progressive backoff; path-scoped\nPKI sign capability. Backlog and security docs updated; tests green.",
          "is_bot": false,
          "headline": "fix(security): complete W50-13 and W50-16–30 audit remediations",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T07:37:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11e83b010ef39d80b03154b4cb8e11e44f0ca15c",
          "body": "Add P0/P1 W50-01–W50-30 backlog from full-codebase audit 7f32c606 and\nimplement Critical/High fixes:\n\n- ESO: require inbound token (SA auto-login opt-in only)\n- Webhook: TLS cert/key required (plaintext only with explicit env)\n- Seal: block all data-plane methods; start sealed with unseal key; seal.\n[…]\nOpenSSL CN validation; auth middleware fail-closed; agent TTL ≤1h\n- Operator Gateway RBAC; install docs for TokenReview role\n\nRemaining W50-13 (account key Secret load/store) Partial; W50-16+ P2 open.",
          "is_bot": false,
          "headline": "fix(security): W50 audit remediation + backlog for all observations",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T06:57:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc56f30f15e50698b0526b4293245d475d6fdc0a",
          "body": "Complete formal 10-cycle structured audit and /review-style multi-pass\naudits of the entire knxvault codebase (not diff-only): core vault,\noperator/ACME, CSI/ESO/webhook, Raft/crypto, deploy RBAC.\n\nReview ID 7f32c606 @ HEAD 5242c30. go test ./... green at audit time.",
          "is_bot": false,
          "headline": "docs(audit): full-codebase 10-cycle + multi-pass security review",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T06:20:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5242c30f86a1e390de48beafcb4cead4b479d78c",
          "body": "Record multi-pass findings for operator multi-issuer/ACME/vaultcompat\nstack (HTTP-01 wiring gaps, webhook SSRF, TOS, ClusterIssuer secrets,\nGateway RBAC). Review ID f29a75bd.",
          "is_bot": false,
          "headline": "docs(audit): formal 10-cycle + review-skill audit for main vs origin",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T06:14:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebc0af30f6a9466612bacabd7b8918f680ab7f48",
          "body": "Implement practical cert-manager replacement beyond private CA:\n\n- internal/acme: RFC 8555 client (x/crypto/acme), HTTP-01, DNS-01\n  (Cloudflare, webhook, memory), self-signed issuer; unit coverage ≥80%\n- Multi-issuer CRDs: vault | acme | selfSigned on Issuer/ClusterIssuer\n- Certificate controller d\n[…]\n Certificate/Issuer fields\n- Samples, support matrix, design docs, HLD/user/admin updates\n- Lab full E2E 41/41 including self-signed multi-issuer path\n\nNo new copyleft deps (golang.org/x/crypto only).",
          "is_bot": false,
          "headline": "feat(operator): multi-issuer ACME/SelfSigned to replace cert-manager",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T06:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a94b3d4267009b67567000623a399c69991afa05",
          "body": "Add operator process environment variables and point at Vault profile\nAppRole registration API.",
          "is_bot": false,
          "headline": "docs(config): document knxvault-operator and AppRole admin env",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T05:50:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "018e830e3ec3d0d963a8e21ddecc666f32b7c62b",
          "body": "Align documentation with shipped operator (W30 + hardening), Vault\nproduct profile (internal/compat/vault), intermediate CA / CSR sign,\nAppRole, and full lab E2E.\n\n- HLD/LLD/diagrams: operator-first TLS, façade adapters, scope updates\n- Phase 4–5 design: mark W30 complete; remaining waves\n- Admin: day2, PKI admin, install, configuration operator env\n- User: getting-started intermediate hierarchy; dummies operator-first\n- Index and recipes cross-links",
          "is_bot": false,
          "headline": "docs: refresh architecture, design, admin, and user guides",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T05:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e737980022ba0fff1fa9f427a7d400b9052860f",
          "body": "Add scripts/lab-full-e2e.sh covering core CLI/API, Vault product profile\n(cert-manager paths), and knxvault-operator CRDs on 192.168.137.131.\nDocument last run at 67d546d; make lab-full-e2e target.",
          "is_bot": false,
          "headline": "test(lab): complete full E2E suite on e2e-test01 (38/38 PASS)",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T05:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67d546dc7556b1606fc6f3f72f9054dce9a3bb97",
          "body": "Add internal/compat/vault product profile (health, auth envelopes, sign\nrequest/response mapping) and expand the thin HTTP adapter so cert-manager\ncan use KNXVault without a real Vault:\n\n- GET /v1/sys/health (200/429/503)\n- Kubernetes + AppRole login, custom auth mounts, X-Vault-Token\n- Full sign bo\n[…]\nnt/sign/:role\n- Admin POST /sys/auth/approle for AppRole registration\n- SignCSR falls back to role-as-CA-name when no PKI role record exists\n\nDocs: cert-manager recipe, API reference, k8s integration.",
          "is_bot": false,
          "headline": "feat(vaultcompat): full cert-manager Vault issuer profile via façade",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T05:29:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4732199bfb708cc47a14ab609aec9e29fbad4d14",
          "body": "Split pure certificate decision into certlogic; vaultiface auth module;\nshared fail helper; remove dead parseCSR and stub CRD; CRD required\nfields/enums; robust lab-operator-e2e. Coverage gate ≥80% on pure\npackages (89.9%). Full E2E PASS on 192.168.137.131.",
          "is_bot": false,
          "headline": "refactor(operator): hygiene — extract certlogic, tighten CRDs, lab e2e",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T05:17:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b553bc1b134da75f48fdb454e0a79dca0aa2904b",
          "body": null,
          "is_bot": false,
          "headline": "docs: note native pki APIs used by operator",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:49:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c06d24129ddc85e6c07f1edb6c2ab9aa70a44c12",
          "body": "SA/k8s login with token fallback, leader election, issuer Ready via\nGET /pki/ca/by-name, issue returns ca_id, Secret annotations, renew\npreference, CSR POST /pki/sign, delivery Secret|None, reconcile backoff,\nnamespaced RBAC example. Coverage gate ≥80% on pure logic packages.\nLab E2E validated on 192.168.137.131 (37 SSH unavailable).",
          "is_bot": false,
          "headline": "feat(operator): P0–P2 hardening for cert-manager replacement",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a291924137552535f0784ba58558edd4f019671",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix .gitignore after coverage artifact noise",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:23:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e56d80b101c236f47110efc91b99c9531ad3031b",
          "body": "Implement knxvault-operator with controller-runtime: KNXVaultCA,\nIssuer/ClusterIssuer, Certificate (TLS Secret), CertificateRequest,\noptional Ingress annotation shim. Add make build-operator, 80% pure-logic\ncoverage gate, lab e2e, and pki-replace-cert-manager docs. Align k8s\ndeps with controller-runtime v0.22. Lab e2e PASS on 192.168.137.131\n(192.168.137.37 SSH unavailable).",
          "is_bot": false,
          "headline": "feat(operator): ship W30 CRD automation replacing cert-manager",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:23:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f597b084b84e2e4eb6b07912fd7b892cf060595",
          "body": "Detail W30-01–W30-10 (Certificate CRD, renew, Issuer, Ingress shim,\nkind e2e, docs, migration, CSR). Align phase4-ecosystem design with P0.",
          "is_bot": false,
          "headline": "docs(backlog): expand W30 P0 program for cert-manager replacement",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:02:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec8807212cabb57228bc1ba2efb043ea546a4116",
          "body": "Add W30-02–W30-10 high-priority items for native Certificate/CA\nautomation so clusters use KNXVault PKI without cert-manager.",
          "is_bot": false,
          "headline": "docs(backlog): P0 operator CRDs to replace cert-manager",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T03:02:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74f57b52bc2321d4bbcc3107c37f61f0c526d6be",
          "body": "Print stderr note when kv get redacts values so users discover\n--show-secrets. Add docs-lint (check-kv-get-docs) to make all, unit\nand e2e coverage for redaction hint, and fix remaining bare examples.",
          "is_bot": false,
          "headline": "fix(cli): hint on redacted kv get; lint bare docs examples",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T02:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7445b4567721ad0f129525435aa44e135ce00212",
          "body": "Require KNXVAULT_UNSEAL_KEY for Raft across install, K8s Secret, recipes,\nand operator guidance. Document doctor verify, ready fields, and CLI\nKV redaction in getting-started and Day-2 paths.",
          "is_bot": false,
          "headline": "docs: complete P0–P3 admin/user updates from lab E2E",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T02:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19e8f642b20c83f7cee173fcf682c1efc784da12",
          "body": "Document 20/20 smoke on 192.168.137.131 (health, doctor, auth, KV, PKI).\nRequire KNXVAULT_UNSEAL_KEY in Raft single-node recipes after serve failure.",
          "is_bot": false,
          "headline": "docs: record lab E2E PASS on e2e-test01 (single-node Raft)",
          "author_name": "build01",
          "author_login": null,
          "committed_at": "2026-07-16T02:08:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b973d5329f3973efd48cf32c9508c42ac3f4b433",
          "body": "Remove redis.go/redis_client.go and introduce valkey.go plus a generic\nRESP client. Configure via KNXVAULT_VALKEY_CACHE_URL (KNXVAULT_REDIS_CACHE_URL\ndeprecated alias). Valkey is the documented Apache 2.0 cache; redis:// URLs\nstill parse during migration. Update W33 docs and add config/cache tests.",
          "is_bot": false,
          "headline": "refactor(cache): replace Redis client with Valkey RESP backend",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T10:28:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4412b03b3c8f3eb66d7e3fa2e7e01af17c57a720",
          "body": "Format new test and source files with gofmt. Resolve golangci-lint\nfindings in kvlabels middleware, redis client, tenant integration test,\nand remove unused invalidatePolicyHash helper.",
          "is_bot": false,
          "headline": "chore: gofmt and fix lint issues for CI pipeline",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T10:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1542bbb346e6d7a584ef8917a61bc2322c16aaa4",
          "body": "Audit entry forward payloads now use lowercase JSON field names per\naudit.Entry struct tags; align forward_test assertions.",
          "is_bot": false,
          "headline": "fix(review-cycle-5): update SIEM forward test for audit JSON tags",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:47:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bed8941ffd38319f471b656c1b89f232c82dba4",
          "body": "Add /sys/auth/lockout OpenAPI path and enrich PolicySimulateRequest schema.\nAdd EnrichKVResourceLabels middleware regression test. Document lockout\nclear audit and ABAC met status in security-model and BFSI response.",
          "is_bot": false,
          "headline": "fix(review-cycle-5): OpenAPI sync, middleware test, and doc alignment",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:45:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc4d293238cb132439c90d444e3a836a9bd16fb0",
          "body": "Pass resource_labels through policy simulation API for ABAC testing.\nSanitize login failure_reason values in audit (no raw error strings).\nEmit auth.lockout.clear audit on admin break-glass clear. Extend simulate\nunit test for owner_match denial.",
          "is_bot": false,
          "headline": "fix(review-cycle-4): policy simulate labels and audit hygiene",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:45:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7445ddc41a40e63e55ae68f9e5ce7f4a5da5d18",
          "body": "Require auth/agent write for agent delegation (already wired in router).\nAdd handler tests for delegate permission denial and lockout clear API.\nExtend OpenAPI AuditEntryResponse and LockoutClearRequest schemas.",
          "is_bot": false,
          "headline": "fix(review-cycle-3): delegate RBAC tests and OpenAPI audit schema",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f49b95288baa61f429c2960b7926b0e74c7a8e5",
          "body": "Set failure_reason on lockout rejection for K8s/OIDC/token login. Sanitize\ntoken login failure audit messages. Deduplicate lockout tracking via\nnoteLockoutFailure. Cap DB/SSH lease renewal grace at 24h separately from\nPKI RenewGrace; add unit test.",
          "is_bot": false,
          "headline": "fix(review-cycle-2): lockout audit reasons and lease renewal grace",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4433852678233f3e56fe1c55253bf6d9d88e24a5",
          "body": "Guard ResourceLabels map access in policy evaluator to prevent nil panics\non owner_match and resource_label conditions. Add JSON tags on audit.Entry\nso SIEM forward payloads include enriched auth fields. LabelsForPath no\nlonger emits spurious secret.metadata audit events; add regression test.",
          "is_bot": false,
          "headline": "fix(review-cycle-1): nil-safe ABAC labels and audit forward schema",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27ff04b17bd715f6dfd48baee48050b9d125e47b",
          "body": "Wire path-aware PKI/inject/KV authorization, ABAC labels and environment\nattributes, auth audit enrichment and lockout, SSH lease orchestration,\npolicy simulate/import CLI, and comprehensive unit tests. Update backlog\nand operator documentation to reflect Complete status.",
          "is_bot": false,
          "headline": "feat: complete W41-W44 backlog items (path auth, ABAC, audit, leases)",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T09:43:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72b15d427b6c773aa3bc74ff34f95261fe836ae0",
          "body": "Code-audit Phase 4-5 items as Complete (19), Partial (25), or Not started (2).\nAdd Status column to Tier I/J/K/L and Phase 5 tables; update gap summaries\nand remove stale \"Not started\" labels where features are already shipped.",
          "is_bot": false,
          "headline": "docs(backlog): reconcile item status with codebase audit",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T06:38:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f12b9919c6f189e34ece6eb6ba87e80c01d3d35",
          "body": null,
          "is_bot": false,
          "headline": "chore: gofmt after review cycle fixes",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T06:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f0135ddd2e53709a9709256f319944bcb5478e3",
          "body": "…avior",
          "is_bot": false,
          "headline": "docs: document cache generation, exposure replay, and bulk revoke beh…",
          "author_name": "KNXVault Docs",
          "author_login": null,
          "committed_at": "2026-07-02T06:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 187,
      "latest_release_at": "2026-07-18T19:33:54Z",
      "latest_release_tag": "v0.5.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 6,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/kubenexis/knxvault",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/kubenexis/knxvault",
          "is_deprecated": false,
          "latest_version": "v0.5.1",
          "repository_url": "https://github.com/kubenexis/knxvault",
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T19:25:48Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-30",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "recipes",
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "api/openapi.yaml"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 31575,
      "source_files_sampled": 560,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/gin-gonic/gin",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.12.0"
        },
        {
          "name": "github.com/go-playground/validator/v10",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v10.30.3"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.10.0"
        },
        {
          "name": "github.com/lni/dragonboat/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.3.8"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.2"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.53.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.82.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.1"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.1"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        },
        {
          "name": "sigs.k8s.io/controller-runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.4"
        },
        {
          "name": "sigs.k8s.io/secrets-store-csi-driver",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "kubenexis",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/298201111?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e49904c5470d0d77d26d1f8bc375295d9cb7a56b",
        "ran_at": "2026-07-24T22:51:34Z",
        "aggregate_score": 3.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kubenexis/knxvault",
    "host": "github.com",
    "name": "knxvault",
    "owner": "kubenexis"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 46,
      "inputs": {
        "security": 36,
        "vitality": 64,
        "community": 24,
        "governance": 24,
        "engineering": 78
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 64,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 187,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "187 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 187
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.5.1",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "critical",
        "name": "Sustainability & Governance",
        "value": 24,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "critical",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 15,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "kubenexis",
              "public_repos": 1,
              "account_age_days": 24
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of kubenexis",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "kubenexis"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "1 public repos, account ~0 yr old",
                "points": 2.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 1
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "good",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "packages": [
                "github.com/kubenexis/knxvault"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 78,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 36,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 31575,
              "source_files_sampled": 560,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/560 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 560,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples",
                "recipes",
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "api/openapi.yaml"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "api/openapi.yaml",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "api/openapi.yaml"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, recipes, samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, recipes, samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T22:51:38.836577Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kubenexis/knxvault.svg",
  "full_name": "kubenexis/knxvault",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.