Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-25 19:56 UTC

manifest-cyber / cli

Public repository containing Manifest CLI Documentation and Releases

ShellMIT★ 3 estrellas⑂ 0 forksdesde feb 2023Ver en GitHub ↗

manifest-cyber/cli tiene un índice de salud de 55 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (75/100) y la más baja, AI Readiness (20/100). Se actualizó por última vez hace 1 día. 3 personas concentran la mayor parte del trabajo reciente.

55
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

55
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Manifest CyberOrganización
21 seguidores38 repositorios públicosdesde jun 2022

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

75Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 1 días
6.2/36Cadencia de commits — 9/52 semanas con commits
12.9/18Volumen de commits — 26 commits en el último año
10/10OpenSSF Scorecard: Maintained — 19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year26
human_commit_share1
days_since_last_push1
active_weeks_last_year9
Cómo se puntúa
27/27Publica versiones — 100 versiones publicadas
36/36Recencia de las versiones — última versión hace 3 días
27/27Cadencia de publicación — una versión cada ~6,2 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count100
latest_release_tagv0.36.3-beta.0
releases_from_tagsno
days_since_latest_release3
mean_days_between_releases6,2

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

27Crítico · 18% del índice global
Cómo se puntúa
4.9/60Estrellas — 3 estrellas
0/25Forks — 0 forks
1.7/15Observadores — 3 observadores
Datos de entrada utilizados
forks0
stars3
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

62Moderado · 24% del índice global
Cómo se puntúa
36/54Factor bus — la mitad de los commits recae en 3 contribuyente(s)
18.2/22.5Distribución de commits — el principal contribuyente firma el 19% de los commits
13.5/13.5Amplitud de contribuyentes — 11 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Datos de entrada utilizados
bus_factor3
contributors_sampled11
top_contributor_share0,189
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
35.5/38.3Aceptación de PR — 26/28 PR decididos fusionados
10.5/15OpenSSF Scorecard: Code-Review — Found 8/11 approved changesets -- score normalized to 7
Datos de entrada utilizados
merged_prs26
open_issues2
closed_issues0
issue_closed_ratio0
closed_unmerged_prs2
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
9.7/25Alcance del propietario — 21 seguidores de manifest-cyber
19.9/25Trayectoria — 38 repos públicos, cuenta de ~4 años
Datos de entrada utilizados
followers21
owner_typeOrganization
is_verified
owner_loginmanifest-cyber
public_repos38
account_age_days1510

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

54Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 2 flujo(s) de trabajo
0/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
16/20OpenSSF Scorecard: CI-Tests — 9 out of 11 merged PRs checked by a CI test -- score normalized to 8
Datos de entrada utilizados
has_ci
has_testsno
has_editorconfigno
has_linter_configno
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

52Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2/2.5CI-Tests — 9 out of 11 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
5.2/7.5Code-Review — Found 8/11 approved changesets -- score normalized to 7
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
4/5SAST — SAST tool is not run on all commits -- score normalized to 8
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,2
Excluidos de la puntuación (sin datos o no aplicable): packaging. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

20Crítico · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
35/40Historial de commits legible — 59 de 90 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,656
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
0/22Pruebas automatizadas
0/11Configuración de lint / formato
0/11Verificación estática de tipos
0/10Entorno reproducible
8.9/10Práctica demostrada con agentes — 4 de los últimos 90 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_testsno
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0,044
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
0/45Código verificable por tipos — Shell sin configuración de verificación de tipos
0/55Tamaños de archivo manejables — no se detectaron archivos fuente
Datos de entrada utilizados
primary_languageShell
largest_source_bytes
source_files_sampled0
oversized_source_files0
Excluidos de la puntuación (sin datos o no aplicable): Tamaños de archivo manejables. Los pesos restantes se han renormalizado.
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_files

Datos clave

3estrellas de GitHub
11contribuidores
26commits en los últimos 12 meses
1días desde el último push
100versiones publicadas
3factor bus
2issues abiertas
ecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

OpenSSF Scorecard 5.2 / 10
5.2agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-25 19:55 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
8CI-Tests9 out of 11 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
7Code-ReviewFound 8/11 approved changesets -- score normalized to 7
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
8SASTSAST tool is not run on all commits -- score normalized to 8
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Todas las dependencias 0

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 0 paquetes directos y 0 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Avisos de dependencias sin evaluar

El cotejo de avisos no pudo ejecutarse para este informe: No resolved dependencies to assess

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 475,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 11903
      },
      "pushed_at": "2026-07-24T14:49:07Z",
      "created_at": "2023-02-01T11:02:46Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T14:49:24Z",
      "description": "Public repository containing Manifest CLI Documentation and Releases",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Shell",
      "significant_languages": [
        "Shell"
      ]
    },
    "owner": {
      "blog": "https://manifestcyber.com",
      "name": "Manifest Cyber",
      "type": "Organization",
      "login": "manifest-cyber",
      "company": null,
      "location": "United States of America",
      "followers": 21,
      "avatar_url": "https://avatars.githubusercontent.com/u/106975015?v=4",
      "created_at": "2022-06-06T13:06:14Z",
      "is_verified": null,
      "public_repos": 38,
      "account_age_days": 1510
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.36.3-beta.0",
          "kind": "prerelease",
          "published_at": "2026-07-21T21:55:38Z"
        },
        {
          "tag": "v0.36.2",
          "kind": "patch",
          "published_at": "2026-07-17T17:07:47Z"
        },
        {
          "tag": "v0.36.1",
          "kind": "patch",
          "published_at": "2026-07-06T23:35:38Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-07-06T22:16:23Z"
        },
        {
          "tag": "v0.35.1-beta.0",
          "kind": "prerelease",
          "published_at": "2026-07-01T19:32:06Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2026-06-17T14:58:13Z"
        },
        {
          "tag": "v0.34.2",
          "kind": "patch",
          "published_at": "2026-06-10T21:50:18Z"
        },
        {
          "tag": "v0.34.1",
          "kind": "patch",
          "published_at": "2026-06-04T17:31:30Z"
        },
        {
          "tag": "v0.35.0-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-28T18:42:58Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2026-05-26T21:12:44Z"
        },
        {
          "tag": "v0.33.1-beta.2",
          "kind": "prerelease",
          "published_at": "2026-05-26T19:01:34Z"
        },
        {
          "tag": "v0.33.1-beta.1",
          "kind": "prerelease",
          "published_at": "2026-05-18T20:30:10Z"
        },
        {
          "tag": "v0.33.1-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-18T17:05:45Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2026-05-14T14:39:39Z"
        },
        {
          "tag": "v0.32.3-beta.1",
          "kind": "prerelease",
          "published_at": "2026-05-13T21:45:07Z"
        },
        {
          "tag": "v0.32.3-beta.0",
          "kind": "prerelease",
          "published_at": "2026-05-13T11:41:07Z"
        },
        {
          "tag": "v0.32.2",
          "kind": "patch",
          "published_at": "2026-05-08T20:41:40Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-05-05T19:24:07Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-04-28T20:29:27Z"
        },
        {
          "tag": "v0.31.2",
          "kind": "patch",
          "published_at": "2026-04-23T19:03:55Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-04-20T18:09:22Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-03-03T19:55:33Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-01-27T20:19:18Z"
        },
        {
          "tag": "v0.30.0-beta.3",
          "kind": "prerelease",
          "published_at": "2026-01-27T00:32:16Z"
        },
        {
          "tag": "v0.30.0-beta.2",
          "kind": "prerelease",
          "published_at": "2025-12-18T14:18:12Z"
        },
        {
          "tag": "v0.30.0-beta.1",
          "kind": "prerelease",
          "published_at": "2025-12-15T21:45:25Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2025-12-12T22:41:29Z"
        },
        {
          "tag": "v0.30.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-12-08T18:25:34Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2025-12-02T15:40:52Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2025-11-25T20:05:20Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2025-11-24T17:04:29Z"
        },
        {
          "tag": "v0.26.2",
          "kind": "patch",
          "published_at": "2025-10-03T17:37:49Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2025-08-29T15:21:12Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2025-08-28T20:25:01Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2025-08-20T16:09:40Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2025-08-15T19:22:47Z"
        },
        {
          "tag": "v0.23.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-08-15T01:33:50Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2025-07-01T12:12:43Z"
        },
        {
          "tag": "v0.21.4-beta.0",
          "kind": "prerelease",
          "published_at": "2025-06-27T15:48:22Z"
        },
        {
          "tag": "v0.22.0-beta.0",
          "kind": "prerelease",
          "published_at": "2025-06-25T19:16:26Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2025-06-13T14:11:20Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2025-06-12T18:10:23Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2025-05-19T12:57:57Z"
        },
        {
          "tag": "v0.21.1-beta.0",
          "kind": "prerelease",
          "published_at": "2025-05-18T14:24:46Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2025-05-05T17:04:08Z"
        },
        {
          "tag": "v0.21.0-rc.1",
          "kind": "prerelease",
          "published_at": "2025-05-05T15:15:20Z"
        },
        {
          "tag": "v0.20.2-beta.0",
          "kind": "prerelease",
          "published_at": "2025-05-02T16:23:52Z"
        },
        {
          "tag": "v0.21.0-rc.0",
          "kind": "prerelease",
          "published_at": "2025-04-30T15:14:30Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2025-04-23T20:29:20Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2025-04-23T16:31:01Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2025-04-21T15:38:25Z"
        },
        {
          "tag": "v0.18.8",
          "kind": "patch",
          "published_at": "2025-04-02T11:30:00Z"
        },
        {
          "tag": "v0.18.7",
          "kind": "patch",
          "published_at": "2025-03-05T19:46:03Z"
        },
        {
          "tag": "v0.18.6",
          "kind": "patch",
          "published_at": "2025-03-04T18:21:52Z"
        },
        {
          "tag": "v0.18.5",
          "kind": "patch",
          "published_at": "2025-03-03T16:59:56Z"
        },
        {
          "tag": "v0.18.4",
          "kind": "patch",
          "published_at": "2025-02-18T17:04:28Z"
        },
        {
          "tag": "v0.18.3",
          "kind": "patch",
          "published_at": "2025-01-16T15:58:40Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2025-01-15T18:06:24Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2024-12-11T11:02:08Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2024-11-26T13:42:18Z"
        },
        {
          "tag": "v0.17.4",
          "kind": "patch",
          "published_at": "2024-11-06T15:15:33Z"
        },
        {
          "tag": "v0.17.3",
          "kind": "patch",
          "published_at": "2024-10-25T21:48:25Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2024-10-01T16:43:20Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2024-09-30T21:03:55Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2024-09-23T16:30:24Z"
        },
        {
          "tag": "v0.17.0-beta.0",
          "kind": "prerelease",
          "published_at": "2024-09-20T19:04:27Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2024-08-27T18:56:47Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2024-08-14T08:35:18Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2024-08-05T16:11:04Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2024-07-21T18:51:59Z"
        },
        {
          "tag": "v0.14.9",
          "kind": "patch",
          "published_at": "2024-06-25T14:59:04Z"
        },
        {
          "tag": "v0.14.8",
          "kind": "patch",
          "published_at": "2024-05-23T12:59:27Z"
        },
        {
          "tag": "v0.14.7",
          "kind": "patch",
          "published_at": "2024-05-16T17:52:57Z"
        },
        {
          "tag": "v0.14.6",
          "kind": "patch",
          "published_at": "2024-05-10T14:50:20Z"
        },
        {
          "tag": "v0.14.5",
          "kind": "patch",
          "published_at": "2024-05-09T17:56:05Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2024-05-07T06:49:07Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2024-05-05T13:45:46Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2024-04-30T15:18:42Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2024-04-18T17:23:13Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2024-03-11T17:08:34Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2024-03-06T13:38:07Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2024-02-29T00:07:14Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2024-02-28T15:52:19Z"
        },
        {
          "tag": "v0.12.6",
          "kind": "patch",
          "published_at": "2023-12-31T15:56:49Z"
        },
        {
          "tag": "v0.12.5",
          "kind": "patch",
          "published_at": "2023-12-31T12:32:48Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2023-12-22T19:28:00Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2023-12-06T17:54:54Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2023-12-01T17:41:40Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2023-11-22T14:51:34Z"
        },
        {
          "tag": "v0.12.1-beta.1",
          "kind": "prerelease",
          "published_at": "2023-11-20T12:58:19Z"
        },
        {
          "tag": "v0.12.1-beta.0",
          "kind": "prerelease",
          "published_at": "2023-11-19T15:16:49Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2023-11-16T11:21:53Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2023-11-04T05:29:33Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2023-09-26T12:05:56Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2023-08-09T22:08:43Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2023-08-01T16:10:07Z"
        },
        {
          "tag": "v0.9.4",
          "kind": "patch",
          "published_at": "2023-07-28T04:48:06Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2023-07-27T13:30:06Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2023-07-25T21:07:39Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2023-07-20T20:49:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4e1525749499ec355e61eabe23cfc96396a9e67d",
          "body": "… (#32)\n\n## Summary\n\nDocuments which Manifest API token scope each CLI flag requires, and how\nto find a product ID, in the public CLI docs. Derived by tracing every\nmanifest-api call the CLI makes and mapping each endpoint to its\npermission guard.\n\n### README.md\n- New **Scope permissions by flag** t\n[…]\nre attached.\n* Included `crat`-specific authentication scope guidance and clarified\nthat `--llm-api-key` is not a Manifest token.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document API token scopes per flag and how to find a product ID…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-24T14:49:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3de8a1ef8f43c67aad37bb59df04ce7144e10fc4",
          "body": "Map the granular permission labels to the composite scope names shown on\nthe token creation screen: Manage SBOMs and VEX (--publish), Manage\nproducts + Manage assets (product flags), and View all pages and data\n(the read scope that covers scan-status polling and --download-vdr).",
          "is_bot": false,
          "headline": "docs: use the UI's composite scope names for token permissions",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-24T14:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ba4bd3a6158261d4f834fdc115afd25f2964da0",
          "body": "--product-id and --product-label only take effect together with --publish\n(the product association runs in the publish flow), so the example without\n--publish would not actually assign the SBOM to a product.",
          "is_bot": false,
          "headline": "docs: add --publish to the product-assignment sbom example",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-23T20:42:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abec2e2b394d66fa2cecae0ce9ae78d4eb6ae049",
          "body": "Adds a scope-permission reference so users know which token permissions\neach publish/product/VDR flag requires:\n\n- README.md: \"Scope permissions by flag\" table in the API Tokens section,\n  and expands the --product-id description with how to find a product ID\n  from its page URL.\n- ARGUMENTS.md: \"To\n[…]\nitionally require \"View all SBOMs and VEX documents\".\ncrat publishes, polls, and downloads a VDR, so its --api-key needs all\nthree publish/VDR scopes; --llm-api-key is unrelated to the Manifest token.",
          "is_bot": false,
          "headline": "docs: document API token scopes per flag and how to find a product ID",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-21T21:38:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27bcffce56345059e556fafd15abb558bed38c56",
          "body": "…ciliation (#29)\n\nAdds --update-product to the publish Snapshots flag reference in\nARGUMENTS.md and a \"Reconciling a Product's Inventory to a Snapshot\"\nsection in README.md. The flag reconciles a product's inventory to a\nsnapshot (removing snapshot-labeled assets that predate the timestamp)\nthen adds the published asset. Requires --product-id and both snapshot\nflags; mutually exclusive with --replace-in-product.",
          "is_bot": false,
          "headline": "docs: document the --update-product flag for snapshot inventory recon…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-07T12:58:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f91d01ec7e23cdc4d473ec3fb03a9a796d2c7e81",
          "body": "…ciliation\n\nAdds --update-product to the publish Snapshots flag reference in\nARGUMENTS.md and a \"Reconciling a Product's Inventory to a Snapshot\"\nsection in README.md. The flag reconciles a product's inventory to a\nsnapshot (removing snapshot-labeled assets that predate the timestamp)\nthen adds the published asset. Requires --product-id and both snapshot\nflags; mutually exclusive with --replace-in-product.",
          "is_bot": false,
          "headline": "docs: document the --update-product flag for snapshot inventory recon…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-07T12:54:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a29e33a02edc0fd21ffce184a99cbb0d15a52476",
          "body": "Documents the new `--supplier` flag on `generate` and `merge`, added to\nthe CLI in manifest-cli.\n\n## Changes\n\n- `ARGUMENTS.md`: `--supplier` row in the Generate and Merge flag\ntables, plus a \"Generate with a Supplier\" example.\n- `README.md`: `--supplier` entry in the generate flag list.\n\nThe flag se\n[…]\non is applied to generated and merged\nSBOM output.\n* Included an example showing how to generate an SBOM with a supplier\nvalue.\n\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document the --supplier flag (#28)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-06T23:18:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80bc6f0142b3782806930b6ce835758f67b3731c",
          "body": "Adds --supplier to the generate and merge flag references in ARGUMENTS.md\nand README.md, plus a generate example. The flag sets the supplier on the\nCycloneDX root component and BOM metadata; for SPDX it sets the package\nsupplier, falling back to --group.",
          "is_bot": false,
          "headline": "docs: document the --supplier flag for generate and merge",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-07-06T23:15:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8d140bcf614234f3bbb5ee971ab6797f0d2e732",
          "body": "## Summary\n\n- Add `csbom` as a supported generator in all relevant references\n(`--generator` flag descriptions and the Generators section)\n- Add `## Generating a C/C++ SBOM with csbom` section to README with\ninstall and usage example, linking to the new dedicated page\n- Add `## Workflow` section to \n[…]\nsh pipeline\n* Updated README and CLI argument docs to list `csbom` in generator\noptions for install/generate and related commands\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom and workflow documentation (#27)",
          "author_name": "Leidson Campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T17:32:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9bcd05c651fb5e9c8f24bb37cdf30b91db7b83d",
          "body": "- Fix \"analyses\" -> \"analyzes\" in csbom.md\n- Remove spdx-json from csbom output formats (cyclonedx-json only)\n- Add workflow command section to ARGUMENTS.md with --workflow-file, --preset, --file flags\n- Add workflow command to ARGUMENTS.md table of contents\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] address review feedback on csbom and workflow docs",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T17:01:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "10506c6595f32835bb6ac0b215e176785c45132c",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom to generator lists in ARGUMENTS.md",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-22T14:27:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9f763a825980b211a57849d48c4ee8641b5691aa",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom releases link to csbom.md",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-19T00:04:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ea52ba407ca213c1f36d634bc70f987ff61553cf",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: [CAP-2551] add csbom and workflow documentation",
          "author_name": "leidson-campos",
          "author_login": "leidson-campos",
          "committed_at": "2026-06-18T23:09:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f1521f4f9f0f4410dbf2537dabcc633094b9c25d",
          "body": "The `--version` flag for SBOM generation has no `-v` shorthand — `-v` is\nbound to `--verbose`. This removes the inaccurate `v,` prefix from the\nflag documentation so users don't try to use a shorthand that doesn't\nexist.",
          "is_bot": false,
          "headline": "docs: correct version flag, no -v shorthand (#25)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-12T21:31:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e061f473745c4102a17277843e2c5115f312e06",
          "body": "The --version flag for SBOM generation has no -v shorthand (-v is bound\nto --verbose). Remove the inaccurate 'v,' prefix from the docs.",
          "is_bot": false,
          "headline": "docs: correct version flag, no -v shorthand",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-12T21:20:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd356d3db5ed6b6a3fb12c6589d69574d761858e",
          "body": "…h flags (#24)\n\n## Summary\n\nDocuments previously-undocumented CLI publish functionality.\n\n**Snapshots**\n- README.md: a *Publishing Snapshots* section covering snapshot mode,\nthe paired `--snapshot-label` / `--snapshot-timestamp` flags, the\ndeactivation sweep, timestamp validation rules, and examples\n[…]\n with snapshot-mode semantics,\nuse cases, required flags, validation constraints, example commands, and\nCI integration guidance.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: document snapshot publishing and previously-undocumented publis…",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T16:02:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c09fd186516f67c0ac5b85cd4bf64a67e5854d93",
          "body": "…lace-in-product",
          "is_bot": false,
          "headline": "docs: add usage guide for deactivate-older, deactivate-label, and rep…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4150a7feeca4eb9010f92955edbee9fffc9369d1",
          "body": "…t publish flags",
          "is_bot": false,
          "headline": "docs: document name, version, deactivate-label, and replace-in-produc…",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:29:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "857ae9ca6f302e5eb31342354f1a1db6c89af164",
          "body": "Add a Publishing Snapshots section to the README and the --snapshot-label\nand --snapshot-timestamp flags to the publish command reference, covering\nsnapshot mode, timestamp validation rules, and usage examples.",
          "is_bot": false,
          "headline": "docs: document snapshot publishing in README and ARGUMENTS",
          "author_name": "Lexi",
          "author_login": "lsell-manifest",
          "committed_at": "2026-06-10T15:19:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50ebc94906fd6f07d50a461c788f960e67ed1bd0",
          "body": "…RLs (PLAT-1692) (#23)\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Documentation**\n* Added comprehensive CLI reference guide documenting all available\ncommands, flags, environment variables, and usage examples\n  * Updated repository URLs for apt and yum package installations\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
          "is_bot": false,
          "headline": "docs: update README, add updated exhausted arguments list, fix fury U…",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-24T17:10:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "884408ed3f3b4ab6ce821e0a9c3528a6a31e44f1",
          "body": null,
          "is_bot": false,
          "headline": "PLAT-1692: Add exhaustive arguments list",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-20T18:16:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "143c518e1c80353bd069a0ed5196defa59787f95",
          "body": null,
          "is_bot": false,
          "headline": "Update fury URLs (added from legacy PR from Ori)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2026-02-20T18:03:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7f25353e68b26375d15464a80bc2e49d01831ac",
          "body": "…n (#22)",
          "is_bot": false,
          "headline": "docs: update readme to include info on how to update to latest versio…",
          "author_name": "Marina",
          "author_login": "marinacabrerarosa",
          "committed_at": "2026-02-03T17:40:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfd374156209d1338da334e0fedfd74f13b5acff",
          "body": null,
          "is_bot": false,
          "headline": "docs: update readme to include info on how to update to latest version",
          "author_name": "Marina Rosa",
          "author_login": "marinacabrerarosa",
          "committed_at": "2026-02-03T16:23:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9872a9e69921984abb7a9237efaa15080320a925",
          "body": null,
          "is_bot": false,
          "headline": "docs: update api token creation screenshots (#21)",
          "author_name": "Marina",
          "author_login": "marinacabrerarosa",
          "committed_at": "2025-12-08T21:36:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1be10f2c0accf7f8f2ccbe81a3c9fcfbda8b1695",
          "body": null,
          "is_bot": false,
          "headline": "docs: update api token creation screenshots",
          "author_name": "Marina Rosa",
          "author_login": "marinacabrerarosa",
          "committed_at": "2025-12-08T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13756bd2a19b595fc1685ec103d0f5af79b4c6ec",
          "body": null,
          "is_bot": false,
          "headline": "feat: update docs for enrichment arg (#20)",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2025-04-30T16:45:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "540f17abcb522ac6855acc56ab599dcac48c1867",
          "body": null,
          "is_bot": false,
          "headline": "feat: update docs for enrichment arg",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2025-04-30T16:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46d4ee7880519bb788f2f2b4cfcf787bdba6c2d3",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): fix install methods [PLAT-459] (#19)",
          "author_name": "meghmanifest",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-22T13:32:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6ce8d47f153682fbe2d77ce433a2490c4c015a0",
          "body": null,
          "is_bot": false,
          "headline": "schedule for cron and pr workflow",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:54:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "233a822140ce396d8a7ae5008fa8df0390eb9af2",
          "body": null,
          "is_bot": false,
          "headline": "attempt for apt",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:32:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae078872c693aca198d2b4179d5779e70352c5cf",
          "body": null,
          "is_bot": false,
          "headline": "ci - attempt fix for scoop and apt",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T18:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05ea8b7d46805b5d84bc769ccb9e65bc1b848a20",
          "body": null,
          "is_bot": false,
          "headline": "update GH action test harness",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T17:59:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d20402535efb701c8d707136b97d1321cc3e91f4",
          "body": null,
          "is_bot": false,
          "headline": "Updates readme and adds test harness (attempt 1)",
          "author_name": "megh",
          "author_login": "meghmanifest",
          "committed_at": "2025-04-21T17:52:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7f7bbf04d6859f945cf56aaffec41cd4ce013ba",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md (#18)",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2025-04-21T14:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a863bd5e6ebbefd6e8a28bc77af076b843c5bb57",
          "body": "Signed-off-by: lsell-manifest <lexi@manifestcyber.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "lsell-manifest",
          "author_login": "lsell-manifest",
          "committed_at": "2025-04-18T17:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3c8a5d18f72f54374aea148974c499b65117a86",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix readme description for active flag (#17)",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2024-09-23T12:39:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f837f997603fd454dcf9172a6a25ecd389452ac",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix readme description for active flag",
          "author_name": "Cody Moore",
          "author_login": "dotCipher",
          "committed_at": "2024-09-23T01:49:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a86c64b0f28bc8c8bf64e75229ee6d8161a3d6f",
          "body": null,
          "is_bot": false,
          "headline": "Add generator installation example (#15)",
          "author_name": "Devon",
          "author_login": "devon-manifest",
          "committed_at": "2024-08-15T17:33:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb26ddcfe143e23b8f07f6aa19bccb61eb28a205",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2024-08-15T17:31:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2aaca154ae5652d6c2eee239fba3d3b2faf8ab7f",
          "body": "- Add active flag\r\n- Remove old sbom default filename reference",
          "is_bot": false,
          "headline": "docs(generate): Active flag documentation [MFST-3107] (#14)",
          "author_name": "Devon",
          "author_login": "devon-manifest",
          "committed_at": "2024-07-26T16:17:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf3cb44fed0ce6c16a59208caa3580e71cad64b8",
          "body": null,
          "is_bot": false,
          "headline": "Add active flag; remove old sbom name default filename",
          "author_name": "Devon Mackay",
          "author_login": "devon-manifest",
          "committed_at": "2024-07-26T16:07:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2677ec5364046efd0ea2c9c1877a6ca60280b221",
          "body": "…h (#13)",
          "is_bot": false,
          "headline": "docs: add info about generator installationshould be in execution pat…",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-06-25T13:16:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfd1c7be0fc28d12fcc43a2723eec8c9ceaff020",
          "body": null,
          "is_bot": false,
          "headline": "fix(docs): update yum repo setup",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-06-08T12:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94b2f52361700e416d966b83c997e28052297397",
          "body": null,
          "is_bot": false,
          "headline": "docs: add generator preset and config",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-23T16:37:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c86fb3e6837e51f74687a21816d1e269cabdeb9d",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): add  install command (#12)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2024-05-08T16:54:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "493a1830ff0cd00c582ef41c090a0f1058279705",
          "body": null,
          "is_bot": false,
          "headline": "docs(install): add  install command",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-08T16:51:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebfabaab41aba940deb505606721691ce0894bac",
          "body": null,
          "is_bot": false,
          "headline": "docs: cleanup deprecation notices",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:17:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3e6039fbc9683e7e111f4eac565fd8af28580b1",
          "body": null,
          "is_bot": false,
          "headline": "docs: update manifest to manifest-cli",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:13:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fe3c871566ec7ad16e4be88b6bdfc40450b018f",
          "body": null,
          "is_bot": false,
          "headline": "docs: update manifest to manifest-cli",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:12:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7793290c276650a5d6872218b64b134f0826707e",
          "body": null,
          "is_bot": false,
          "headline": "docs(publish): product and labels support",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-05-07T16:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d6e06e70aeaad8a9d5e7b137f5e145e750f2bfa",
          "body": null,
          "is_bot": false,
          "headline": "fix(install): use native cd and not pushd/popd",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-02-28T22:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46279e354a0e9a6beeef7659ecc1695af64b0be",
          "body": null,
          "is_bot": false,
          "headline": "chore(install): script updated to support rename",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-02-28T17:04:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa214789427d819baca5743031936ecdee53b73b",
          "body": null,
          "is_bot": false,
          "headline": "chore(docs): add manifest-cli change notice",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2024-01-18T09:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136cd327aec55f6d965767536e8d8cdd785a1560",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md (#10)",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-09-27T17:31:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcf9774cb0007ffeae67df56b259bbc71b42cfcd",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-09-27T17:30:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bed2db235f7421d9aad348553282cfb36b27f62",
          "body": " Use v2 GitHub action to generate and publish SBOMs\r\n\r\nGITHUBERINO NO RATE LIMIT PL0X",
          "is_bot": false,
          "headline": "MFST-44: Eating our dogfood and drinking our champagne! (#9)",
          "author_name": "Alper Demirci",
          "author_login": "alperdemirci",
          "committed_at": "2023-08-17T19:47:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f1f00ead4196cb15d4180d6f50e43c5ab37270",
          "body": "… action to generate and publish SBOMs",
          "is_bot": false,
          "headline": "MFST-44: Eating our dogfood and drinking our champagne! Use v2 GitHub…",
          "author_name": "wey-chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-08-15T21:25:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae3d3e7b939619754d52640eb88d89f903ef03c2",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix formatting issues",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T16:21:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ee51829bdb5a44ef03d48115c7d1dc783fde164",
          "body": null,
          "is_bot": false,
          "headline": "docs: update README.md for CDX versions [MFST-792] (#8)",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-08-01T16:20:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69ec0e548c53157fb3e2cad6b9fc2b18c61503bc",
          "body": null,
          "is_bot": false,
          "headline": "docs: update install script",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T16:06:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67dcc2886cb4fc8b6b35ad6346c4c0635d84a1de",
          "body": null,
          "is_bot": false,
          "headline": "chore: add install scripts",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-08-01T15:18:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9eafd0d27c16f9aeea7430b55fb64bc4006e8293",
          "body": null,
          "is_bot": false,
          "headline": "docs: add labels and deprecate --path (#6)",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-07-26T09:21:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d38cb01191cc84d6b7e3f1324f35ffc85ab8a153",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #7 from manifest-cyber/bardenstein-patch-1",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-07-25T16:35:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fcacd09dda03e2875ce14dce8e72e4b6d929a69",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-07-25T16:33:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa7072b6a24b5dea030ff1155d973fa249cffb98",
          "body": "* Update README.md\r\n\r\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>\r\n\r\n---------\r\n\r\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>\r\nCo-authored-by: manifestori <ori@manifestcyber.com>",
          "is_bot": false,
          "headline": "chore: update Docs for attestation (#5)",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-13T06:25:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cccca871cc9d7b563c7c4bb64f2b2745c2c57c2",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #4 from manifest-cyber/update-docs",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-07-05T14:34:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a19441214153f4a5ebfbb6652663f1019f29a8b7",
          "body": "Explicit callout for package manifests and updated example for pointing to two files\n\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-05T14:12:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6433f272254ae3102e6e41a4b19e5ccd6b21a377",
          "body": "Added best practices, annotations, and fixed some nits\n\nSigned-off-by: Weyland Chiang <71197790+wey-chiang@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-07-03T21:17:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ea19ebcb96c3c2f8df936b3cfd80d9a457ac70",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-22T17:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1399ac4db528f22836618d2cf5ab457211089612",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-16T17:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8984dc4b8b39103a3106ab8d8e49748c6496f780",
          "body": "Signed-off-by: Daniel B <bardenstein@gmail.com>",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-16T17:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6205b7429f879a75b9f298e2c55e5af3318f8db1",
          "body": "Readme cleanup",
          "is_bot": false,
          "headline": "Merge pull request #2 from manifest-cyber/readme-cleanup",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-03-11T16:44:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7b60e7efa29d70643942ecd7bae8a3a6df950ae",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into readme-cleanup",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17afabf887765e5b429115a84e019c8c6289cfb8",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #1 from manifest-cyber/wey-chiang-patch-1",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:43:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a8a6e906a172fa0406105e9cf3e0f6092ca46a0",
          "body": null,
          "is_bot": false,
          "headline": "Delete img2.png",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc210e5e9e101b4681133673a3105e5a46da395e",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-03-11T16:41:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a87f82165093fac71c9fa937897997824c4b086f",
          "body": "Cleaned up parts of the Installation section",
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Weyland Chiang",
          "author_login": "wey-chiang",
          "committed_at": "2023-03-11T14:25:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "610922c434d26412a84d47642c358c619540f268",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:14:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e89fd96f9e548df013dd4041fbc379320eaa458",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:13:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "195126c54213278bc9eb7b97218006febee5e936",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:06:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1006b038363ff148dd6eb73a2ceb83d024eccdd6",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:01:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "572390f76add1c854d3995ab5d861a391878db5a",
          "body": null,
          "is_bot": false,
          "headline": "Images for README",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T14:00:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "916b2ec43f8ed70b8dfd306573bcfcdff427d538",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c971e25282fd23c2e06e6f8486db167a8ed518d",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:55:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc47bd0dd4f8bf4be1b0180a59b47cfa758e93d",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f5bbd2ca60f18b9d337edd4d27a6bf7175b9a65",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Daniel B",
          "author_login": "bardenstein",
          "committed_at": "2023-03-11T13:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0e64345ab57a393f6bc55f22734a9d2129d7d35",
          "body": null,
          "is_bot": false,
          "headline": "chore: add license",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-02-21T16:23:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69c528e7200db7d37e754d6e6748beae61a4561c",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "Andrew Defee",
          "author_login": "adefee",
          "committed_at": "2023-02-10T18:08:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "170c563a22726c1eaf8bff7a3297217b37d2f2a6",
          "body": null,
          "is_bot": false,
          "headline": "Initial commit",
          "author_name": "manifestori",
          "author_login": "manifestori",
          "committed_at": "2023-02-01T11:02:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 26,
      "latest_release_at": "2026-07-21T21:55:38Z",
      "latest_release_tag": "v0.36.3-beta.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 6.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 0,
      "stars": 3,
      "watchers": 3,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": null,
      "source_files_sampled": 0,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 26,
        "open_issues": 2,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 3,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "manifestori",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/116580393?v=4"
        },
        {
          "type": "User",
          "login": "lsell-manifest",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/174354346?v=4"
        },
        {
          "type": "User",
          "login": "adefee",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/4471948?v=4"
        },
        {
          "type": "User",
          "login": "bardenstein",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/862262?v=4"
        },
        {
          "type": "User",
          "login": "wey-chiang",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/71197790?v=4"
        },
        {
          "type": "User",
          "login": "meghmanifest",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/207568321?v=4"
        },
        {
          "type": "User",
          "login": "leidson-campos",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/252052331?v=4"
        },
        {
          "type": "User",
          "login": "dotCipher",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/3977074?v=4"
        },
        {
          "type": "User",
          "login": "marinacabrerarosa",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/218649872?v=4"
        },
        {
          "type": "User",
          "login": "devon-manifest",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/146471916?v=4"
        }
      ],
      "contributors_sampled": 11,
      "top_contributor_share": 0.189
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "install.test.yml",
        "production.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 7,
            "reason": "Found 8/11 approved changesets -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 8,
            "reason": "SAST tool is not run on all commits -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4e1525749499ec355e61eabe23cfc96396a9e67d",
        "ran_at": "2026-07-25T19:55:54Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T00:42:33Z",
      "oldest_open_prs": [
        {
          "number": 30,
          "created_at": "2026-07-15T11:08:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 31,
          "created_at": "2026-07-15T11:08:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T14:49:08Z",
      "ci_last_conclusion": "STARTUP_FAILURE",
      "oldest_open_issues": [
        {
          "number": 11,
          "created_at": "2024-03-29T17:25:12Z",
          "last_comment_at": "2024-04-30T16:53:10Z",
          "last_comment_author": "manifestori"
        },
        {
          "number": 26,
          "created_at": "2026-06-17T23:46:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/manifest-cyber/cli",
    "host": "github.com",
    "name": "cli",
    "owner": "manifest-cyber"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 52,
        "vitality": 75,
        "community": 27,
        "governance": 62,
        "engineering": 54
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "commits_last_year": 26,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "26 commits in the last year",
                "points": 12.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.36.3-beta.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 6.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 27,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 7,
            "inputs": {
              "forks": 0,
              "stars": 3,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "3 stars",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 62,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 11,
              "top_contributor_share": 0.189
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 19% of commits",
                "points": 18.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 19
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "11 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "merged_prs": 26,
              "open_issues": 2,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "26/28 decided PRs merged",
                "points": 35.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 26,
                      "decided": 28
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 8/11 approved changesets -- score normalized to 7",
                "points": 10.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "followers": 21,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "manifest-cyber",
              "public_repos": 38,
              "account_age_days": 1510
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "21 followers of manifest-cyber",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 21,
                      "login": "manifest-cyber"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "38 public repos, account ~4 yr old",
                "points": 19.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 38
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 54,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "9 out of 11 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 8/11 approved changesets -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "critical",
        "name": "AI Readiness",
        "value": 20,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.656,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "59 of 90 human commits state their intent (structured subject or explanatory body)",
                "points": 35,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 59,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 9,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.044,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 90 commits agent-authored or agent-credited",
                "points": 8.9,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "critical",
            "name": "Code legibility for models",
            "note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "manageable_file_sizes"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "primary_language": "Shell",
              "largest_source_bytes": null,
              "source_files_sampled": 0,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Shell without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Shell"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "no source files detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_source_files",
                    "params": {}
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T19:56:12.861623Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/manifest-cyber/cli.svg",
  "full_name": "manifest-cyber/cli",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadas.