Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"minfraud",
"maxmind"
],
"is_fork": false,
"size_kb": 8683,
"has_wiki": false,
"homepage": "https://maxmind.github.io/minfraud-api-node/",
"languages": {
"Shell": 5177,
"JavaScript": 1490,
"TypeScript": 206303
},
"pushed_at": "2026-07-29T14:24:08Z",
"created_at": "2018-12-24T19:46:07Z",
"owner_type": "Organization",
"updated_at": "2026-07-27T19:19:04Z",
"description": "Node.js API for MaxMind minFraud",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://www.maxmind.com",
"name": "MaxMind",
"type": "Organization",
"login": "maxmind",
"company": null,
"location": null,
"followers": 330,
"avatar_url": "https://avatars.githubusercontent.com/u/1181834?v=4",
"created_at": "2011-11-08T21:15:12Z",
"is_verified": null,
"public_repos": 100,
"account_age_days": 5377
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v9.1.0",
"kind": "minor",
"published_at": "2026-07-21T14:31:56Z"
},
{
"tag": "v9.0.0",
"kind": "major",
"published_at": "2026-06-29T19:49:17Z"
},
{
"tag": "v8.3.0",
"kind": "minor",
"published_at": "2026-01-20T18:56:20Z"
},
{
"tag": "v8.2.1",
"kind": "patch",
"published_at": "2025-11-25T17:53:11Z"
},
{
"tag": "v8.2.0",
"kind": "minor",
"published_at": "2025-11-20T20:16:51Z"
},
{
"tag": "v8.1.0",
"kind": "minor",
"published_at": "2025-05-23T22:05:55Z"
},
{
"tag": "v8.0.0",
"kind": "major",
"published_at": "2025-02-10T17:11:16Z"
},
{
"tag": "v7.1.0-beta.1",
"kind": "prerelease",
"published_at": "2024-09-06T17:43:06Z"
},
{
"tag": "v7.0.0",
"kind": "major",
"published_at": "2024-07-08T21:30:08Z"
},
{
"tag": "v7.0.0-beta.1",
"kind": "prerelease",
"published_at": "2024-06-17T16:43:36Z"
},
{
"tag": "v6.1.0",
"kind": "minor",
"published_at": "2024-04-16T21:46:02Z"
},
{
"tag": "v6.0.0",
"kind": "major",
"published_at": "2023-12-05T22:09:25Z"
},
{
"tag": "v5.0.0",
"kind": "major",
"published_at": "2023-05-17T17:45:51Z"
},
{
"tag": "v4.7.0",
"kind": "minor",
"published_at": "2023-02-21T17:01:25Z"
},
{
"tag": "v4.6.0",
"kind": "minor",
"published_at": "2022-08-31T19:57:26Z"
},
{
"tag": "v4.5.0",
"kind": "minor",
"published_at": "2022-03-28T18:03:48Z"
},
{
"tag": "v4.4.0",
"kind": "minor",
"published_at": "2022-01-25T19:08:37Z"
},
{
"tag": "v4.3.0",
"kind": "minor",
"published_at": "2021-08-31T15:28:29Z"
},
{
"tag": "v4.2.0",
"kind": "minor",
"published_at": "2021-08-18T16:13:03Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2021-07-12T15:19:21Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2021-06-29T16:43:26Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2021-06-22T20:07:55Z"
},
{
"tag": "v3.4.0",
"kind": "minor",
"published_at": "2021-04-13T15:12:50Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2021-02-16T15:55:41Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2021-02-02T22:39:52Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2021-01-19T16:53:58Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2021-01-11T14:49:15Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2020-11-09T19:57:46Z"
},
{
"tag": "v1.10.0",
"kind": "minor",
"published_at": "2020-10-14T15:28:56Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2020-09-30T15:25:25Z"
},
{
"tag": "v1.8.0",
"kind": "minor",
"published_at": "2020-07-17T16:21:31Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2020-06-15T15:48:38Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2020-04-06T22:19:45Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2020-03-26T17:21:28Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2020-02-21T22:29:20Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2020-01-09T18:34:06Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2019-11-04T16:04:11Z"
},
{
"tag": "v1.1.1",
"kind": "patch",
"published_at": "2019-10-30T14:07:31Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2019-09-24T20:46:00Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2019-09-19T21:10:06Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2019-08-22T15:13:57Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2019-07-12T20:43:38Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2019-06-26T21:31:55Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2019-06-18T18:42:22Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2019-06-13T22:52:53Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2019-06-13T19:40:27Z"
}
],
"recent_commits": [
{
"oid": "5d84d6f596ca3bc6c4107bc7c9be6825eef1b4f9",
"body": "…ode-26.0.1\n\nBump @types/node from 25.9.3 to 26.1.1",
"is_bot": false,
"headline": "Merge pull request #1908 from maxmind/dependabot/npm_and_yarn/types/n…",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-07-27T19:17:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b1681ed5b5497f9df1d08ae6aaf8c49075a2863f",
"body": "…l-15f4d34eb1\n\nBump the codeql group with 3 updates",
"is_bot": false,
"headline": "Merge pull request #1928 from maxmind/dependabot/github_actions/codeq…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-27T16:30:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ad082389e04c06f53a00bda9c08c56b382cff3a",
"body": "…ns/checkout-7.0.1\n\nBump actions/checkout from 7.0.0 to 7.0.1",
"is_bot": false,
"headline": "Merge pull request #1929 from maxmind/dependabot/github_actions/actio…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-27T16:27:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc11d3e1d321126431f12c0eb7910baf1bc725d7",
"body": "…ise-action-4.2.1\n\nBump jdx/mise-action from 4.2.0 to 4.2.1",
"is_bot": false,
"headline": "Merge pull request #1931 from maxmind/dependabot/github_actions/jdx/m…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-27T16:20:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f41105aff894a7919d8745da8533a2f2f358536d",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.2.0 to 4.2.1.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/e6a8b3978addb5a52f2b4cd9d91e\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.2.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 4.2.0 to 4.2.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T14:07:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2478d0a3e449668d1f95b8af85ddc43f4e48edf1",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 7.0.0 to 7.0.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T14:07:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4bd7529d5de359f675c1c2e04d9544565fd8a81",
"body": "Bumps the codeql group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).\n\n\nUpdates `github/codeql-action/init` fr\n[…]\nanalyze\n dependency-version: 4.37.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: codeql\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump the codeql group with 3 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T14:06:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e633aade27fabfc36c78826e2b6a1c2af311e1a",
"body": "…n-dependabot-are-visible\n\nAdd workflow that fails when Dependabot updates error",
"is_bot": false,
"headline": "Merge pull request #1927 from maxmind/wstorey/stf-1124-failures-to-ru…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-22T17:45:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7d1c4b7ec80621257b1cad6f08feb0d9c128f83",
"body": "Dependabot version update failures only surface as a red triangle in\nthe Dependabot tab, which nobody checks. This weekly scheduled workflow\nfails if any \"Dependabot Updates\" run concluded with failure,\nstartup_failure, or timed_out in the last 8 days, so a broken ecosystem\nsurfaces as a red scheduled run that emails a human.\n\nSee maxmind/device-android#61 for the reference implementation.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add Dependabot failure watcher workflow",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-22T16:11:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "673116a33b4912ac7495eee26d39d75a56a1dec7",
"body": "…ons-dependabot-updates-weekly-and-group\n\nRun Dependabot updates weekly and group CodeQL updates",
"is_bot": false,
"headline": "Merge pull request #1925 from maxmind/wstorey/stf-983-run-github-acti…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-21T20:20:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bd9c3a275dea5c78d8cc0a8a9398ab5b72c79565",
"body": "Release 9.1.0",
"is_bot": false,
"headline": "Merge pull request #1924 from maxmind/greg/stf-1074",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-21T19:53:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a75ceb6af2fb7ca11b0eb715dd6d7eebe6852e7",
"body": "Dependabot treats the github/codeql-action subpath actions (init,\nanalyze, autobuild) as separate dependencies and opens a separate PR\nfor each. CI fails unless they are all updated together. Group them so\nthat they arrive as a single PR.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Group CodeQL action updates",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-21T18:51:45Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7d951385a2e0bb7afb8ba43bf6ac52b7b87bd440",
"body": "We now review dependency updates weekly rather than daily, so daily\nupdate runs only generate churn. Check for updates once a week on\nMonday morning instead.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Run Dependabot updates weekly",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-21T18:51:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c8c1ee1d0c4fa8092c4d6016bbaa568834b3dee8",
"body": null,
"is_bot": false,
"headline": "Prepare for 9.1.0",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-21T14:31:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b663139004896e7fd432b1915b9df878cf8c6711",
"body": null,
"is_bot": false,
"headline": "Set a release date",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-21T14:31:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af22d62b256e406edab0e768c2599de4ae5d94eb",
"body": "…b/codeql-action/init-4.37.0\n\nBump github/codeql-action/init from 4.36.3 to 4.37.0",
"is_bot": false,
"headline": "Merge pull request #1919 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-20T17:54:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb9f2ebc5b18bcfafdcfc6dbe0896516a4f93f06",
"body": "…b/codeql-action/autobuild-4.37.0\n\nBump github/codeql-action/autobuild from 4.36.3 to 4.37.0",
"is_bot": false,
"headline": "Merge pull request #1920 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-20T17:54:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7718bb38065d75f8a3ad96bb79f492226f295961",
"body": "…b/codeql-action/analyze-4.37.0\n\nBump github/codeql-action/analyze from 4.36.3 to 4.37.0",
"is_bot": false,
"headline": "Merge pull request #1918 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-20T17:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a03dd19304186d05381f6ded1afd190de0af623",
"body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.3 to 26.1.1.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\n\n- dependency-name: \"@types/node\"\n dependency-version: 26.0.1\n dependency-type: direct:development\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump @types/node from 25.9.3 to 26.1.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T17:47:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "85e583c8d2bef80814a9975dac91ded433d89cb5",
"body": "Migrate Jest to vitest",
"is_bot": false,
"headline": "Merge pull request #1921 from maxmind/jest-to-vitest",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-07-20T17:44:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c493023579b7e2656814adddfbdd4c84818832be",
"body": "…ns/setup-node-7.0.0\n\nBump actions/setup-node from 6.4.0 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #1922 from maxmind/dependabot/github_actions/actio…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-20T16:58:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "105135fcaf7309e1725c84ee20f65d7fc1f5490b",
"body": "Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020)\n\n---\n[…]\ndependency-name: actions/setup-node\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/setup-node from 6.4.0 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T14:03:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "57514930877ba64d0e3bae24600988ade010b07c",
"body": "…o-anonymizer\n\nAdd residential proxy data to anonymizer object",
"is_bot": false,
"headline": "Merge pull request #1917 from maxmind/greg/stf-1005-add-residential-t…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-17T22:17:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "34069f747106f4b17bd7274e6ee13d01a6bb2191",
"body": "The Vitest docs recommend this form so the hints survive transforms\nthat strip comments. The current Oxc-based transform keeps them either\nway, but the documented behavior is comment stripping, so a future\ntoolchain change could silently invalidate plain hints.",
"is_bot": false,
"headline": "Use @preserve form for v8 coverage ignore hints",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T20:37:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "436fc9beb714753aa067430ada7a8a2b4beab9cd",
"body": "The assertions were weakened because Jest's --experimental-vm-modules\ncreated errors in a different realm, breaking instanceof. Vitest runs\nnative ESM without VM sandboxing, so the workaround is no longer\nneeded.",
"is_bot": false,
"headline": "Restore strict instanceof assertions for parse-error causes",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T16:31:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5018592fbc32bf0a5a53fd58e072169c6e4895c",
"body": null,
"is_bot": false,
"headline": "Update development docs for Vitest",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T02:24:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b04f1d214dca8570aaa32332eed6c1f86e205ca",
"body": "Both e2e packages now use Vitest, which handles TypeScript directly, so\nthe ts package drops ts-jest and @types/jest. Each package gets a local\nvitest.config to anchor its test root; otherwise Vitest walks up and\nuses the repository config. The CI steps no longer need the\nexperimental-vm-modules flag, and the Jest globals carve-out is removed\nfrom the ESLint config.",
"is_bot": false,
"headline": "Migrate e2e test suites from Jest to Vitest",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T02:24:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a287c36752d8ef42401da9d4d72cdbe3c42419af",
"body": "npm swallowed the --coverage flag in 'npm test --coverage', so the\ncoverage thresholds were never checked in CI. Use the test:coverage\nscript, which runs Vitest with coverage enabled.",
"is_bot": false,
"headline": "Enforce coverage thresholds in CI",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T02:24:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59bc8faafba7209201ed3a0b82186d7e6816d37a",
"body": "Spec files were excluded from tsc and ts-jest ran in transpile-only\nmode, so they were never type-checked. Run tsc against\ntsconfig.test.json in the lint script and fix the errors it surfaced:\nthe specs referenced RequestInfo, which @types/node does not declare\nglobally.",
"is_bot": false,
"headline": "Type-check spec files during lint",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T02:24:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9a236eecee985370e76ab66688097844d7d4102",
"body": "Replace jest, ts-jest, and @types/jest with vitest and\n@vitest/coverage-v8. Specs now import test APIs explicitly from\n'vitest' instead of relying on injected globals.\n\nThe v8 coverage provider surfaced gaps the previous setup missed (CI\nnever passed --coverage through npm). Add tests for the legacy\n[…]\nnt, non-Error fetch rejections, orders without a referrer\nURI, and transaction reports with no identifier fields. Annotate two\ndefensive email-normalization branches that validation makes\nunreachable.",
"is_bot": false,
"headline": "Migrate test suite from Jest to Vitest",
"author_name": "kevcenteno",
"author_login": "kevcenteno",
"committed_at": "2026-07-17T02:24:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1344f1914704bba8a1ba0a94c43f149e23e78dd4",
"body": "Bumps node (26.1.0 -> 26.5.0) and lychee (0.23.0 -> 0.24.2) via\n`mise up`. Lychee 0.24.0 replaced the boolean `include_fragments`\nconfig option with an enum (none/anchor-only/text-only/full); migrate\nlychee.toml to `include_fragments = \"full\"` so both anchor fragments\n(`#section`) and text fragments (`#:~:text=example`) are checked.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update mise tools",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-16T23:37:25Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "17e46b227642b7e93b98243be027df98523c582a",
"body": "This surfaces the new residential sub-object nested within the\nanonymizer object in the minFraud Insights and Factors ip_address\nresponse. The IpAddress model reuses GeoIP2-node's AnonymizerRecord\ntype directly and the response parsing recursively camelCases nested\nobjects, so the new field flows th\n[…]\nt types it.\nThis commit updates the fixture and test coverage and documents the\nchange, along with the future dependency bump, in the changelog.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add residential proxy data to anonymizer object",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-16T23:37:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b18969ac8034222f342de876766d14f516e91e55",
"body": "The 7.1.0 release adds the residential property to the\nAnonymizerRecord type, which is needed to support the new\nanonymizer.residential data added in this release.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Require @maxmind/geoip2-node 7.1.0 for residential data",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-16T23:37:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e3a82f5b321a33063b395469f001b4cc18b9c42d",
"body": "Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action\n[…]\nme: github/codeql-action/autobuild\n dependency-version: 4.37.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/autobuild from 4.36.3 to 4.37.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-15T14:06:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "73c5d6121012926f026582d8a3b78a12fbc144f3",
"body": "Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/comp\n[…]\ncy-name: github/codeql-action/init\n dependency-version: 4.37.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/init from 4.36.3 to 4.37.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-15T14:05:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "006f183f8c445eb21334c714dd94b2581ec7bd86",
"body": "Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/c\n[…]\nname: github/codeql-action/analyze\n dependency-version: 4.37.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/analyze from 4.36.3 to 4.37.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-15T14:03:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "028bea55b89fe05be608193139ebb6a1d790936a",
"body": "…b/codeql-action/analyze-4.36.3\n\nBump github/codeql-action/analyze from 4.36.2 to 4.36.3",
"is_bot": false,
"headline": "Merge pull request #1912 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-09T15:38:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6142fc33c89845df13b46499c0732e846ea9f0ff",
"body": "…b/codeql-action/init-4.36.3\n\nBump github/codeql-action/init from 4.36.2 to 4.36.3",
"is_bot": false,
"headline": "Merge pull request #1913 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-09T15:35:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9a885ac58df784776b177ca7c8d10921fc5ba03",
"body": "…b/codeql-action/autobuild-4.36.3\n\nBump github/codeql-action/autobuild from 4.36.2 to 4.36.3",
"is_bot": false,
"headline": "Merge pull request #1914 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-09T15:20:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a7cb8c5a04170895f79d9181d8175e54eb892f2",
"body": "Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action\n[…]\nme: github/codeql-action/autobuild\n dependency-version: 4.36.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/autobuild from 4.36.2 to 4.36.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T14:06:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eb3973c1a50267123d29db5d99f6e1e64abf00f8",
"body": "Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/comp\n[…]\ncy-name: github/codeql-action/init\n dependency-version: 4.36.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/init from 4.36.2 to 4.36.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T14:05:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ef5935ed10544c11c7d865c3aed868273339110",
"body": "Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/c\n[…]\nname: github/codeql-action/analyze\n dependency-version: 4.36.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action/analyze from 4.36.2 to 4.36.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T14:04:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcda41f03527f5fe7361276d2d1e39e2ed30e90e",
"body": "…nd-patch-e9b91ed5f8\n\nBump the minor-and-patch group across 1 directory with 2 updates",
"is_bot": false,
"headline": "Merge pull request #1906 from maxmind/dependabot/npm_and_yarn/minor-a…",
"author_name": "mm-jpoole",
"author_login": "mm-jpoole",
"committed_at": "2026-06-30T21:16:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a70d099d31da80d1ceb33b40b0a3ea8ee6e31134",
"body": "Bumps the minor-and-patch group with 2 updates in the / directory: [globals](https://github.com/sindresorhus/globals) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint).\n\n\nUpdates `globals` from 17.6.0 to 17.7.0\n- [Release notes](http\n[…]\ndependency-version: 8.62.0\n dependency-type: direct:development\n update-type: version-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump the minor-and-patch group across 1 directory with 2 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T14:02:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "316fca8b7b5ac5be38f8bdf5b03d13e64b44f874",
"body": "Release 9.0.0",
"is_bot": false,
"headline": "Merge pull request #1905 from maxmind/greg/stf-855",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-30T02:47:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29de6937fc12951cd88442c86fdb3e7903ba1192",
"body": "If the version bump was already committed on the release branch, the\nworking tree is clean, npm version is skipped, and the unconditional\ngit commit died with \"nothing to commit\" under set -e.\n\nVerify package.json is at the target version after the update block\n(catching a genuinely failed replacement), then only commit when there\nare changes to commit.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Make release script tolerate an already-bumped package.json",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T19:48:04Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cb4c573b3fc42f148cc6117e818495e5db653383",
"body": null,
"is_bot": false,
"headline": "Set release date",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T19:13:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf56a41c202c801539e502ac88e822e72045dac3",
"body": "And remove `maxmind` as a direct dependency.",
"is_bot": false,
"headline": "Update @maxmind/geoip2-node",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T19:12:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d94d523655906208ea930f74b3ee73f8e1afdff1",
"body": null,
"is_bot": false,
"headline": "Add node to mise config",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T19:05:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2724f310bcce58568aad63690fd1070ea1682feb",
"body": "Cleanups before a major release",
"is_bot": false,
"headline": "Merge pull request #1903 from maxmind/greg/stf-809",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-29T17:54:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "38ac8989c415c017fe5b485c1eb1cfbb74526a66",
"body": "…rcore/zizmor-action-0.5.7\n\nBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7",
"is_bot": false,
"headline": "Merge pull request #1904 from maxmind/dependabot/github_actions/zizmo…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-29T16:02:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0eeb59097b47900ae609e1ceeaef08bf722bfaf",
"body": "The IP-literal referrer tests use RFC 5737 / RFC 3849 documentation addresses\n(192.0.2.1, [2001:db8::1]) that never resolve; exclude them so the link check\ndoesn't fail or hang on them.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Exclude reserved example IPs from the lychee link check",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:46:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "13ebe717a39ac17700abe120d75135f7cb037e81",
"body": "For JS callers, `{ host: null }`, `{ timeout: null }`, and `{ fetcher: null }`\npreviously slipped past the `!== undefined` checks and failed later (a bad URL,\na non-callable fetcher, or a NaN timeout signal). Validate each up front and\nthrow `ArgumentError`. Also add a test asserting the `host` option changes the\nrequest URL.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Validate WebServiceClient option member types",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:46:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "91fc00ce1459f10c28c8f4bc37f02fd9a06861e3",
"body": "Replace the inaccurate \"deeply clones an object\" JSDoc with the actual\ncontract: arrays and plain objects are deep key-converted, while primitives and\nnon-plain objects (Date, Error, RegExp, etc.) pass through unchanged. Add tests\nlocking in the Date/Error/RegExp passthrough.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Document camelcaseKeys' contract and cover non-plain-object passthrough",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:36:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fb5928a585818cb7eef6f40a8e20038e8b496755",
"body": "The record `customInputs` form changes serialization, so assert that\n`Transaction.toString()` emits the expected `custom_inputs` payload, not just\nthe constructor state.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Verify record-form customInputs serialization",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:35:43Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6c096e118a3c6afa2d295e3e72637a954df6e278",
"body": "The single-label-host guard rejected valid IPv6-literal referrers like\n`https://[2001:db8::1]/` (an IPv6 literal has no dot), which was stricter than\nthe former `validator.isURL`. Exempt IP literals from the dot requirement.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Allow IP-literal referrer URIs",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:35:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4bfd52cdd94717c5e82887f91f63b61843011905",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Drop the unused host option from the clientWith test helper",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:22:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "21c7d5f1df96b8f35bfa322ddce3019de185b722",
"body": "* Update the stale `WebServiceClient` constructor example in CLAUDE.md to the\n options-object form (the positional `timeout, host` form now throws).\n* Document on `Transaction.customInputs` that input keys are snake_cased on the\n wire (e.g. `fizzBuzz` -> `fizz_buzz`), to match portal-configured ke\n[…]\nELOG: note that a fourth positional constructor argument now throws, and\n list the newly-exported `WebServiceClientOptions` type.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix and extend the docs for the constructor and customInputs changes",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-29T15:22:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "749d6dc915b39192818f2e323dd2fb48f4533150",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.7\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T14:06:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3b3e9f8b950059a68c18dddcee0d532a10e39fb9",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update CHANGELOG for the pre-major-release cleanups",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:18:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6f4a43915549dbf77da9fd57ab21c55f08f0dd65",
"body": "The WebServiceClient tests now drive requests through an injected `fetcher`\nthat returns canned `Response`s and records the requests made, instead of\nmocking at the HTTP layer with nock. A dedicated test asserts the request\nshape (method, path, POST body, auth header) directly; error/status cases\nre\n[…]\nrts — exercising the real timeout signal deterministically.\n\nThis removes the `nock` dev dependency (which was on a beta release).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Replace nock with the injected fetcher in web service tests",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:18:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "62363bdcdf1e7423b31977319a88408936a7935c",
"body": "Replace the three `validator` uses with built-ins:\n\n* email.ts: reimplement the `isEmail`/`isFQDN` input guards with small regex\n helpers (covered by the existing email.spec.ts cases, including IDN domains\n and trailing-dot rejections).\n* order.ts: the `referrerUri` `isURL` check was effectively v\n[…]\neplace the test-only `isJSON` with a local\n `JSON.parse` helper.\n\nDrops `validator` and `@types/validator` from the dependencies.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Remove the validator production dependency",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:18:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "08bebe2613ccb594137bc6349b45c5dbb32ca985",
"body": "Match geoip2-node's utility name for cross-library consistency. This is an\ninternal helper (not exported from the package), so the rename has no effect on\nconsumers.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Rename camelizeResponse to camelcaseKeys",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:11:34Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4d4dc3bddcb57245dcbc1ee353942ca99abc3920",
"body": "TransactionProps.customInputs was typed CustomInput[] but the stored field is\na Record, and the value was always run through Object.assign to flatten it.\nAdditively widen the input type to\n`CustomInput[] | Record<string, boolean | number | string>` and handle both:\nan array is flattened as before, a record is used directly. Existing\nCustomInput[] callers are unaffected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Accept customInputs as a plain record",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:11:34Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fc6473921196ea86eace10ba496b5f17a05f53af",
"body": "Transaction.toString() builds a shallow copy via Object.assign({}, this), so\nthe nested billing/shipping/creditCard objects were still the caller's\ninstances — and the address2 -> address_2 and was3DSecureSuccessful ->\nwas_3d_secure_successful renames mutated them in place (a caller's Billing\nwould \n[…]\nn address_2 after serialization). Rebuild each\nrenamed object as a fresh object instead, leaving the caller's instances\nuntouched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Stop sanitizeKeys() from mutating caller-owned objects",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:11:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e4d6959478e17e86e18145a3859eff2e4269ba8f",
"body": "Change the WebServiceClient constructor from\n`(accountID, licenseKey, timeout?, host?)` to\n`(accountID, licenseKey, options?: Options | number)`, matching geoip2-node.\n`Options` carries `timeout`, `host`, and a new `fetcher` (a custom `fetch`\nimplementation, useful for proxies/dispatchers and testin\n[…]\nas a fourth positional argument must switch to `{ host }`.\n\nRequests now go through `this.fetcher` rather than the global `fetch`.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Accept an options object and an injectable fetcher in the client",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T20:11:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dc38a9947eb0b7210d4a93c2866e883bac57e377",
"body": "Give ArgumentError an optional `cause` option and forward it to the Error\nconstructor, matching WebServiceError and the geoip2-node error classes. This\nis additive; no current caller passes a cause.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Preserve underlying cause on ArgumentError",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T19:38:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cf57ae040502adf02ff274aaba9912bf923a27c1",
"body": "Replace the plain `string` type on `code` with `WebServiceErrorCode`, an open\n`ClientErrorCode | (string & {})` union, mirroring geoip2-node. This offers\nautocompletion for the five client-generated codes while still accepting any\ncode the web service returns. The `ClientErrorCode` and `WebServiceEr\n[…]\n\nwith the closed `ClientErrorCode`, so a typo at a throw site is a compile\nerror. The server-returned `data.code` path stays open.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Type WebServiceError.code with an open ClientErrorCode union",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-26T19:38:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d25fe8995d2b1e01e6b6674179e92449e1759f63",
"body": "Throw WebServiceError instances and preserve error causes",
"is_bot": false,
"headline": "Merge pull request #1902 from maxmind/greg/stf-803",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-24T19:41:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "717ed8040c470cdf3c6e16bfe9d0d13d280e5f3a",
"body": "A FETCH_ERROR previously surfaced only \"TypeError - fetch failed\", with\nthe real reason (DNS failure, refused connection, TLS error, etc.) hidden\nin the cause. Consumers that log only `code`/`error` never saw it.\n\nAppend the underlying cause's message to the error string so the reason\nis visible without inspecting `cause`, which is still attached.\n\nSTF-803\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Include the underlying cause in the FETCH_ERROR message",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-24T16:56:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c94db28bb7a1db1caaeabde080a5884c8a58c810",
"body": "The web service client rejected with plain objects, which meant errors\nwere not Error instances and the underlying cause (for example, the\nnetwork error behind a FETCH_ERROR) was discarded.\n\nIntroduce a WebServiceError class that extends Error and carries the\nexisting code/error/status/url propertie\n[…]\n cause. Capture the cause at every throw site. Export\nWebServiceError, ArgumentError, and the WebServiceClientError type.\n\nSTF-803\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Throw WebServiceError instances and preserve error causes",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-24T16:38:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "77349d26a64e36700bf419a22c299af7760ba110",
"body": "…ns/checkout-7.0.0\n\nBump actions/checkout from 6.0.3 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #1899 from maxmind/dependabot/github_actions/actio…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-24T15:58:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af3714afb55e9dc7003564cca1a305991c0c88e8",
"body": "…ise-action-4.2.0\n\nBump jdx/mise-action from 4.1.0 to 4.2.0",
"is_bot": false,
"headline": "Merge pull request #1901 from maxmind/dependabot/github_actions/jdx/m…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-24T15:50:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f713c7929e0b8e43bedc693b93f0599f0dd86e9",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.1.0 to 4.2.0.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/dba19683ed58901619b14f395a24\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.2.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 4.1.0 to 4.2.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-24T14:04:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1b27570252ef67713ee147a167f2dcf256dc66a0",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.3 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-24T14:02:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a306294ebadce752d9b85641f87d903fc90338a",
"body": "…nd-patch-de2a0335a9\n\nBump the minor-and-patch group across 1 directory with 4 updates",
"is_bot": false,
"headline": "Merge pull request #1898 from maxmind/dependabot/npm_and_yarn/minor-a…",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-23T16:11:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f45b5ffe0ef09405241c61964c430128c7ab6af",
"body": "Bumps the minor-and-patch group with 4 updates in the / directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [eslint](https://github.com/eslint/eslint), [prettier](https://github.com/prettier/prettier) and [typescript-eslint](https://github.com/typescrip\n[…]\ndependency-version: 8.61.0\n dependency-type: direct:development\n update-type: version-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump the minor-and-patch group across 1 directory with 4 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T14:03:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c1c2c3712302dee64a92fbfb3b4165749894ad41",
"body": "…nd-patch-d1f6f6ab95\n\nBump the minor-and-patch group across 1 directory with 3 updates",
"is_bot": false,
"headline": "Merge pull request #1895 from maxmind/dependabot/npm_and_yarn/minor-a…",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-15T20:04:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "50276cb5e8b41646ccfc53ba8d2b2e722780b246",
"body": "Bumps the minor-and-patch group with 3 updates in the / directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [eslint](https://github.com/eslint/eslint) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/type\n[…]\ndependency-version: 8.60.1\n dependency-type: direct:development\n update-type: version-update:semver-patch\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump the minor-and-patch group across 1 directory with 3 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T14:03:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfb7138e4e9397542a256f4754b6209646ea6107",
"body": "Disable npm caching in release workflow",
"is_bot": false,
"headline": "Merge pull request #1894 from maxmind/wstorey/fix-zizmor",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-11T16:59:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "843db97a96be71c5c6b02d3c5a193ca6a172a364",
"body": "zizmor flags cache-poisoning in workflows that publish artifacts: a\npoisoned cache entry restored during a release run could taint the\npublished package. Disable setup-node's package manager cache in\nrelease.yml.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Disable npm caching in release workflow",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-11T16:13:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7886d23b8a2aa1ba31d88bd9ace3118f7c356672",
"body": "…b/codeql-action-4.36.2\n\nBump github/codeql-action from 4.36.1 to 4.36.2",
"is_bot": false,
"headline": "Merge pull request #1892 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-11T16:00:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6f80e9b9730743a2067886c0c068cb7bd455d1e",
"body": "…ise-action-4.1.0\n\nBump jdx/mise-action from 4.0.1 to 4.1.0",
"is_bot": false,
"headline": "Merge pull request #1893 from maxmind/dependabot/github_actions/jdx/m…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-11T15:58:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1fec8d731cdb4d613bf5e97b442305edce8bb331",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.0.1 to 4.1.0.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/1648a7812b9aeae629881980618f\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.1.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 4.0.1 to 4.1.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-11T14:05:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8692b90d20d6b5040bf37dd60a35941c941304fa",
"body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8\n[…]\nendency-name: github/codeql-action\n dependency-version: 4.36.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action from 4.36.1 to 4.36.2",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-11T14:05:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed093764d4e346a54f015a691adec459c303e19f",
"body": "…b/codeql-action-4.36.1\n\nBump github/codeql-action from 4.36.0 to 4.36.1",
"is_bot": false,
"headline": "Merge pull request #1890 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-09T16:58:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "75778b62b5519104fe0294582da415e8e80f9e99",
"body": "…ns/checkout-6.0.3\n\nBump actions/checkout from 6.0.2 to 6.0.3",
"is_bot": false,
"headline": "Merge pull request #1891 from maxmind/dependabot/github_actions/actio…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-09T15:34:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1dc6135c8fa88b581819a49c0e38100fa7037071",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n dependency-version: 6.0.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.2 to 6.0.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T14:05:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9422fef36383bc7ac108c4aedbea8dc7cdf0c6bc",
"body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/7\n[…]\nendency-name: github/codeql-action\n dependency-version: 4.36.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump github/codeql-action from 4.36.0 to 4.36.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T14:04:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e5842883c8a3fadad26518df401226b865c64c2a",
"body": "…ise-action-4.0.1\n\nBump jdx/mise-action from 3.6.1 to 4.0.1",
"is_bot": false,
"headline": "Merge pull request #1888 from maxmind/dependabot/github_actions/jdx/m…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-08T15:15:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0ae107bd50e81dee156b94277286c8585fd36fe0",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 3.6.1 to 4.0.1.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/6d1e696aa24c1aa1bcc1adea0212\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.0.1\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 3.6.1 to 4.0.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-08T14:04:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "74c0933a46357c69d7810a97aff74cc1492cc0d9",
"body": "Validate and update links (STF-557)",
"is_bot": false,
"headline": "Merge pull request #1886 from maxmind/greg/stf-557",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-05T21:27:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c090eedb658ebcc9fbc5761b3e27813963590f85",
"body": "Drop node 18 and 20. Add 24",
"is_bot": false,
"headline": "Merge pull request #1882 from maxmind/kevin/drop-old-node",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-05T15:23:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63a65b36630e32468465fa7129fbe85206c3d8df",
"body": "Validated all links with lychee and updated those that redirected\nelsewhere to their canonical destinations:\n\n- README.md: dev.maxmind.com/minfraud/api-documentation/responses?lang=en#errors\n -> .../responses/?lang=en#errors (trailing slash before query; was a 308)\n- README.md: www.maxmind.com/en/s\n[…]\nnical npm git clone URL and is left unchanged. Historical CHANGELOG.md\nentries are intentionally left unchanged.\n\nPart of STF-557.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update stale and redirecting links",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-04T22:00:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dce1e2d115ff5474c12079cfca344fea16540934",
"body": "Adds a lychee configuration and a Links GitHub Actions workflow so that\nstale or redirecting links are caught automatically going forward. The\nchecker runs on push, pull request, and weekly to catch external link\nrot. max_redirects is 0 so links that have moved are surfaced and can be\nupdated to the\n[…]\nlog. lychee is\npinned via mise (0.23.0), which is the single source of version truth for\nboth local runs and CI.\n\nPart of STF-557.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add lychee link checker config and CI workflow",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-04T22:00:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5e60987385dab5a576d9b471ebf33953cc4660ef",
"body": null,
"is_bot": false,
"headline": "Remove URL imports",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-04T20:30:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fcc8863ab73ef87a6a31406942839161c5e96325",
"body": null,
"is_bot": false,
"headline": "Fix validator imports",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-04T19:56:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1452270eaa7bed63c23ab446ed761a912b93084f",
"body": null,
"is_bot": false,
"headline": "Bump version number in package.json",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-04T19:44:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "16bb923de4c8d0efacf32be38fcd19d80797bf88",
"body": null,
"is_bot": false,
"headline": "Fix error message",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2026-06-04T19:39:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f4cd9396495c50424883885e9b97bbc458c921a",
"body": "…b/codeql-action-4.36.0\n\nBump github/codeql-action from 4.35.5 to 4.36.0",
"is_bot": false,
"headline": "Merge pull request #1884 from maxmind/dependabot/github_actions/githu…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-01T20:02:43Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 46,
"commits_last_year": 308,
"latest_release_at": "2026-07-21T14:31:56Z",
"latest_release_tag": "v9.1.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 46,
"days_since_latest_release": 8,
"mean_days_between_releases": 84.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@maxmind/minfraud-api-node",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"maxmind",
"minfraud",
"minfraud score",
"minfraud insights",
"minfraud factors"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@maxmind/minfraud-api-node",
"is_deprecated": false,
"latest_version": "9.1.0",
"repository_url": "https://github.com/maxmind/minfraud-api-node",
"versions_count": 46,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 46418,
"first_published_at": "2019-06-13T19:37:31.223000Z",
"latest_published_at": "2026-07-21T14:34:20.002000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 8
}
]
},
"popularity": {
"forks": 8,
"stars": 14,
"watchers": 12,
"fork_history": {
"days": [
{
"date": "2019-03-13",
"count": 1
},
{
"date": "2019-10-22",
"count": 1
},
{
"date": "2020-01-28",
"count": 2
},
{
"date": "2022-02-07",
"count": 1
},
{
"date": "2023-10-26",
"count": 1
},
{
"date": "2024-03-21",
"count": 1
},
{
"date": "2024-09-05",
"count": 1
}
],
"complete": true,
"collected": 8,
"total_forks": 8
},
"star_history": null,
"open_issues_and_prs": 5
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"mise.toml"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"e2e/ts/tsconfig.json",
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 54575,
"source_files_sampled": 51,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 13354
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 4,
"malicious_count": 0,
"assessed_package": "npm:@maxmind/minfraud-api-node@9.1.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@maxmind/geoip2-node",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^7.1.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@maxmind/geoip2-node",
"direct": true,
"version": "7.1.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@bcoe/v8-coverage",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/runtime",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "@eslint-community/eslint-utils",
"direct": false,
"version": "4.9.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/regexpp",
"direct": false,
"version": "4.12.2",
"ecosystem": "npm"
},
{
"name": "@eslint/config-array",
"direct": false,
"version": "0.23.5",
"ecosystem": "npm"
},
{
"name": "@eslint/config-helpers",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "@eslint/core",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "10.0.1",
"ecosystem": "npm"
},
{
"name": "@eslint/object-schema",
"direct": false,
"version": "3.0.5",
"ecosystem": "npm"
},
{
"name": "@eslint/plugin-kit",
"direct": false,
"version": "0.7.2",
"ecosystem": "npm"
},
{
"name": "@gerrit0/mini-shiki",
"direct": false,
"version": "3.23.0",
"ecosystem": "npm"
},
{
"name": "@humanfs/core",
"direct": false,
"version": "0.19.2",
"ecosystem": "npm"
},
{
"name": "@humanfs/node",
"direct": false,
"version": "0.16.8",
"ecosystem": "npm"
},
{
"name": "@humanfs/types",
"direct": false,
"version": "0.15.0",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/module-importer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/retry",
"direct": false,
"version": "0.4.3",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@napi-rs/wasm-runtime",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "@oxc-project/types",
"direct": false,
"version": "0.139.0",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-android-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-freebsd-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm-gnueabihf",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-ppc64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-s390x-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-openharmony-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-wasm32-wasi",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-arm64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-x64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/pluginutils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@shikijs/engine-oniguruma",
"direct": false,
"version": "3.23.0",
"ecosystem": "npm"
},
{
"name": "@shikijs/langs",
"direct": false,
"version": "3.23.0",
"ecosystem": "npm"
},
{
"name": "@shikijs/themes",
"direct": false,
"version": "3.23.0",
"ecosystem": "npm"
},
{
"name": "@shikijs/types",
"direct": false,
"version": "3.23.0",
"ecosystem": "npm"
},
{
"name": "@shikijs/vscode-textmate",
"direct": false,
"version": "10.0.2",
"ecosystem": "npm"
},
{
"name": "@standard-schema/spec",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@tybys/wasm-util",
"direct": false,
"version": "0.10.3",
"ecosystem": "npm"
},
{
"name": "@types/chai",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/deep-eql",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "@types/esrecurse",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/hast",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "26.1.1",
"ecosystem": "npm"
},
{
"name": "@types/unist",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/eslint-plugin",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/parser",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/project-service",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/scope-manager",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/tsconfig-utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/type-utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/types",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/typescript-estree",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/utils",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/visitor-keys",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "@vitest/coverage-v8",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.16.0",
"ecosystem": "npm"
},
{
"name": "acorn-jsx",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "6.15.0",
"ecosystem": "npm"
},
{
"name": "argparse",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "ast-v8-to-istanbul",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "5.0.6",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "deep-is",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "detect-libc",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "entities",
"direct": false,
"version": "4.5.0",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "10.5.0",
"ecosystem": "npm"
},
{
"name": "eslint-config-prettier",
"direct": false,
"version": "10.1.8",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "9.1.2",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "11.2.0",
"ecosystem": "npm"
},
{
"name": "esquery",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "esrecurse",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "estraverse",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "esutils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-json-stable-stringify",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "fast-levenshtein",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "flatted",
"direct": false,
"version": "3.4.2",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "17.7.0",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "html-escaper",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "7.0.5",
"ecosystem": "npm"
},
{
"name": "imurmurhash",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "is-extglob",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "is-glob",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-coverage",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-report",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-reports",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "10.0.0",
"ecosystem": "npm"
},
{
"name": "json-buffer",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "json-stable-stringify-without-jsonify",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "keyv",
"direct": false,
"version": "4.5.4",
"ecosystem": "npm"
},
{
"name": "levn",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "linkify-it",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "lunr",
"direct": false,
"version": "2.3.9",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "magicast",
"direct": false,
"version": "0.5.3",
"ecosystem": "npm"
},
{
"name": "make-dir",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "markdown-it",
"direct": false,
"version": "14.2.0",
"ecosystem": "npm"
},
{
"name": "maxmind",
"direct": false,
"version": "5.0.6",
"ecosystem": "npm"
},
{
"name": "mdurl",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "10.2.5",
"ecosystem": "npm"
},
{
"name": "mmdb-lib",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.16",
"ecosystem": "npm"
},
{
"name": "natural-compare",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "obug",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "optionator",
"direct": false,
"version": "0.9.4",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "path-exists",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.5",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.19",
"ecosystem": "npm"
},
{
"name": "prelude-ls",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "3.8.4",
"ecosystem": "npm"
},
{
"name": "punycode",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "punycode.js",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "rolldown",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.5",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "tiny-lru",
"direct": false,
"version": "13.0.0",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "ts-api-utils",
"direct": false,
"version": "2.5.0",
"ecosystem": "npm"
},
{
"name": "tslib",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "type-check",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "typedoc",
"direct": false,
"version": "0.28.19",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "6.0.3",
"ecosystem": "npm"
},
{
"name": "typescript-eslint",
"direct": false,
"version": "8.62.0",
"ecosystem": "npm"
},
{
"name": "uc.micro",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "8.3.0",
"ecosystem": "npm"
},
{
"name": "uri-js",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.1.5",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "word-wrap",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "yaml",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "yocto-queue",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 204,
"direct_count": 1,
"indirect_count": 203
}
},
"maintainership": {
"issues": {
"open_prs": 5,
"merged_prs": 1196,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 6,
"closed_unmerged_prs": 725
},
"bus_factor": 3,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "dhogan8",
"commits": 436,
"avatar_url": "https://avatars.githubusercontent.com/u/52248962?v=4"
},
{
"type": "User",
"login": "oschwald",
"commits": 303,
"avatar_url": "https://avatars.githubusercontent.com/u/278835?v=4"
},
{
"type": "User",
"login": "kevcenteno",
"commits": 257,
"avatar_url": "https://avatars.githubusercontent.com/u/1154185?v=4"
},
{
"type": "User",
"login": "horgh",
"commits": 167,
"avatar_url": "https://avatars.githubusercontent.com/u/282924?v=4"
},
{
"type": "User",
"login": "wesrice",
"commits": 123,
"avatar_url": "https://avatars.githubusercontent.com/u/397711?v=4"
},
{
"type": "User",
"login": "oalders",
"commits": 72,
"avatar_url": "https://avatars.githubusercontent.com/u/96205?v=4"
},
{
"type": "User",
"login": "mm-jpoole",
"commits": 54,
"avatar_url": "https://avatars.githubusercontent.com/u/113927341?v=4"
},
{
"type": "User",
"login": "mm-kevcenteno",
"commits": 47,
"avatar_url": "https://avatars.githubusercontent.com/u/215178874?v=4"
},
{
"type": "User",
"login": "PatrickCroninMM",
"commits": 45,
"avatar_url": "https://avatars.githubusercontent.com/u/145998312?v=4"
},
{
"type": "User",
"login": "rajnihatti",
"commits": 41,
"avatar_url": "https://avatars.githubusercontent.com/u/47989320?v=4"
}
],
"contributors_sampled": 24,
"top_contributor_share": 0.26
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codeql-analysis.yml",
"dependabot-failure-watcher.yml",
"links.yml",
"lint.yml",
"release.yml",
"test.yml",
"zizmor.yml"
],
"has_docs_dir": false,
"linter_configs": [
"eslint.config.mjs"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 6,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 25 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 8,
"reason": "dependency not pinned by hash detected -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 7,
"reason": "3 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "5d84d6f596ca3bc6c4107bc7c9be6825eef1b4f9",
"ran_at": "2026-07-30T01:20:39Z",
"aggregate_score": 8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-29T15:01:00Z",
"oldest_open_prs": [
{
"number": 1916,
"created_at": "2026-07-13T14:03:10Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1923,
"created_at": "2026-07-21T11:07:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1926,
"created_at": "2026-07-21T19:54:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1930,
"created_at": "2026-07-27T14:07:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1932,
"created_at": "2026-07-29T14:24:20Z",
"last_comment_at": "2026-07-29T14:24:38Z",
"last_comment_author": "coderabbitai"
}
],
"last_merged_pr_at": "2026-07-27T19:17:39Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/maxmind/minfraud-api-node",
"host": "github.com",
"name": "minfraud-api-node",
"owner": "maxmind"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"security": 84,
"vitality": 94,
"community": 49,
"governance": 83,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 94,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 96,
"inputs": {
"commits_last_year": 308,
"human_commit_share": 0.78,
"days_since_last_push": 0,
"active_weeks_last_year": 46
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "46/52 weeks with commits",
"points": 31.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 46
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "308 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 308
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 92,
"inputs": {
"releases_count": 46,
"latest_release_tag": "v9.1.0",
"releases_from_tags": false,
"days_since_latest_release": 8,
"mean_days_between_releases": 84.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "46 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 46
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 8 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~84.9 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 84.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 2,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 2 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 2
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 49,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 31,
"inputs": {
"forks": 8,
"stars": 14,
"watchers": 12,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "14 stars",
"points": 18.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 14
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "8 forks",
"points": 7,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 8
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "12 watchers",
"points": 5.8,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 12
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"packages": [
"@maxmind/minfraud-api-node"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 46418
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "46,418 downloads/month across npm",
"points": 62.2,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 46418,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 83,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "good",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 76,
"inputs": {
"bus_factor": 3,
"contributors_sampled": 24,
"top_contributor_share": 0.26
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "3 contributor(s) cover half of all commits",
"points": 36,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 3
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 26% of commits",
"points": 16.6,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 26
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "24 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 24
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 25 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 86,
"inputs": {
"merged_prs": 1196,
"open_issues": 0,
"closed_issues": 6,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 725
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "1196/1921 decided PRs merged",
"points": 23.8,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 1196,
"decided": 1921
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"followers": 330,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "maxmind",
"public_repos": 100,
"account_age_days": 5377
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "330 followers of maxmind",
"points": 18.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 330,
"login": "maxmind"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "100 public repos, account ~14 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 100
}
},
{
"code": "account_age_years",
"params": {
"years": 14
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@maxmind/minfraud-api-node"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 8
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 8 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 8
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "46 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 46
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "7 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 7
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.mjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"topics": [
"minfraud",
"maxmind"
],
"has_wiki": false,
"homepage": "https://maxmind.github.io/minfraud-api-node/",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://maxmind.github.io/minfraud-api-node/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "2 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 2
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 84,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 25 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "3 existing vulnerabilities detected",
"points": 5.2,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@maxmind/minfraud-api-node@9.1.0 runtime dependency closure — what installing the published package pulls in — 4 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@maxmind/minfraud-api-node@9.1.0",
"assessed": 4
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 4,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 4,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 6
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 94,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.846,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 13354
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "66 of 78 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 66,
"sampled": 78
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"mise.toml"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"e2e/ts/tsconfig.json",
"tsconfig.json"
],
"agent_commit_share": 0.28,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.22
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "mise.toml",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "mise.toml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.mjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "e2e/ts/tsconfig.json, tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "e2e/ts/tsconfig.json, tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "28 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 28,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "22 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 22,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 54575,
"source_files_sampled": 51,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/51 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 51,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-30T01:21:07.152624Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/maxmind/minfraud-api-node.svg",
"full_name": "maxmind/minfraud-api-node",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}