Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 484,
"has_wiki": false,
"homepage": null,
"languages": {
"PHP": 54518,
"Shell": 2455
},
"pushed_at": "2026-07-22T17:42:27Z",
"created_at": "2015-05-22T20:26:41Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T17:42:32Z",
"description": "Shared code for the MaxMind Web Service PHP client APIs",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "PHP",
"significant_languages": [
"PHP"
]
},
"owner": {
"blog": "https://www.maxmind.com",
"name": "MaxMind",
"type": "Organization",
"login": "maxmind",
"company": null,
"location": null,
"followers": 331,
"avatar_url": "https://avatars.githubusercontent.com/u/1181834?v=4",
"created_at": "2011-11-08T21:15:12Z",
"is_verified": null,
"public_repos": 100,
"account_age_days": 5370
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.11.1",
"kind": "patch",
"published_at": "2026-01-13T17:57:27Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2025-11-20T18:33:49Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2024-11-14T23:17:13Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2022-03-28T17:43:41Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2020-11-02T17:01:59Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2020-10-01T17:25:09Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2020-05-06T15:58:50Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2019-12-12T15:58:37Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2018-02-12T22:32:38Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2017-07-10T17:38:36Z"
}
],
"recent_commits": [
{
"oid": "244566ddeb072f444f45b164875b6f0a8110253f",
"body": "…-dependabot-are-visible\n\nAdd workflow that fails when Dependabot updates error",
"is_bot": false,
"headline": "Merge pull request #129 from maxmind/wstorey/stf-1124-failures-to-run…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-22T17:42:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf1acc31b1927c1309af045bc394020e6e6a2657",
"body": "Dependabot version update failures only surface as a red triangle in\nthe Dependabot tab, which nobody checks. This weekly scheduled workflow\nfails if any \"Dependabot Updates\" run concluded with failure,\nstartup_failure, or timed_out in the last 8 days, so a broken ecosystem\nsurfaces as a red scheduled run that emails a human.\n\nSee maxmind/device-android#61 for the reference implementation.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add Dependabot failure watcher workflow",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-22T16:12:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3e1b9e9081c8d23d0ded64a2fda9b5a01bbb2c2f",
"body": "…ns-dependabot-updates-weekly-and-group\n\nRun Dependabot updates weekly",
"is_bot": false,
"headline": "Merge pull request #128 from maxmind/wstorey/stf-983-run-github-actio…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-07-21T20:08:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f339a351aed22d5151f1a792149ae5c4be096632",
"body": "We now review dependency updates weekly rather than daily, so daily\nupdate runs only generate churn. Check for updates once a week on\nMonday morning instead.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Run Dependabot updates weekly",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-07-21T18:51:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1adf5d6c1f12677159dd225a9d944d680481cfcf",
"body": "…core/zizmor-action-0.5.7\n\nBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7",
"is_bot": false,
"headline": "Merge pull request #127 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-29T16:07:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a96ef28c7632ffd28753dc8ae5d323668bd5ea27",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.7\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T14:02:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a065c4c9fef73ed43e51104667d519702e6eee2",
"body": "…s/checkout-7.0.0\n\nBump actions/checkout from 6.0.3 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #125 from maxmind/dependabot/github_actions/action…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-24T16:01:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2782fe97ade3d687e04cc388ab695b5565363909",
"body": "…se-action-4.2.0\n\nBump jdx/mise-action from 4.1.0 to 4.2.0",
"is_bot": false,
"headline": "Merge pull request #126 from maxmind/dependabot/github_actions/jdx/mi…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-24T15:55:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "250f1e49edbfb04cccf6e366a52a6883ea3dd390",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.1.0 to 4.2.0.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/dba19683ed58901619b14f395a24\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.2.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 4.1.0 to 4.2.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-24T14:02:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50f979f8ad61e397e8628bd6a01d1ec60be3e6fb",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.3 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-24T14:02:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c74d1a4577b2832ed7159ff55b4bb30b035531b",
"body": "…mathur/setup-php-2.37.2\n\nBump shivammathur/setup-php from 2.37.1 to 2.37.2",
"is_bot": false,
"headline": "Merge pull request #124 from maxmind/dependabot/github_actions/shivam…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-15T15:44:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6207d0308a2a0b8b484a3b0ace9e749e24a56f37",
"body": "Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php) from 2.37.1 to 2.37.2.\n- [Release notes](https://github.com/shivammathur/setup-php/releases)\n- [Commits](https://github.com/shivammathur/setup-php/compare/7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc...f3e473d116dcccaddc5834248c87\n[…]\ndency-name: shivammathur/setup-php\n dependency-version: 2.37.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump shivammathur/setup-php from 2.37.1 to 2.37.2",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T14:02:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9acec07dc0ddb23ac19edeb2109cc4648db2cb22",
"body": "…se-action-4.1.0\n\nBump jdx/mise-action from 4.0.1 to 4.1.0",
"is_bot": false,
"headline": "Merge pull request #123 from maxmind/dependabot/github_actions/jdx/mi…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-11T16:11:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aedda3bac4bd6d6ca855945d2aeaebad968580dc",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.0.1 to 4.1.0.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/1648a7812b9aeae629881980618f\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.1.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 4.0.1 to 4.1.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-11T14:02:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8febf4855f4315c5adc9927d968eb5d24d65bb3b",
"body": "…s/checkout-6.0.3\n\nBump actions/checkout from 6.0.2 to 6.0.3",
"is_bot": false,
"headline": "Merge pull request #122 from maxmind/dependabot/github_actions/action…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-09T15:52:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4ded7e2807583a41013edb05671c7072b8bb0a9",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n dependency-version: 6.0.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.2 to 6.0.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T14:03:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "571763dcf59a4b94b73f78fbfcf5260bab4199dc",
"body": "…se-action-4.0.1\n\nBump jdx/mise-action from 3.6.1 to 4.0.1",
"is_bot": false,
"headline": "Merge pull request #121 from maxmind/dependabot/github_actions/jdx/mi…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-08T16:04:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef49e14eda56361c1b9edc0b98fce19276e3b62c",
"body": "Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 3.6.1 to 4.0.1.\n- [Release notes](https://github.com/jdx/mise-action/releases)\n- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/jdx/mise-action/compare/6d1e696aa24c1aa1bcc1adea0212\n[…]\n\n- dependency-name: jdx/mise-action\n dependency-version: 4.0.1\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump jdx/mise-action from 3.6.1 to 4.0.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-08T14:03:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2b84929e6d865e9618ac634270b745fcd2eb534",
"body": "Validate and update links (STF-557)",
"is_bot": false,
"headline": "Merge pull request #120 from maxmind/greg/stf-557",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-06-05T21:28:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f7d6dc6a3b1379f8be9a27f51443675843916bf",
"body": "Part of STF-557.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add lychee link checker config and CI workflow",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-06-04T22:00:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fb954f46b2fbbaa1fdabf8b85903dd693f18e3de",
"body": "…core/zizmor-action-0.5.6\n\nBump zizmorcore/zizmor-action from 0.5.5 to 0.5.6",
"is_bot": false,
"headline": "Merge pull request #119 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-05-26T15:08:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62fb75112d912aaa3baaa70eea8e6c9d54ad2f91",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.5 to 0.5.6.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/a16621b09c6db4281f81a93cb393b05dcd7b7165...5f14fd08f7cf1cb1609c1e\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.6\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-25T20:09:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aa7b8ab59daa5487e226ead54ae5219b9f736354",
"body": "…mathur/setup-php-2.37.1\n\nBump shivammathur/setup-php from 2.37.0 to 2.37.1",
"is_bot": false,
"headline": "Merge pull request #117 from maxmind/dependabot/github_actions/shivam…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-05-22T15:40:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "adff04e4d3fa29bfdf3aa45f2ba24cffad5c36fd",
"body": "…core/zizmor-action-0.5.5\n\nBump zizmorcore/zizmor-action from 0.5.3 to 0.5.5",
"is_bot": false,
"headline": "Merge pull request #118 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-05-22T15:39:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b37787161327e7da7de8be2a59f71e83b051161f",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.3 to 0.5.5.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...a16621b09c6db4281f81a9\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.5\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T15:19:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2cd140dcf322aed831a8c1cdc612dbb2efe980fc",
"body": "Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php) from 2.37.0 to 2.37.1.\n- [Release notes](https://github.com/shivammathur/setup-php/releases)\n- [Commits](https://github.com/shivammathur/setup-php/compare/accd6127cb78bee3e8082180cb391013d204ef9f...7c071dfe9dc99bdf297fa79cb49e\n[…]\ndency-name: shivammathur/setup-php\n dependency-version: 2.37.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump shivammathur/setup-php from 2.37.0 to 2.37.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T15:19:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "916f8ca365c502a514d22dc79abb137b2ee1bdd9",
"body": "Restore declare_strict_types enforcement (STF-223)",
"is_bot": false,
"headline": "Merge pull request #116 from maxmind/greg/stf-223",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-04-21T19:38:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "feed7240f351942b19beea043ff5cb50d74b6e9c",
"body": "php-cs-fixer v3.95.0 added a `strategy` option to `declare_strict_types`\nand set `@Symfony:risky` to `'strategy' => 'remove'` (see\nhttps://github.com/PHP-CS-Fixer/PHP-CS-Fixer/pull/9384), which causes the\npreset we inherit to strip `declare(strict_types=1);` from every file on\nthe next CI run. Overr\n[…]\nre-v3.95 behavior — strict types stay declared.\n\nThe one test-only file that didn't already have the declaration had it\nadded by the fixer; it is not part of the library's public API.\n\nCloses STF-223.",
"is_bot": false,
"headline": "Restore strict_types enforcement in php-cs-fixer config",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-04-21T18:54:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d415ea4111beea1e6f333ef8a4ef27e71d59a74",
"body": "…core/zizmor-action-0.5.3\n\nBump zizmorcore/zizmor-action from 0.5.2 to 0.5.3",
"is_bot": false,
"headline": "Merge pull request #115 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-04-21T16:28:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "837c7309e5a534a68f3ca10e3f2a021ad6d1a77e",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.2 to 0.5.3.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f3159\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-20T16:27:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32e31bf47ab1a32e01c6aa077b178ed2b9699330",
"body": "…mathur/setup-php-2.37.0\n\nBump shivammathur/setup-php from 2.36.0 to 2.37.0",
"is_bot": false,
"headline": "Merge pull request #114 from maxmind/dependabot/github_actions/shivam…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-03-23T15:14:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20ec222b53b1b9828a5d076fe6d34a379aeaaa24",
"body": "Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php) from 2.36.0 to 2.37.0.\n- [Release notes](https://github.com/shivammathur/setup-php/releases)\n- [Commits](https://github.com/shivammathur/setup-php/compare/44454db4f0199b8b9685a5d763dc37cbf79108e1...accd6127cb78bee3e8082180cb39\n[…]\ndency-name: shivammathur/setup-php\n dependency-version: 2.37.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump shivammathur/setup-php from 2.36.0 to 2.37.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-23T14:15:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8ee7314d5104c2d7e7c345a4093d109398c77943",
"body": "…core/zizmor-action-0.5.2\n\nBump zizmorcore/zizmor-action from 0.5.0 to 0.5.2",
"is_bot": false,
"headline": "Merge pull request #113 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-03-16T16:02:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "152989db263a4f487edb1e265b5ec6522d6da059",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.0 to 0.5.2.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/0dce2577a4760a2749d8cfb7a84b7d5585ebcb7d...71321a20a9ded102f6e9ce\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.5.0 to 0.5.2",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-16T14:13:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d2b8f4585f2f14c0a3bf6e186121935d15a9fe1",
"body": "…core/zizmor-action-0.5.0\n\nBump zizmorcore/zizmor-action from 0.4.1 to 0.5.0",
"is_bot": false,
"headline": "Merge pull request #112 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-02-09T18:27:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8312614a71891687981060fd4a5197b9ca4744bf",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.4.1 to 0.5.0.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/135698455da5c3b3e55f73f4419e481ab68cdd95...0dce2577a4760a2749d8cf\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.5.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.4.1 to 0.5.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-09T15:46:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "60f4ea711ea8b562142a81240510acfeb885370a",
"body": "…core/zizmor-action-0.4.1\n\nBump zizmorcore/zizmor-action from 0.3.0 to 0.4.1",
"is_bot": false,
"headline": "Merge pull request #110 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-01-26T18:11:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "72a28dbf609546059b2522b97efd2e3f8c81d0a5",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.3.0 to 0.4.1.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/e639db99335bc9038abc0e066dfcd72e23d26fb4...135698455da5c3b3e55f73\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.4.1\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.3.0 to 0.4.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-26T18:05:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ddea3048f573ca77244b16efbf5c7b4f33b304f",
"body": "Fix from new php-cs-fixer",
"is_bot": false,
"headline": "Merge pull request #111 from maxmind/greg/new-php-cs-fixer",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-01-26T18:04:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "979727e84cd5e70847f1408f9bc4d03b5cd9c0bc",
"body": null,
"is_bot": false,
"headline": "Fix from new php-cs-fixer",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-26T16:10:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ab87b496fd0ab36e13c4e69214f244ec945b233",
"body": "…s/checkout-6.0.2\n\nBump actions/checkout from 6.0.1 to 6.0.2",
"is_bot": false,
"headline": "Merge pull request #109 from maxmind/dependabot/github_actions/action…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-01-23T16:11:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bed0d9e81473d9b9839d3058da054cd05a2c63f8",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.1 to 6.0.2.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/8e8c483db84b4bee98b60c0\n[…]\n- dependency-name: actions/checkout\n dependency-version: 6.0.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 6.0.1 to 6.0.2",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-23T14:03:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2b42267d2de1050d7ea92a793dcb1b9de9c7d73c",
"body": "Prepare for release",
"is_bot": false,
"headline": "Merge pull request #108 from maxmind/greg/eng-3822",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-01-13T18:15:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c309236b5a5555b96cf560089ec3cead12d845d2",
"body": null,
"is_bot": false,
"headline": "Ignore cache dir",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:56:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "027574449402cfac268ec28c0e9de58abdd23872",
"body": "PHPUnit 10 requires data provider methods to be static. This fixes\nthe deprecation warning for invalidAuthCodes().\n\nCo-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Make data provider method static for PHPUnit 10",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:30:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "eb87032ccf841feb6ac7d7471d1fdc400a3a03d0",
"body": "PHPUnit 10 is the latest version that supports our minimum PHP 8.1\nrequirement. Update phpunit.xml.dist to use the PHPUnit 10 schema\nand configuration format.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Upgrade PHPUnit from 8/9 to 10",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:30:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3a2ed9b5192ef35d1933bcb05c6d68e19f5308f7",
"body": "Expand single-line empty class definitions to multi-line format\nwith braces on separate lines, removing the need for phpcs:disable\ncomments.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Use PSR-12 compliant class brace style for empty exception classes",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:15:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e2e86b61f43a64a666f20fb6c66298b29bb29e48",
"body": "Mark properties that are only set in the constructor as readonly\nto enforce immutability at the language level.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add readonly modifier to immutable properties",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:12:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "55339b453f15bca900e8982a9f3a934a8db20631",
"body": "Use array spread syntax instead of array_push() for cleaner,\nmore idiomatic PHP.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Replace array_push with spread operator",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:11:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f3adc03d11462bcb4f1fe31e7a1b098ba61dce00",
"body": "Replace strstr() with str_contains() and substr() prefix check with\nstr_starts_with() for better readability and performance.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Use PHP 8.0 string functions",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:10:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "55a126f640f87864794086565c8d525790127d08",
"body": "curl_init() can return false on failure, which would cause a TypeError\nwhen assigned to the typed property or returned from getCurlHandle().\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Handle curl_init() failure in RequestFactory",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:05:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "84530342efea85eed0cafc6d9805bb662f3c059f",
"body": "- Convert PHPDoc property types to native PHP 7.4+ property types\n- Add native return types to methods that only had PHPDoc types\n- Change \\Exception to \\Throwable for broader exception compatibility\n- Increase PHPStan level from 6 to 8\n- Fix type issues in tests for PHPStan level 8 compliance\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add native property and return types, increase PHPStan to level 8",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T17:00:12Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "40c21e094abb7fc4f4959a1572261de8a09818c3",
"body": "Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update copyright year to 2026",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T16:48:04Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "17213eac616f0fa737ee52890574d19fc8efc0f7",
"body": "PSR-2 was deprecated in 2019 and superseded by PSR-12.\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Update coding standard reference from PSR-2 to PSR-12",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T16:47:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a0c07a8a80cd36b0007b425312b58cdf8b7cc0f6",
"body": "Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add CHANGELOG entry for 0.11.1",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-13T16:46:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0b27c709e4d5dadf44f9a28dedc46b1b3462bb62",
"body": "Pin GitHub Actions to SHA for security",
"is_bot": false,
"headline": "Merge pull request #107 from maxmind/greg/eng-3770",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2026-01-08T22:17:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73f8c22d7cb1cae2397b6dcc09bd9433c0c83977",
"body": "Update official GitHub Actions (actions/*, github/*) to use pinned\ncommit SHAs instead of version tags. This satisfies zizmor's\nunpinned-action-reference security check.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Pin GitHub Actions to SHA for security",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2026-01-07T22:14:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "bc3e7f0beba521ea56e90799391807430b963010",
"body": "Remove curl_close() calls",
"is_bot": false,
"headline": "Merge pull request #105 from reedy/curl_close",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-12-29T17:04:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "159bc218a8a2919a8a291240e01d8788c675eb30",
"body": "test.yml: Test on PHP 8.5",
"is_bot": false,
"headline": "Merge pull request #106 from reedy/patch-1",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-12-29T16:46:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04ed0e0e5eafb4f2599524cf4a90c5abd6714050",
"body": null,
"is_bot": false,
"headline": "test.yml: Test on PHP 8.5",
"author_name": "Sam Reed",
"author_login": "reedy",
"committed_at": "2025-12-27T15:41:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31d6452a101dba5f8254883de39d91fe704fc3da",
"body": "No-op since PHP 8.0, deprecated in PHP 8.5. Package needs 8.1\n\nhttps://php.watch/versions/8.5/curl_close-curl_share_close-deprecated",
"is_bot": false,
"headline": "Remove curl_close() calls",
"author_name": "Reedy",
"author_login": "reedy",
"committed_at": "2025-12-27T15:24:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c68454dbae93b7b80c50af1c69af167e44ca976",
"body": "Update Dependabot cooldown to 7 days",
"is_bot": false,
"headline": "Merge pull request #104 from maxmind/greg/eng-3638",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-12-15T20:51:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df33b2e9b12c3bc5bc6212081c6a2d5fe4895b2b",
"body": null,
"is_bot": false,
"headline": "Update Dependabot cooldown from 4 to 7 days",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-12-12T17:20:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5a3cc9e791eee95c984f28764ad9f23d85735c5",
"body": "Improve release script reliability (ENG-1733)",
"is_bot": false,
"headline": "Merge pull request #103 from maxmind/greg/eng-1733",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-12-05T04:02:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dfe99aa78c52b8031d5b71d75cb4e5ab5df359c",
"body": "- Remove redundant git push --tags (gh release create handles tags)\n- Support pre-release versions in changelog parsing\n- Quote date command substitution for defensive programming\n- Fix shellcheck SC2162: add -r flag to read command\n- Apply shfmt formatting",
"is_bot": false,
"headline": "Fix release script consistency issues",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-12-04T15:02:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91f8a9fc48b34afeb530c29bc8c45385015004da",
"body": null,
"is_bot": false,
"headline": "Add pre-flight checks to release script",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-12-03T18:12:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7981268e2ef86d6527746897a8f8ad2ea573c6f5",
"body": "…mathur/setup-php-2.36.0\n\nBump shivammathur/setup-php from 2.35.5 to 2.36.0",
"is_bot": false,
"headline": "Merge pull request #102 from maxmind/dependabot/github_actions/shivam…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-12-02T15:53:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8d47df7fb66fd4effdc20d1711cfbd0bb3c9172a",
"body": "Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php) from 2.35.5 to 2.36.0.\n- [Release notes](https://github.com/shivammathur/setup-php/releases)\n- [Commits](https://github.com/shivammathur/setup-php/compare/bf6b4fbd49ca58e4608c9c89fba0b8d90bd2a39f...44454db4f0199b8b9685a5d763dc\n[…]\ndency-name: shivammathur/setup-php\n dependency-version: 2.36.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump shivammathur/setup-php from 2.35.5 to 2.36.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-02T14:05:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04eb012ace145ef5e4037997e2cdac2ad64360d6",
"body": "…core/zizmor-action-0.3.0\n\nBump zizmorcore/zizmor-action from 0.2.0 to 0.3.0",
"is_bot": false,
"headline": "Merge pull request #101 from maxmind/dependabot/github_actions/zizmor…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-11-27T16:21:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29b9c40ba8c524926286f810342a4b1a000ef6aa",
"body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.2.0 to 0.3.0.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/e673c3917a1aef3c65c972347ed84ccd013ecda4...e639db99335bc9038abc0e\n[…]\nency-name: zizmorcore/zizmor-action\n dependency-version: 0.3.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump zizmorcore/zizmor-action from 0.2.0 to 0.3.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-27T14:05:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e74895df2e3f869735a56aeed7ad1cb2979197a2",
"body": "Add branch validation checks to release script",
"is_bot": false,
"headline": "Merge pull request #100 from maxmind/greg/eng-3512",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-11-26T18:27:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6578f74c4e7cbc7ec709a1b7afbf7a3f37302aeb",
"body": null,
"is_bot": false,
"headline": "Add branch validation checks to release script",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-11-25T21:27:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "387d951d60cfb451b415440545747e004bcec080",
"body": "…/checkout-6\n\nBump actions/checkout from 5 to 6",
"is_bot": false,
"headline": "Merge pull request #99 from maxmind/dependabot/github_actions/actions…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-11-25T17:27:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d30a034ab039a0f08bce4acb670747ddc649eae9",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v5...v6)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n dependency-version: '6'\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump actions/checkout from 5 to 6",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-25T14:05:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c366e9a4c11dbcb37b792d8b854d7ac74b8b74b",
"body": "Release 0.11.0",
"is_bot": false,
"headline": "Merge pull request #98 from maxmind/greg/eng-3323",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-11-20T20:00:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b9e3d3472213361eebdb3ab8879e91b8952091b",
"body": null,
"is_bot": false,
"headline": "Update copyright year",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-11-20T18:33:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "03f48502c7978ed899faeabc3278a39ae440d1c4",
"body": null,
"is_bot": false,
"headline": "Add change log for 0.11.0",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-11-20T18:32:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "12fef95f2325c784b6ddd723f19b79e8eb193b9f",
"body": "Set Dependabot cooldown period",
"is_bot": false,
"headline": "Merge pull request #97 from maxmind/greg/eng-3236",
"author_name": "mm-kevcenteno",
"author_login": "mm-kevcenteno",
"committed_at": "2025-10-31T12:49:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24eb70c1e73413b97558e5c4343b5d8e5a095397",
"body": "This addresses the zizmor findings by setting a cooldown period of 4 days\nfor all package ecosystems in dependabot.yml.\n\nRelated to: ENG-3236",
"is_bot": false,
"headline": "Set Dependabot cooldown period to 4 days",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-10-30T21:27:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d199d2148d5d6970f8b986d81014e7e11af2dd64",
"body": "Fix phpstan failures",
"is_bot": false,
"headline": "Merge pull request #96 from maxmind/greg/fix-phpstan",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-10-14T16:31:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76cfcd30463ee58d3f30d77ce99db93da0683615",
"body": "This was causing issues with PHPStan and should no longer be necessary.\nPHP has support these constants for quite some time as well.",
"is_bot": false,
"headline": "Stop trying to support curl versions from 2007",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-10-13T14:42:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "871cea7ffb19137f3270805d1555adb6e39b4d16",
"body": null,
"is_bot": false,
"headline": "Improve typing on $options",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-10-13T14:42:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d3e66ef12ad15ddbbb2f883ea6b195ce90d7e45",
"body": "…tion-does-not-depend-on-astral-shsetup-uv\n\nRun zizmor via zizmorcore/zizmor-action",
"is_bot": false,
"headline": "Merge pull request #95 from maxmind/wstorey/eng-3188-zizmor-github-ac…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-10-10T17:40:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e207e223adb8bee71b090daa97afbeca615ab8d5",
"body": null,
"is_bot": false,
"headline": "Run zizmor via zizmorcore/zizmor-action",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-10-09T22:10:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa49ace28971fed34d6621b50390ca3d84a7aac6",
"body": "…sh/setup-uv-7.0.0\n\nBump astral-sh/setup-uv from 6.8.0 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #94 from maxmind/dependabot/github_actions/astral-…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-10-08T15:56:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "459867fd0eb859764c71b18e673a50b414954256",
"body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 6.8.0 to 7.0.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/d0cc045d04ccac9d8b7881df0226f9e82c39688e...eb1897b8dc4b5d5bfe39a428a8f2304605e0983c)\n\n---\n[…]\ndependency-name: astral-sh/setup-uv\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump astral-sh/setup-uv from 6.8.0 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-08T14:05:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c388736331c99ed689107c744c2095ddeefeff6",
"body": "…sh/setup-uv-6.8.0\n\nBump astral-sh/setup-uv from 6.7.0 to 6.8.0",
"is_bot": false,
"headline": "Merge pull request #93 from maxmind/dependabot/github_actions/astral-…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-10-01T17:24:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb47dff16306cb5104c3ddda80b4b3dd1695a74d",
"body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 6.7.0 to 6.8.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/b75a909f75acd358c2196fb9a5f1299a9a8868a4...d0cc045d04ccac9d8b7881df0226f9e82c39688e)\n\n---\n[…]\ndependency-name: astral-sh/setup-uv\n dependency-version: 6.8.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump astral-sh/setup-uv from 6.7.0 to 6.8.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-01T14:06:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "119ae33e071a29ba1e0e151161da822683f2dce1",
"body": "…_codesniffer-3.staror-4.star\n\nUpdate squizlabs/php_codesniffer requirement from 3.* to 3.* || 4.*",
"is_bot": false,
"headline": "Merge pull request #90 from maxmind/dependabot/composer/squizlabs/php…",
"author_name": "Gregory Oschwald",
"author_login": "oschwald",
"committed_at": "2025-09-19T17:39:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d95fa788b032ac3a9440687b19da79a479ae8767",
"body": null,
"is_bot": false,
"headline": "Require PHP_CodeSniffer 4+",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-09-19T17:17:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2395d0ff824db91a9442d9da9c07bd39b96b7f3",
"body": "Updates the requirements on [squizlabs/php_codesniffer](https://github.com/PHPCSStandards/PHP_CodeSniffer) to permit the latest version.\n- [Release notes](https://github.com/PHPCSStandards/PHP_CodeSniffer/releases)\n- [Changelog](https://github.com/PHPCSStandards/PHP_CodeSniffer/blob/4.x/CHANGELOG-4.\n[…]\n.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: squizlabs/php_codesniffer\n dependency-version: 4.0.0\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Update squizlabs/php_codesniffer requirement from 3.* to 3.* || 4.*",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-19T17:17:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92016ec63438176d70238d28707a8372370f6ecc",
"body": "…athur/setup-php-2.35.5\n\nBump shivammathur/setup-php from 2.35.4 to 2.35.5",
"is_bot": false,
"headline": "Merge pull request #92 from maxmind/dependabot/github_actions/shivamm…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-09-19T15:24:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b4fac1609761418be95b9dffce3b3365e3e2921",
"body": "Bumps [shivammathur/setup-php](https://github.com/shivammathur/setup-php) from 2.35.4 to 2.35.5.\n- [Release notes](https://github.com/shivammathur/setup-php/releases)\n- [Commits](https://github.com/shivammathur/setup-php/compare/ec406be512d7077f68eed36e63f4d91bc006edc4...bf6b4fbd49ca58e4608c9c89fba0\n[…]\ndency-name: shivammathur/setup-php\n dependency-version: 2.35.5\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump shivammathur/setup-php from 2.35.4 to 2.35.5",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-19T14:04:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7bd9004cf5562612dd0d7ce8728c2bccc24729e",
"body": "update zizmor to version 1.13.0",
"is_bot": false,
"headline": "Merge pull request #91 from maxmind/mmavletkulov/zizmore-update",
"author_name": "mmpnelson",
"author_login": "mmpnelson",
"committed_at": "2025-09-18T14:54:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21174c0dd07e85d049465d14aa295241a36c926d",
"body": null,
"is_bot": false,
"headline": "update zizmor to version 1.13.0",
"author_name": "Marsel Mavletkulov",
"author_login": "marselester",
"committed_at": "2025-09-16T18:10:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a7534211e2e565bfcd998bd600e6137ba354e29",
"body": "…sh/setup-uv-6.7.0\n\nBump astral-sh/setup-uv from 6.6.1 to 6.7.0",
"is_bot": false,
"headline": "Merge pull request #89 from maxmind/dependabot/github_actions/astral-…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-09-15T17:50:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e639de5e3f1797facfd202c05d1c1c516e135ec3",
"body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 6.6.1 to 6.7.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/557e51de59eb14aaaba2ed9621916900a91d50c6...b75a909f75acd358c2196fb9a5f1299a9a8868a4)\n\n---\n[…]\ndependency-name: astral-sh/setup-uv\n dependency-version: 6.7.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump astral-sh/setup-uv from 6.6.1 to 6.7.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-15T14:36:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c695c7147e804b9f160df2558d836457ffb0f2ff",
"body": "…sh/setup-uv-6.6.1\n\nBump astral-sh/setup-uv from 6.6.0 to 6.6.1",
"is_bot": false,
"headline": "Merge pull request #88 from maxmind/dependabot/github_actions/astral-…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-09-03T18:19:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "89c7820775b346ed5bc0d05f5baf00dc609ef611",
"body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 6.6.0 to 6.6.1.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/4959332f0f014c5280e7eac8b70c90cb574c9f9b...557e51de59eb14aaaba2ed9621916900a91d50c6)\n\n---\n[…]\ndependency-name: astral-sh/setup-uv\n dependency-version: 6.6.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "Bump astral-sh/setup-uv from 6.6.0 to 6.6.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-03T10:17:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "64b9159f0fb2c43a85743d54a9a8f65982a8420a",
"body": "…athur/setup-php-2.35.4\n\nBump shivammathur/setup-php from 2.35.3 to 2.35.4",
"is_bot": false,
"headline": "Merge pull request #87 from maxmind/dependabot/github_actions/shivamm…",
"author_name": "William Storey",
"author_login": "horgh",
"committed_at": "2025-08-26T15:00:11Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 10,
"commits_last_year": 115,
"latest_release_at": "2026-01-13T17:57:27Z",
"latest_release_tag": "v0.11.1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 29,
"days_since_latest_release": 190,
"mean_days_between_releases": 345.4
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "maxmind/web-service-common",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "packagist",
"matches_repo": true,
"registry_url": "https://packagist.org/packages/maxmind/web-service-common",
"is_deprecated": false,
"latest_version": "v0.11.1",
"repository_url": "https://github.com/maxmind/web-service-common-php",
"versions_count": 19,
"total_downloads": 91492039,
"dependents_count": 3,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2410707,
"first_published_at": null,
"latest_published_at": "2026-01-13T17:56:03Z",
"latest_version_yanked": null,
"days_since_latest_publish": 190
}
]
},
"popularity": {
"forks": 14,
"stars": 297,
"watchers": 13,
"fork_history": {
"days": [
{
"date": "2015-06-10",
"count": 1
},
{
"date": "2015-06-30",
"count": 1
},
{
"date": "2015-07-26",
"count": 1
},
{
"date": "2016-11-04",
"count": 1
},
{
"date": "2017-01-23",
"count": 1
},
{
"date": "2018-05-09",
"count": 1
},
{
"date": "2018-08-08",
"count": 1
},
{
"date": "2018-11-20",
"count": 1
},
{
"date": "2018-12-12",
"count": 1
},
{
"date": "2019-02-25",
"count": 1
},
{
"date": "2020-01-17",
"count": 1
},
{
"date": "2020-03-24",
"count": 1
},
{
"date": "2022-10-16",
"count": 1
},
{
"date": "2025-12-27",
"count": 1
}
],
"complete": true,
"collected": 14,
"total_forks": 14
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"mise.toml"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 22602,
"source_files_sampled": 17,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"composer.json"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 8,
"direct_affected_count": 0
},
"ecosystems": [
"packagist"
],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "composer/ca-bundle",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "ext-curl",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "ext-json",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "friendsofphp/php-cs-fixer",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "php",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "phpstan/phpstan",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "phpunit/phpunit",
"direct": false,
"version": null,
"ecosystem": "packagist"
},
{
"name": "squizlabs/php_codesniffer",
"direct": false,
"version": null,
"ecosystem": "packagist"
}
],
"collected": true,
"truncated": false,
"total_count": 8,
"direct_count": 0,
"indirect_count": 8
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 119,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 2,
"closed_unmerged_prs": 8
},
"bus_factor": 2,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "oschwald",
"commits": 139,
"avatar_url": "https://avatars.githubusercontent.com/u/278835?v=4"
},
{
"type": "User",
"login": "horgh",
"commits": 73,
"avatar_url": "https://avatars.githubusercontent.com/u/282924?v=4"
},
{
"type": "User",
"login": "faktas2",
"commits": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/104642023?v=4"
},
{
"type": "User",
"login": "NajiObeid",
"commits": 8,
"avatar_url": "https://avatars.githubusercontent.com/u/23505832?v=4"
},
{
"type": "User",
"login": "andyjack",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/8292769?v=4"
},
{
"type": "User",
"login": "ugexe",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/239748?v=4"
},
{
"type": "User",
"login": "rafl",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/25669?v=4"
},
{
"type": "User",
"login": "marselester",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/823099?v=4"
},
{
"type": "User",
"login": "mmpnelson",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/191616823?v=4"
},
{
"type": "User",
"login": "willemstuursma",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/701299?v=4"
}
],
"contributors_sampled": 27,
"top_contributor_share": 0.495
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"dependabot-failure-watcher.yml",
"links.yml",
"lint.yml",
"test.yml",
"zizmor.yml"
],
"has_docs_dir": false,
"linter_configs": [
".php-cs-fixer.php",
"phpstan.neon"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 18 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "244566ddeb072f444f45b164875b6f0a8110253f",
"ran_at": "2026-07-23T16:06:19Z",
"aggregate_score": 8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T17:43:13Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-22T17:42:26Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/maxmind/web-service-common-php",
"host": "github.com",
"name": "web-service-common-php",
"owner": "maxmind"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"security": 80,
"vitality": 75,
"community": 60,
"governance": 79,
"engineering": 66
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 75,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"commits_last_year": 115,
"human_commit_share": 0.75,
"days_since_last_push": 0,
"active_weeks_last_year": 29
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "29/52 weeks with commits",
"points": 20.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 29
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "115 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 115
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "moderate",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"releases_count": 10,
"latest_release_tag": "v0.11.1",
"releases_from_tags": false,
"days_since_latest_release": 190,
"mean_days_between_releases": 345.4
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "10 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 10
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 190 days ago",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "release_recency",
"params": {
"days": 190
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~345.4 days",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 345.4
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 60,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"forks": 14,
"stars": 297,
"watchers": 13,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "297 stars",
"points": 40.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 297
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "14 forks",
"points": 9.3,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 14
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "13 watchers",
"points": 6,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 13
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"packages": [
"maxmind/web-service-common"
],
"dependents": 3,
"ecosystems": "packagist",
"total_downloads": 91492039,
"monthly_downloads": 2410707
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,410,707 downloads/month across packagist",
"points": 80,
"status": "met",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2410707,
"ecosystems": "packagist"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "3 packages depend on it",
"points": 4,
"status": "partial",
"details": [
{
"code": "registry_dependents",
"params": {
"count": 3
}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 79,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 27,
"top_contributor_share": 0.495
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 50% of commits",
"points": 11.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 50
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "27 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 27
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 18 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"merged_prs": 119,
"open_issues": 0,
"closed_issues": 2,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 8
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "119/127 decided PRs merged",
"points": 35.8,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 119,
"decided": 127
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"followers": 331,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "maxmind",
"public_repos": 100,
"account_age_days": 5370
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "331 followers of maxmind",
"points": 18.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 331,
"login": "maxmind"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "100 public repos, account ~14 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 100
}
},
{
"code": "account_age_years",
"params": {
"years": 14
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 91,
"inputs": {
"packages": [
"maxmind/web-service-common"
],
"ecosystems": "packagist",
"any_deprecated": false,
"min_days_since_publish": 190
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on packagist",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "packagist"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 190 days ago",
"points": 26,
"status": "partial",
"details": [
{
"code": "publish_recency",
"params": {
"days": 190
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "19 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 19
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 66,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".php-cs-fixer.php, phpstan.neon",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".php-cs-fixer.php, phpstan.neon"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "at_risk",
"name": "Documentation",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 80,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 12,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 6,
"scorecard_aggregate": 8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 18 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 5
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 60,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.813,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "61 of 75 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 61,
"sampled": 75
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 77,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [
"mise.toml"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.15,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.25
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "mise.toml",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "mise.toml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".php-cs-fixer.php, phpstan.neon",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".php-cs-fixer.php, phpstan.neon"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "15 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 15,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "25 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 25,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "PHP",
"largest_source_bytes": 22602,
"source_files_sampled": 17,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "PHP without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "PHP"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/17 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 17,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-07-23T16:06:45.714724Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/maxmind/web-service-common-php.svg",
"full_name": "maxmind/web-service-common-php",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}