Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-24 13:09 UTC

open-banking-io / clients

Zero-knowledge open banking — server-to-server SDKs (.NET, Node, Python, Rust, Go, Java, Ruby, PHP) and the openbanking CLI for open-banking.io

Go · Python · TypeScriptMIT★ 5 estrellas⑂ 2 forksdesde jun 2026Ver en GitHub ↗

open-banking-io/clients tiene un índice de salud de 64 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Engineering Quality (84/100) y la más baja, Sustainability & Governance (44/100). Se actualizó por última vez hace 2 días. Una sola persona concentra la mayor parte del trabajo reciente.

64
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

64
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

open-banking-ioOrganización
3 seguidores10 repositorios públicosdesde jun 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
Gogithub.com/open-banking-io/clients/gov0.3.0-3hace 6 días
Gogithub.com/open-banking-io/clients/cliv0.2.12-14hace 5 días
Mavenio.open-banking:open-banking-io-client0.3.0-3hace 5 días
crates.ioopen-banking-io0.3.0183hace 5 díaszero-knowledgeecdhfintechpsd2open-bankingapi-bindingscryptography
npm@open-banking-io/n8n-nodes-open-banking-ioapunta a otro repositorio; no se puntúa0.2.27399hace 5 díasn8n-community-node-packagen8nopen-bankingpsd2bankingtransactionsfintech
npm@open-banking-io/client0.3.02604hace 5 díasopen-bankingpsd2zero-knowledgeencryptionfintech
Packagistopen-banking-io/clientapunta a otro repositorio; no se puntúav0.3.003hace 6 díasbankingecdhzero-knowledgeopen-bankingpsd2

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

75Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 2 días
4.8/36Cadencia de commits — 7/52 semanas con commits
18/18Volumen de commits — 161 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year161
human_commit_share0,75
days_since_last_push2
active_weeks_last_year7
Cómo se puntúa
27/27Publica versiones — 34 versiones publicadas
36/36Recencia de las versiones — última versión hace 5 días
27/27Cadencia de publicación — una versión cada ~0 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count34
latest_release_tagn8n/v0.2.2
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases0
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

46En riesgo · 18% del índice global
Cómo se puntúa
9.8/60Estrellas — 5 estrellas
0/25Forks — 2 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks2
stars5
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template
Cómo se puntúa
32.6/80Descargas mensuales — 278 descargas/mes en crates, go, maven, npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesgithub.com/open-banking-io/clients/go, github.com/open-banking-io/clients/cli, io.open-banking:open-banking-io-client, open-banking-io, @open-banking-io/client
dependents
ecosystemscrates, go, maven, npm
total_downloads55
monthly_downloads278
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

44En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.5/22.5Distribución de commits — el principal contribuyente firma el 98% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,976
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
33.8/38.3Aceptación de PR — 122/138 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/22 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs122
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs16
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
4.3/25Alcance del propietario — 3 seguidores de open-banking-io
7.8/25Trayectoria — 10 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers3
owner_typeOrganization
is_verified
owner_loginopen-banking-io
public_repos10
account_age_days44
Cómo se puntúa
25/25Publicado y resoluble — 5 paquete(s) en crates, go, maven, npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 14 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/open-banking-io/clients/go, github.com/open-banking-io/clients/cli, io.open-banking:open-banking-io-client, open-banking-io, @open-banking-io/client
ecosystemscrates, go, maven, npm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

84Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 23 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon
0/9.6Hooks de pre-commit
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_configno
Cómo se puntúa
30/30README
0/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://open-banking.io
10/10Descripción del repositorio
10/10Topics — 10 topics
10/10Wiki
Datos de entrada utilizados
topicsbanking, cli, fintech, open-banking, psd2, sdk, zero-knowledge, aisp, europe, openbanking
has_wiki
homepagehttps://open-banking.io
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

77Bueno · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — sin datos
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
1.2/2.5CII-Best-Practices — badge detected: Passing
0/7.5Code-Review — Found 0/22 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — sin datos
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate7,1
Excluidos de la puntuación (sin datos o no aplicable): branch_protection, signed_releases. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
25/25Dependencias indirectas libres de avisos conocidos — ninguna dependencia indirecta tiene un aviso conocido
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories0
affected_packages0
assessed_packages3
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejó el cierre de dependencias en tiempo de ejecución de maven:io.open-banking:open-banking-io-client@0.3.0 —lo que arrastra la instalación del paquete publicado—: 3 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

76Bueno · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 74 de 75 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,987
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
12.6/18Arranque con un solo comando — cli/go.mod, dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj, dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj (convención del toolchain, sin ejecutor de tareas)
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon
11/11Verificación estática de tipos — n8n/tsconfig.json, node/tsconfig.json
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 53 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 25 de los últimos 100 commits son actualizaciones automáticas de dependencias
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Datos de entrada utilizados
has_nixno
has_tests
lockfilesCargo.lock, Gemfile.lock, go.sum, package-lock.json
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_config
typecheck_configsn8n/tsconfig.json, node/tsconfig.json
agent_commit_share0,53
toolchain_manifestscli/go.mod, dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj, dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj, go/go.mod, java/pom.xml, rust/Cargo.toml
dependency_bot_commit_share0,25
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
55/55Tamaños de archivo manejables — 0/199 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes18.292
source_files_sampled199
oversized_source_files0

Datos clave

5estrellas de GitHub
2contribuidores
161commits en los últimos 12 meses
2días desde el último push
34versiones publicadas
1factor bus
1issues abiertas
crates.io, Go, Maven, npm, Packagist, PyPI, RubyGemsecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • npm package '@open-banking-io/n8n-nodes-open-banking-io' points at a different repository (https://github.com/open-banking-io/n8n); excluded from ecosystem scoring
  • packagist package 'open-banking-io/client' points at a different repository (https://github.com/open-banking-io/client-php); excluded from ecosystem scoring
  • Could not fetch npm package 'open-banking-io-zapier' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

Historial de estrellas y forks 0 ★ / 2 ⇿
0Estrellas
2Forks

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

111222212026-062026-062026-06
OpenSSF Scorecard 7.1 / 10
7.1agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-24 13:09 UTC

10Binary-Artifactsno binaries found in the repo
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
5CII-Best-Practicesbadge detected: Passing
0Code-ReviewFound 0/22 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/dSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
1Vulnerabilities9 existing vulnerabilities detected
Dependencias directas 20
RegistroPaqueteRestricción de versiónManifiesto
PyPIbeancount>=3.0beancount/pyproject.toml
PyPIbeangulp>=0.2beancount/pyproject.toml
PyPIopen-banking-io>=0.2beancount/pyproject.toml
PyPIpyyaml>=6.0beancount/pyproject.toml
Gogithub.com/open-banking-io/clients/gov0.2.0cli/go.mod
Gogolang.org/x/termv0.45.0cli/go.mod
Mavencom.fasterxml.jackson.core:jackson-databind${jackson.version}java/pom.xml
PyPIcryptography>=49.0python/pyproject.toml
PyPIhttpx>=0.28python/pyproject.toml
crates.iop2560.13rust/Cargo.toml
crates.iohkdf0.12rust/Cargo.toml
crates.iosha20.10rust/Cargo.toml
crates.ioaes-gcm0.10rust/Cargo.toml
crates.iobase640.22rust/Cargo.toml
crates.ioserde1rust/Cargo.toml
crates.ioserde_json1rust/Cargo.toml
crates.ioureq3rust/Cargo.toml
crates.iothiserror2rust/Cargo.toml
crates.iozeroize1rust/Cargo.toml
npmzapier-platform-core19.0.0zapier/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Avisos de dependencias 0

Instalar maven:io.open-banking:open-banking-io-client@0.3.0 arrastra 3 paquetes, directos y transitivos: 0 tienen avisos conocidos, de los cuales 0 son dependencias directas.

Ningún aviso conocido afecta a las dependencias evaluadas.

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "banking",
        "cli",
        "fintech",
        "open-banking",
        "psd2",
        "sdk",
        "zero-knowledge",
        "aisp",
        "europe",
        "openbanking"
      ],
      "is_fork": false,
      "size_kb": 1417,
      "has_wiki": true,
      "homepage": "https://open-banking.io",
      "languages": {
        "C#": 52949,
        "Go": 201896,
        "PHP": 63588,
        "Java": 62891,
        "Ruby": 33865,
        "Rust": 44805,
        "Python": 107174,
        "JavaScript": 76021,
        "TypeScript": 86373
      },
      "pushed_at": "2026-07-22T12:10:00Z",
      "created_at": "2026-06-09T14:38:43Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T11:12:56Z",
      "description": "Zero-knowledge open banking — server-to-server SDKs (.NET, Node, Python, Rust, Go, Java, Ruby, PHP) and the openbanking CLI for open-banking.io",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Python",
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "open-banking-io",
      "company": null,
      "location": null,
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/292148346?v=4",
      "created_at": "2026-06-09T14:38:16Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 44
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "n8n/v0.2.2",
          "kind": "other",
          "published_at": "2026-07-18T17:18:39Z"
        },
        {
          "tag": "cli/v0.2.12",
          "kind": "other",
          "published_at": "2026-07-18T16:22:15Z"
        },
        {
          "tag": "cli/v0.2.11",
          "kind": "other",
          "published_at": "2026-07-18T14:16:22Z"
        },
        {
          "tag": "php/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:48Z"
        },
        {
          "tag": "java/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:48Z"
        },
        {
          "tag": "rust/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:48Z"
        },
        {
          "tag": "ruby/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:48Z"
        },
        {
          "tag": "go/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:43Z"
        },
        {
          "tag": "node/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:41Z"
        },
        {
          "tag": "python/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:14:40Z"
        },
        {
          "tag": "dotnet/v0.3.0",
          "kind": "other",
          "published_at": "2026-07-18T14:10:30Z"
        },
        {
          "tag": "erpnext/v0.1.3",
          "kind": "other",
          "published_at": "2026-07-09T15:58:40Z"
        },
        {
          "tag": "erpnext/v0.1.2",
          "kind": "other",
          "published_at": "2026-07-09T15:48:23Z"
        },
        {
          "tag": "erpnext/v0.1.1",
          "kind": "other",
          "published_at": "2026-07-09T15:21:06Z"
        },
        {
          "tag": "erpnext/v0.1.0",
          "kind": "other",
          "published_at": "2026-07-09T14:44:34Z"
        },
        {
          "tag": "beancount/v0.1.0",
          "kind": "other",
          "published_at": "2026-07-04T20:27:42Z"
        },
        {
          "tag": "n8n/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-26T21:17:01Z"
        },
        {
          "tag": "cli/v0.2.7",
          "kind": "other",
          "published_at": "2026-06-16T19:55:51Z"
        },
        {
          "tag": "cli/v0.2.6",
          "kind": "other",
          "published_at": "2026-06-12T08:48:18Z"
        },
        {
          "tag": "cli/v0.2.5",
          "kind": "other",
          "published_at": "2026-06-11T06:28:53Z"
        },
        {
          "tag": "cli/v0.2.4",
          "kind": "other",
          "published_at": "2026-06-11T05:50:35Z"
        },
        {
          "tag": "cli/v0.2.3",
          "kind": "other",
          "published_at": "2026-06-10T23:45:50Z"
        },
        {
          "tag": "cli/v0.2.2",
          "kind": "other",
          "published_at": "2026-06-10T23:02:36Z"
        },
        {
          "tag": "cli/v0.2.1",
          "kind": "other",
          "published_at": "2026-06-10T22:36:59Z"
        },
        {
          "tag": "cli/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T22:25:15Z"
        },
        {
          "tag": "cli/v0.1.0",
          "kind": "other",
          "published_at": "2026-06-10T21:52:55Z"
        },
        {
          "tag": "ruby/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:26:04Z"
        },
        {
          "tag": "java/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:26:03Z"
        },
        {
          "tag": "rust/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:26:02Z"
        },
        {
          "tag": "node/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:26:01Z"
        },
        {
          "tag": "python/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:25:56Z"
        },
        {
          "tag": "dotnet/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:25:50Z"
        },
        {
          "tag": "php/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T22:22:10Z"
        },
        {
          "tag": "go/v0.2.0",
          "kind": "other",
          "published_at": "2026-06-10T21:21:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f5323180f7f82fda0b8d8cab7c3eaacb454fbd70",
          "body": "n8n API requests previously went out with n8n's default User-Agent and\nno open-banking version, unlike the other SDKs. Add a versioned\n`User-Agent: open-banking-io/n8n/<version>` header to every authenticated\nrequest from `apiRequest`.\n\nThe version is derived from package.json (via a new shared/vers\n[…]\n so tsc/vitest resolve the JSON\nimport. Bumped to 0.2.2.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(n8n): send versioned User-Agent on API requests [v0.2.2] (#139)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T17:15:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8035b2d89fdedf7b43b5c462aeec30c046b7c0c7",
          "body": "The CLI's raw token-exchange request (POST /auth/cli/token) set only\nContent-Type, so it went out as Go's default Go-http-client/1.1 with no\nproduct or version. Set a User-Agent of open-banking-io/cli/<version>\nusing the already-threaded App.Version (defaults to \"dev\").\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): send versioned User-Agent on login token exchange (#138)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T16:20:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e874ef11806adb6f58b0dc9d4e8a53f787f6a58d",
          "body": "…(#137)\n\nThe `node/v0.3.0` publish (run 29647665857) signed provenance successfully\nbut the final registry PUT failed with `E404 ... PUT\nhttps://registry.npmjs.org/@open-banking-io%2fclient`. A 404 on PUT to an\nalready-existing package is npm masking a 403 authorization failure: the\npublish reached \n[…]\nance --access public`; no static NPM_TOKEN reintroduced.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(node): restore npm >= 11.5.1 upgrade for OIDC trusted publishing …",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T15:21:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb0003c6da3bcc5c98b018c35ae75dd83d955dc3",
          "body": "Add a 5-arg constructor overload accepting a Duration requestTimeout,\nstored on the instance (defaulting to the existing 30s REQUEST_TIMEOUT\nwhen null) and applied in sendGet/postJson instead of the constant. The\nexisting 4-arg constructor and fromCredentials/fromBundle factories are\nunchanged and d\n[…]\ns against a hung\nserver, and bumps the version to 0.3.0.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(java): configurable per-request timeout [v0.3.0] (#133)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:43:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80423d69a89f72a1e1b11453dbab28e58e68b94e",
          "body": "Add optional, append-only keyword args to OpenBankingIO::Client:\nopen_timeout:/read_timeout: (applied to the internally built Net::HTTP)\nand http_client: (any object responding to #request, used as-is instead\nof building Net::HTTP -- for proxies, custom CA/mTLS, connection pooling).\nThreaded through\n[…]\nr,\nincluding the User-Agent header. Bump 0.2.1 -> 0.3.0.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ruby): configurable timeouts + injectable HTTP client (#131)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:37:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "13689a32d66f51dc9a3fa24b1b61ccfbccbe7af7",
          "body": "CLI releases v0.2.8, v0.2.9 and v0.2.10 all failed at the \"Sign checksums\n(keyless)\" step, so no GitHub Release, binaries, or Homebrew tap update has\nshipped since v0.2.7 (`brew install` still serves 0.2.7).\n\nRoot cause: sigstore/cosign-installer @v4.1.2 installs a cosign whose default\nflipped to `-\n[…]\nfollow-up can\nmigrate to the bundle format deliberately.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): pin cosign to v2.4.3 to unblock release signing (#136)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:35:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9bc8e5612b541e3c0dde6c73f8fcdad0420f252b",
          "body": "* feat(php): custom cURL options + configurable timeouts [v0.3.0]\n\nAdd an optional 4th constructor arg `array $options` (append-only) to\n`Client`, threaded through `fromCredentials`. Supported keys:\n\n- `curl_options`: map of `CURLOPT_* => value` applied LAST via\n  curl_setopt_array, so callers win o\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(php): custom cURL options + configurable timeouts [v0.3.0] (#135)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:29:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30f7908f7c02b6f9254c3bf5f635e0c7aa0e7122",
          "body": "…v0.3.0] (#127)\n\n* feat(node): support custom fetch implementation (custom HTTP agent) [v0.3.0]\n\nAdd an optional `fetch?: typeof globalThis.fetch` to OpenBankingClientOptions\nso integrators can supply their own transport (proxy, custom CA/mTLS, keep-alive,\nconnection pooling) by passing a fetch boun\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(node): support custom fetch implementation (custom HTTP agent) […",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:24:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69653b173cc076c3214f0c3ab9f9691ce97195fc",
          "body": "Add an optional `timeout: float | None = None` kwarg to\n`OpenBankingClient.__init__` and thread it through `from_credentials`.\nThe timeout is applied only when no `http_client` is injected, when\nconstructing the default `httpx.Client`; a caller-supplied client is\nused as-is and never has its timeout\n[…]\nAgent behavior\nis unchanged. Bumps the package to 0.3.0.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(python): optional timeout for default httpx client [v0.3.0] (#130)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:22:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "86434a253f02ccf13d337f4a3776a7e40ead63a3",
          "body": "Add an append-only `OpenBankingClient::builder(...)` returning\n`OpenBankingClientBuilder` with chainable `.agent(ureq::Agent)`,\n`.connect_timeout(Duration)`, `.timeout(Duration)`, and `.build()`.\n\nThe default agent construction is refactored into shared private\nhelpers (`build_agent` / `default_agen\n[…]\ngent / validation parity, and bump\nthe version to 0.3.0.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rust): client builder with custom agent + timeouts [v0.3.0] (#129)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:20:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a899251a004faab33d1aa6ff6a03676e06bf6245",
          "body": "…0.3.0] (#128)\n\n* feat(go): NewWithOptions with custom HTTP client/transport/timeout [v0.3.0]\n\nAdd an append-only functional-options constructor to the Go SDK so integrators\ncan bring their own HTTP transport (proxy, custom CA / mTLS, connection pooling)\nand configure timeouts without the positional\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(go): NewWithOptions with custom HTTP client/transport/timeout [v…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:19:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "deaaee08680112c510518ed0f4eb2f71d0bb5bab",
          "body": "Surface the already-wired App.HTTPClient via opt-in configuration, keeping\ndefault behavior identical (nil client → SDK default).\n\n- Add a global --timeout <duration> flag, parsed in main.go and stripped\n  before dispatch so it applies to every command's HTTP calls.\n- Add OPENBANKING_CA_CERT env: a \n[…]\nlly untouched (SDK require bump is a release-time step).\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): --timeout flag and custom CA for HTTP client (#134)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:13:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9b816de7dfff1e9317ff7163914ca3ccc14d8b32",
          "body": "…] (#132)\n\nAdd an optional `TimeSpan? timeout = null` parameter to the\nOpenBankingClient constructor (append-only, after `httpClient`). It is\napplied only to the default HttpClient the SDK creates when no client is\ninjected; a caller-owned HttpClient is never mutated. Threaded through\nFromCredentials/FromBundle. Bumps the package version to 0.3.0.\n\n\nClaude-Session: https://claude.ai/code/session_01KezUhW1knvXBjf7GAaeJLt\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dotnet): optional request timeout for default HttpClient [v0.3.0…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-18T00:07:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c441f2cc2d287066e937d04378b7b52fcabb01cb",
          "body": "Bumps [prettier](https://github.com/prettier/prettier) from 3.9.4 to 3.9.5.\n- [Release notes](https://github.com/prettier/prettier/releases)\n- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/prettier/prettier/compare/3.9.4...3.9.5)\n\n---\nupdated\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump prettier from 3.9.4 to 3.9.5 in /node (#119)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:47:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "75a87b843bf800e12d63e775f8dda00d4cb0ef1a",
          "body": "…ava (#122)\n\nBumps [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) from 4.10.2.0 to 4.10.3.0.\n- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)\n- [Commits](https://github.com/spotbugs/spotbugs-maven-plugin/compare/spotbugs-ma\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump com.github.spotbugs:spotbugs-maven-plugin in /j…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:46:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bad64dd85ef8f06d53e401a207bbf3cd7a95b59c",
          "body": "Bumps [golang.org/x/term](https://github.com/golang/term) from 0.44.0 to 0.45.0.\n- [Commits](https://github.com/golang/term/compare/v0.44.0...v0.45.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/term\n  dependency-version: 0.45.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 in /cli (#120)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:43:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd21049017a69fabdb1d74487c5f19993465b17d",
          "body": "Bumps [eslint](https://github.com/eslint/eslint) from 10.6.0 to 10.7.0.\n- [Release notes](https://github.com/eslint/eslint/releases)\n- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.7.0)\n\n---\nupdated-dependencies:\n- dependency-name: eslint\n  dependency-version: 10.7.0\n  dependency-\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump eslint from 10.6.0 to 10.7.0 in /node (#123)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:42:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f403ca3478eee47f133370d10cef0f51982e080f",
          "body": "Bumps [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) from 6.1.1 to 6.1.2.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.1...r6.1.2)\n\n---\nupdated-dependencies:\n- depend\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump org.junit.jupiter:junit-jupiter in /java (#121)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:39:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1cd7bb43109ee9882b79c6b4ef27cb1f7cf28cdf",
          "body": "…e (#124)\n\nBumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.63.0 to 8.64.0.\n- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)\n- [Changelog](https://github.com/typescript-eslint/typescript-es\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump typescript-eslint from 8.63.0 to 8.64.0 in /nod…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:38:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e030fced40f47903437ae2b440f30d91a53a39ed",
          "body": "---\nupdated-dependencies:\n- dependency-name: Microsoft.NET.Test.Sdk\n  dependency-version: 18.8.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1 (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4fa5937d3f6e87ffd7a9d476f065db18c738e4f",
          "body": "Bumps the actions group with 4 updates: [actions/setup-node](https://github.com/actions/setup-node), [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action), [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [taiki-e/install-action](https://github.com/taiki-e/in\n[…]\npe: version-update:semver-minor\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the actions group with 4 updates (#126)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T23:34:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0168aa4d8e0fddb82680db2a9b058281cdddaa0e",
          "body": "…#116)\n\nPre-filled submission guide (steps, compliant listing copy, verified logo/\nprivacy/support URLs, compliance table) for the one part that can't be\nautomated: the Frappe Cloud web-UI submission under the org owner's login.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(erpnext): add PUBLISHING.md — Frappe Cloud Marketplace runbook (…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-11T21:19:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "63c41f383db60a4ecedee70daf0b45de4f91f3ce",
          "body": "Frappe Cloud's parser does value.replace(' ','').replace(',',' ') before\nNpmSpec(), so the space form '>=15.0.0 <16.0.0' collapsed to the invalid\n'>=15.0.0<16.0.0' and kept failing with 'Invalid version format'. The\ncomma form '>=15.0.0,<16.0.0' (what hrms uses) parses to a valid bounded\nrange.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(erpnext): use comma form for frappe-dependencies (v0.1.3) (#118)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-09T15:57:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "889b6553146115ed2a0f3ec940851d82d25a41c1",
          "body": "…1.2) (#117)\n\nFrappe Cloud Marketplace rejects the app with 'Invalid version format …\nuse NPM-style semver ranges' because pyproject had no\n[tool.bench.frappe-dependencies]. Add it (frappe/erpnext >=15.0.0 <16.0.0,\nmatching the tested v15 bench), same field frappe/hrms uses.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(erpnext): declare Frappe/ERPNext compat for the marketplace (v0.…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-09T15:47:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5b063993ac9646363a2f3419a86233f4fb8324b",
          "body": "* feat(erpnext): marketplace readiness — mirror CI, lint, v0.1.1\n\nPrep for a Frappe Cloud Marketplace listing (App Auditor / app-authoring\nguidelines want passing CI with linters + server tests):\n\n- erpnext/.github/workflows/ci.yml — CI for the mirror repo (ruff + pytest\n  on 3.10/3.11/3.13); dorman\n[…]\nic.com>\n\n* ci(erpnext): pin ruff to 0.13.1 for reproducible lint (CodeRabbit)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(erpnext): marketplace readiness — mirror CI + lint (v0.1.1) (#115)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-09T15:20:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ba4929388b2e95b23c88a35ae7e5a6969ac2d804",
          "body": "* feat(erpnext): add release + mirror distribution infrastructure\n\nThe ERPNext app was installable only from a local monorepo checkout. Give\nit the same subtree-split mirror distribution as n8n/php/zapier so users can\n`bench get-app https://github.com/open-banking-io/erpnext`.\n\n- publish-erpnext.yml\n[…]\nt)\n- RELEASING.md <dir> enumeration now includes beancount/erpnext/zapier/cli\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(erpnext): release + mirror distribution infrastructure (#114)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-09T14:43:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1d542c16d8cef6b7cdbe98e70cac9741dfb8969a",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(zapier): add CHANGELOG.md (required by zapier promote) (#113)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T22:36:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7f665081e881d445ce3bbd81c0b80a6c9510e092",
          "body": "* feat(zapier): App Directory publication prep, release 1.0.1\n\nAddresses the remaining zapier validate warnings ahead of the public\nApp Directory submission:\n\n- D028: flags.cleanInputData = false app-wide; ''/null inputs now\n  handled explicitly (lookbackDays and limit treat '' as unset)\n- D002: aut\n[…]\n+coderabbitai[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(zapier): App Directory publication prep; release 1.0.1 (#112)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T22:27:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8b15c3bd50294926764a51d4d0214393cd06cf1e",
          "body": "…n (#111)\n\nThe platform enforces version contiguity relative to existing versions\n(0.1.2 demanded 0.1.1; 0.2.0 demanded 0.1.x). No version has ever been\nuploaded, and new integrations canonically start at 1.0.0 (the zapier\ninit scaffold default) — which is exempt as the initial version.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(zapier): version 1.0.0 — Zapier's canonical first upload versio…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T21:50:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "05a889acd6f54fd62815cd7d2fba20a106525bf6",
          "body": "…sion to be an x.y.0 (#110)\n\nThe platform enforces patch contiguity (0.1.2 requires 0.1.1 to exist);\n0.1.0/0.1.1 tags never uploaded due to earlier push failures, so start\nthe platform history cleanly at 0.2.0.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(zapier): bump to 0.2.0 — Zapier requires the first uploaded ver…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T21:39:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "902dbc3501aa582504a0bf640978974671762533",
          "body": "…), release 0.1.2 (#109)\n\nzapier push runs server-side integration checks; D009 blocks a search\nwith no input fields. Find Account gains an optional case-insensitive\nquery filter over IBAN/BBAN/names/bank; empty query still lists all.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(zapier): add search field to Find Account (integration check D009…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T21:35:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "152362206bcdd53f99fc393f744dc7477a9c0875",
          "body": "* fix(zapier): pin zapier-platform-core to exact version, release 0.1.1\n\nzapier push rejects range specifiers (^19.0.0) — the v0.1.0 release\nfailed at the final upload step on this. Pin core (and schema) to\n19.0.0 exactly, add a test guarding the exact-pin requirement, and bump\nto 0.1.1 for a clean \n[…]\n\n\n* test(zapier): assert exact pins independently, not cross-package equality\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(zapier): pin zapier-platform-core exactly; release 0.1.1 (#108)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T21:23:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98e787f8bbd6e913f197d9c575c25d5ed6550799",
          "body": "Registered via one-time bootstrap workflow on the mirror repo; the app id\nand key are not secrets — ZAPIER_DEPLOY_KEY (CI secret) authenticates.\nRequired by zapier push in the mirror publish workflow.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(zapier): commit .zapierapprc app link (id 243680) (#107)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T21:09:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c1511c53bbdb718f87c8db64e7e1df4c5b16244e",
          "body": "…w follow-ups (#106)\n\n* fix(erpnext): make the app installable and usable — review follow-ups\n\nAdversarial review found the app had never been run against a real bench:\n\n- Add the missing app-package __init__.py (with __version__): setuptools\n  discovered zero packages, so `bench get-app` produced a\n[…]\nre(erpnext): align Python minimum at 3.10 (pyproject, classifiers, CI matrix)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(erpnext): make the app installable and usable — adversarial revie…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T17:29:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "47f02ed5f92ba5892a580f2041668d587e274466",
          "body": "…(#105)\n\n* fix(zapier): make the app deployable — review follow-ups\n\nAdversarial review found the integration had never been validated against\nthe Zapier platform:\n\n- index.js: triggers/searches/creates were arrays; AppSchema requires\n  objects keyed by operation key, so `zapier push` failed validat\n[…]\nrefactor(zapier): shared listAccounts helper; test pending-finalization dedup\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(zapier): make the app deployable — adversarial review follow-ups …",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T17:24:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2cb39e98cef55e94d55fa4961e2dcae76d7cf007",
          "body": "… (#104)\n\nBumps the actions group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.2` |\n| [actions/setup-java](https://github.com/actions/setup-java) | `5.4.0` | `5.5.0` |\n| [github/codeql-a\n[…]\npe: version-update:semver-minor\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the actions group across 1 directory with 6 updates…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T16:55:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a171b425e6c9e6e54c6cfc077d19e8e4c501f3",
          "body": "…a (#98)\n\nBumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) from 2.22.0 to 2.22.1.\n- [Commits](https://github.com/FasterXML/jackson/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson.core:jackson-databind\n  dependency-version: 2.22.1\n\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump com.fasterxml.jackson.core:jackson-databind in /jav…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T16:50:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bac54a70a177e49c33705783f979fe4fda80688b",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.4 to 25.9.5.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @types/node from 25.9.4 to 25.9.5 in /node (#101)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T16:49:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7951a4b56566c85564ea0069cf109728dee6759e",
          "body": "…de (#99)\n\nBumps [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) from 4.1.9 to 4.1.10.\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)\n- [Commits](https://github\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @vitest/coverage-v8 from 4.1.9 to 4.1.10 in /no…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T16:44:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6253721cf2cffee55f457d397e8d860c747f0fc8",
          "body": "* chore: apply remaining CodeRabbit findings from #86/#96\n\nFollow-ups that never became resolvable review threads (failed-to-post\ninline comments and outside-diff notes):\n\n- ci.yml: persist-credentials: false on every checkout (repo-wide pass\n  deferred from both PRs)\n- changed-packages.yml: concurr\n[…]\nnoreply@anthropic.com>\n\n* fix(zapier): cap per-account fetch concurrency at 4\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: apply remaining CodeRabbit findings from #86/#96 (#103)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-08T16:37:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8360d4c9a030ce61c55067c4a7eed8f720ca2873",
          "body": "* feat: add Zapier integration app\n\nZapier app for open-banking.io — mirrors the n8n node architecture:\nvendored zero-knowledge envelope (Web Crypto, zero deps), z.request()-based\nAPI client, polling trigger with cursor+dedup, and full test suite.\n\n- lib/envelope.js: vendored decryptor (byte-identic\n[…]\n<noreply@anthropic.com>\n\n---------\n\nCo-authored-by: john-frandsen <john@open-banking.io>\nCo-authored-by: Nicolaj Hartmann <nhh@softwarehuset.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add Zapier integration app (#96)",
          "author_name": "John Frandsen",
          "author_login": "john-frandsen",
          "committed_at": "2026-07-08T11:02:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c6eee82e5390d24ae0a83aa5dfe159fd5c6e76ec",
          "body": "* feat: add ERPNext Open Banking integration app\n\nAdds erpnext_open_banking — a Frappe/ERPNext app that syncs bank\ntransactions from open-banking.io into ERPNext's Bank Transaction\ndoctype, ready for the Bank Reconciliation Tool.\n\nKey differentiators vs the existing GoCardless app:\n- No eIDAS/QWAC c\n[…]\ny@anthropic.com>\n\n---------\n\nCo-authored-by: john-frandsen <john@open-banking.io>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: ERPNext Open Banking integration app (#86)",
          "author_name": "John Frandsen",
          "author_login": "john-frandsen",
          "committed_at": "2026-07-08T10:45:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d76764c80fd17ade0c3a62b31a365e2b141d2ce",
          "body": "The pull_request-triggered report job gets a read-only GITHUB_TOKEN on\nfork PRs, so posting the sticky comment failed with 403. Split it into\nthe workflow_run pattern: the PR job now only detects changed dirs and\nuploads them as an artifact, and a new trusted workflow posts the\ncomment with a write \n[…]\ns the comment body\nfrom booleans and verifies the claimed PR number against the run's\nhead SHA, since the artifact comes from untrusted PR code.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: make changed-packages comment work for fork PRs (#97)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-07T22:12:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd4730860e3e2a02ef441173d951446f2672be93",
          "body": "Bumps [eslint](https://github.com/eslint/eslint) from 10.5.0 to 10.6.0.\n- [Release notes](https://github.com/eslint/eslint/releases)\n- [Commits](https://github.com/eslint/eslint/compare/v10.5.0...v10.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: eslint\n  dependency-version: 10.6.0\n  dependency-\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump eslint from 10.5.0 to 10.6.0 in /node (#90)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T08:32:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0834078094b60e01d5eece13ebc5f0b6b1aae8d8",
          "body": "…e (#88)\n\nBumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.62.0 to 8.63.0.\n- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)\n- [Changelog](https://github.com/typescript-eslint/typescript-esl\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump typescript-eslint from 8.62.0 to 8.63.0 in /nod…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T08:31:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7054e99c030d8165f629bf7e6c41f591187b1fa3",
          "body": "Bumps [prettier](https://github.com/prettier/prettier) from 3.8.4 to 3.9.4.\n- [Release notes](https://github.com/prettier/prettier/releases)\n- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/prettier/prettier/compare/3.8.4...3.9.4)\n\n---\nupdated\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump prettier from 3.8.4 to 3.9.4 in /node (#89)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T06:34:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d5887e90fd38d9057c7647f6a7c2f8afc4c97ba",
          "body": "…s (#94)\n\nBumps the actions group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.1` | `4.0.2` |\n| [actions/setup-dotnet](https://github.com/actions/setup-dotnet) | `5.3.0` | `5.4.0` |\n| [golangci/g\n[…]\npe: version-update:semver-patch\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the actions group across 1 directory with 10 update…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-05T19:53:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b56eab861576cefa727c420db2f936cc67778cf",
          "body": "Bumps [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) from 6.1.0 to 6.1.1.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.0...r6.1.1)\n\n---\nupdated-dependencies:\n- depend\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump org.junit.jupiter:junit-jupiter in /java (#87)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-05T19:50:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ef7ff319a9b8decfd655e6fab4869ab4eba521d",
          "body": "* Add beancount-openbanking-io importer package\n\nNew top-level `beancount/` integration (mirroring the `n8n/` precedent): a\nBeancount/beangulp importer that pulls transactions from open-banking.io into a\nplaintext-accounting ledger via the official `open-banking-io` Python SDK.\n\n- src/ layout, hatch\n[…]\no\n  avoid an extra fetch.\n- Tests for both cases.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add beancount-openbanking-io importer package (#93)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-04T19:55:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0dfc482ee37d0226a28b0724c5bd55c29abf2f24",
          "body": "n8n verification flagged the `overrides` block as [HIGH] — it's not allowed\nin community node packages. Each community package installs into an isolated\ndependency tree, so the overrides had no effect on the published artifact\n(only dist/ is shipped; lodash/uuid/form-data were dev-transitive only).\n\n[…]\nand the version bump — the\nplatform-optional @emnapi entries CI resolves are preserved, avoiding the\nlockfile-sync (EUSAGE) drift.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "n8n: remove overrides field, publish 0.2.1 (#92)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-07-02T12:02:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b1862a5bcd019705f675c525da1ebf354a0713e5",
          "body": "…coded string (#85)\n\n__version__ was hardcoded to \"0.1.0\" while pyproject.toml declares\n\"0.2.1\" — it went stale after the 0.2.0 release and never got bumped.\nDerive it dynamically from importlib.metadata so it can never drift again.\nAdded a regression test that asserts __version__ matches the installed\npackage metadata.\n\nCo-authored-by: john-frandsen <john@open-banking.io>",
          "is_bot": false,
          "headline": "fix(python): derive __version__ from package metadata instead of hard…",
          "author_name": "John Frandsen",
          "author_login": "john-frandsen",
          "committed_at": "2026-06-29T19:01:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa91c06023db9f68a5a1f67661cb9daac6156ad2",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.3 to 25.9.4.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @types/node from 25.9.3 to 25.9.4 in /node (#80)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T21:20:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8574081db91a5b5cb8e8f2f38a2903db9dff7940",
          "body": "… (#84)\n\n- Wrap HTTP errors in execute() and poll() in NodeApiError so the n8n\n  UI gets status code and response context. NodeOperationError instances\n  in execute() re-throw as-is so per-item context is preserved.\n- Fix the codex `node` package prefix in both .node.json files: from\n  the placeholder `n8n-nodes-base.*` to the scoped npm name\n  `@open-banking-io/n8n-nodes-open-banking-io.*`.",
          "is_bot": false,
          "headline": "n8n: address verification feedback (NodeApiError + codex node prefix)…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-26T21:11:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea5865453d99b2e9bb746eacdd87940160ad233c",
          "body": "…s (#83)\n\nBumps the actions group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `6.0.3` | `7.0.0` |\n| [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` |\n| [actions/setup-\n[…]\npe: version-update:semver-patch\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the actions group across 1 directory with 10 update…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T16:44:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36c31e2db5fe4167156a9b38d2bf95d5f789f898",
          "body": "Bumps [zeroize](https://github.com/RustCrypto/utils) from 1.8.2 to 1.9.0.\n- [Commits](https://github.com/RustCrypto/utils/compare/zeroize-v1.8.2...zeroize-v1.9.0)\n\n---\nupdated-dependencies:\n- dependency-name: zeroize\n  dependency-version: 1.9.0\n  dependency-type: direct:production\n  update-type: ver\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "build(deps): bump zeroize from 1.8.2 to 1.9.0 in /rust (#78)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T16:42:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fcb92e09acd1db9edff11be841795e93d3643a1",
          "body": "…e (#81)\n\nBumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.61.1 to 8.62.0.\n- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)\n- [Changelog](https://github.com/typescript-eslint/typescript-esl\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump typescript-eslint from 8.61.1 to 8.62.0 in /nod…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T16:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59853b6f1748026a5a3566d22bc02ce46470ed0e",
          "body": "---\nupdated-dependencies:\n- dependency-name: Microsoft.NET.Test.Sdk\n  dependency-version: 18.7.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump Microsoft.NET.Test.Sdk from 18.6.0 to 18.7.0 (#82)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T16:39:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef282e359ff426a2ca6c37d704dd30947f27f087",
          "body": "…lugin (#77)\n\nBumps [org.sonatype.central:central-publishing-maven-plugin](https://github.com/sonatype/central-publishing-maven-plugin) from 0.10.0 to 0.11.0.\n- [Commits](https://github.com/sonatype/central-publishing-maven-plugin/commits)\n\n---\nupdated-dependencies:\n- dependency-name: org.sonatype.c\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump org.sonatype.central:central-publishing-maven-p…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T19:25:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d49d6a15849f2fb11a362be9e0b1642065abcc6",
          "body": "The project earned the OpenSSF Best Practices 'passing' badge. Embedding the\nbadge in the README is what Scorecard's CII-Best-Practices check detects, so\nthis also moves that check off 0.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add OpenSSF Best Practices badge (passing, project 13284) (#76)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:42:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "060fe33f0403cd4f9f2ff3e33119c8418dfc7d05",
          "body": "…ctices) (#74)\n\nCloses the two doc gaps from the OpenSSF Best Practices audit:\n- Add CHANGELOG.md documenting the per-package versioning scheme and pointing\n  to GitHub Releases for detailed notes.\n- SECURITY.md: state explicit response targets (48h ack, 7-day assessment,\n  ~90-day coordinated disclosure) instead of acknowledgement-only.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add CHANGELOG and explicit vuln-response timeline (CII Best Pra…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:39:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dc2abf01bdd5962c3f8f624bc2a06b9639659395",
          "body": "… (#75)\n\ncosign signs the checksums but produces no provenance, so Scorecard warns\n'does not have provenance' on every CLI release. Add actions/attest-build-\nprovenance for the binaries and attach the bundle to the release as\n*.intoto.jsonl, so future releases carry both a signature and SLSA provena\n[…]\nN of last 4 signed' part of the score rises on its own as the pre-cosign\nreleases v0.2.4-v0.2.6 roll out of the 4-release window.)\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: add SLSA build provenance to CLI releases (Signed-Releases)…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:37:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f9f8d6637bb62090791002db0f8d53a17196c1ec",
          "body": "…sions) (#73)\n\nThe workflow defaulted to top-level 'contents: write'; move it to read-only\nat the top and grant write only on the release job that tags + creates the\nGitHub Release. This is the only workflow with a top-level write token, which\nis what OpenSSF Scorecard's Token-Permissions check penalizes.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: scope release.yml write permission to the job (Token-Permis…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:10:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "30b52c1681a4b9a79a8607282826266b305201a7",
          "body": "…k) (#71)\n\nAdds a native Go fuzz target, FuzzDecryptEnvelope, over the zero-knowledge\nenvelope wire parser in go/envelope.go. The envelope is attacker-influenced\nciphertext from the network and its fixed header is sliced purely by length,\nso 'never panic on malformed input' is the invariant worth fu\n[…]\nth no crashes. CI runs the seed corpus plus a 20s exploratory\npass. Scorecard detects the native FuzzXxx target (Fuzzing 0 -> 10).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: add envelope-parser fuzzing (OpenSSF Scorecard Fuzzing chec…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:10:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f1078e373d2b40e73a355425bc672e4363926eb",
          "body": "The CLI's API base URL was only settable via `login` (writing apiBaseUrl into\nthe saved credentials bundle), so pointing it at staging/local meant re-running\nlogin or hand-editing the bundle. Add an OPENBANKING_API_BASE_URL environment\nvariable: when set it overrides the saved bundle's apiBaseUrl fo\n[…]\nintegration test (override redirects the\nclient) and a unit test (blank override is a no-op); documents the var in the\nCLI README.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): add OPENBANKING_API_BASE_URL env override (#72)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T20:06:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6224475fd4a6a1248d6c16e425a74a59874ba8f3",
          "body": "* n8n: add optional API Base URL Override to credential (0.2.0)\n\nThe API base URL was only configurable via the apiBaseUrl field buried inside\nthe pasted credentials bundle, so pointing the node at staging/local meant\nexporting and pasting a different bundle. Add an optional 'API Base URL\nOverride' \n[…]\nrrides (esbuild/lodash/uuid/form-data) unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: raise OpenSSF Scorecard (SAST, vulns, signing, pinning) (#70)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T19:54:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee824326f8b3e0cd16b4a7a5442d5b1e2a598386",
          "body": "The API base URL was only configurable via the apiBaseUrl field buried inside\nthe pasted credentials bundle, so pointing the node at staging/local meant\nexporting and pasting a different bundle. Add an optional 'API Base URL\nOverride' field on the credential: when set it overrides the bundle's\napiBa\n[…]\ne, the trigger node and the credential Test);\nempty keeps current behaviour. Logic lives in a new resolveBundle() helper.\n\nAdds resolveBundle unit tests and a node-level override test; bumps to 0.2.0.",
          "is_bot": false,
          "headline": "n8n: add optional API Base URL Override to credential (0.2.0) (#69)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T19:23:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a553096c802d237f8b084ba88c751e02a63c8681",
          "body": "* php: bump phpunit to ^13\n\n* php: require PHP >=8.2 with phpunit ^11||^12, test matrix 8.2-8.5",
          "is_bot": false,
          "headline": "php: bump phpunit to ^13 (#62)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:53:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03680a79511f793bfd0c943aafdf53ac8df65683",
          "body": "* ruby: update simplecov-cobertura and standard (lockfile)\n\n* ruby: regenerate Gemfile.lock for simplecov-cobertura 3.2 and standard 1.55",
          "is_bot": false,
          "headline": "ruby: update simplecov-cobertura and standard (#63)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:50:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83a5a72abc7a9736aecaefec10aee75d650b09aa",
          "body": "* node: bump dev dependencies (eslint 10, vitest 4, typescript 6)\n\n- @eslint/js ^9.39.4 -> ^10.0.1\n- eslint ^9.39.4 -> ^10.5.0\n- @vitest/coverage-v8 ^3.2.6 -> ^4.1.9\n- vitest ^3.2.6 -> ^4.1.9\n- typescript ^5.7.2 -> ^6.0.3\n- tsup ^8.3.5 -> ^8.5.1\n- typescript-eslint ^8.61.0 -> ^8.61.1\n- @types/node ^\n[…]\n ignoreDeprecations: \"6.0\" to tsconfig so the tsup DTS build (which\ninjects baseUrl via rollup-plugin-dts) does not error under TypeScript 6.\n\n* node: regenerate package-lock.json to match bumped deps",
          "is_bot": false,
          "headline": "node: bump dev dependencies (eslint 10, vitest 4, typescript 6) (#59)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:50:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d38bd2c053517ffcc1c6b34a00ea52c8fa3092a",
          "body": "* n8n: bump dev dependencies (eslint, typescript 6, vitest 4, n8n-workflow 2)\n\nBump the n8n community node's dev dependencies. ESLint is held at v9\n(not v10) because eslint-plugin-n8n-nodes-base 1.16.6 still calls the\ncontext.getFilename() API that ESLint 10 removed; v10 would break the\ncommunity-no\n[…]\nd in TS 6).\n- envelope.ts: return Uint8Array<ArrayBuffer> from base64ToBytes so Web\n  Crypto BufferSource args typecheck under @types/node 25.\n\n* n8n: regenerate package-lock.json to match bumped deps",
          "is_bot": false,
          "headline": "n8n: bump dev dependencies (#65)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:49:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad9da31be469573e3cf25b8eec3ad2f5091b7db1",
          "body": null,
          "is_bot": false,
          "headline": "dotnet: bump coverlet.collector to 10.0.1 (#61)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:38:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee7ebaf5840d83f8226fb4100e082a8cda3d8368",
          "body": "…#60)",
          "is_bot": false,
          "headline": "python: bump dependencies (cryptography 49 floor, pytest 9, mypy 2) (…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T18:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d712af2a6a899bf233034da986f84abaa1ae6fab",
          "body": "* ci: skip per-package build/test steps when the package is unchanged\n\nCI and Coverage ran the full multi-language matrix on every PR, even when\nonly one package changed. Add a paths-filter 'changes' job to both\nworkflows and gate each language job's steps on whether that package (or\nshared fixtures\n[…]\nequired status check (passes on skipped/success, fails on\nfailure/cancelled).\n\nThis lets branch protection require just semgrep, gitleaks, ci-gate and\ncoverage-gate instead of ~30 per-matrix contexts.",
          "is_bot": false,
          "headline": "ci: skip per-package builds when the package is unchanged (#68)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T17:47:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b746a2ba9f73d3a9c3fb63a8f95670312a17e4f",
          "body": null,
          "is_bot": false,
          "headline": "rust: bump thiserror to 2 and ureq to 3 (#64)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-16T10:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed9747d42a93031b79e3eacf33068668abf5bdc0",
          "body": "…hing (#67)",
          "is_bot": false,
          "headline": "n8n(mirror): run publish in Production environment for trusted publis…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T21:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad0157e6c059076a0a09b7492c3cd22a89c953d2",
          "body": "…(#66)\n\nn8n verification clones the repo from package.json.repository and looks for the\nnode/credential source at the repo ROOT — it does not honour repository.directory,\nso the monorepo subdirectory layout fails (\"can't find credential file in repo\").\n\nMirror the n8n/ package to a dedicated repo wh\n[…]\ng-io/n8n and verification finds the source at the root.\n- package.json repository -> open-banking-io/n8n (drop directory).\n\nDevelopment stays in this monorepo; the mirror is publish/verification only.",
          "is_bot": false,
          "headline": "n8n: publish via subtree-split mirror to open-banking-io/n8n (0.1.5) …",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T21:11:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b04304310d1a205841b397ee089e7b4a59dedfe",
          "body": null,
          "is_bot": false,
          "headline": "ci(n8n): publish via npm trusted publishing (drop NODE_AUTH_TOKEN) (#58)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:52:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9de7b07776c15d3b06ecdc9ac9189313cd5282e",
          "body": "@n8n/scan-community-package flagged two issues:\n- no-restricted-globals: use `crypto.subtle` instead of `globalThis.crypto.subtle`\n  (crypto is an allowed global; globalThis is not).\n- valid-peer-dependencies: add peerDependencies { \"n8n-workflow\": \"*\" }.\n\nAlso add repository.directory: \"n8n\" so n8n can locate the credential/node\nsource within this monorepo (\"can't find credential file in repo\").",
          "is_bot": false,
          "headline": "n8n: fix verified-scanner violations (0.1.4) (#57)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:44:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7de0cc0687aa8a9a2e8625575fe722dcf5f3fb9b",
          "body": "… (0.1.3) (#56)\n\nReplace the generic placeholder node icon with the real open-banking.io brand\nmark (square SVG extracted from .github/logo.svg) so it renders on the n8n\nnodes panel and the creators portal. Add the wordmark logo banner to the README\nso the npm package page shows branding, matching the other clients. Bump 0.1.3.",
          "is_bot": false,
          "headline": "n8n: use the open-banking.io brand mark as node icon + logo in README…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:33:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03936b7a9c70d6966bf2c921fe80f27223c0200c",
          "body": null,
          "is_bot": false,
          "headline": "n8n: release 0.1.2 (author email in published metadata) (#55)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:22:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a37b913c6977ab3307809809a7c09867bec182c",
          "body": null,
          "is_bot": false,
          "headline": "n8n: add author email info@open-banking.io (#54)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:18:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6867ba5203387bc86e97b2937b56eb145f1a6297",
          "body": "* n8n: release 0.1.1 via CI with npm provenance\n\n0.1.0 was published locally and therefore carries no provenance, which n8n's\nverified-community-node submission requires. Bump to 0.1.1 and publish through\nGitHub Actions: add NODE_AUTH_TOKEN auth to the publish step so the OIDC\n`--provenance` publish authenticates. The NODE_AUTH_TOKEN secret is configured\non the Production environment; swap to npm trusted publishing when available.\n\n* n8n: drop redundant section-divider and restatement comments",
          "is_bot": false,
          "headline": "n8n: release 0.1.1 with npm provenance (CI publish) (#53)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T20:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a180315f3e9a05ab94a55b4b15c2436842a5db65",
          "body": "Publishing the unscoped name failed with E404 because the org npm token can\ncreate @open-banking-io/* packages but not arbitrary unscoped names. Scoping\nthe package matches the other eight clients, works with the existing token,\nand still satisfies n8n's verified-node naming rule (@scope/n8n-nodes-*). The\npublish workflow already passes --access public for the scoped package.",
          "is_bot": false,
          "headline": "n8n: scope package as @open-banking-io/n8n-nodes-open-banking-io (#52)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T19:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bec2fc19eb540d84f886daa8a8d3a0620212a30b",
          "body": "* n8n: add open-banking.io community node package\n\nAdds a new top-level `n8n/` package (`n8n-nodes-open-banking-io`) — a\nself-contained, zero-runtime-dependency n8n community node that pulls bank\naccounts, balances and transactions from open-banking.io into workflows.\n\n- Credential \"Open Banking IO \n[…]\nbuild on\nNode 20 and 24. Installing with --ignore-scripts skips that build; lint,\ntypecheck, build and the 18 tests all pass without it. The published package\nhas zero runtime dependencies regardless.",
          "is_bot": false,
          "headline": "n8n: add open-banking.io community node package (#51)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-15T19:29:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7266a486d29c7f1dfdbc19b251c2f8e3f88e89c9",
          "body": "Each language row in the \"Pick your language\" table now carries a live\nversion badge (NuGet, npm, PyPI, crates.io, pkg.go.dev, Maven Central,\nRubyGems, Packagist) and links the package name to its public registry\npage instead of only the in-repo guide.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add per-package version badges and registry links to README (#50)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-12T22:04:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5509a6f837b89202120c616ca5b3c8bc7d52080a",
          "body": "Make the openbanking CLI a pleasure to use while keeping dependencies\nminimal (one new dep: golang.org/x/term; everything else pure stdlib).\n\nNew internal/ui package with terminal detection, a color theme\n(NO_COLOR / --no-color aware), a loading spinner, an interactive\nselector (arrow keys via raw m\n[…]\nee output formats, the selector\nfallback, current-account resolution, the interactive menu, and\ncompletion; run clean under -race.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cli: UX overhaul — colors, formats, current account, completion (#49)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-12T08:46:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41dc7306e43aa3f79e8645aa5813e5a6d21ddc7b",
          "body": "…ge (#48)\n\nThe root README mixed too much language-specific implementation detail:\nit inlined code in all eight languages and repeated the full encryption\nenvelope byte layout, which was also duplicated across every per-language\nREADME and the security docs.\n\n- Root README: lead with the open-bankin\n[…]\nADME (io.open-banking, matching the pom), and bump the\n  stale Java 0.1.0 / Rust \"0.1\" version snippets to the published releases.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: refocus root README on getting started, split detail per langua…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-11T06:46:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c134cc4e0bfdd55757dd4a3c47772fa1911f690",
          "body": "…2.1) (#47)\n\n* Brand all package READMEs with the open-banking.io logo + bump to 0.2.1\n\nAdd the open-banking.io logo mark to every registry-facing README (crates.io,\nnpm, PyPI, NuGet, Maven, RubyGems, Packagist, pkg.go.dev) and the monorepo\nroot, via a centered banner pointing at .github/logo.png (a\n[…]\non (0.2.1) doesn't match\nthe locked self-version.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Brand all package READMEs with the open-banking.io logo (+ bump to 0.…",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-11T06:27:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "74bc5e28f6177cd6fab58643cabd8b60ffa022d6",
          "body": "Connecting a new bank needs an interactive consent redirect (browser), so it\nbelongs in the web app, not a headless CLI. Drop the connect command, its files\nand tests, and the docs; the CLI keeps banks (read-only listing), connections,\naccounts, transactions and sync. Backend is unchanged — this is a CLI-scoped\nchange. A test locks in that connect is now an unknown command.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cli: remove the connect command (#46)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-11T05:48:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fca6c645fe5b5cfe9d0bb57c8da62b5f36d1c4ae",
          "body": "The browser authorize page submits the unlocked key via a real <form> POST\n(OAuth response_mode=form_post style) instead of fetch(), so it isn't blocked by\nCORS/mixed-content. The loopback parses application/x-www-form-urlencoded (code,\nstate, privateKey, publicKey); JSON stays as a fallback. The POST replies with\nthe closeable success page since the browser navigates here.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cli: accept the browser relay as a form POST (fix CORS) (#45)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T23:44:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5663befe903016d09bb523d30d7a8ee623002784",
          "body": "openbanking login now sets up everything in one step. After the PKCE browser\nlogin, the authorize page POSTs the passphrase-unlocked encryption key to the\nCLI's localhost loopback (browser -> 127.0.0.1 only; the server never sees the\nprivate key). The loopback accepts the relay POST (CORS scoped to \n[…]\ny a state nonce + PKCE), validates the key, and saves the full bundle.\nThe legacy GET ?code= path + 'key import' remain as a headless fallback.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLI: one-step login via browser-relay (zero-knowledge) (#44)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T23:00:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d94e67bafd6c3ed8ee865a883b99caa5647b8c02",
          "body": "* php/python/dotnet: raise SDK test coverage\n\nAdd tests for the previously-uncovered factory, error, and edge-case paths\nacross the three SDK clients (tests only — no src changes):\n\n- PHP:    lines 88.4% -> 99.6% (23 -> 39 tests)\n- Python: total 83%  -> 100%  (23 -> 50 tests)\n- .NET:   line 89.6%/br\n[…]\n(some deliberately malformed for negative tests).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Raise PHP, Python, and .NET SDK test coverage (#43)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:53:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9b549320a37bbd30074295a202c25d366b98b4a0",
          "body": "Binary + terminal command is now 'openbanking'; product/display name is\n'open-banking.io CLI'. Updated all usage strings, help, version output, tests,\nREADME, the browser title, the GitHub Release title, and the Homebrew formula\n(Openbanking / openbanking.rb, brew install open-banking-io/tap/openbanking).\nThe tap step now clears old formulae so the stale obank.rb is removed.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Rename CLI: obank -> openbanking (product: open-banking.io CLI) (#42)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:36:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0e96f2ff5db4f67a6434ff9004256d42ce9d344c",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.2 to 25.9.3.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Nicolaj Helmer Hartmann <nhh@softwarehuset.com>",
          "is_bot": true,
          "headline": "Bump @types/node from 25.9.2 to 25.9.3 in /node (#40)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-10T22:35:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e7d0304d5a1d5eafa2d1f6f94f175d7d4e76c513",
          "body": "Binary + terminal command is now 'openbanking'; product/display name is\n'open-banking.io CLI'. Updated all usage strings, help, version output, tests,\nREADME, the browser title, the GitHub Release title, and the Homebrew formula\n(Openbanking / openbanking.rb, brew install open-banking-io/tap/openbanking).\nThe tap step now clears old formulae so the stale obank.rb is removed.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Rename CLI: obank -> openbanking (product: open-banking.io CLI) (#41)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:34:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ee61ae33e67f39c3a945f63aa3bd5a5839a5b233",
          "body": "On any push to main touching cli/**, compute the next obank patch from the latest\ncli/v* tag and push it via PAT -> publish-cli.yml builds + releases + updates the\ntap. Add gomod /cli to Dependabot so a new Go SDK release bumps the CLI's go.mod,\nwhich is itself a cli/** change -> auto-release. No more manual Actions -> Release\nfor the CLI.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Auto-release obank on CLI/SDK changes (#39)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:28:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "55307eaa3878bd6ff6a94666ca9e4690aa03a21c",
          "body": "* Fix CI: revert java spotless/gjf to JDK-17-safe versions; coverage go 1.25\n\n* dependabot: ignore semver-major across all language ecosystems (stop breaking bumps)\n\n* java: add unit tests for OpenBankingClient and model invariants\n\nCoverage was concentrated in OpenBankingClient (82% line / 51% bran\n[…]\n->97.4%, branch 53.6%->93.6%, method 86.9%->100%.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "java: raise test coverage for OpenBankingClient and models (#38)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:19:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c0dfb303aa75b7a3137350c6a86e99f039d1a71b",
          "body": "Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 2.44.0 to 2.46.1.\n- [Release notes](https://github.com/diffplug/spotless/releases)\n- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)\n- [Commits](https://github.com/diffplug/spotless/\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump com.diffplug.spotless:spotless-maven-plugin in /java (#37)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-10T22:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ed6f13f54ee6cb3349f9a32c7c60e623f0e8ff4",
          "body": "* Fix CI: revert java spotless/gjf to JDK-17-safe versions; coverage go 1.25\n\n* dependabot: ignore semver-major across all language ecosystems (stop breaking bumps)",
          "is_bot": false,
          "headline": "Fix red main: java toolchain + coverage go; block major dep bumps (#36)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:11:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10519ffe56949ffc428013118ee4a19bd8cc8212",
          "body": "Point the CLI's default API base URL at the canonical host, open-banking.io, and\nupdate the test fixtures to match. The `bank.core.ci/zk/v1` HKDF info string in\nthe envelope spec is a crypto domain-separation constant (shared byte-for-byte\nacross the backend, SPA and all 8 SDKs) — left unchanged so decryption interop\nholds.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLI: default to open-banking.io (not bank.core.ci) (#35)",
          "author_name": "Nicolaj Helmer Hartmann",
          "author_login": "nicolaj-hartmann",
          "committed_at": "2026-06-10T22:07:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 34,
      "commits_last_year": 161,
      "latest_release_at": "2026-07-18T17:18:39Z",
      "latest_release_tag": "n8n/v0.2.2",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/open-banking-io/clients/go",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/open-banking-io/clients/go",
          "is_deprecated": false,
          "latest_version": "v0.3.0",
          "repository_url": "https://github.com/open-banking-io/clients",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T00:43:10Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "github.com/open-banking-io/clients/cli",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/open-banking-io/clients/cli",
          "is_deprecated": false,
          "latest_version": "v0.2.12",
          "repository_url": "https://github.com/open-banking-io/clients",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T16:20:39Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "io.open-banking:open-banking-io-client",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/io.open-banking/open-banking-io-client",
          "is_deprecated": false,
          "latest_version": "0.3.0",
          "repository_url": "https://github.com/open-banking-io/clients",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T14:25:36Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "open-banking-io",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "zero-knowledge",
            "ecdh",
            "fintech",
            "psd2",
            "open-banking",
            "api-bindings",
            "cryptography"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/open-banking-io",
          "is_deprecated": false,
          "latest_version": "0.3.0",
          "repository_url": "https://github.com/open-banking-io/clients",
          "versions_count": 3,
          "total_downloads": 55,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 18,
          "first_published_at": "2026-06-10T13:31:06.534533Z",
          "latest_published_at": "2026-07-18T14:15:22.767612Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 5
        },
        {
          "name": "@open-banking-io/n8n-nodes-open-banking-io",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "n8n-community-node-package",
            "n8n",
            "open-banking",
            "psd2",
            "banking",
            "transactions",
            "fintech"
          ],
          "ecosystem": "npm",
          "matches_repo": false,
          "registry_url": "https://www.npmjs.com/package/@open-banking-io/n8n-nodes-open-banking-io",
          "is_deprecated": false,
          "latest_version": "0.2.2",
          "repository_url": "https://github.com/open-banking-io/n8n",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 739,
          "first_published_at": "2026-06-15T19:55:21.243000Z",
          "latest_published_at": "2026-07-18T17:19:43.913000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@open-banking-io/client",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "open-banking",
            "psd2",
            "zero-knowledge",
            "encryption",
            "fintech"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@open-banking-io/client",
          "is_deprecated": false,
          "latest_version": "0.3.0",
          "repository_url": "https://github.com/open-banking-io/clients",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 260,
          "first_published_at": "2026-06-10T12:57:47.513000Z",
          "latest_published_at": "2026-07-18T15:21:57.688000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "open-banking-io/client",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "Banking",
            "ecdh",
            "zero-knowledge",
            "open-banking",
            "psd2"
          ],
          "ecosystem": "packagist",
          "matches_repo": false,
          "registry_url": "https://packagist.org/packages/open-banking-io/client",
          "is_deprecated": false,
          "latest_version": "v0.3.0",
          "repository_url": "https://github.com/open-banking-io/client-php",
          "versions_count": 3,
          "total_downloads": 0,
          "dependents_count": 0,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 0,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T00:29:30Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 5,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-29",
            "count": 1
          },
          {
            "date": "2026-06-30",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 9
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "n8n/tsconfig.json",
        "node/tsconfig.json"
      ],
      "toolchain_manifests": [
        "cli/go.mod",
        "dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj",
        "dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj",
        "go/go.mod",
        "java/pom.xml",
        "rust/Cargo.toml"
      ],
      "largest_source_bytes": 18292,
      "source_files_sampled": 199,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "beancount/pyproject.toml",
        "cli/go.mod",
        "erpnext/pyproject.toml",
        "go/go.mod",
        "java/pom.xml",
        "n8n/package.json",
        "node/package.json",
        "php/composer.json",
        "python/pyproject.toml",
        "ruby/Gemfile",
        "rust/Cargo.toml",
        "zapier/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 3,
        "malicious_count": 0,
        "assessed_package": "maven:io.open-banking:open-banking-io-client@0.3.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "go",
        "maven",
        "npm",
        "packagist",
        "pypi",
        "rubygems"
      ],
      "dependencies": [
        {
          "name": "beancount",
          "manifest": "beancount/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.0"
        },
        {
          "name": "beangulp",
          "manifest": "beancount/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.2"
        },
        {
          "name": "open-banking-io",
          "manifest": "beancount/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.2"
        },
        {
          "name": "pyyaml",
          "manifest": "beancount/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "github.com/open-banking-io/clients/go",
          "manifest": "cli/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "cli/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jackson.version}"
        },
        {
          "name": "cryptography",
          "manifest": "python/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=49.0"
        },
        {
          "name": "httpx",
          "manifest": "python/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.28"
        },
        {
          "name": "p256",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "hkdf",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "sha2",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "aes-gcm",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "base64",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "serde",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "ureq",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "thiserror",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "zeroize",
          "manifest": "rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "zapier-platform-core",
          "manifest": "zapier/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 122,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 16
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "nicolaj-hartmann",
          "commits": 121,
          "avatar_url": "https://avatars.githubusercontent.com/u/7979529?v=4"
        },
        {
          "type": "User",
          "login": "john-frandsen",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/297707064?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.976
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-release-cli.yml",
        "changed-packages-comment.yml",
        "changed-packages.yml",
        "ci.yml",
        "codeql.yml",
        "coverage.yml",
        "gitleaks.yml",
        "publish-beancount.yml",
        "publish-cli.yml",
        "publish-dotnet.yml",
        "publish-erpnext.yml",
        "publish-go.yml",
        "publish-java.yml",
        "publish-n8n.yml",
        "publish-node.yml",
        "publish-php.yml",
        "publish-python.yml",
        "publish-ruby.yml",
        "publish-rust.yml",
        "publish-zapier.yml",
        "release.yml",
        "scorecard.yml",
        "semgrep.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".golangci.yml",
        ".php-cs-fixer.dist.php",
        "eslint.config.js",
        "phpstan.neon"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "Gemfile.lock",
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 5,
            "reason": "badge detected: Passing",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/22 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f5323180f7f82fda0b8d8cab7c3eaacb454fbd70",
        "ran_at": "2026-07-24T13:09:30Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T12:10:57Z",
      "oldest_open_prs": [
        {
          "number": 140,
          "created_at": "2026-07-22T12:05:31Z",
          "last_comment_at": "2026-07-22T12:07:24Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 141,
          "created_at": "2026-07-22T12:05:32Z",
          "last_comment_at": "2026-07-22T12:06:23Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 142,
          "created_at": "2026-07-22T12:05:33Z",
          "last_comment_at": "2026-07-22T12:08:19Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 143,
          "created_at": "2026-07-22T12:05:40Z",
          "last_comment_at": "2026-07-22T12:08:25Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 144,
          "created_at": "2026-07-22T12:05:43Z",
          "last_comment_at": "2026-07-22T12:08:23Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 145,
          "created_at": "2026-07-22T12:05:47Z",
          "last_comment_at": "2026-07-22T12:08:25Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 146,
          "created_at": "2026-07-22T12:05:50Z",
          "last_comment_at": "2026-07-22T12:08:27Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 147,
          "created_at": "2026-07-22T12:10:01Z",
          "last_comment_at": "2026-07-22T12:10:55Z",
          "last_comment_author": "github-actions"
        }
      ],
      "last_merged_pr_at": "2026-07-18T17:15:30Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 95,
          "created_at": "2026-07-07T20:19:09Z",
          "last_comment_at": "2026-07-08T20:38:34Z",
          "last_comment_author": "nicolaj-hartmann"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/open-banking-io/clients",
    "host": "github.com",
    "name": "clients",
    "owner": "open-banking-io"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 77,
        "vitality": 75,
        "community": 46,
        "governance": 44,
        "engineering": 84
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "commits_last_year": 161,
              "human_commit_share": 0.75,
              "days_since_last_push": 2,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "161 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 161
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 34,
              "latest_release_tag": "n8n/v0.2.2",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "34 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 46,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 2,
              "stars": 5,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "packages": [
                "github.com/open-banking-io/clients/go",
                "github.com/open-banking-io/clients/cli",
                "io.open-banking:open-banking-io-client",
                "open-banking-io",
                "@open-banking-io/client"
              ],
              "dependents": null,
              "ecosystems": "crates, go, maven, npm",
              "total_downloads": 55,
              "monthly_downloads": 278
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "278 downloads/month across crates, go, maven, npm",
                "points": 32.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 278,
                      "ecosystems": "crates, go, maven, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.976
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "merged_prs": 122,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 16
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "122/138 decided PRs merged",
                "points": 33.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 122,
                      "decided": 138
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "open-banking-io",
              "public_repos": 10,
              "account_age_days": 44
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of open-banking-io",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "open-banking-io"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~0 yr old",
                "points": 7.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/open-banking-io/clients/go",
                "github.com/open-banking-io/clients/cli",
                "io.open-banking:open-banking-io-client",
                "open-banking-io",
                "@open-banking-io/client"
              ],
              "ecosystems": "crates, go, maven, npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "5 package(s) on crates, go, maven, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 5,
                      "ecosystems": "crates, go, maven, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "14 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 84,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "23 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "banking",
                "cli",
                "fintech",
                "open-banking",
                "psd2",
                "sdk",
                "zero-knowledge",
                "aisp",
                "europe",
                "openbanking"
              ],
              "has_wiki": true,
              "homepage": "https://open-banking.io",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://open-banking.io",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: Passing",
                "points": 1.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the maven:io.open-banking:open-banking-io-client@0.3.0 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:io.open-banking:open-banking-io-client@0.3.0",
                  "assessed": 3
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 3,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 3,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.987,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "74 of 75 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 74,
                      "sampled": 75
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "Gemfile.lock",
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "n8n/tsconfig.json",
                "node/tsconfig.json"
              ],
              "agent_commit_share": 0.53,
              "toolchain_manifests": [
                "cli/go.mod",
                "dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj",
                "dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj",
                "go/go.mod",
                "java/pom.xml",
                "rust/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.25
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "cli/go.mod, dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj, dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "cli/go.mod, dotnet/src/OpenBankingIO.Client/OpenBankingIO.Client.csproj, dotnet/tests/OpenBankingIO.Client.Tests/OpenBankingIO.Client.Tests.csproj"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml, .php-cs-fixer.dist.php, eslint.config.js, phpstan.neon"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "n8n/tsconfig.json, node/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "n8n/tsconfig.json, node/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "53 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 53,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "25 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 25,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 18292,
              "source_files_sampled": 199,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/199 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 199,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "npm package '@open-banking-io/n8n-nodes-open-banking-io' points at a different repository (https://github.com/open-banking-io/n8n); excluded from ecosystem scoring",
    "packagist package 'open-banking-io/client' points at a different repository (https://github.com/open-banking-io/client-php); excluded from ecosystem scoring",
    "Could not fetch npm package 'open-banking-io-zapier' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T13:09:48.861872Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/open-banking-io/clients.svg",
  "full_name": "open-banking-io/clients",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo, Maven, crates.io, npm, Packagist.