Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 01:44 UTC

pombredanne / packageurl-python

Python implementation of the package url spec

PythonLicencia propia★ 0 estrellas⑂ 0 forksdesde oct 2021forkVer en GitHub ↗

pombredanne/packageurl-python tiene un índice de salud de 20 sobre 100, lo que lo sitúa en la banda Crítico. Su puntuación más alta es Sustainability & Governance (35/100) y la más baja, Community & Adoption (9/100). Se actualizó por última vez hace 1742 días. Una sola persona concentra la mayor parte del trabajo reciente.

20
global / 100
Crítico

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

20
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Abandonment Policy applies a 85% multiplier to weighted overall health.

Titularidad

Philippe OmbredanneCuenta personal
568 seguidores28.295 repositorios públicosdesde mar 2011@aboutcode-org @aboutcode-data @package-url @clearlydefined @nexB

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
PyPIpackageurl-pythonapunta a otro repositorio; no se puntúa0.17.631.828.97857hace 244 díaspackageurlpackage-managerpackage-url

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

17Crítico · 22% del índice global
Cómo se puntúa
0/36Recencia de push — último push hace 1742 días
0/36Cadencia de commits — 0/52 semanas con commits
0/18Volumen de commits — 0 commits en el último año
0/10OpenSSF Scorecard: Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Datos de entrada utilizados
commits_last_year0
human_commit_share1
days_since_last_push1742
active_weeks_last_year0
Cómo se puntúa
16.2/27Publica versiones — 26 etiquetas de versión (sin releases de GitHub)
0/36Recencia de las versiones — última versión hace 1755 días
19.8/27Cadencia de publicación — una versión cada ~111,8 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count26
latest_release_tagv0.9.6
releases_from_tags
days_since_latest_release1755
mean_days_between_releases111,8
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

9Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
0/22.5README
16.9/22.5Licencia — archivo de licencia presente, no es una licencia reconocida
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readmeno
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

35En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
7.4/22.5Distribución de commits — el principal contribuyente firma el 67% de los commits
9.5/13.5Amplitud de contribuyentes — 7 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 12 contributing companies or organizations
Datos de entrada utilizados
bus_factor1
contributors_sampled7
top_contributor_share0,673
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
19.8/25Alcance del propietario — 568 seguidores de pombredanne
25/25Trayectoria — 28.295 repos públicos, cuenta de ~15 años
Datos de entrada utilizados
followers568
owner_typeUser
is_verified
owner_loginpombredanne
public_repos28.295
account_age_days5610
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

22Crítico · 20% del índice global
Cómo se puntúa
0/24Flujos de trabajo de CI
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_cino
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

10Crítico
Cómo se puntúa
0/30README
0/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
0/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readmeno
has_docs_dirno
has_descriptionno

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

29Crítico · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 12 contributing companies or organizations
0/10Dangerous-Workflow — sin datos
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5Licencia — license file detected
0/7.5Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
0/5Packaging — sin datos
0/5Pinned-Dependencies — sin datos
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — sin datos
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate2,9
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

31En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
28.3/40Historial de commits legible — 53 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,53
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
0/11Verificación estática de tipos
0/10Entorno reproducible
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — sin datos
Datos de entrada utilizados
has_nixno
has_tests
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Pinned-Dependencies. Los pesos restantes se han renormalizado.
Cómo se puntúa
0/45Código verificable por tipos — Python sin configuración de verificación de tipos
55/55Tamaños de archivo manejables — 0/13 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePython
largest_source_bytes16.444
source_files_sampled13
oversized_source_files0

Datos clave

0estrellas de GitHub
7contribuidores
0commits en los últimos 12 meses
1742días desde el último push
26versiones publicadas
1factor bus
0issues abiertas
PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Community profile unavailable
  • pypi package 'packageurl-python' points at a different repository (https://github.com/package-url/packageurl-python); excluded from ecosystem scoring
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 2.9 / 10
2.9agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 01:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 12 contributing companies or organizations
n/dDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
0Maintained0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
n/dPackagingpackaging workflow not detected
n/dPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
n/dToken-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 5893,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Python": 68565
      },
      "pushed_at": "2021-10-18T12:52:00Z",
      "created_at": "2021-10-18T12:51:30Z",
      "owner_type": "User",
      "updated_at": "2021-10-18T12:51:31Z",
      "description": "Python implementation of the package url spec",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://aboutcode.org",
      "name": "Philippe Ombredanne",
      "type": "User",
      "login": "pombredanne",
      "company": "@aboutcode-org  @aboutcode-data @package-url @clearlydefined @nexB ",
      "location": "Earth",
      "followers": 568,
      "avatar_url": "https://avatars.githubusercontent.com/u/675997?v=4",
      "created_at": "2011-03-17T21:45:06Z",
      "is_verified": null,
      "public_repos": 28295,
      "account_age_days": 5610
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2021-10-05T11:37:10Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2021-10-04T15:44:41Z"
        },
        {
          "tag": "0.9.4",
          "kind": "patch",
          "published_at": "2021-02-02T09:56:53Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2020-10-06T17:24:06Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2020-09-14T17:55:42Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2020-08-05T10:29:24Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2020-05-21T16:51:43Z"
        },
        {
          "tag": "v0.8.7",
          "kind": "patch",
          "published_at": "2019-08-15T11:49:04Z"
        },
        {
          "tag": "v0.8.6",
          "kind": "patch",
          "published_at": "2019-08-15T10:12:38Z"
        },
        {
          "tag": "v0.8.5",
          "kind": "patch",
          "published_at": "2019-01-03T15:36:56Z"
        },
        {
          "tag": "v0.8.4",
          "kind": "patch",
          "published_at": "2018-12-21T13:49:52Z"
        },
        {
          "tag": "v0.8.3",
          "kind": "patch",
          "published_at": "2018-12-20T14:18:16Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2018-12-18T15:51:15Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2018-11-07T18:27:32Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2018-11-07T16:04:37Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2018-10-07T17:46:39Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2018-10-05T15:42:52Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2018-02-16T22:59:27Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2017-11-27T16:51:53Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2017-11-21T22:17:14Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2017-11-18T06:47:07Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2017-11-18T06:43:03Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2017-11-16T18:54:32Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2017-11-15T11:29:31Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2017-11-15T11:15:27Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2017-11-14T18:04:03Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "31f372d17bcb4ff0841aeaadc8d25857f78ccf81",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Upgrade version to 0.9.6 for release",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-05T11:37:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a29af1e7ad2329e0924475c71ec29595044feb5c",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Improved support for codeload.github.com in url2purl #47",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-05T11:35:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "255e2324151b2c81711ace1b3fdd2de4b4fbe417",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Drop support for Python 2 (#63)",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2021-10-05T11:25:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe770b101d5fbe786498a641df9d90f62d3c4bb4",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for new github URLs in url2purl #47",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-05T10:06:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "601436fc284c3d66be7aef20c6bb7c9ecde50736",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Improve the quality of the Github url2purl results #47",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-05T09:43:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2380511dae91d9caa90759a23130b15a8551f03d",
          "body": "Signed-off-by: Tushar Goel <tushar.goel.dav@gmail.com>\r\n\r\nCo-authored-by: tdruez <489057+tdruez@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Resolve bugs in Github URLS (#58)",
          "author_name": "Tushar Goel",
          "author_login": "TG1999",
          "committed_at": "2021-10-05T09:30:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b60499fd4ad15fd2ba5873c094a20b60fbf40fd",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Bump version for 0.9.5 release",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-04T15:44:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78b6e389ee7bba95de540494c7595b37f2885ac7",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for \"archive/refs/tags/\" github URLs in url2purl #47",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-10-04T15:40:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "291e11bea47f07616b94dc46eb489af4ba425658",
          "body": "Fix Python 2 compatibility issue #57",
          "is_bot": false,
          "headline": "Merge pull request #59 from package-url/57-python2",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2021-02-02T09:56:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65f96fdb31e6003ebb24c19704066fffe8ac2a2d",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Fix Python 2 compatibility issue #57",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2021-02-02T09:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3e72c2f47fb08034204d803ff3e42d0135a87b5",
          "body": "* Remove code duplication on registration of url2purl patterns #54\r\n\r\nSigned-off-by: Thomas Druez <tdruez@nexb.com>\r\n\r\n* Fix format and indent #54\r\n\r\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Remove code duplication on registration of url2purl patterns #54 (#56)",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2020-11-03T15:24:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "636226aba12c5421a2e7790b5f091aca4c1ef927",
          "body": "* Add support for bitbucket download URL\r\n\r\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>\r\n\r\n* Add support for github blob URLs\r\n\r\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>\r\n\r\n* Adding support for github raw URLs\r\n\r\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>\r\n\r\n* Adding support fo\n[…]\n.dav@gmail.com>\r\n\r\n* Add support for various GH URLs\r\nAdd tests\r\n\r\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>\r\n\r\n* Proper indentation\r\n\r\nCo-authored-by: tdruez <tdruez@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add support for bitbucket download URL (#51)",
          "author_name": "Tushar Goel",
          "author_login": "TG1999",
          "committed_at": "2020-11-03T14:28:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c03973cee9f6f2a71980ffa741c61c29a6da712b",
          "body": "Extend url2purl support for NPM and Yarn web URLs. Fixes #38.",
          "is_bot": false,
          "headline": "Merge pull request #46 from scovetta/npm-web-url",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-10-26T17:24:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d270780b7645d86a70bba5aee560b1feda005fa",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Clarify release process",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-10-06T21:45:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1abaadc5b6132b9dd31ed85fd1f45f3d7ead1bee",
          "body": "Upgrade CHANGELOG and bump version to 0.9.3",
          "is_bot": false,
          "headline": "Merge pull request #50 from package-url/release",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-10-06T17:24:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cde4f477cb05307e486441373660d8b43112ae9",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Upgrade CHANGELOG and bump version to 0.9.3",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-10-06T16:55:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96ed0b5cf8d0ebf7668c93faf09d9351c3b12670",
          "body": "Add contributed Django lookup and filters #48",
          "is_bot": false,
          "headline": "Merge pull request #49 from package-url/48-lookup-filter",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-10-06T16:31:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23a31f61cb387c9198a4912025340c0c05313508",
          "body": "- Deprecation warning included to provide hint on the migration\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Move the django_models module to django.models #48",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-10-06T09:21:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da265da54896d7e9965e5b7a1018d781925c935e",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add a PackageURLFilter class for Django FilterSet implementations #48",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-10-06T09:13:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d47009f23bc6c688d26b6c8af7de0e4c75ccfa7",
          "body": "…ngo class #48\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add QuerySet utils to lookup and filter along the PackageURLMixin Dja…",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-10-06T09:09:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c5215630087a79c563563acf601e8d917e89bb2",
          "body": "Signed-off-by: Michael Scovetta <michael.scovetta@microsoft.com>",
          "is_bot": false,
          "headline": "Extend url2purl support for NPM and Yarn web URLs. Fixes #18.",
          "author_name": "Michael Scovetta",
          "author_login": null,
          "committed_at": "2020-09-19T06:59:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47c5bf81d1b0257db1606e648cab773bc0366b10",
          "body": "New release 0.9.2",
          "is_bot": false,
          "headline": "Merge pull request #45 from package-url/new-release",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T18:00:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aee27d46e545d3129c59e613681803f8a7e73c8b",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Recommend a single API for purl2url/url2purl",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T17:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b76ba569f855674f7d1c8532a888efa76cdb555e",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Update CHANGELOG and bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T17:07:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79ce1dcb7ee7f823a6cd19b1c1f39369d29ea03a",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Add CHANGELOG to wheels",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T17:07:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b5a1359f441c225630103ea5ed177ff61a25579",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Add usage and release doc to README",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T17:07:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3200c6df03440ff96bc19f23bbe249638d08d206",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Test on Python 3.7 and 3.8",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T16:56:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aad1f90efd1595dd7cea0bde74e193a9296c0c14",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Ignore pytest directory",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T16:56:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fad638e61671bea312ff5062b73d2190e9232cfe",
          "body": "Make url2purl and purl2url the main functions for these modules.\n\n\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Use get_url and get_purl functions as aliases",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T16:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75fb8438e26b569944daa286758b076c20a372e2",
          "body": "dict is ordered by default now.\nAlso format code.\n\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Use dict on Python 3 rather than OrderedDict",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T16:55:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f7253275ba1bf87eb7a9443ee8c0a89030d13f5",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Use SPDX license id",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T16:54:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "143356c6097028c5fb3919aa29aee9f1344beaa5",
          "body": "Improve GitHub URLs support in url2purl",
          "is_bot": false,
          "headline": "Merge pull request #44 from package-url/43-github-raw",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-09-14T13:50:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "897a9009e949fa604a206c9df5d54d437b8e2483",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Improve GutHub support for \"v\" prefixed version in url2purl #43",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-09-14T12:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcc3480cc83eebecf4688ea98a2c1fa24523f8e5",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for GitHub \"raw\" URLs in url2purl #43",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-09-14T12:24:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46116009b6815fc7c31bf4319bdb7d18f79fa066",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Update changelog and authors for v0.9.1",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-08-05T10:29:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e67082be781b9f0ad8bd3c76d14d57dfbb9bb321",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-08-05T10:15:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bcbe63bef0caa3eb8d44031c3ded35d7e81a927a",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'upstream/36-null-vs-blank'",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-08-05T10:12:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f638bb65ab9639ebb935aa0fa583fdba40ab0024",
          "body": "…s #36\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Refine to_dict `empty` to always apply for consistency on empty value…",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-08-05T08:10:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f093258a3a3340cadda2e18850e16a10fa6deb4",
          "body": "Adds support for hackage PURLS",
          "is_bot": false,
          "headline": "Merge pull request #41 from TG1999/hackage",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-07-29T17:32:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "334900ed16809e93ea9f2412dcacb8fce12249b7",
          "body": "Signed-off-by: TG1999 <tushar.goel.dav@gmail.com>",
          "is_bot": false,
          "headline": "Adds support for hackage PURLS",
          "author_name": "TG1999",
          "author_login": "TG1999",
          "committed_at": "2020-07-29T16:28:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5615312f6cb1f50c2153adaa06e4cb5c3538d2e",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Fix deprecation warning #36",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-07-29T06:19:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2e962fe97801cfe2ecfdc6f6cec9850aced93df",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Update empty values in place in `to_dict` #36",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-07-29T05:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "487efb5a8b505a43672b6099ec7f8a60f3e6417b",
          "body": "Add a `empty=None` param on the `PackageURL.to_dict` method to allow custom value like empty string '' in place of None\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Remove the null=True on CharField fields of the PackageURLMixin #36",
          "author_name": "Thomas Druez",
          "author_login": "tdruez",
          "committed_at": "2020-07-28T17:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bd11791db01bef0c06ce707763ce4a090c906c7",
          "body": "Add support converting PURLs to URLs",
          "is_bot": false,
          "headline": "Merge pull request #39 from TG1999/purl_url",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-07-26T14:27:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97fb5413dc40216d2fe0a72197fecc5aaec5196e",
          "body": "Supported PURLS are bitbucket, cargo, github, gitlab, gems\n\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>",
          "is_bot": false,
          "headline": "Add support for converting PURLS to URLS",
          "author_name": "TG1999",
          "author_login": "TG1999",
          "committed_at": "2020-07-26T13:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73c848e005efc2f0f821424c3b850dffcf417633",
          "body": "Add support for github and BitBucket URLs",
          "is_bot": false,
          "headline": "Merge pull request #34 from TG1999/github",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-07-26T09:37:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f61bea4a5deb5e347a35e3b252890ec180f57d71",
          "body": "URLs like\nhttps://raw.githubusercontent.com/volatilityfoundation/dwarf2json/master/LICENSE.txt\nhttps://api.github.com/repos/nexB/scancode-toolkit/commits/40593af0df6c8378d2b180324b97cb439fa11d66\nhttps://codeload.github.com/nexB/scancode-toolkit/tar.gz/v3.1.1\nhttps://github.com/package-url/packageurl-js/tree/master/test/data\nhttps://bitbucket.org/TG1999/first_repo/src/master\nhttps://gitlab.com/TG1999/firebase/-/tree\n\nSigned-off-by: TG1999 <tushar.goel.dav@gmail.com>",
          "is_bot": false,
          "headline": "Add support for converting URLs to PURLs",
          "author_name": "TG1999",
          "author_login": "TG1999",
          "committed_at": "2020-07-26T07:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00b7df61173be3c19eb65ce166271aed0e9ae00c",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Enhance CHANGELOG",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-05-21T16:51:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f59dee3cc70f73356c4967444145be6961e4e39",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Prepare for new release 0.9.0",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-05-21T16:46:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d487b07e485591cdb2d84b8fb5ab918c316206af",
          "body": "Increase version field length in PackageURLMixin\r\n\r\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Merge pull request #30 from JonoYang/increase-version-length",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-05-21T16:42:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c4dd4e99d6ae0805d9001bcd0d3d7e06b8c9769",
          "body": "Signed-off-by: Jono Yang <jyang@nexb.com>",
          "is_bot": false,
          "headline": "Use older string format in set_package_url()",
          "author_name": "Jono Yang",
          "author_login": "JonoYang",
          "committed_at": "2020-04-23T19:40:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a4f0927bc722ad563fab63d4acf21cf56a54e06",
          "body": "Signed-off-by: Jono Yang <jyang@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Jono Yang",
          "author_login": "JonoYang",
          "committed_at": "2020-04-23T19:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c736bdbc2d474d70c8637241d1624707becd3fe",
          "body": "Signed-off-by: Jono Yang <jyang@nexb.com>",
          "is_bot": false,
          "headline": "Increase version field length in PackageURLMixin",
          "author_name": "Jono Yang",
          "author_login": "JonoYang",
          "committed_at": "2020-04-23T19:13:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "564cda81094382cb5cc1fc229b4e4905cfd8b89d",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Update CHANGELOG for cargo support",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-04-05T15:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b8a4e48bd76a561573c8c8d0a199b116ab1f873",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Format code for whitespaces",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-04-05T14:34:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dff37a44ce4438dab4715d736d2e4c874a04102b",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version and add files to wheels",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-04-05T14:33:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b42c8a5719371dcb30b2f0fff0d9e70f0ebaa80",
          "body": "Make PackageURL type hashable",
          "is_bot": false,
          "headline": "Merge pull request #29 from haikoschol/hashable_purls",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-04-05T14:27:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a3a0bdf0aed92e8026ddbc18c6bd7dcd6b0aeaf",
          "body": "Before this change it was not possible to store PackageURL instances in\na set or other collection that calls __hash__(). This change implements\n__hash__() as the hash of the string representation of the object.\n\nFixes #28\n\nSigned-off-by: Haiko Schol <hs@haikoschol.com>",
          "is_bot": false,
          "headline": "Make PackageURL type hashable",
          "author_name": "Haiko Schol",
          "author_login": "haikoschol",
          "committed_at": "2020-04-04T15:07:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a762fbd361a253e3c12f7fff61c305b6a69d0ed8",
          "body": "Add support for rust packages\r\n\r\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Merge pull request #24 from TG1999/rust-package",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2020-03-31T13:28:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "274e768e01516ea32f97c0ae8d3ac4d98b7b0318",
          "body": "Signed-off-by: TG1999 <tushar.goel.dav@gmail.com>",
          "is_bot": false,
          "headline": "Add support for rust packages",
          "author_name": "TG1999",
          "author_login": "TG1999",
          "committed_at": "2020-03-31T13:23:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a577ff85176e9ff242e6bd8f7b33db097a0e0a25",
          "body": "README: Update links to point to travis.com",
          "is_bot": false,
          "headline": "Merge pull request #22 from package-url/sschuberth-patch-1",
          "author_name": "Sebastian Schuberth",
          "author_login": "sschuberth",
          "committed_at": "2019-09-16T09:39:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd630bbf5cd6cd2d41e87a8695e275a33bc9243e",
          "body": "travis.org is in the process of being consolidated into travis.com.",
          "is_bot": false,
          "headline": "README: Update links to point to travis.com",
          "author_name": "Sebastian Schuberth",
          "author_login": "sschuberth",
          "committed_at": "2019-08-27T13:04:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd1a372eb61e6d6c66d699044542f39720c5b935",
          "body": "Somehow the last bump was missing the PR from @tdruez\n\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version again",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-08-15T11:49:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53bad815bd21d44f1d29cfbb588dfc7e579aec33",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-08-15T11:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b51283101a094acb1105b5a71c09c028d1a00822",
          "body": "Add max_length validation in the set_package_url of PackageURLMixin\r\n\r\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Merge pull request #21 from package-url/max_length-validation",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-08-14T18:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26ca612c69ff27943e5031f04e41c0a8a7f08d12",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add max_length validation in the set_package_url of PackageURLMixin",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2019-08-14T12:55:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70a3b32c43a969a22fb7793ab6e19cd4d447d772",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Usr simpler sdist for setup \"release\" alias",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-01-03T15:42:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d3b87b9796b05d10a81ff94c390e951d0cd4eab",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-01-03T15:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdbb5837d715e4880a393cab376a206cfb6bb525",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Ignore tox",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-01-03T15:36:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7de9dea2f02c171471d73d07243f0c4f3d2e9719",
          "body": "Add support for nuget, pypi, and sourceforge in url2purl",
          "is_bot": false,
          "headline": "Merge pull request #19 from package-url/url2purl",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2019-01-02T16:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56e817b645c43e7f2c07f4ab6557c0da07e32f97",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Remove the dependencies on pip internal for wheel matching",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2019-01-02T16:03:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c292e850a71f8d67256af7cb66e440ea218d0aee",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add some entry in the test data",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T22:48:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94db98c54713996d117f1106fe0b53f61c962c0a",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Refine the purl_from_pattern function to handle unwanted matched fields",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T22:42:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf114f70b519f33fcac2bb682797f4d6fdc8e823",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Refine and simplify all regex patterns",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T22:17:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7d3a7e60eb3b6d1a139b9d3b7a2fef32a402e82",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for sourceforge.net in the url2purl module",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T19:30:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c3dbdd99fe48d13ecf07698345c519952881a95",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for nuget in the url2purl module",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T16:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4e409e26fbb63d1d43d596ff572e6ef61e38ab8",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add support for pypi in the url2purl module",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T14:09:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bef05b0af08c9500de1556ee865f23d94241269",
          "body": "- Replace the rubygems logic by this new logic\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add a `purl_from_pattern` function for simple pattern matching",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-28T13:43:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0e7c9f64a066540bb1b7273b8615e3a8fa53d6f",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-21T13:49:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1294b279a9b02885faf3a97fbaef1131f5331688",
          "body": "Fix qualifiers string vs. dict nature",
          "is_bot": false,
          "headline": "Merge pull request #18 from package-url/qualifiers-dict",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-21T13:48:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c486db4b678b472813c760f80d8faff2b699c7cf",
          "body": "Before this, we were saving a dict() in the qualifiers field of\nPackageURLMixin resulting in damaged data (Django being smart enough\nwould serialize the dict() to a string. That string would not be usable\nto recreate a qualifiers mapping afterwards.\n\n\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Set qualifiers as a string when setting fields",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-21T13:41:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f5e6324e25e1688ccaaad95a6f3b823c0ba962c",
          "body": "Calling PackageURL.to_dict(encode=True) will return a string instead of\na mapping. Otherwise we now always use and return OrderedDict for\nqualifiers\n\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Return a string for qualifiers in PackageURL.to_dict()",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-21T13:38:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47a43e6e10748a9a3d2615d696c1b9ef8ae805f7",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Correct Travis URL target",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-20T14:32:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4084fe87b6e2d1ca7f2f1d286804fe4bd7cc9c3",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump verision",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-20T14:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d69a7de97b5546501c298de814462d32cb32c00",
          "body": "Add a url2purl module for Package URL creation from arbitrary URLs",
          "is_bot": false,
          "headline": "Merge pull request #17 from tdruez/url2purl",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-20T14:16:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ca9954a74cec981e9d8211be6f7cb7aa7d9d679",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add a MIT license header to source code files",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-20T12:05:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "484d21cb2bafc725678802d5153272e8e9388933",
          "body": "Includes:\n- Support for maven, npm, rubygems\n- route.py routing module\n- Data driven test suite\n\nSigned-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add a url2purl module for Package URL creation from arbitrary URLs",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-20T09:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "254876f6c93114728b3f35a75c92a83c58af76f5",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-18T15:51:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da02f186d5fb4a8b9db44ff519326f44906dc265",
          "body": "Add a set_package_url method on PackageURLMixin",
          "is_bot": false,
          "headline": "Merge pull request #16 from tdruez/patch-1",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-12-18T10:16:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2ed8f22e4c1b4f524d5fb992762ee39aa6d3251",
          "body": "Signed-off-by: Thomas Druez <tdruez@nexb.com>",
          "is_bot": false,
          "headline": "Add a set_package_url method on PackageURLMixin",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-12-18T10:10:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9668230f29f1666f4f01f3983beefe8fac856a3",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump patch version #12",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T18:27:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd37c8834f227e8ee60ba4d09216b1bd278d0d49",
          "body": "Add missing import #12",
          "is_bot": false,
          "headline": "Merge pull request #15 from tdruez/patch-1",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T18:25:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68695f66c435d776b12420210fe05da3a11ccaee",
          "body": null,
          "is_bot": false,
          "headline": "Add missing import #12",
          "author_name": "tdruez",
          "author_login": "tdruez",
          "committed_at": "2018-11-07T16:36:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7890ca0e9c9c78cce69f3c8c3b9766e12d2ea402",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Bump version and update setup to new layout #12",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T16:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "374a6109f5ff5d03e79fde1798403b23a8fa8c15",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Update setup to better handle py.test",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T16:04:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a0f0f3c33cbc2236aa00f0d78f87285dddcd096",
          "body": "Add Django models as a contribution\r\n\r\nSigned-off-by: Thomas Druez <tdruez@nexb.com>\r\nSigned-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Merge pull request #14 from package-url/django-models-contrib",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T15:40:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "116305d9fa33af578e85f80cbe34891da318a862",
          "body": "Add extra validation to qualifiers",
          "is_bot": false,
          "headline": "Merge pull request #13 from package-url/validate-qualifiers",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T06:14:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b09332018325c94bf8a31ccd1e3c802d0010ed89",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Add django_models congributed Django model #12",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T06:12:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bdb212b51343d2fa60f02581ff500bcade223130",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Use directory for Python module #12",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-07T06:11:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1723c4909b5b38e5814c06b461875604e81878cf",
          "body": "Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>",
          "is_bot": false,
          "headline": "Add extra validation to qualifiers",
          "author_name": "Philippe Ombredanne",
          "author_login": "pombredanne",
          "committed_at": "2018-11-06T20:47:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 0,
      "latest_release_at": "2021-10-05T11:37:10Z",
      "latest_release_tag": "v0.9.6",
      "releases_from_tags": true,
      "days_since_last_push": 1742,
      "active_weeks_last_year": 0,
      "days_since_latest_release": 1755,
      "mean_days_between_releases": 111.8
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "packageurl-python",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "package",
            "url",
            "package manager",
            "package url",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: MIT License",
            "Operating System :: OS Independent",
            "Programming Language :: Python",
            "Programming Language :: Python :: 3 :: Only",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.8",
            "Programming Language :: Python :: 3.9",
            "Topic :: Software Development :: Libraries",
            "Topic :: Utilities",
            "Typing :: Typed"
          ],
          "ecosystem": "pypi",
          "matches_repo": false,
          "registry_url": "https://pypi.org/project/packageurl-python/",
          "is_deprecated": false,
          "latest_version": "0.17.6",
          "repository_url": "https://github.com/package-url/packageurl-python",
          "versions_count": 57,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 31828978,
          "first_published_at": "2017-11-18T06:47:47.052773Z",
          "latest_published_at": "2025-11-24T15:20:17.998933Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 244
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 16444,
      "source_files_sampled": 13,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "setup.cfg",
        "setup.py"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "pombredanne",
          "commits": 101,
          "avatar_url": "https://avatars.githubusercontent.com/u/675997?v=4"
        },
        {
          "type": "User",
          "login": "tdruez",
          "commits": 32,
          "avatar_url": "https://avatars.githubusercontent.com/u/489057?v=4"
        },
        {
          "type": "User",
          "login": "TG1999",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/34160672?v=4"
        },
        {
          "type": "User",
          "login": "JonoYang",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/6044800?v=4"
        },
        {
          "type": "User",
          "login": "jpopelka",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/288686?v=4"
        },
        {
          "type": "User",
          "login": "sschuberth",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/349154?v=4"
        },
        {
          "type": "User",
          "login": "haikoschol",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/539509?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.673
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 12 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "31f372d17bcb4ff0841aeaadc8d25857f78ccf81",
        "ran_at": "2026-07-27T01:43:55Z",
        "aggregate_score": 2.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [
        {
          "number": 1,
          "created_at": "2021-10-18T12:52:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/pombredanne/packageurl-python",
    "host": "github.com",
    "name": "packageurl-python",
    "owner": "pombredanne"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "critical",
      "name": "Overall health",
      "note": "Abandonment Policy applies a 85% multiplier to weighted overall health.",
      "notes": [
        {
          "code": "abandonment_overall_adjustment",
          "params": {
            "cap": 0,
            "pct": 85
          }
        }
      ],
      "value": 20,
      "inputs": {
        "security": 29,
        "vitality": 17,
        "community": 9,
        "governance": 35,
        "engineering": 22,
        "abandonment_cap": null,
        "abandonment_state": "at_risk",
        "abandonment_multiplier": 85,
        "weighted_overall_before_abandonment": 23,
        "overall_after_abandonment_multiplier": 20
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "critical",
        "name": "Vitality",
        "value": 17,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "critical",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "commits_last_year": 0,
              "human_commit_share": 1,
              "days_since_last_push": 1742,
              "active_weeks_last_year": 0
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1742 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1742
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "0/52 weeks with commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "0 commits in the last year",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.9.6",
              "releases_from_tags": true,
              "days_since_latest_release": 1755,
              "mean_days_between_releases": 111.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1755 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1755
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~111.8 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 111.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "cap": null,
              "state": "at_risk",
              "guards": [],
              "signals": [
                "release_stall",
                "scorecard_unmaintained"
              ],
              "red_flag": true,
              "multiplier_pct": 85,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": 1,
              "unanswered_open_issues": 0,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1755,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "no human commit for 1755 days; 2 unmet obligation(s): releases stalled, Scorecard reports it unmaintained",
                "points": 85,
                "status": "partial",
                "details": [
                  {
                    "code": "abandonment_flagged",
                    "params": {
                      "days": 1755,
                      "count": 2,
                      "signals": "releases stalled, Scorecard reports it unmaintained"
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 9,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 19,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 35,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.673
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 67% of commits",
                "points": 7.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 67
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 12 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "followers": 568,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "pombredanne",
              "public_repos": 28295,
              "account_age_days": 5610
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "568 followers of pombredanne",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 568,
                      "login": "pombredanne"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "28295 public repos, account ~15 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 28295
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "critical",
        "name": "Engineering Quality",
        "value": 22,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 29,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 29,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 2.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 12 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 31,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 28,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.53,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "53 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 28.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 53,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 24,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 16444,
              "source_files_sampled": 13,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/13 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 13,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable",
    "pypi package 'packageurl-python' points at a different repository (https://github.com/package-url/packageurl-python); excluded from ecosystem scoring",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T01:44:03.063517Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/pombredanne/packageurl-python.svg",
  "full_name": "pombredanne/packageurl-python",
  "license_state": "custom",
  "license_spdx": null
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPyPI.