Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"tekton-pipelines",
"tekton",
"github",
"pipeline",
"kubernetes",
"continuous-delivery",
"pipelines-as-code",
"gitlab",
"ci",
"bitbucket",
"gitops"
],
"is_fork": false,
"size_kb": 78996,
"has_wiki": true,
"homepage": "https://pipelinesascode.com",
"languages": {
"Go": 3487952,
"Shell": 88231,
"Python": 31194,
"Makefile": 9406,
"Go Template": 11587
},
"pushed_at": "2026-07-21T10:21:44Z",
"created_at": "2021-04-06T13:26:01Z",
"owner_type": "Organization",
"updated_at": "2026-07-21T10:21:49Z",
"description": "Pipelines-as-Code for Tekton",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://tekton.dev",
"name": "Tekton",
"type": "Organization",
"login": "tektoncd",
"company": null,
"location": null,
"followers": 1421,
"avatar_url": "https://avatars.githubusercontent.com/u/47602533?v=4",
"created_at": "2019-02-13T14:53:43Z",
"is_verified": null,
"public_repos": 24,
"account_age_days": 2715
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.48.1",
"kind": "patch",
"published_at": "2026-07-17T13:48:26Z"
},
{
"tag": "v0.42.3",
"kind": "patch",
"published_at": "2026-07-17T13:39:45Z"
},
{
"tag": "v0.49.0",
"kind": "minor",
"published_at": "2026-07-06T12:59:38Z"
},
{
"tag": "v0.42.2",
"kind": "patch",
"published_at": "2026-06-15T07:19:37Z"
},
{
"tag": "v0.37.8",
"kind": "patch",
"published_at": "2026-06-12T13:43:39Z"
},
{
"tag": "v0.39.7",
"kind": "patch",
"published_at": "2026-06-09T18:31:33Z"
},
{
"tag": "v0.42.1",
"kind": "patch",
"published_at": "2026-06-08T16:18:26Z"
},
{
"tag": "v0.39.6",
"kind": "patch",
"published_at": "2026-06-08T14:41:54Z"
},
{
"tag": "v0.48.0",
"kind": "minor",
"published_at": "2026-06-04T16:28:32Z"
},
{
"tag": "v0.47.0",
"kind": "minor",
"published_at": "2026-05-26T08:24:42Z"
},
{
"tag": "v0.46.0",
"kind": "minor",
"published_at": "2026-05-06T11:27:46Z"
},
{
"tag": "v0.45.0",
"kind": "minor",
"published_at": "2026-04-08T08:38:24Z"
},
{
"tag": "v0.44.0",
"kind": "minor",
"published_at": "2026-03-31T18:49:00Z"
},
{
"tag": "v0.43.0",
"kind": "minor",
"published_at": "2026-03-12T10:28:22Z"
},
{
"tag": "v0.42.0",
"kind": "minor",
"published_at": "2026-02-23T14:42:23Z"
},
{
"tag": "v0.37.7",
"kind": "patch",
"published_at": "2026-02-23T14:00:10Z"
},
{
"tag": "v0.39.5",
"kind": "patch",
"published_at": "2026-02-19T18:57:07Z"
},
{
"tag": "v0.37.6",
"kind": "patch",
"published_at": "2026-02-19T14:43:04Z"
},
{
"tag": "v0.37.5",
"kind": "patch",
"published_at": "2026-01-29T15:13:18Z"
},
{
"tag": "v0.39.4",
"kind": "patch",
"published_at": "2026-01-29T15:14:58Z"
},
{
"tag": "v0.41.1",
"kind": "patch",
"published_at": "2026-01-29T10:33:18Z"
},
{
"tag": "v0.41.0",
"kind": "minor",
"published_at": "2026-01-20T14:11:55Z"
},
{
"tag": "v0.40.0",
"kind": "minor",
"published_at": "2025-12-19T06:49:11Z"
},
{
"tag": "v0.39.3",
"kind": "patch",
"published_at": "2025-12-15T17:36:46Z"
},
{
"tag": "v0.37.4",
"kind": "patch",
"published_at": "2025-12-15T09:42:51Z"
},
{
"tag": "v0.35.4",
"kind": "patch",
"published_at": "2025-12-04T04:41:54Z"
},
{
"tag": "v0.39.2",
"kind": "patch",
"published_at": "2025-11-19T11:02:58Z"
},
{
"tag": "v0.37.3",
"kind": "patch",
"published_at": "2025-11-18T08:39:26Z"
},
{
"tag": "v0.39.1",
"kind": "patch",
"published_at": "2025-11-18T07:41:53Z"
},
{
"tag": "v0.37.2",
"kind": "patch",
"published_at": "2025-11-10T04:40:32Z"
},
{
"tag": "v0.39.0",
"kind": "minor",
"published_at": "2025-11-04T17:28:24Z"
},
{
"tag": "v0.37.1",
"kind": "patch",
"published_at": "2025-10-01T09:30:13Z"
},
{
"tag": "v0.38.0",
"kind": "minor",
"published_at": "2025-09-26T06:21:33Z"
},
{
"tag": "v0.37.0",
"kind": "minor",
"published_at": "2025-08-12T11:40:15Z"
},
{
"tag": "v0.35.3",
"kind": "patch",
"published_at": "2025-07-16T18:29:05Z"
},
{
"tag": "v0.35.2",
"kind": "patch",
"published_at": "2025-07-04T16:53:16Z"
},
{
"tag": "v0.36.0",
"kind": "minor",
"published_at": "2025-06-26T15:30:13Z"
},
{
"tag": "v0.35.1",
"kind": "patch",
"published_at": "2025-06-04T13:07:41Z"
},
{
"tag": "v0.35.0",
"kind": "minor",
"published_at": "2025-05-26T15:19:51Z"
},
{
"tag": "v0.34.0",
"kind": "minor",
"published_at": "2025-05-06T13:43:40Z"
},
{
"tag": "v0.33.2",
"kind": "patch",
"published_at": "2025-05-02T08:04:29Z"
},
{
"tag": "v0.33.1",
"kind": "patch",
"published_at": "2025-04-16T10:34:37Z"
},
{
"tag": "v0.33.0",
"kind": "minor",
"published_at": "2025-02-14T14:28:54Z"
},
{
"tag": "v0.32.0",
"kind": "minor",
"published_at": "2025-01-21T10:35:04Z"
},
{
"tag": "v0.28.2",
"kind": "patch",
"published_at": "2025-01-07T13:23:58Z"
},
{
"tag": "v0.29.1",
"kind": "patch",
"published_at": "2025-01-07T13:23:36Z"
},
{
"tag": "v0.31.0",
"kind": "minor",
"published_at": "2024-12-17T10:56:53Z"
},
{
"tag": "v0.30.0",
"kind": "minor",
"published_at": "2024-11-27T11:51:15Z"
},
{
"tag": "v0.29.0",
"kind": "minor",
"published_at": "2024-11-08T16:55:33Z"
},
{
"tag": "v0.28.1",
"kind": "patch",
"published_at": "2024-10-31T16:23:11Z"
},
{
"tag": "v0.28.0",
"kind": "minor",
"published_at": "2024-09-19T17:40:55Z"
},
{
"tag": "v0.27.2",
"kind": "patch",
"published_at": "2024-07-05T11:31:26Z"
},
{
"tag": "v0.27.1",
"kind": "patch",
"published_at": "2024-06-10T15:39:31Z"
},
{
"tag": "v0.24.7",
"kind": "patch",
"published_at": "2024-05-30T09:57:00Z"
},
{
"tag": "v0.27.0",
"kind": "minor",
"published_at": "2024-05-06T15:20:57Z"
},
{
"tag": "v0.24.6",
"kind": "patch",
"published_at": "2024-05-06T14:39:36Z"
},
{
"tag": "v0.26.0",
"kind": "minor",
"published_at": "2024-04-18T11:57:55Z"
},
{
"tag": "v0.25.0",
"kind": "minor",
"published_at": "2024-03-25T15:21:09Z"
},
{
"tag": "v0.24.5",
"kind": "patch",
"published_at": "2024-03-22T14:37:32Z"
},
{
"tag": "v0.24.4",
"kind": "patch",
"published_at": "2024-03-21T14:02:29Z"
},
{
"tag": "v0.24.3",
"kind": "patch",
"published_at": "2024-03-19T16:23:42Z"
},
{
"tag": "v0.24.2",
"kind": "patch",
"published_at": "2024-03-12T13:01:33Z"
},
{
"tag": "v0.24.1",
"kind": "patch",
"published_at": "2024-02-14T16:31:12Z"
},
{
"tag": "v0.24.0",
"kind": "minor",
"published_at": "2024-02-05T14:01:16Z"
},
{
"tag": "v0.23.0",
"kind": "minor",
"published_at": "2024-01-09T09:51:56Z"
},
{
"tag": "v0.22.6",
"kind": "patch",
"published_at": "2024-01-02T12:13:30Z"
},
{
"tag": "v0.22.5",
"kind": "patch",
"published_at": "2023-12-15T14:02:13Z"
},
{
"tag": "v0.22.4",
"kind": "patch",
"published_at": "2023-11-23T10:10:32Z"
},
{
"tag": "v0.22.3",
"kind": "patch",
"published_at": "2023-11-21T12:25:21Z"
},
{
"tag": "v0.22.2",
"kind": "patch",
"published_at": "2023-11-16T08:22:54Z"
},
{
"tag": "v0.22.1",
"kind": "patch",
"published_at": "2023-11-13T10:57:32Z"
},
{
"tag": "v0.22.0",
"kind": "minor",
"published_at": "2023-11-10T09:05:21Z"
},
{
"tag": "v0.21.5",
"kind": "patch",
"published_at": "2023-10-31T14:38:00Z"
},
{
"tag": "v0.21.4",
"kind": "patch",
"published_at": "2023-10-20T07:48:16Z"
},
{
"tag": "v0.17.7",
"kind": "patch",
"published_at": "2023-10-20T07:28:36Z"
},
{
"tag": "v0.19.6",
"kind": "patch",
"published_at": "2023-10-20T09:04:23Z"
},
{
"tag": "v0.17.6",
"kind": "patch",
"published_at": "2023-10-18T15:19:51Z"
},
{
"tag": "v0.19.5",
"kind": "patch",
"published_at": "2023-10-18T14:48:27Z"
},
{
"tag": "v0.21.3",
"kind": "patch",
"published_at": "2023-10-17T11:10:03Z"
},
{
"tag": "v0.21.2",
"kind": "patch",
"published_at": "2023-10-10T12:49:07Z"
},
{
"tag": "v0.21.1",
"kind": "patch",
"published_at": "2023-09-26T11:34:53Z"
},
{
"tag": "v0.21.0",
"kind": "minor",
"published_at": "2023-09-13T18:01:46Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2023-08-25T06:56:16Z"
},
{
"tag": "v0.19.4",
"kind": "patch",
"published_at": "2023-08-04T08:37:21Z"
},
{
"tag": "v0.19.3",
"kind": "patch",
"published_at": "2023-08-01T15:58:54Z"
},
{
"tag": "v0.17.5",
"kind": "patch",
"published_at": "2023-08-01T14:00:28Z"
},
{
"tag": "v0.17.4",
"kind": "patch",
"published_at": "2023-06-09T12:03:37Z"
},
{
"tag": "v0.19.2",
"kind": "patch",
"published_at": "2023-06-08T14:05:48Z"
},
{
"tag": "v0.19.1",
"kind": "patch",
"published_at": "2023-05-24T15:19:57Z"
},
{
"tag": "v0.19.0",
"kind": "minor",
"published_at": "2023-05-04T09:10:44Z"
},
{
"tag": "v0.15.6",
"kind": "patch",
"published_at": "2023-04-19T09:46:58Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2023-04-18T13:34:40Z"
},
{
"tag": "v0.17.3",
"kind": "patch",
"published_at": "2023-04-18T11:26:19Z"
},
{
"tag": "v0.17.2",
"kind": "patch",
"published_at": "2023-03-30T12:31:01Z"
},
{
"tag": "v0.17.1",
"kind": "patch",
"published_at": "2023-03-08T15:15:55Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2023-03-02T14:50:12Z"
},
{
"tag": "v0.15.5",
"kind": "patch",
"published_at": "2023-02-06T11:46:56Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2023-02-06T10:59:31Z"
},
{
"tag": "v0.15.4",
"kind": "patch",
"published_at": "2023-02-06T11:01:40Z"
},
{
"tag": "v0.15.3",
"kind": "patch",
"published_at": "2023-01-19T11:50:50Z"
}
],
"recent_commits": [
{
"oid": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
"body": "Corrected the default container image path for the controller in the\nmulti-controller documentation to point to the correct GitHub Container\nRegistry repository.\n\nFixes #2559\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "docs: Update controller image path in multi-controller docs",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-21T10:21:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4dfe8e76d8674cb78bc70bd5b84201f05799323",
"body": "When updating a Bitbucket Cloud token via update-token, also\nprompt for the Atlassian account email and update\ngit_provider.user on the Repository CR. Without this, tokens\nrotated via the CLI leave a stale username that causes 401\nerrors on all provider API calls.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cli): set BB Cloud email in update-token",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-21T07:54:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "558561804964b529a161aea871788868687b0378",
"body": "this deletes the gemini config from PaC repo\nbecause gemini code review is decommisioned and\nit is no longer needed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "chore: delete gemini config from repo",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-20T18:43:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0feb33f9f5b2ead03cc2d510df497577b6ebee14",
"body": "Replace testify/assert with gotest.tools/v3/assert in\ninfo_test.go and task_status_test.go to match the project's\nstandard assertion library and eliminate mixed usage.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "test: use gotest.tools/v3/assert consistently",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-20T12:09:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9f1fe585601252cf88ded8a2487dde0cb25fdb3",
"body": "Tekton Hub has been shut down and is no longer supported in\nOSP 1.24. Remove all TektonHub-specific code, configuration,\ntests, and documentation, leaving only Artifact Hub integration.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(hub): remove Tekton Hub support",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-20T12:09:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6e3f736a86b0e89103b84dfda95e5999075a0c72",
"body": "Added logic to extract and display error messages from waiting container\nstates, which occur when secrets or other configuration issues prevent\npod creation. This allows users to see the actual error (e.g., \"secret\nnot found\") in the pipeline failure output instead of just a generic\nreason code. Als\n[…]\ns to include container creation and pod creation errors.\n\nFixes #2751\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12208\nCo-Authored-By: Gemini\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "feat: capture container creation error messages in logs",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-20T10:08:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad947f41d3d277edd7b761a030d5911dc3cc72c5",
"body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\n\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump actions/setup-go in the github-actions group",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T07:25:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d121ae3e51f0ffdcdcd3391a674b6877a7af0ec",
"body": "Bumps the go-dependencies group with 1 update: [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty).\n\n\nUpdates `github.com/mattn/go-isatty` from 0.0.22 to 0.0.23\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)\n\n---\nupdated-dependencies:\n- dependency-name: github\n[…]\n dependency-version: 0.0.23\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump github.com/mattn/go-isatty in the go-dependencies group",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T07:18:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e25db4412aa0a70b220da6dc1e2a268b386c7131",
"body": "Enabled verbose JSON logging with connection timeouts and retries for\ngosmee clients to make end-to-end test failures easier to debug.\nIsolated Gitea and GitHub Enterprise webhook client logs into their\nown directories and files to prevent them from overwriting or\nappending to shared main logs. Upda\n[…]\non script to\ngather these new logs, capture internal Kubernetes gosmee deployment\ndetails when available, and redact the newly added webhook URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "test: Improve gosmee client debugging for end-to-end tests",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-17T10:11:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a054817abb339b0eef99e76aab00ed42bd571d89",
"body": "Updated the AI code reviewer prompt to provide more detailed guidance on\nreview standards. Enhanced instructions to clarify what constitutes\nactionable findings versus nits, added explicit severity level\ndefinitions for consistent issue categorization, and improved guidance\non when and how to provid\n[…]\nuggestions. These changes aim to\nproduce more focused and useful pull request reviews by setting clearer\nexpectations for the reviewer's behavior.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: refine paco code review prompt",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-17T10:07:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f314275a165afc0641f3e6cef98bbecf0e51134",
"body": "Extend Paco's structured review response with a difficulty rating, a\nshort explanation, and a security-sensitivity flag. Explain the rating\ncriteria in the model prompt so scores account for change size,\ncomplexity, risk, and blast radius while keeping summary-only runs\nconsistent with full reviews.\n[…]\nthe review instructions to suppress subjective formatting,\nnaming, and phrasing nits unless they affect correctness, security, or\nmaintainability.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "feat: score review difficulty and other paco impro",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-17T10:07:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad2dcdb267f0d0b5ad99f3366bb4365d277c2fe0",
"body": "Added an automated code review pipeline powered by AI to analyze pull\nrequest diffs against project-specific guidelines. This was done to help\ndevelopers catch bugs, style violations, and security flaws early by\nposting inline comments and a persistent overview summary directly onto\nGitHub pull requests.\n\nThis using opencode cli backend (but thats an implementation detail) and\nsupport custom review rules via a .tekton/ai/REVIEW.md file.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "feat: Introduce Paco AI code review",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-17T08:34:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29c47b6e5245b6f115934cc6e4a889e60909dab1",
"body": "Remove the Status []RepositoryRunStatus field from the Repository\nCR to eliminate informer cache churn caused by updating the CR on\nevery PipelineRun completion. CLI commands now query PipelineRuns\ndirectly via label selectors instead of reading repo status.\n\n- Delete updateRepoRunStatus reconciler \n[…]\n ShowLastSHA, ShowStatus, ShowLastAge\n- Update deepcopy, test helpers, informer transform, golden files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
"is_bot": false,
"headline": "refactor: remove Repository CR pipelinerun_status field",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-16T07:18:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f6a391687b88008a8b4cc264077508b7a1c8181c",
"body": "Replace IsCollaborator (which returns true for read-only collaborators)\nwith CollaboratorPermission to verify the sender has write or admin\nor owner access before allowing pipeline runs. Also fix\nCreateForkPullRequest to grant access to SecondUserName instead of\nTargetRefName.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "fix(gitea): check write/admin permission instead of collaborator only",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-16T06:08:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84829463a99d791164a3ef8f7f5dc1cd00fc6766",
"body": "Adds TestOTelMetrics, a consolidated e2e test for the OC→OTel metrics\nmigration in Pipelines-as-Code (PR #2567). The test scrapes two pods:\n\nController (app.kubernetes.io/name=controller):\n- Asserts http_client_* metrics from knative k8s client OTel instrumentation\n- Asserts go_* runtime metrics\n- C\n[…]\ne metrics\n\nVerified locally with PAC controller and watcher deployed to kind via ko.\n\nRelates to tektoncd/pipelines-as-code#2567\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: add e2e test for OpenCensus to OpenTelemetry metrics migration",
"author_name": "Khurram Baig",
"author_login": "khrm",
"committed_at": "2026-07-16T04:12:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "69c4496b1d39ca6d22eff42a499bd7626e40e949",
"body": "Add missing unit tests for low-coverage packages identified via\ncodecov analysis: params/clients, cli, bootstrap, pipelinerunmetrics,\nwebhook, and llm/llm-context. Also exclude test-helper packages from\ncodecov accounting and add a codecov badge to README.\n\nCoverage improvements:\n- params/clients: 1\n[…]\n: 39.6% -> 81.3%\n- webhook: 47.9% -> 70.9%\n- llm: 46.8% -> 57.9%\n- llm/context: 38.8% -> 77.5%\n\nOverall project statement coverage: 65.6% -> 68.3%\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "test: raise unit test coverage across packages",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-15T13:47:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5438a1e06ea50062a79fe8fcd52f456a1b974a46",
"body": "The warning about the old profiling.enable key is migration\nguidance that describes historical state rather than current\nbehavior. Since the old key no longer works, only the current\nruntime-profiling key needs to be documented.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "docs(profiling): remove deprecated key callout",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-15T09:04:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "35ee9df55f472c448f203fb60b566fbc27efd06f",
"body": "The Gitea cancel run test used a hardcoded sleep before sending the\ncancel comment. This caused test failures when the webhook relay took\nlonger than expected to deliver the event, sending the cancel command\nbefore the pipeline run existed. Replaced the sleep with a check that\nwaits for the pipeline run to be created first.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "test: Wait for pipelinerun to be created before cancellation",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-15T07:32:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "85b606bb30f6b42d645cd79526dfd5ceba629f88",
"body": "The apiextensions-apiserver indirect dependency is updated\nfrom v0.35.6 to v0.36.2 along with the corresponding\nk8s.io/apiserver transitive dependency. The vendored files\nreflect upstream changes including a new StorageMigrating\ncondition type and the removal of the deprecated\nprotomessage compatibility shim.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "chore: bump k8s.io/apiextensions-apiserver to v0.36.2",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-10T08:07:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c6483e2865399ae6794a5a3f57f2fac628bdd93",
"body": "Bumps the go-dependencies group with 1 update: [k8s.io/client-go](https://github.com/kubernetes/client-go).\n\n\nUpdates `k8s.io/client-go` from 0.35.6 to 0.36.2\n- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/kubernetes/client-go/compare/v\n[…]\n dependency-version: 0.36.2\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump k8s.io/client-go in the go-dependencies group",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T08:07:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2e845ef225649de5ab631288562795a1c4037e83",
"body": "rh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
"is_bot": false,
"headline": "refractor: split gitea_test.go into focused files",
"author_name": "KMI1011",
"author_login": "KMI1011",
"committed_at": "2026-07-10T07:32:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85cad747dee15d9847c04cec0d79a4c4fab5789a",
"body": null,
"is_bot": false,
"headline": "fix: bump knative.dev/pkg and semconv to fix otel schema panic",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-09T16:56:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0fe2198bfa19188481c1a166b368df68055fc1e2",
"body": "Dependabot generates automated commit messages that often violate line\nlength or body formatting rules. Added a check to bypass commit\nvalidation for dependabot pull requests, allowing these automated\nupdates to proceed without linting failures.",
"is_bot": false,
"headline": "ci: skip commit validation on dependabot PRs",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-09T16:56:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c421e079e553bbf0b3fcdf7291fca29ee66e6b7",
"body": null,
"is_bot": false,
"headline": "ci: ignore go-github and ghinstallation in dependabot",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-09T16:56:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b3981bc20b55759649f413d515452f7161b029b",
"body": "Bumps the go-dependencies group with 15 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/bradleyfalzon/ghinstallation/v2](https://github.com/bradleyfalzon/ghinstallation) | `2.18.0` | `2.19.0` |\n| [github.com/google/cel-go](https://github.com/google/cel-go) | `0.28.1` | `0.29.2` |\n[…]\nx: pin ghinstallation to v2.18.0\n\nDowngraded ghinstallation from v2.19.0 to v2.18.0 and removed the unused\ngo-github v88 dependency that was pulled in transitively.\n\nfix: pin ghinstallation to v2.18.0",
"is_bot": true,
"headline": "ci: bump the go-dependencies group with 15 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T16:56:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "717f163e6fd3bfef22bd51108202c1049050bd7e",
"body": "Added Go module tracking to the Dependabot configuration to keep Go\ndependencies updated. Since we can now group these updates together, we\ncan prevent an excessive number of pull requests.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: Readd Go module updates in Dependabot",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-09T12:38:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "912f4e6b3b4147f4143f45e9cedbf2e767f562fd",
"body": "- Update Go version from 1.26.4 to 1.26.5 in go.mod\n- Addresses crypto/tls Encrypted Client Hello privacy leak\n- CVE-2026-42505 / GO-2026-5856 fixed in go1.26.5\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cve): CVE-2026-42505 - update Go to 1.26.5",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-09T11:50:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2a8413915cd80a6217b6eb3d50018b449082550a",
"body": "The test waited on the PR head SHA status which is already green from\nthe pull_request run, then slept 5s; a delayed push webhook made\nGetStandardParams fail fatally on its first iteration with zero push\npipelineruns.\n\nWait for both pipelineruns to succeed after the merge and make\nGetStandardParams \n[…]\nhecking helper is patient\nenough to retry while things are still warming up, instead of quitting\nat the first empty result.\n\nAI-assisted-by: Cursor\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "fix(e2e): wait for push pipelinerun in gitea params test",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-08T11:47:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e270e68e403cf5f937f48e6e5ea73ea663818888",
"body": "The GitLab token auto-rotation feature revoked the old token via the\nself-rotate API before making the first Kubernetes API call that\ncould fail with a permission error. If the subsequent Secret update\nfailed, the old token was already revoked and the new token was\ndiscarded, irrecoverably destroyin\n[…]\n the\nrotation is aborted with a clear error while the old token is still\nvalid, so nothing is lost.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(gitlab): verify write access before rotating token",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-08T08:23:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "73cb521a48abeca491396811ac795e5a0039ece2",
"body": "Document that provider code must use v.Logger instead of\nrun.Clients.Log, since the provider logger carries standard\ncontext variables (provider, repository, event-id). This\nprevents regressions of the pattern fixed in the recent\nprovider logging commits.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "chore: add provider logginf guidance to AGENTS.md",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-08T05:52:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b89b22edfa4ae5a6c296b11b8a39e6c01cd7caab",
"body": "The token auto-rotation logging in the GitLab provider's\nsetClient was still using run.Clients.Log instead of the\nprovider's own logger. This logger lacks the standard context\nvariables (provider, repository, event-id) that v.Logger\ncarries.\n\nFollow-up-to: https://github.com/tektoncd/pipelines-as-code/pull/2827\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(provider): use provider logger in gitlab setClient",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-08T05:52:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "939d30a4365440484d4319046065af596601a37a",
"body": "The run.CLients.Log logger is created early and does not have the\nstandard context variables. The provider logger is used primarily and\nwhile technically possible because pointers, provider.Logger == nil is\nan illegal state.\n\nAssisted-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(provider): always use log using Provider logger",
"author_name": "Andrew Thorp",
"author_login": "aThorp96",
"committed_at": "2026-07-07T13:08:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e62d212d539ff389a82f4ca257aa9a7655cf042",
"body": "Complete the refactor started in 39271f36a which removed the wait\nhelpers polling the deprecated Repository CR Status field. Three\nloose ends were left behind and are tied off here.\n\nFix zero-minimum wait semantics. The removed helpers compared with\n\">\" so MinNumberStatus: 0 meant \"wait for one\". Th\n[…]\nross 22\nE2E test files are deleted.\n\nValidated with go test ./test/pkg/wait and a compile of the e2e\ntagged test package.\n\nAssisted-by: Claude Code\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "refactor(e2e): finish Repository.Status removal in waits",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-07T11:16:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "39271f36a191962287f27270b75ebc52084c3f84",
"body": "The Repository CR's Status field is deprecated and will be removed.\nThis refactors E2E test wait helpers to use PipelineRun objects directly\ninstead of polling Repository.Status:\n\n- Remove UntilRepositoryUpdated and UntilRepositoryHasStatusReason\n- Remove FailOnRepoCondition from wait.Opts\n- Modify \n[…]\ninstead\n of repo.Status fields\n- Migrate all ~40 call sites across 20 test files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(e2e): remove reliance on Repository.Status in wait functions",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-07T07:39:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1433ee8668857940524d58b6c8510d4d8552d7b8",
"body": "Add Forgejo to the webhook setup used by `tkn pac create repo` and\n`tkn pac webhook add`. Create the repository webhook and store the\ntoken and webhook secret for runtime use.\n\nHandle repository URLs with `.git` suffixes, trailing slashes,\ninstance subpaths, and SSH forms without blocking manual set\n[…]\noken permission is needed and clarify when the CLI\ncreates the provider secret.\n\nFixes #2755.\n\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>\nSigned-off-by: Katie Mulliken <mulliken@redhat.com>",
"is_bot": false,
"headline": "feat(webhook): add Forgejo CLI setup",
"author_name": "Katie Mulliken",
"author_login": "SecKatie",
"committed_at": "2026-07-06T12:02:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e0badfa041319b55f201e956df9ecf152923581f",
"body": "Pipelines-as-Code automatically rotated GitLab access tokens to\nprevent pipeline failures caused by expired credentials. Expiring\ntokens were replaced with new tokens and updated in the corresponding\nKubernetes Secret, reducing manual maintenance. Shared secrets from the\nglobal repository were exclu\n[…]\ns. This behavior is disabled\nby default but could be turned on via repository configuration.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-11153\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "feat: Implement automatic GitLab access rotation",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-06T11:22:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7bd2cc1be180b32ada848ab65d1090d32e6bf1a2",
"body": "Removed the testrr integration, including the upload script, CI\nenvironment variables, and documentation. The testrr service is no\nlonger used to track test results from Tekton and GitHub Actions.\n\nIt was never really used and created a lot of resources waste, so we are\nremoving it to simplify our CI/CD pipeline and reduce unnecessary\ndependencies.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: Remove testrr test reporting from the CI environment",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-06T09:04:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27ac5d7e2567f21b5ae281fa54db0fcc89dd3c80",
"body": "The reconciler is a shared controller object. It can work on more than one\nPipelineRun at the same time. Some values it used while loading Git provider\ncredentials were stored on that shared object, even though they only belonged\nto the PipelineRun currently being processed.\n\nThat could let one Pipe\n[…]\non. Also copy Repository objects before merging global settings, so\nwe do not modify objects that came from the shared informer cache.\n\nFixes #2824\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "fix(reconciler): avoid shared state",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-03T13:29:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63e8059d17c3fde3e60fd1dc07b48b260d9996a5",
"body": "Updated the documentation and scaffolding templates to clarify task\nresolution behaviors. Explicitly distinguished annotation-based task\ninlining from native Tekton Hub resolver syntax because combining them\ncaused configuration errors. Replaced outdated git-clone catalog URLs\nwith the correct Artifact Hub links to ensure accurate references.\n\nFixes #2814\nAI-assisted-by: OpenAI ChatGPT\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "docs: Clarify task resolution in the pipeline documentation",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-03T07:53:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccba1d5ca7a56c0eb66c102420bb553c8581f48b",
"body": "this commit reverts a github link in docs from using\nmain branch to point to a specific commit to make\npermalink lint happy.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "chore: use commit sha to prevent permalint lint error",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-03T07:31:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e30e597f4318d7438df004401802772ff56e6429",
"body": "Label removal events on GitLab merge requests were incorrectly triggering\npipeline runs. The hasOnlyLabelsChanged check used an OR condition that\nmatched both additions and removals. Changed to compare current vs previous\nlabel count so only label additions are processed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(gitlab): discard label removal events on merge requests",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-07-03T07:31:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8a7f21344bdf3ab247c8759fdcbefff42f8a62fc",
"body": "- Upgrade github.com/tektoncd/pipeline from v1.13.1 to v1.14.0\n- Fixes GHSA-cv4x-93xx-wgfj / CVE-2026-33022: controller panic via long\n resolver name in TaskRun/PipelineRun (GenerateDeterministicNameFromSpec)\n- Fixes GO-2023-1901: Pipelines do not validate child UIDs\n- Co-upgrade transitive deps pu\n[…]\n,text} minor bumps\n- Ran: go mod tidy && go mod verify && go mod vendor\n\nResolves: SRVKP-11100\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cve): CVE-2026-33022 - upgrade tektoncd/pipeline v1.13.1 → v1.14.0",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-07-03T05:20:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "03cd060cbf610d5343af4d10e8bbf0e3d66279e6",
"body": "Added a Go formatting check to the linting process using gofumpt.\nIntegrated this verification step into the local Makefile lint target\nand the automated Tekton CI pipeline to ensure consistent code style\nacross the repository.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: Enforce Go code formatting checks in lint pipeline",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-02T13:42:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8966a5331f743fe9e68d2262da1234b2391e4cb",
"body": "Code was reformatted using fumpt to improve consistency with Go\nformatting standards. This includes adjusting line breaks in function\ncalls and adding parentheses for better readability where function\narguments span multiple lines. chore: reformat files with make fumpt",
"is_bot": false,
"headline": "chore: reformat code with fumpt",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-02T08:43:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6dfcd60091c46844449e91a38bf38b76bea56c47",
"body": "Switch Bitbucket Cloud setup away from app-password language and\nmake the CLI collect the Atlassian account email used for API token\nauthentication. Webhook creation now uses that email with the scoped\nAPI token instead of authenticating with the repository owner.\n\nKeep Repository CRD shape unchange\n[…]\nthe CLI auth flow, token rotation prompt, and generated git auth\nsecret behavior.\n\nFixes #2818\nJira https://redhat.atlassian.net/browse/SRVKP-12685\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "fix: bitbucket API tokens instead of app-passwords",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-01T15:55:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8fdee04551602b8af9ef267e121863f045c256e5",
"body": "Addresses SRVKP-12311 by moving unit coverage publishing to a\ndedicated GitHub Actions workflow. The workflow runs on pull requests,\npushes to main, and manual dispatch, then uploads coverage with the\nunit-tests flag through Codecov OIDC.\n\nRemove the older Tekton Codecov uploader steps that relied o\n[…]\no longer suggests Codecov coverage ownership.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12311\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: add codecov oidc upload",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-07-01T09:33:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9d51949f5027d41d9e8941ffa651a541acd8188f",
"body": "Explain that disabling GitLab PipelineRun status comments does not\nhide validation errors from PipelineRuns in the `.tekton/` directory.\nThis keeps the note in normal prose instead of an info callout, so\nthe GitLab guide reads as a continuous troubleshooting section.\n\nSigned-off-by: Estee Cohen <estherco@post.bgu.ac.il>\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "docs: clarify GitLab comment strategy behavior",
"author_name": "Estee Cohen",
"author_login": "EsteeCohen",
"committed_at": "2026-07-01T09:16:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ffc50929a53e9d07fda018ac73bd6f899a31310d",
"body": null,
"is_bot": false,
"headline": "fix(llm): run default AI roles on completed PipelineRuns",
"author_name": "BoseKarthikeyan",
"author_login": "BoseKarthikeyan",
"committed_at": "2026-06-30T09:21:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d2cde6492c70ac4f983f6fede548dd138c5d73b",
"body": "Knative's config-observability ConfigMap only exposes a flat\ntracing-sampling-rate, so at fractional rates each service in the chain\nrolls independently — PaC can drop a trace while Tekton keeps it, leaving\nexecution spans whose parent_spanID points at nothing. Switching to the\nOTel SDK opens up OTE\n[…]\nonally not honored per Konflux-CI\nADR 0061. otlptracegrpc and otlptracehttp promoted from indirect to direct\ndependencies.\n\nAssisted-by: Claude Code\nSigned-off-by: Josiah England <jengland@redhat.com>",
"is_bot": false,
"headline": "fix(tracing): direct OTel SDK setup for chain-coherent sampling",
"author_name": "Josiah England",
"author_login": "ci-operator",
"committed_at": "2026-06-30T05:31:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e1a2f48ed544837c80ea38487d1ed728df82c819",
"body": "Replace duplicate 404 and non-404 error subtests with a\ntable-driven test to satisfy the dupl linter.\n\nFixes https://github.com/tektoncd/pipelines-as-code/issues/2653\n\nrh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
"is_bot": false,
"headline": "fix: downgrade 404 API responses from error to debug log level",
"author_name": "KMI1011",
"author_login": "KMI1011",
"committed_at": "2026-06-29T14:14:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "74939ef42af88d708302559927406a59c7f16bbb",
"body": "Reduce PR noise by grouping all GitHub Actions dependency updates into a\nsingle consolidated pull request, improving workflow efficiency.",
"is_bot": false,
"headline": "chore: Configure Dependabot to group GitHub Actions updates",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-29T08:16:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f045c6cf34367dbc09d0e0da9cdd72f9610b76d",
"body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\ns:\n- dependency-name: actions/cache\n dependency-version: 6.1.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/cache from 5.0.5 to 6.1.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T06:41:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aa462865bb55ec617868b0f23451bc03ebcd0452",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n dependency-version: 6.5.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T06:41:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0a781dbea31c5b894d6419b95df9fd2eb6f2cb1d",
"body": "Bumps [ko-build/setup-ko](https://github.com/ko-build/setup-ko) from 0.9 to 0.10.\n- [Release notes](https://github.com/ko-build/setup-ko/releases)\n- [Commits](https://github.com/ko-build/setup-ko/compare/d006021bd0c28d1ce33a07e7943d48b079944c8d...61b4d1d396f5b2e7d6bb6fefdce3dc38d1a13445)\n\n---\nupdate\n[…]\ndependency-name: ko-build/setup-ko\n dependency-version: '0.10'\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump ko-build/setup-ko from 0.9 to 0.10",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T06:40:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82843027ab11abb03ce42f4603361cc3718e9ee9",
"body": "Cache ListOrgTeams API responses per organization to avoid\nredundant API calls when checking policy for the same org\nacross multiple allowed teams evaluations.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "feat(forgejo): cache org teams in policy check",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-26T13:57:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "181a27faf760794cb3104995f0dcc88c12cb6be9",
"body": "this allows e2e workflow run on any changes in hack/\ndirectory as there are all the script used across\nworkflow file.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "chore(ci): allow e2e workflow run hack/* changes",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-26T09:15:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e8ac13de68283c7aade7524100f9ba0f980f6569",
"body": "Use per-resource kubectl get with --- separators when collecting\npipelineruns, repositories, and configmaps in CI log artifacts so\neach resource is a distinct YAML document.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): separate collected resources with YAML document markers",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-26T09:15:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9fb79c78fc4bb95b6aafeac654f2ab76cebcdf1e",
"body": "Add table-driven unit tests for pkg/provider/gitea/parse_payload.go:\n\n- TestParsePayloadPullRequest covers the opened, synchronized, label_updated\n and closed actions (event type, trigger target and label extraction).\n- TestParsePayloadPush covers the head_commit path and the before-SHA fallback.\n-\n[…]\noad helper builds the request and calls ParsePayload, and\nprPayload builds pull_request webhook bodies.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Kshitiz Jain <kshitizj@gmail.com>",
"is_bot": false,
"headline": "test(gitea): add unit tests for parse_payload",
"author_name": "Kshitiz Jain",
"author_login": "kshitizj03",
"committed_at": "2026-06-25T09:21:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fff1dac7fad8183449d7521d3a6c0e797b06efe6",
"body": "Tekton workspaces are shallow detached-HEAD clones; remote tracking\nrefs like origin/main are not available after git fetch -a --tags.\nUsing {{revision}} (the triggering commit SHA) matches the pattern\nalready used in .tekton/release-pipeline.yaml.",
"is_bot": false,
"headline": "fix: use revision instead of origin/main for nightly branch checkout",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-23T13:51:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f765bcb26a4da9fd5cd13137179450683953f56",
"body": "actions/checkout v7 now refuses to fetch fork pull request code in\npull_request_target workflows by default to prevent pwn request\nattacks. Add allow-unsafe-pr-checkout: true to the e2e workflow\ncheckout step that needs to build and test fork PR code with\nrepository secrets.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): allow checkout of fork PR code in pull_request_target workflow",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-23T11:27:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6554d32b4a9b867c0d3ecc9b902e2b5b358ce38c",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-23T08:09:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "20a29a92b595e6e1c7794d1f9d0771b9554eb14f",
"body": "Value.Emit() is deprecated in the updated OpenTelemetry SDK;\nreplace with Value.String() to resolve linter warning.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(tracing): use String instead of deprecated Emit",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-23T07:10:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d39d0d9b0924b8133e16d99d3e5997e1ef058b5",
"body": "- Update github.com/tektoncd/pipeline from v1.11.1 to v1.13.1\n- Co-upgrades: cel-go v0.28.1, go-scm v1.15.22, otel v1.44.0,\n zap v1.28.0, k8s.io/* v0.35.5, grpc v1.81.1\n\nCVE-2026-33022 (GHSA-cv4x-93xx-wgfj, CVSS 6.5 Medium):\nTekton Pipelines controller panic via long resolver name in\nGenerateDeterm\n[…]\nIs (pkg/apis, pkg/client) and does not run the\nTekton controller binary.\n\nResolves: SRVKP-9042\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "chore(deps): bump tektoncd/pipeline to v1.13.1",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-23T07:10:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2ad17d4501ebcc8021b929c13ae397fcff5c8554",
"body": "Updated the Homebrew installation documentation to include instructions\nfor trusting the tap to support newer Homebrew versions. Added steps\nto handle macOS Gatekeeper blocking the binary on first run, and\ndefined corresponding caveats in the release configuration.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "docs: Update homebrew installation instructions for tap trust",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-22T11:19:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3dcf4ae3040e688935b84886bb4d6bbd9f6498a5",
"body": "this commits adds a reason in log message that why the\nPipelineRun is cancelled so to make it clear to users.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "refactor: enhance log message for cancel-in-progress",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-19T15:22:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c38b0283fe109f5d9dcdfc9a215e07788e112a6c",
"body": "Addresses Go stdlib vulnerabilities that require upgrading the compiler\ntoolchain from Go 1.25.11 to Go 1.26.4.\n\nCVEs fixed:\n- CVE-2026-27137 (GO-2026-4599): Incorrect email constraints in crypto/x509\n- CVE-2026-27138 (GO-2026-4600): Panic in name constraint checking in crypto/x509\n- CVE-2026-25679 \n[…]\n these fixes require Go 1.26.x.\nNo dependency changes: go.sum unchanged, go mod verify passes.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(security): upgrade Go from 1.25.11 to 1.26.4 to fix 23 stdlib CVEs",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-18T13:37:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1c0fabcc29f8a87bf2cb7169d2914b8321bbe684",
"body": "Replaced the local HTTP-based git-clone stepaction with the official\nTekton Hub resolver across Tekton workflows. Removed the redundant\nlocal stepaction definition file to keep configuration centralized.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: Use git-clone artifacthub stepactions",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-17T11:37:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aeb85ab653e95a4ddac059a2909cc41468097d36",
"body": "Preserves the error chain for errors.Is/errors.As callers.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: use %w instead of %s for error wrapping in DetectPacInstallation",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-17T11:37:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cc818de1b009f8c117952eb651a783143c56e605",
"body": "Add notes to the configmap and docs clarifying that\ncustom-console-url-pr-details, custom-console-url-namespace,\nand custom-console-url-pr-tasklog must all be configured when\ncustom-console-url is set. Also document console URL precedence\norder and add the missing custom-console-url-namespace example.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(consoleui): document required custom console settings",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-17T05:22:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52fd4ae9ff914eb88fda2013ec33f611b1726f15",
"body": "Upgrade golang.org/x/crypto from v0.50.0 to v0.52.0 to address the\nfollowing vulnerabilities in the SSH package:\n\n- CVE-2026-42508 (GO-2026-5021): auth bypass via unenforced @revoked status in ssh/knownhosts\n- CVE-2026-39833 (GO-2026-5005): key constraints not enforced in ssh/agent\n- CVE-2026-39832 \n[…]\n3.0\n- golang.org/x/text: v0.36.0 → v0.37.0\n\nAll fixed in v0.52.0 (minimum safe patch version).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cve): upgrade golang.org/x/crypto v0.50.0 → v0.52.0 to fix 13 CVEs",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-17T03:54:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3180f7ca1db2856ddcc1f1e968c414d0cb89a812",
"body": "this commit fixes the linting issues after a new\nvale release changes the rule I guess.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "fix(ci): linting issue after new release",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-16T12:59:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6035f789cdf72090f5b6a58e3dece394323c3bf",
"body": "Upgrade go directive in go.mod from go1.25.7 to go1.25.11 to address\nthe following Go standard library vulnerabilities:\n\n- CVE-2026-42507 (GO-2026-5039): arbitrary inputs in errors without escaping in net/textproto\n- CVE-2026-42504 (GO-2026-5038): quadratic complexity in mime.WordDecoder.DecodeHeade\n[…]\not escaped in html/template\n\nAll fixed in go1.25.11 (minimum safe patch in the go1.25.x line).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cve): upgrade Go stdlib to go1.25.11 to fix 16 CVEs",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-16T11:04:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f06dcf55cf3d3f83af65ac8fc9733448b545a4f5",
"body": "Upgrade golang.org/x/net from v0.53.0 to v0.55.0 to address the\nfollowing vulnerabilities in golang.org/x/net:\n\n- CVE-2026-39821 (GO-2026-5026): failure to reject ASCII-only Punycode-encoded labels\n- CVE-2026-42506 (GO-2026-5025): incorrect handling of namespaced elements in foreign content\n- CVE-20\n[…]\n/text: v0.36.0 → v0.37.0\n\nNote: A separate PR upgrades x/crypto to v0.52.0 to fix 13 SSH CVEs.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(cve): upgrade golang.org/x/net v0.53.0 → v0.55.0 to fix 6 CVEs",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-16T11:03:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cbd582d0eef060094da1bbac907a1d6764b210df",
"body": "… in the set client",
"is_bot": false,
"headline": "feat(bitbucketdatacenter): allow service accounts to not require user…",
"author_name": "Ruben Rodrigues",
"author_login": "Ru13en",
"committed_at": "2026-06-09T18:56:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe709aecfe20b4da430a686463f655b4e1ebefac",
"body": "gosmee v0.31.1 fixed an inverted TLS flag (InsecureSkipVerify was\nnegated), so the flag now works correctly. Restore it for e2e tests\nthat use self-signed minica certificates and unpin the version to\npick up the security fixes in v0.31.1+.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "fix(ci): restore --insecure-skip-tls-verify and unpin gosmee version",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-09T15:08:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f9c939d7369a9d246ced54404e90642a2d963655",
"body": "The e2e workflow now installs the minica CA certificate into the system\ntrust store, so gosmee no longer needs to skip TLS verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): remove --insecure-skip-tls-verify flag from gosmee client",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-09T12:01:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ce4774d3f94b07ecc723a920d8312412d730a091",
"body": "we've seen some failure in E2E test which could\nbe surfaced due to recent gosmee release so using\nv0.31.0 version to see the affect.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "chore: stick gosmee version to v0.31.0",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-09T11:22:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85f323a53088693acf3e403ff9b6219ce346cc9c",
"body": "Update release notes format reference to use the new\nTekton Github org name as well as product name,\nreplacing openshift-pipelines and OpenShift references.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "chore(release-notes): update org and branding refs",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-09T08:56:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70faf9f9220253a15f9d71058faeb11097824a78",
"body": "Gosmee starts before startpaac generates minica certs and before\nupdate-ca-certificates runs. Even after the CA is installed, the\nalready-running gosmee process doesn't pick it up since Go loads\nthe cert pool at startup. This only affects the downstream\nconnection to the PAC controller inside the ephemeral CI cluster,\nnot the upstream SSE connection or any git provider connections.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): skip TLS verification for gosmee client in e2e tests",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-08T12:23:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5bee3b79913be2d55892b4b1dc7306301701e88b",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n dependency-version: 6.0.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-07T11:12:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "402d5c7eeece881cb082ec68e9e8b61709e39ace",
"body": "Removed logic that blindly accepted the X-GitHub-Enterprise-Host header\nand now validate that it matches the repository URL in the webhook payload.\nAdded webhook signature verification before token generation to ensure\nthe payload hasn't been tampered with. This prevents an attacker from\nredirecting token requests to their own server by forging the Enterprise\nHost header.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "fix: prevent GitHub Enterprise header hijacking in app token requests",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-04T15:57:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee5d9b0a55afcd66b09ebce0d9d58d30c050cdb5",
"body": "Use DeepCopy when reusing cached Pipeline and Task objects across\nPipelineRuns. Without this, inlineTasks mutates the cached\noriginal, contaminating subsequent runs that reference the same\nremote pipeline.\n\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(resolve): deep-copy cached resources before inlining",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-04T15:50:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "001782829e82b83ecb3da903f5a024ca0826b64c",
"body": "Scope GitHub App installation tokens so they cannot access\nrepositories beyond the triggering one. Normal webhooks now\nextract the repository ID from the payload and pass it to\nInstallationTokenOptions. Incoming webhooks lack a payload\nrepo ID, so a new RepositoryNames field lets SetClient scope\nt\n[…]\npe providers and extend SetClient's\nfallback to reissue a scoped token when either field is set.\n\nCo-Authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(github): scope App token to triggering repo",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-04T15:50:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd262aa3b7ad12ea664f9d654351a8766f2c1306",
"body": "this updates the message about deprecation of secret passing\nin URL query parameters so which would be removed in future\nrelease.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
"is_bot": false,
"headline": "chore: update incoming webhook legacy params deprecation message",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-06-04T11:39:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c03760fd7181c2b5da1e4ce4356279bf322a7ae",
"body": "Signed-off-by: Shubham Bhardwaj <shubbhar@redhat.com>",
"is_bot": false,
"headline": "fix(security): redact query string from incoming webhook log",
"author_name": "Shubham Bhardwaj",
"author_login": "infernus01",
"committed_at": "2026-06-03T15:42:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "223e39c0ec6d784114d566364a7c6eb99964172a",
"body": "The notify-slack script looked for e2e-test-output.log which was\nnever produced by gotestsum. Switch to parsing e2e-test-output.json\nusing jq so scheduled run failures are reported to Slack.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): parse JSON test output for Slack notifications",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-06-03T11:45:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "885427460c5323b1267bd10eccbcd59a29baa1bf",
"body": "The pipelines-as-code-controller ServiceAccount had cluster-wide delete\npermission on secrets that was never used in the codebase. This change\nremoves the unused permission to follow the principle of least privilege.\n\nThe controller only requires 'get' permission on secrets for:\n- Incoming webhook v\n[…]\nate, delete) for managing the\nlifecycle of pac-gitauth-* secrets.\n\nVerification:\n- All unit tests pass (2816 tests)\n- Linting passes\n- Watcher permissions unchanged\n- No functional impact\n\nFixes #2743",
"is_bot": false,
"headline": "fix: remove unused secrets/delete permission from controller",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-06-03T06:58:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d0454b7d2cd8ddef53fc8c6b147851b053acff2",
"body": "Bumps [mxschmitt/action-tmate](https://github.com/mxschmitt/action-tmate) from 3.23 to 3.24.\n- [Release notes](https://github.com/mxschmitt/action-tmate/releases)\n- [Changelog](https://github.com/mxschmitt/action-tmate/blob/master/RELEASE.md)\n- [Commits](https://github.com/mxschmitt/action-tmate/com\n[…]\ndency-name: mxschmitt/action-tmate\n dependency-version: '3.24'\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump mxschmitt/action-tmate from 3.23 to 3.24",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T14:47:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67cfa525176645dee0e19297584436c0526f6183",
"body": "Replace the obsolete profiling.enable ConfigMap key with\nruntime-profiling (enabled/disabled). Remove the K_METRICS_CONFIG\ncontroller section since the controller now uses ConfigMap-based\nobservability via the eventing adapter. Document that controller\nprofiling requires a pod restart as the adapter\n[…]\nconfig once\nat startup. Add CONFIG_OBSERVABILITY_NAME prerequisite for the\nwebhook.\n\nFixes #2633\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(profiling): update guide for OTel migration",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-05-29T12:34:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3811249c246b4084b1f2e337069c0ccf412ac516",
"body": "Update knative/eventing to v0.49.0 which includes the pprof server\nfix (knative/eventing#9008). Also bumps k8s.io to v0.35.4,\nknative/pkg, and golang.org/x dependencies.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "chore(deps): bump knative/eventing to v0.49.0",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-05-29T12:34:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bb2f82a9cfac342fe22a948cc7b7c035d9ec4a3",
"body": "Add configurable TLS settings for the PAC controller via\ndeployment environment variables. This allows the Tekton Operator\nto propagate TLS configuration (min version, cipher suites, curve\npreferences) to the controller without code changes.\n\n- Add pkg/tlsconfig package for parsing TLS configuration\n[…]\n_CURVE_PREFERENCES env vars to the controller deployment\n with secure defaults matching Tekton Results\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
"is_bot": false,
"headline": "feat: add TLS configuration support",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-05-28T12:49:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4dac4d6d836a59f2ec81cb3d5f0f132227b9c102",
"body": "Deprecated the Tekton Hub catalog integration across documentation,\nconfiguration settings, and resource resolution. Added deprecation\nwarnings via logger messages, Kubernetes events on Repository CRs,\nand automated comments on pull requests when resources were resolved\nfrom Tekton Hub catalogs. Thi\n[…]\nnge prepared users for the complete\nremoval of Tekton Hub support in a future release, encouraging them\nto migrate to Artifact Hub or remote URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "feat: Add deprecation warnings for Tekton Hub integration",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-05-28T12:06:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "69fa323d60c2436976059296b33993a03ecd5553",
"body": "When a version tag (e.g. v0.47.0) is pushed, the container workflow's\ntag sanitization converts dots to dashes producing v0-47-0 images.\nThe release pipeline generates release.yaml referencing v0.47.0\n(with dots), causing a mismatch where manifests point to nonexistent\nimage tags.\n\nAdd a condition for refs/tags/v* that uses the tag name as-is, since\nDocker image tags support dots.\n\nCloses #2741",
"is_bot": false,
"headline": "fix(release): preserve dots in image tags for version tag pushes",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-05-27T08:37:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32820cbb4c98d6b66e40e5445c20e5f85459e678",
"body": "Enable Gitea/Forgejo provider to resolve remote taskRef URLs using\nthe provider's authenticated API instead of returning \"not\nsupported\". Supports branch, tag, and commit SHA URL formats.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(gitea): implement GetTaskURI for remote task resolution",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-05-27T08:28:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "529a725ac61ca5c4e0a0e35408e36c16fe238e33",
"body": "When a merge request originates from a fork the bot cannot access,\npost an informative comment on the MR explaining the issue. Uses\nCreateComment with an update marker to prevent duplicate comments\non reconciler retries.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "fix(gitlab): post MR comment on inaccessible fork",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-05-25T10:11:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c7b0e06e41e7d3834292bd66e13dee95f195c9d",
"body": "The watcher observes PipelineRun status but does not own it.\nDisable generated status synchronization so informer cache\ntransforms cannot trigger UpdateStatus calls against the\nPipelineRun /status subresource.\n\nThis avoids forbidden errors on clusters where the watcher\nonly has metadata and spec-level PipelineRun permissions.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "fix(reconciler): skip watcher status updates",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-05-20T11:46:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b9a6f1842eb647014055bb183f76fb724f0b3d6",
"body": "The gomodguard_v2 linter was introduced in v2.12.0 but the CI\nimage was still on v2.10.1, causing lint failures with unknown\nlinter error.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
"is_bot": false,
"headline": "ci: update golangci-lint to v2.12.2",
"author_name": "Akshay Pant",
"author_login": "theakshaypant",
"committed_at": "2026-05-20T10:09:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9db1feca2d2b030a3f08ffac7f1710928f5d11f8",
"body": "Updated gomodguard to gomodguard_v2 for the latest linter\nversion. Also disabled the inline check in govet to reduce\nfalse positives during code analysis.\n\nError was:\n\nlevel=warning msg=\"The linter 'gomodguard' is deprecated (since v2.12.0)\ndue to: new major version. Replaced by gomodguard_v2.\" leve\n[…]\nta) ^\ntest/pkg/configmap/configmap.go:22:11: inline: cannot inline: type\nparameter inference is not yet supported (govet) maps.Copy(newData,\ndata)\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
"is_bot": false,
"headline": "chore: update golangci linter configuration",
"author_name": "Chmouel Boudjnah",
"author_login": "chmouel",
"committed_at": "2026-05-20T03:18:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "445941b2cc745ff67afc9fcc9549a3b66a011b74",
"body": "Previously, CEL expressions in Pipelines-as-Code only had access to\nthe core CEL operators, which limited users to basic comparisons and\nlogical expressions. Functions like join(), replace(), substring(),\nand other string/list manipulation operations were unavailable,\nforcing users to work around th\n[…]\nparison, since the output is a single\ndynamic file path that varies per test run.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(cel): enable string and list extension functions in CEL expressions",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-05-19T15:07:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f841d2d728d228f4008fa0cb336793e5a182cd74",
"body": "When a pull request is merged in Bitbucket Data Center, the resulting\npush event contains a merge commit that reports no file changes. This\ncaused on-path-change and on-cel-expression filters to silently skip\nPipelineRuns because the changed files list was always empty.\n\nThe fix detects merge commit\n[…]\n for on-path-change annotation surviving a PR merge push\n- Add unit tests for getMergeCommitChanges and merge commit GetFiles path\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(bitbucket-datacenter): detect changes on merged PR push",
"author_name": "Zaki Shaikh",
"author_login": "zakisk",
"committed_at": "2026-05-19T10:57:42Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 100,
"commits_last_year": 575,
"latest_release_at": "2026-07-17T13:48:26Z",
"latest_release_tag": "v0.48.1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 51,
"days_since_latest_release": 4,
"mean_days_between_releases": 5.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/openshift-pipelines/pipelines-as-code",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": false,
"registry_url": "https://pkg.go.dev/github.com/openshift-pipelines/pipelines-as-code",
"is_deprecated": false,
"latest_version": "v0.49.0",
"repository_url": "https://github.com/openshift-pipelines/pipelines-as-code",
"versions_count": 113,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-06T12:02:19Z",
"latest_version_yanked": null,
"days_since_latest_publish": 15
}
]
},
"popularity": {
"forks": 135,
"stars": 203,
"watchers": 9,
"fork_history": {
"days": [
{
"date": "2021-04-06",
"count": 1
},
{
"date": "2021-04-22",
"count": 1
},
{
"date": "2021-05-20",
"count": 1
},
{
"date": "2021-07-01",
"count": 1
},
{
"date": "2021-08-12",
"count": 1
},
{
"date": "2021-08-16",
"count": 1
},
{
"date": "2021-08-29",
"count": 1
},
{
"date": "2021-09-14",
"count": 1
},
{
"date": "2021-10-14",
"count": 1
},
{
"date": "2021-11-11",
"count": 1
},
{
"date": "2021-11-15",
"count": 1
},
{
"date": "2021-11-17",
"count": 1
},
{
"date": "2021-11-19",
"count": 1
},
{
"date": "2021-11-24",
"count": 1
},
{
"date": "2021-11-29",
"count": 1
},
{
"date": "2021-12-20",
"count": 1
},
{
"date": "2022-01-21",
"count": 1
},
{
"date": "2022-01-26",
"count": 1
},
{
"date": "2022-02-07",
"count": 1
},
{
"date": "2022-02-15",
"count": 1
},
{
"date": "2022-03-11",
"count": 1
},
{
"date": "2022-03-24",
"count": 1
},
{
"date": "2022-03-25",
"count": 1
},
{
"date": "2022-04-04",
"count": 2
},
{
"date": "2022-04-07",
"count": 1
},
{
"date": "2022-04-18",
"count": 1
},
{
"date": "2022-06-08",
"count": 1
},
{
"date": "2022-06-09",
"count": 2
},
{
"date": "2022-07-07",
"count": 1
},
{
"date": "2022-07-16",
"count": 1
},
{
"date": "2022-08-17",
"count": 1
},
{
"date": "2022-08-30",
"count": 1
},
{
"date": "2022-10-05",
"count": 1
},
{
"date": "2022-10-16",
"count": 1
},
{
"date": "2022-11-01",
"count": 1
},
{
"date": "2022-11-18",
"count": 1
},
{
"date": "2023-01-06",
"count": 1
},
{
"date": "2023-01-11",
"count": 1
},
{
"date": "2023-01-13",
"count": 1
},
{
"date": "2023-01-19",
"count": 1
},
{
"date": "2023-02-14",
"count": 1
},
{
"date": "2023-03-09",
"count": 1
},
{
"date": "2023-03-25",
"count": 1
},
{
"date": "2023-03-26",
"count": 2
},
{
"date": "2023-03-29",
"count": 2
},
{
"date": "2023-04-25",
"count": 1
},
{
"date": "2023-04-26",
"count": 1
},
{
"date": "2023-05-03",
"count": 1
},
{
"date": "2023-05-17",
"count": 1
},
{
"date": "2023-06-21",
"count": 1
},
{
"date": "2023-07-12",
"count": 1
},
{
"date": "2023-09-04",
"count": 1
},
{
"date": "2023-10-15",
"count": 1
},
{
"date": "2023-10-25",
"count": 1
},
{
"date": "2023-11-06",
"count": 1
},
{
"date": "2023-11-16",
"count": 1
},
{
"date": "2023-12-07",
"count": 1
},
{
"date": "2023-12-13",
"count": 1
},
{
"date": "2024-02-04",
"count": 1
},
{
"date": "2024-03-14",
"count": 1
},
{
"date": "2024-03-22",
"count": 2
},
{
"date": "2024-04-08",
"count": 1
},
{
"date": "2024-06-04",
"count": 1
},
{
"date": "2024-06-05",
"count": 1
},
{
"date": "2024-06-20",
"count": 1
},
{
"date": "2024-06-28",
"count": 1
},
{
"date": "2024-07-02",
"count": 1
},
{
"date": "2024-07-16",
"count": 1
},
{
"date": "2024-10-15",
"count": 1
},
{
"date": "2024-11-26",
"count": 1
},
{
"date": "2024-11-28",
"count": 1
},
{
"date": "2024-11-30",
"count": 1
},
{
"date": "2024-12-03",
"count": 1
},
{
"date": "2024-12-27",
"count": 1
},
{
"date": "2025-01-03",
"count": 1
},
{
"date": "2025-01-18",
"count": 1
},
{
"date": "2025-01-22",
"count": 1
},
{
"date": "2025-01-30",
"count": 2
},
{
"date": "2025-02-06",
"count": 1
},
{
"date": "2025-02-11",
"count": 1
},
{
"date": "2025-02-23",
"count": 1
},
{
"date": "2025-02-28",
"count": 1
},
{
"date": "2025-03-14",
"count": 1
},
{
"date": "2025-03-20",
"count": 1
},
{
"date": "2025-04-15",
"count": 1
},
{
"date": "2025-05-08",
"count": 1
},
{
"date": "2025-05-28",
"count": 1
},
{
"date": "2025-06-05",
"count": 1
},
{
"date": "2025-06-13",
"count": 1
},
{
"date": "2025-06-20",
"count": 1
},
{
"date": "2025-06-30",
"count": 1
},
{
"date": "2025-07-20",
"count": 1
},
{
"date": "2025-08-04",
"count": 1
},
{
"date": "2025-08-10",
"count": 1
},
{
"date": "2025-09-30",
"count": 1
},
{
"date": "2025-10-14",
"count": 1
},
{
"date": "2025-11-21",
"count": 1
},
{
"date": "2025-12-17",
"count": 1
},
{
"date": "2026-01-17",
"count": 1
},
{
"date": "2026-01-28",
"count": 1
},
{
"date": "2026-02-17",
"count": 1
},
{
"date": "2026-02-19",
"count": 1
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-03-15",
"count": 1
},
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-24",
"count": 1
},
{
"date": "2026-03-30",
"count": 1
},
{
"date": "2026-04-08",
"count": 1
},
{
"date": "2026-04-16",
"count": 1
},
{
"date": "2026-04-20",
"count": 1
},
{
"date": "2026-05-13",
"count": 2
},
{
"date": "2026-05-15",
"count": 1
},
{
"date": "2026-05-28",
"count": 1
},
{
"date": "2026-06-01",
"count": 1
},
{
"date": "2026-06-04",
"count": 1
},
{
"date": "2026-06-08",
"count": 1
},
{
"date": "2026-06-09",
"count": 1
},
{
"date": "2026-06-18",
"count": 1
},
{
"date": "2026-06-20",
"count": 1
},
{
"date": "2026-06-21",
"count": 1
},
{
"date": "2026-07-21",
"count": 1
}
],
"complete": true,
"collected": 129,
"total_forks": 135
},
"star_history": {
"days": [
{
"date": "2021-05-27",
"count": 2
},
{
"date": "2021-06-07",
"count": 1
},
{
"date": "2021-06-25",
"count": 1
},
{
"date": "2021-06-29",
"count": 1
},
{
"date": "2021-07-03",
"count": 1
},
{
"date": "2021-07-04",
"count": 1
},
{
"date": "2021-07-05",
"count": 1
},
{
"date": "2021-07-06",
"count": 2
},
{
"date": "2021-09-01",
"count": 1
},
{
"date": "2021-09-08",
"count": 1
},
{
"date": "2021-09-19",
"count": 1
},
{
"date": "2021-09-21",
"count": 1
},
{
"date": "2021-10-13",
"count": 1
},
{
"date": "2021-10-26",
"count": 1
},
{
"date": "2021-11-17",
"count": 2
},
{
"date": "2021-11-23",
"count": 1
},
{
"date": "2021-11-24",
"count": 1
},
{
"date": "2021-12-09",
"count": 1
},
{
"date": "2021-12-10",
"count": 2
},
{
"date": "2021-12-15",
"count": 1
},
{
"date": "2021-12-20",
"count": 1
},
{
"date": "2022-01-08",
"count": 1
},
{
"date": "2022-01-11",
"count": 1
},
{
"date": "2022-02-08",
"count": 1
},
{
"date": "2022-03-01",
"count": 1
},
{
"date": "2022-03-04",
"count": 1
},
{
"date": "2022-03-08",
"count": 1
},
{
"date": "2022-03-16",
"count": 1
},
{
"date": "2022-03-17",
"count": 1
},
{
"date": "2022-04-01",
"count": 1
},
{
"date": "2022-04-08",
"count": 1
},
{
"date": "2022-04-11",
"count": 1
},
{
"date": "2022-04-12",
"count": 1
},
{
"date": "2022-04-19",
"count": 1
},
{
"date": "2022-04-27",
"count": 1
},
{
"date": "2022-04-29",
"count": 1
},
{
"date": "2022-05-13",
"count": 1
},
{
"date": "2022-05-14",
"count": 1
},
{
"date": "2022-05-17",
"count": 1
},
{
"date": "2022-05-25",
"count": 1
},
{
"date": "2022-06-10",
"count": 1
},
{
"date": "2022-06-14",
"count": 1
},
{
"date": "2022-06-22",
"count": 1
},
{
"date": "2022-06-25",
"count": 1
},
{
"date": "2022-07-14",
"count": 1
},
{
"date": "2022-07-21",
"count": 1
},
{
"date": "2022-08-05",
"count": 1
},
{
"date": "2022-08-07",
"count": 1
},
{
"date": "2022-08-23",
"count": 1
},
{
"date": "2022-10-19",
"count": 1
},
{
"date": "2022-11-05",
"count": 1
},
{
"date": "2022-12-13",
"count": 1
},
{
"date": "2022-12-14",
"count": 1
},
{
"date": "2022-12-29",
"count": 1
},
{
"date": "2023-01-17",
"count": 1
},
{
"date": "2023-01-27",
"count": 2
},
{
"date": "2023-02-03",
"count": 1
},
{
"date": "2023-02-06",
"count": 1
},
{
"date": "2023-02-09",
"count": 1
},
{
"date": "2023-02-16",
"count": 1
},
{
"date": "2023-03-01",
"count": 1
},
{
"date": "2023-03-15",
"count": 1
},
{
"date": "2023-03-25",
"count": 2
},
{
"date": "2023-03-28",
"count": 1
},
{
"date": "2023-04-08",
"count": 1
},
{
"date": "2023-04-11",
"count": 1
},
{
"date": "2023-04-12",
"count": 1
},
{
"date": "2023-04-15",
"count": 1
},
{
"date": "2023-04-21",
"count": 1
},
{
"date": "2023-04-24",
"count": 1
},
{
"date": "2023-04-25",
"count": 1
},
{
"date": "2023-04-30",
"count": 1
},
{
"date": "2023-05-02",
"count": 1
},
{
"date": "2023-05-25",
"count": 1
},
{
"date": "2023-05-31",
"count": 1
},
{
"date": "2023-06-01",
"count": 1
},
{
"date": "2023-06-08",
"count": 1
},
{
"date": "2023-06-20",
"count": 1
},
{
"date": "2023-06-21",
"count": 1
},
{
"date": "2023-07-04",
"count": 1
},
{
"date": "2023-07-08",
"count": 1
},
{
"date": "2023-07-13",
"count": 1
},
{
"date": "2023-07-24",
"count": 1
},
{
"date": "2023-08-28",
"count": 1
},
{
"date": "2023-09-04",
"count": 1
},
{
"date": "2023-09-08",
"count": 1
},
{
"date": "2023-09-20",
"count": 1
},
{
"date": "2023-09-25",
"count": 2
},
{
"date": "2023-10-03",
"count": 1
},
{
"date": "2023-10-30",
"count": 1
},
{
"date": "2023-11-10",
"count": 1
},
{
"date": "2023-12-08",
"count": 1
},
{
"date": "2023-12-19",
"count": 1
},
{
"date": "2023-12-21",
"count": 1
},
{
"date": "2023-12-28",
"count": 1
},
{
"date": "2024-01-02",
"count": 1
},
{
"date": "2024-01-19",
"count": 1
},
{
"date": "2024-02-07",
"count": 2
},
{
"date": "2024-02-20",
"count": 1
},
{
"date": "2024-02-26",
"count": 1
},
{
"date": "2024-02-28",
"count": 1
},
{
"date": "2024-03-11",
"count": 1
},
{
"date": "2024-03-27",
"count": 1
},
{
"date": "2024-04-02",
"count": 1
},
{
"date": "2024-04-09",
"count": 2
},
{
"date": "2024-04-25",
"count": 1
},
{
"date": "2024-05-06",
"count": 1
},
{
"date": "2024-05-08",
"count": 1
},
{
"date": "2024-06-05",
"count": 1
},
{
"date": "2024-06-18",
"count": 1
},
{
"date": "2024-06-19",
"count": 1
},
{
"date": "2024-06-20",
"count": 1
},
{
"date": "2024-07-16",
"count": 1
},
{
"date": "2024-07-21",
"count": 1
},
{
"date": "2024-08-02",
"count": 1
},
{
"date": "2024-08-08",
"count": 1
},
{
"date": "2024-08-13",
"count": 1
},
{
"date": "2024-09-27",
"count": 1
},
{
"date": "2024-10-16",
"count": 1
},
{
"date": "2024-10-20",
"count": 1
},
{
"date": "2024-10-27",
"count": 1
},
{
"date": "2024-10-28",
"count": 1
},
{
"date": "2024-11-10",
"count": 1
},
{
"date": "2024-11-15",
"count": 1
},
{
"date": "2024-11-30",
"count": 1
},
{
"date": "2024-12-25",
"count": 1
},
{
"date": "2025-01-09",
"count": 2
},
{
"date": "2025-02-07",
"count": 1
},
{
"date": "2025-02-12",
"count": 4
},
{
"date": "2025-02-13",
"count": 2
},
{
"date": "2025-02-24",
"count": 1
},
{
"date": "2025-02-26",
"count": 1
},
{
"date": "2025-03-19",
"count": 1
},
{
"date": "2025-03-21",
"count": 1
},
{
"date": "2025-04-23",
"count": 1
},
{
"date": "2025-05-21",
"count": 2
},
{
"date": "2025-05-27",
"count": 1
},
{
"date": "2025-05-30",
"count": 1
},
{
"date": "2025-06-07",
"count": 1
},
{
"date": "2025-06-11",
"count": 4
},
{
"date": "2025-07-01",
"count": 2
},
{
"date": "2025-07-06",
"count": 1
},
{
"date": "2025-08-30",
"count": 1
},
{
"date": "2025-10-10",
"count": 1
},
{
"date": "2025-10-11",
"count": 1
},
{
"date": "2025-10-22",
"count": 1
},
{
"date": "2025-11-07",
"count": 1
},
{
"date": "2025-11-19",
"count": 1
},
{
"date": "2025-11-26",
"count": 1
},
{
"date": "2026-01-08",
"count": 1
},
{
"date": "2026-01-30",
"count": 1
},
{
"date": "2026-02-03",
"count": 1
},
{
"date": "2026-02-06",
"count": 1
},
{
"date": "2026-02-08",
"count": 1
},
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-10",
"count": 1
},
{
"date": "2026-03-16",
"count": 1
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-23",
"count": 1
},
{
"date": "2026-03-28",
"count": 1
},
{
"date": "2026-04-01",
"count": 1
},
{
"date": "2026-04-04",
"count": 2
},
{
"date": "2026-04-08",
"count": 1
},
{
"date": "2026-04-09",
"count": 1
},
{
"date": "2026-04-14",
"count": 1
},
{
"date": "2026-04-19",
"count": 1
},
{
"date": "2026-04-23",
"count": 1
},
{
"date": "2026-04-26",
"count": 1
},
{
"date": "2026-05-02",
"count": 1
},
{
"date": "2026-05-04",
"count": 2
},
{
"date": "2026-05-16",
"count": 1
},
{
"date": "2026-05-30",
"count": 1
},
{
"date": "2026-06-03",
"count": 1
},
{
"date": "2026-06-04",
"count": 1
},
{
"date": "2026-06-05",
"count": 1
},
{
"date": "2026-06-07",
"count": 1
},
{
"date": "2026-06-16",
"count": 1
},
{
"date": "2026-06-22",
"count": 1
},
{
"date": "2026-06-23",
"count": 1
},
{
"date": "2026-07-03",
"count": 2
},
{
"date": "2026-07-07",
"count": 1
}
],
"complete": true,
"collected": 203,
"total_stars": 203
},
"open_issues_and_prs": 80
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"samples"
],
"has_llms_txt": true,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
"vendor/github.com/emicklei/go-restful/v3/Makefile",
"vendor/github.com/felixge/httpsnoop/Makefile",
"vendor/github.com/hashicorp/go-retryablehttp/Makefile",
"vendor/github.com/juju/ansiterm/Makefile",
"vendor/github.com/ktrysmt/go-bitbucket/Makefile",
"vendor/github.com/munnerz/goautoneg/Makefile",
"vendor/github.com/pkg/errors/Makefile",
"vendor/github.com/prometheus/procfs/Makefile",
"vendor/github.com/spf13/cobra/Makefile",
"vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
"vendor/go.opentelemetry.io/otel/Makefile",
"vendor/go.uber.org/atomic/Makefile",
"vendor/go.uber.org/multierr/Makefile",
"vendor/go.uber.org/zap/Makefile",
"vendor/google.golang.org/grpc/Makefile",
"vendor/sigs.k8s.io/json/Makefile"
],
"api_schema_files": [
"vendor/github.com/google/gnostic-models/extensions/extension.proto",
"vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
"vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
"vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
"vendor/k8s.io/api/admission/v1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
"vendor/k8s.io/api/apidiscovery/v2/generated.proto",
"vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
"vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
"vendor/k8s.io/api/apps/v1/generated.proto",
"vendor/k8s.io/api/apps/v1beta1/generated.proto",
"vendor/k8s.io/api/apps/v1beta2/generated.proto",
"vendor/k8s.io/api/authentication/v1/generated.proto",
"vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
"vendor/k8s.io/api/authentication/v1beta1/generated.proto",
"vendor/k8s.io/api/authorization/v1/generated.proto",
"vendor/k8s.io/api/authorization/v1beta1/generated.proto",
"vendor/k8s.io/api/autoscaling/v1/generated.proto",
"vendor/k8s.io/api/autoscaling/v2/generated.proto",
"vendor/k8s.io/api/batch/v1/generated.proto",
"vendor/k8s.io/api/batch/v1beta1/generated.proto",
"vendor/k8s.io/api/certificates/v1/generated.proto",
"vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
"vendor/k8s.io/api/certificates/v1beta1/generated.proto",
"vendor/k8s.io/api/coordination/v1/generated.proto",
"vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
"vendor/k8s.io/api/coordination/v1beta1/generated.proto",
"vendor/k8s.io/api/core/v1/generated.proto",
"vendor/k8s.io/api/discovery/v1/generated.proto",
"vendor/k8s.io/api/discovery/v1beta1/generated.proto",
"vendor/k8s.io/api/events/v1/generated.proto",
"vendor/k8s.io/api/events/v1beta1/generated.proto",
"vendor/k8s.io/api/extensions/v1beta1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
"vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
"vendor/k8s.io/api/networking/v1/generated.proto",
"vendor/k8s.io/api/networking/v1beta1/generated.proto",
"vendor/k8s.io/api/node/v1/generated.proto",
"vendor/k8s.io/api/node/v1alpha1/generated.proto",
"vendor/k8s.io/api/node/v1beta1/generated.proto",
"vendor/k8s.io/api/policy/v1/generated.proto",
"vendor/k8s.io/api/policy/v1beta1/generated.proto",
"vendor/k8s.io/api/rbac/v1/generated.proto",
"vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
"vendor/k8s.io/api/rbac/v1beta1/generated.proto",
"vendor/k8s.io/api/resource/v1/generated.proto",
"vendor/k8s.io/api/resource/v1alpha3/generated.proto",
"vendor/k8s.io/api/resource/v1beta1/generated.proto",
"vendor/k8s.io/api/resource/v1beta2/generated.proto",
"vendor/k8s.io/api/scheduling/v1/generated.proto",
"vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
"vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
"vendor/k8s.io/api/storage/v1/generated.proto",
"vendor/k8s.io/api/storage/v1alpha1/generated.proto",
"vendor/k8s.io/api/storage/v1beta1/generated.proto",
"vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
"vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
"vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
"vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
"vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"docs/go.mod",
"go.mod"
],
"largest_source_bytes": 92818,
"source_files_sampled": 518,
"oversized_source_files": 3,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
"vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
"vendor/go.opentelemetry.io/otel/AGENTS.md",
"vendor/go.opentelemetry.io/otel/CLAUDE.md"
],
"agent_instruction_max_bytes": 12245
},
"dependencies": {
"manifests": [
"docs/go.mod",
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "google.golang.org/grpc",
"direct": false,
"version": "v1.81.1",
"severity": "critical",
"ecosystem": "go",
"cvss_score": 9.1,
"advisory_ids": [
"GHSA-hrxh-6v49-42gf"
],
"fixed_version": "1.82.1",
"advisory_count": 1,
"oldest_advisory_days": 0
},
{
"name": "github.com/tektoncd/pipeline",
"direct": true,
"version": "v1.14.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2023-1901",
"GO-2026-4730"
],
"fixed_version": null,
"advisory_count": 2,
"oldest_advisory_days": 700
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 14
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 2,
"critical": 1
},
"advisory_count": 4,
"affected_count": 3,
"assessed_count": 156,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 7,
"direct_affected_count": 1
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.0"
},
{
"name": "github.com/AlecAivazis/survey/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.3.7"
},
{
"name": "github.com/bradleyfalzon/ghinstallation/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.18.0"
},
{
"name": "github.com/chzyer/readline",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.1"
},
{
"name": "github.com/cloudevents/sdk-go/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.16.2"
},
{
"name": "github.com/fvbommel/sortorder",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/gobwas/glob",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.3"
},
{
"name": "github.com/google/cel-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.29.2"
},
{
"name": "github.com/google/go-cmp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/google/go-github/scrape",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260403152401-96a365122246"
},
{
"name": "github.com/google/go-github/v84",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v84.0.0"
},
{
"name": "github.com/google/go-github/v85",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v85.0.0"
},
{
"name": "github.com/hako/durafmt",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210608085754-5c1018a4e16b"
},
{
"name": "github.com/jenkins-x/go-scm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.15.31"
},
{
"name": "github.com/jonboulle/clockwork",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.0"
},
{
"name": "github.com/juju/ansiterm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/ktrysmt/go-bitbucket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.10.0"
},
{
"name": "github.com/mattn/go-colorable",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.15"
},
{
"name": "github.com/mattn/go-isatty",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.23"
},
{
"name": "github.com/mgutz/ansi",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20200706080929-d51e80ef957d"
},
{
"name": "github.com/mitchellh/mapstructure",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.0"
},
{
"name": "github.com/pkg/errors",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.1"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/tektoncd/pipeline",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.14.0"
},
{
"name": "gitlab.com/gitlab-org/api/client-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.46.0"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.uber.org/zap",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.28.0"
},
{
"name": "golang.org/x/exp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260312153236-7ab1446f8b90"
},
{
"name": "golang.org/x/oauth2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.22.0"
},
{
"name": "golang.org/x/text",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.40.0"
},
{
"name": "gopkg.in/yaml.v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
},
{
"name": "gotest.tools/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.5.2"
},
{
"name": "k8s.io/api",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/apimachinery",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/client-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/utils",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260319190234-28399d86e0b5"
},
{
"name": "knative.dev/eventing",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.49.2"
},
{
"name": "knative.dev/pkg",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260622140654-39ebae2ee2dc"
},
{
"name": "sigs.k8s.io/yaml",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/golang-jwt/jwt/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.5.2"
},
{
"name": "github.com/prometheus/client_model",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/prometheus/common",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.69.0"
},
{
"name": "golang.org/x/term",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260526163538-3dc84a4a5aaa"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
},
{
"name": "k8s.io/klog/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.140.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
"direct": true,
"version": "v3.0.0",
"ecosystem": "go"
},
{
"name": "github.com/alecaivazis/survey/v2",
"direct": true,
"version": "v2.3.7",
"ecosystem": "go"
},
{
"name": "github.com/bradleyfalzon/ghinstallation/v2",
"direct": true,
"version": "v2.18.0",
"ecosystem": "go"
},
{
"name": "github.com/chzyer/readline",
"direct": true,
"version": "v1.5.1",
"ecosystem": "go"
},
{
"name": "github.com/cloudevents/sdk-go/v2",
"direct": true,
"version": "v2.16.2",
"ecosystem": "go"
},
{
"name": "github.com/fvbommel/sortorder",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/gobwas/glob",
"direct": true,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v4",
"direct": true,
"version": "v4.5.2",
"ecosystem": "go"
},
{
"name": "github.com/google/cel-go",
"direct": true,
"version": "v0.29.2",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": true,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-github/scrape",
"direct": true,
"version": "v0.0.0-20260403152401-96a365122246",
"ecosystem": "go"
},
{
"name": "github.com/google/go-github/v84",
"direct": true,
"version": "v84.0.0",
"ecosystem": "go"
},
{
"name": "github.com/google/go-github/v85",
"direct": true,
"version": "v85.0.0",
"ecosystem": "go"
},
{
"name": "github.com/hako/durafmt",
"direct": true,
"version": "v0.0.0-20210608085754-5c1018a4e16b",
"ecosystem": "go"
},
{
"name": "github.com/jenkins-x/go-scm",
"direct": true,
"version": "v1.15.31",
"ecosystem": "go"
},
{
"name": "github.com/jonboulle/clockwork",
"direct": true,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/juju/ansiterm",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/ktrysmt/go-bitbucket",
"direct": true,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-colorable",
"direct": true,
"version": "v0.1.15",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": true,
"version": "v0.0.23",
"ecosystem": "go"
},
{
"name": "github.com/mgutz/ansi",
"direct": true,
"version": "v0.0.0-20200706080929-d51e80ef957d",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/mapstructure",
"direct": true,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": true,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": true,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": true,
"version": "v0.69.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "github.com/tektoncd/pipeline",
"direct": true,
"version": "v1.14.0",
"ecosystem": "go"
},
{
"name": "gitlab.com/gitlab-org/api/client-go",
"direct": true,
"version": "v1.46.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": true,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/zap",
"direct": true,
"version": "v1.28.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": true,
"version": "v0.0.0-20260312153236-7ab1446f8b90",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": true,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": true,
"version": "v0.22.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": true,
"version": "v0.0.0-20260526163538-3dc84a4a5aaa",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": true,
"version": "v1.36.12-0.20260120151049-f2248ac996af",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v2",
"direct": true,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "gotest.tools/v3",
"direct": true,
"version": "v3.5.2",
"ecosystem": "go"
},
{
"name": "k8s.io/api",
"direct": true,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/apimachinery",
"direct": true,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/client-go",
"direct": true,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/klog/v2",
"direct": true,
"version": "v2.140.0",
"ecosystem": "go"
},
{
"name": "k8s.io/utils",
"direct": true,
"version": "v0.0.0-20260319190234-28399d86e0b5",
"ecosystem": "go"
},
{
"name": "knative.dev/eventing",
"direct": true,
"version": "v0.49.2",
"ecosystem": "go"
},
{
"name": "knative.dev/pkg",
"direct": true,
"version": "v0.0.0-20260622140654-39ebae2ee2dc",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/yaml",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "cel.dev/expr",
"direct": false,
"version": "v0.25.1",
"ecosystem": "go"
},
{
"name": "github.com/42wim/httpsig",
"direct": false,
"version": "v1.2.4",
"ecosystem": "go"
},
{
"name": "github.com/andybalholm/cascadia",
"direct": false,
"version": "v1.3.3",
"ecosystem": "go"
},
{
"name": "github.com/antlr/antlr4/runtime/go/antlr",
"direct": false,
"version": "v1.4.10",
"ecosystem": "go"
},
{
"name": "github.com/antlr4-go/antlr/v4",
"direct": false,
"version": "v4.13.1",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/blang/semver/v4",
"direct": false,
"version": "v4.0.0",
"ecosystem": "go"
},
{
"name": "github.com/blendle/zapdriver",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/cenkalti/backoff/v5",
"direct": false,
"version": "v5.0.3",
"ecosystem": "go"
},
{
"name": "github.com/cert-manager/cert-manager",
"direct": false,
"version": "v1.20.1",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/cloudevents/sdk-go/observability/opentelemetry/v2",
"direct": false,
"version": "v2.16.2",
"ecosystem": "go"
},
{
"name": "github.com/cloudevents/sdk-go/sql/v2",
"direct": false,
"version": "v2.16.2",
"ecosystem": "go"
},
{
"name": "github.com/coreos/go-oidc/v3",
"direct": false,
"version": "v3.18.0",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.2-0.20180830191138-d8f796af33cc",
"ecosystem": "go"
},
{
"name": "github.com/davidmz/go-pageant",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/emicklei/go-restful/v3",
"direct": false,
"version": "v3.13.0",
"ecosystem": "go"
},
{
"name": "github.com/evanphx/json-patch/v5",
"direct": false,
"version": "v5.9.11",
"ecosystem": "go"
},
{
"name": "github.com/felixge/httpsnoop",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/fxamacker/cbor/v2",
"direct": false,
"version": "v2.9.1",
"ecosystem": "go"
},
{
"name": "github.com/go-fed/httpsig",
"direct": false,
"version": "v1.1.1-0.20201223112313-55836744818e",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v3",
"direct": false,
"version": "v3.0.5",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v4",
"direct": false,
"version": "v4.1.4",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/zapr",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/errors",
"direct": false,
"version": "v0.22.7",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/jsonpointer",
"direct": false,
"version": "v0.22.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/jsonreference",
"direct": false,
"version": "v0.21.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/strfmt",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/cmdutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/conv",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/fileutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/jsonname",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/jsonutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/loading",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/mangling",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/netutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/stringutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/typeutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-openapi/swag/yamlutils",
"direct": false,
"version": "v0.25.5",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/google/gnostic-models",
"direct": false,
"version": "v0.7.1",
"ecosystem": "go"
},
{
"name": "github.com/google/go-querystring",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/grpc-ecosystem/grpc-gateway/v2",
"direct": false,
"version": "v2.29.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-cleanhttp",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-retryablehttp",
"direct": false,
"version": "v0.7.8",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-version",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/imfing/hextra",
"direct": false,
"version": "v0.12.0",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/json-iterator/go",
"direct": false,
"version": "v1.1.12",
"ecosystem": "go"
},
{
"name": "github.com/kballard/go-shellquote",
"direct": false,
"version": "v0.0.0-20180428030007-95032a82bc51",
"ecosystem": "go"
},
{
"name": "github.com/kelseyhightower/envconfig",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/lunixbochs/vtclean",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/concurrent",
"direct": false,
"version": "v0.0.0-20180306012644-bacd9c7ef1dd",
"ecosystem": "go"
},
{
"name": "github.com/modern-go/reflect2",
"direct": false,
"version": "v1.0.3-0.20250322232337-35a7c28c31ee",
"ecosystem": "go"
},
{
"name": "github.com/munnerz/goautoneg",
"direct": false,
"version": "v0.0.0-20191010083416-a7dc8b61c822",
"ecosystem": "go"
},
{
"name": "github.com/oklog/ulid/v2",
"direct": false,
"version": "v2.1.1",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.23.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/otlptranslator",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.20.1",
"ecosystem": "go"
},
{
"name": "github.com/puerkitobio/goquery",
"direct": false,
"version": "v1.12.0",
"ecosystem": "go"
},
{
"name": "github.com/rickb777/date",
"direct": false,
"version": "v1.22.0",
"ecosystem": "go"
},
{
"name": "github.com/rickb777/plural",
"direct": false,
"version": "v1.4.10",
"ecosystem": "go"
},
{
"name": "github.com/robfig/cron/v3",
"direct": false,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": false,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/x448/float16",
"direct": false,
"version": "v0.8.4",
"ecosystem": "go"
},
{
"name": "github.com/xlzd/gotp",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.69.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/runtime",
"direct": false,
"version": "v0.69.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/prometheus",
"direct": false,
"version": "v0.66.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
"direct": false,
"version": "v1.44.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/proto/otlp",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/atomic",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/automaxprocs",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/multierr",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v2",
"direct": false,
"version": "v2.4.4",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.56.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": false,
"version": "v0.15.0",
"ecosystem": "go"
},
{
"name": "gomodules.xyz/jsonpatch/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260526163538-3dc84a4a5aaa",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": false,
"version": "v1.81.1",
"ecosystem": "go"
},
{
"name": "gopkg.in/evanphx/json-patch.v4",
"direct": false,
"version": "v4.13.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/inf.v0",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": false,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "k8s.io/apiextensions-apiserver",
"direct": false,
"version": "v0.36.2",
"ecosystem": "go"
},
{
"name": "k8s.io/kube-openapi",
"direct": false,
"version": "v0.0.0-20260330154417-16be699c7b31",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/gateway-api",
"direct": false,
"version": "v1.5.1",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/json",
"direct": false,
"version": "v0.0.0-20250730193827-2d320260d730",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/randfill",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/structured-merge-diff/v6",
"direct": false,
"version": "v6.3.2",
"ecosystem": "go"
},
{
"name": "@axe-core/playwright",
"direct": false,
"version": "^4.10.1",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "^1.49.1",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/postcss",
"direct": false,
"version": "^4.1.18",
"ecosystem": "npm"
},
{
"name": "postcss-cli",
"direct": false,
"version": "^11.0.1",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "^3.8.0",
"ecosystem": "npm"
},
{
"name": "prettier-plugin-go-template",
"direct": false,
"version": "^0.0.15",
"ecosystem": "npm"
},
{
"name": "tailwindcss",
"direct": false,
"version": "^4.1.18",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 163,
"direct_count": 54,
"indirect_count": 109
}
},
"maintainership": {
"issues": {
"open_prs": 10,
"merged_prs": 2014,
"open_issues": 70,
"closed_ratio": 0.88,
"closed_issues": 515,
"closed_unmerged_prs": 252
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "chmouel",
"commits": 2290,
"avatar_url": "https://avatars.githubusercontent.com/u/98980?v=4"
},
{
"type": "User",
"login": "zakisk",
"commits": 223,
"avatar_url": "https://avatars.githubusercontent.com/u/49492007?v=4"
},
{
"type": "User",
"login": "savitaashture",
"commits": 107,
"avatar_url": "https://avatars.githubusercontent.com/u/9441662?v=4"
},
{
"type": "User",
"login": "theakshaypant",
"commits": 84,
"avatar_url": "https://avatars.githubusercontent.com/u/16561942?v=4"
},
{
"type": "User",
"login": "piyush-garg",
"commits": 31,
"avatar_url": "https://avatars.githubusercontent.com/u/19270240?v=4"
},
{
"type": "User",
"login": "aThorp96",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/28596783?v=4"
},
{
"type": "User",
"login": "sm43",
"commits": 21,
"avatar_url": "https://avatars.githubusercontent.com/u/55777192?v=4"
},
{
"type": "User",
"login": "PuneetPunamiya",
"commits": 15,
"avatar_url": "https://avatars.githubusercontent.com/u/32545638?v=4"
},
{
"type": "User",
"login": "vdemeester",
"commits": 15,
"avatar_url": "https://avatars.githubusercontent.com/u/6508?v=4"
},
{
"type": "User",
"login": "infernus01",
"commits": 13,
"avatar_url": "https://avatars.githubusercontent.com/u/89133323?v=4"
}
],
"contributors_sampled": 59,
"top_contributor_share": 0.776
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codecov.yaml",
"container.yaml",
"e2e.yaml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yaml",
".golangci.yml",
".pylintrc"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 7,
"reason": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 8,
"reason": "Found 17/20 approved changesets -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 33 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 0,
"reason": "dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 7,
"reason": "dependency not pinned by hash detected -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 8,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 6,
"reason": "4 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
"ran_at": "2026-07-22T02:12:12Z",
"aggregate_score": 5.7,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T13:36:38Z",
"oldest_open_prs": [
{
"number": 2655,
"created_at": "2026-04-08T09:02:29Z",
"last_comment_at": "2026-07-16T11:44:33Z",
"last_comment_author": "chmouel"
},
{
"number": 2848,
"created_at": "2026-07-10T19:24:17Z",
"last_comment_at": "2026-07-21T07:29:37Z",
"last_comment_author": "chmouel"
},
{
"number": 2854,
"created_at": "2026-07-15T12:23:38Z",
"last_comment_at": "2026-07-15T18:09:09Z",
"last_comment_author": "chmouel"
},
{
"number": 2856,
"created_at": "2026-07-16T08:41:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2859,
"created_at": "2026-07-16T11:10:41Z",
"last_comment_at": "2026-07-21T06:28:58Z",
"last_comment_author": "chmouel"
},
{
"number": 2867,
"created_at": "2026-07-21T11:07:16Z",
"last_comment_at": "2026-07-21T11:07:40Z",
"last_comment_author": "pipelines-as-code"
},
{
"number": 2868,
"created_at": "2026-07-21T11:09:17Z",
"last_comment_at": "2026-07-21T11:47:47Z",
"last_comment_author": "chmouel"
},
{
"number": 2869,
"created_at": "2026-07-21T12:56:50Z",
"last_comment_at": "2026-07-21T13:02:50Z",
"last_comment_author": "chmouel"
},
{
"number": 2870,
"created_at": "2026-07-21T13:02:08Z",
"last_comment_at": "2026-07-21T13:14:09Z",
"last_comment_author": "codecov"
},
{
"number": 2871,
"created_at": "2026-07-21T13:30:25Z",
"last_comment_at": "2026-07-21T13:33:08Z",
"last_comment_author": "codecov"
}
],
"last_merged_pr_at": "2026-07-21T10:21:44Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 508,
"created_at": "2022-04-01T13:59:38Z",
"last_comment_at": "2026-02-26T11:40:23Z",
"last_comment_author": "chmouel"
},
{
"number": 724,
"created_at": "2022-06-09T08:42:43Z",
"last_comment_at": "2025-10-15T09:37:31Z",
"last_comment_author": "chmouel"
},
{
"number": 732,
"created_at": "2022-06-20T06:56:49Z",
"last_comment_at": "2026-02-26T11:40:05Z",
"last_comment_author": "chmouel"
},
{
"number": 780,
"created_at": "2022-08-01T15:57:45Z",
"last_comment_at": "2026-02-26T11:39:49Z",
"last_comment_author": "chmouel"
},
{
"number": 790,
"created_at": "2022-08-09T12:42:02Z",
"last_comment_at": "2026-02-26T11:40:07Z",
"last_comment_author": "chmouel"
},
{
"number": 828,
"created_at": "2022-09-09T12:32:05Z",
"last_comment_at": "2026-02-26T11:40:31Z",
"last_comment_author": "chmouel"
},
{
"number": 924,
"created_at": "2022-10-17T13:23:32Z",
"last_comment_at": "2026-02-26T11:40:19Z",
"last_comment_author": "chmouel"
},
{
"number": 933,
"created_at": "2022-10-20T10:25:52Z",
"last_comment_at": "2026-02-26T11:40:43Z",
"last_comment_author": "chmouel"
},
{
"number": 934,
"created_at": "2022-10-20T10:29:41Z",
"last_comment_at": "2026-02-26T11:40:18Z",
"last_comment_author": "chmouel"
},
{
"number": 998,
"created_at": "2022-11-21T07:04:20Z",
"last_comment_at": "2026-02-26T11:40:36Z",
"last_comment_author": "chmouel"
},
{
"number": 1049,
"created_at": "2022-12-05T12:02:37Z",
"last_comment_at": "2026-02-26T15:23:46Z",
"last_comment_author": "chmouel"
},
{
"number": 1070,
"created_at": "2022-12-12T15:15:51Z",
"last_comment_at": "2026-02-26T11:51:25Z",
"last_comment_author": "chmouel"
},
{
"number": 1098,
"created_at": "2023-01-05T11:28:07Z",
"last_comment_at": "2026-02-26T11:40:08Z",
"last_comment_author": "chmouel"
},
{
"number": 1112,
"created_at": "2023-01-19T11:18:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1152,
"created_at": "2023-02-14T11:04:32Z",
"last_comment_at": "2026-02-26T11:51:20Z",
"last_comment_author": "chmouel"
},
{
"number": 1227,
"created_at": "2023-04-12T07:07:13Z",
"last_comment_at": "2026-02-26T11:41:47Z",
"last_comment_author": "chmouel"
},
{
"number": 1235,
"created_at": "2023-04-13T14:52:59Z",
"last_comment_at": "2026-02-26T13:50:34Z",
"last_comment_author": "tekton-pac-bot"
},
{
"number": 1237,
"created_at": "2023-04-17T09:46:26Z",
"last_comment_at": "2026-02-26T11:40:55Z",
"last_comment_author": "chmouel"
},
{
"number": 1246,
"created_at": "2023-04-22T12:57:18Z",
"last_comment_at": "2026-02-26T11:42:27Z",
"last_comment_author": "chmouel"
},
{
"number": 1291,
"created_at": "2023-05-18T07:12:16Z",
"last_comment_at": "2026-03-06T10:32:53Z",
"last_comment_author": "mikem-of"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/tektoncd/pipelines-as-code",
"host": "github.com",
"name": "pipelines-as-code",
"owner": "tektoncd"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"security": 62,
"vitality": 95,
"community": 75,
"governance": 65,
"engineering": 96
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 95,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"commits_last_year": 575,
"human_commit_share": 0.9,
"days_since_last_push": 0,
"active_weeks_last_year": 51
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "51/52 weeks with commits",
"points": 35.3,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 51
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "575 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 575
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 100,
"latest_release_tag": "v0.48.1",
"releases_from_tags": false,
"days_since_latest_release": 4,
"mean_days_between_releases": 5.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~5.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 5.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 75,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"forks": 135,
"stars": 203,
"watchers": 9,
"growth_state": "organic",
"growth_factor_pct": 100
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "203 stars",
"points": 37.4,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 203
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "135 forks",
"points": 17.7,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 135
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "9 watchers",
"points": 5,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 9
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 65,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 38,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 59,
"top_contributor_share": 0.776
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 78% of commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 78
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "59 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 59
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 33 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 87,
"inputs": {
"merged_prs": 2014,
"open_issues": 70,
"closed_issues": 515,
"issue_closed_ratio": 0.88,
"closed_unmerged_prs": 252
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "88% of issues closed",
"points": 41.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 88
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2014/2266 decided PRs merged",
"points": 34,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2014,
"decided": 2266
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 17/20 approved changesets -- score normalized to 8",
"points": 12,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"followers": 1421,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "tektoncd",
"public_repos": 24,
"account_age_days": 2715
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1,421 followers of tektoncd",
"points": 22.7,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1421,
"login": "tektoncd"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "24 public repos, account ~7 yr old",
"points": 22.2,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 24
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 96,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 94,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yaml, .golangci.yml, .pylintrc",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml, .pylintrc"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
"points": 14,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"tekton-pipelines",
"tekton",
"github",
"pipeline",
"kubernetes",
"continuous-delivery",
"pipelines-as-code",
"gitlab",
"ci",
"bitbucket",
"gitops"
],
"has_wiki": true,
"homepage": "https://pipelinesascode.com",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://pipelinesascode.com",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "11 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 11
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 62,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 5.7
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
"points": 1.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 17/20 approved changesets -- score normalized to 8",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 33 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "dangerous workflow patterns detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 3.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "4 existing vulnerabilities detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 156 resolved dependencies against OSV; 7 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 156
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 7
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 85,
"inputs": {
"source": "osv",
"advisories": 4,
"affected_packages": 3,
"assessed_packages": 156,
"unassessed_packages": 7,
"affected_by_severity": "critical 1, unknown 2",
"direct_affected_packages": 1
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "1 affected: github.com/tektoncd/pipeline v1.14.0 (unknown)",
"points": 26.6,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "github.com/tektoncd/pipeline v1.14.0 (unknown)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 700 days ago",
"points": 37.2,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 1,
"oldest": 700
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 156,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 17
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 96,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"has_llms_txt": true,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
"vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
"vendor/go.opentelemetry.io/otel/AGENTS.md",
"vendor/go.opentelemetry.io/otel/CLAUDE.md"
],
"agent_instruction_max_bytes": 12245
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": "llms.txt present",
"points": 15,
"status": "met",
"details": [
{
"code": "llms_txt_present",
"params": {}
}
],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "90 of 90 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 90,
"sampled": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 97,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
"vendor/github.com/emicklei/go-restful/v3/Makefile",
"vendor/github.com/felixge/httpsnoop/Makefile",
"vendor/github.com/hashicorp/go-retryablehttp/Makefile",
"vendor/github.com/juju/ansiterm/Makefile",
"vendor/github.com/ktrysmt/go-bitbucket/Makefile",
"vendor/github.com/munnerz/goautoneg/Makefile",
"vendor/github.com/pkg/errors/Makefile",
"vendor/github.com/prometheus/procfs/Makefile",
"vendor/github.com/spf13/cobra/Makefile",
"vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
"vendor/go.opentelemetry.io/otel/Makefile",
"vendor/go.uber.org/atomic/Makefile",
"vendor/go.uber.org/multierr/Makefile",
"vendor/go.uber.org/zap/Makefile",
"vendor/google.golang.org/grpc/Makefile",
"vendor/sigs.k8s.io/json/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.26,
"toolchain_manifests": [
"docs/go.mod",
"go.mod"
],
"dependency_bot_commit_share": 0.1
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yaml, .golangci.yml, .pylintrc",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml, .pylintrc"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "26 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 26,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "10 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 10,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 7,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 92818,
"source_files_sampled": 518,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/518 source files over 60KB",
"points": 54.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 518,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"samples"
],
"has_mcp_signal": false,
"api_schema_files": [
"vendor/github.com/google/gnostic-models/extensions/extension.proto",
"vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
"vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
"vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
"vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
"vendor/k8s.io/api/admission/v1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
"vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
"vendor/k8s.io/api/apidiscovery/v2/generated.proto",
"vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
"vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
"vendor/k8s.io/api/apps/v1/generated.proto",
"vendor/k8s.io/api/apps/v1beta1/generated.proto",
"vendor/k8s.io/api/apps/v1beta2/generated.proto",
"vendor/k8s.io/api/authentication/v1/generated.proto",
"vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
"vendor/k8s.io/api/authentication/v1beta1/generated.proto",
"vendor/k8s.io/api/authorization/v1/generated.proto",
"vendor/k8s.io/api/authorization/v1beta1/generated.proto",
"vendor/k8s.io/api/autoscaling/v1/generated.proto",
"vendor/k8s.io/api/autoscaling/v2/generated.proto",
"vendor/k8s.io/api/batch/v1/generated.proto",
"vendor/k8s.io/api/batch/v1beta1/generated.proto",
"vendor/k8s.io/api/certificates/v1/generated.proto",
"vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
"vendor/k8s.io/api/certificates/v1beta1/generated.proto",
"vendor/k8s.io/api/coordination/v1/generated.proto",
"vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
"vendor/k8s.io/api/coordination/v1beta1/generated.proto",
"vendor/k8s.io/api/core/v1/generated.proto",
"vendor/k8s.io/api/discovery/v1/generated.proto",
"vendor/k8s.io/api/discovery/v1beta1/generated.proto",
"vendor/k8s.io/api/events/v1/generated.proto",
"vendor/k8s.io/api/events/v1beta1/generated.proto",
"vendor/k8s.io/api/extensions/v1beta1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
"vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
"vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
"vendor/k8s.io/api/networking/v1/generated.proto",
"vendor/k8s.io/api/networking/v1beta1/generated.proto",
"vendor/k8s.io/api/node/v1/generated.proto",
"vendor/k8s.io/api/node/v1alpha1/generated.proto",
"vendor/k8s.io/api/node/v1beta1/generated.proto",
"vendor/k8s.io/api/policy/v1/generated.proto",
"vendor/k8s.io/api/policy/v1beta1/generated.proto",
"vendor/k8s.io/api/rbac/v1/generated.proto",
"vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
"vendor/k8s.io/api/rbac/v1beta1/generated.proto",
"vendor/k8s.io/api/resource/v1/generated.proto",
"vendor/k8s.io/api/resource/v1alpha3/generated.proto",
"vendor/k8s.io/api/resource/v1beta1/generated.proto",
"vendor/k8s.io/api/resource/v1beta2/generated.proto",
"vendor/k8s.io/api/scheduling/v1/generated.proto",
"vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
"vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
"vendor/k8s.io/api/storage/v1/generated.proto",
"vendor/k8s.io/api/storage/v1alpha1/generated.proto",
"vendor/k8s.io/api/storage/v1beta1/generated.proto",
"vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
"vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
"vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
"vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
"vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
"vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "samples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "samples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring"
],
"report_type": "repository",
"generated_at": "2026-07-22T02:12:45.089451Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tektoncd/pipelines-as-code.svg",
"full_name": "tektoncd/pipelines-as-code",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}