Registro público
Informe de salud del softwareesquema 0.26.0 · métricas 1.13.0 · 2026-07-22 02:12 UTC

tektoncd / pipelines-as-code

Pipelines-as-Code for Tekton

GoApache-2.0★ 203 estrellas⑂ 135 forksdesde abr 2021Ver en GitHub ↗

tektoncd/pipelines-as-code tiene un índice de salud de 79 sobre 100, lo que lo sitúa en la banda Bueno. Su puntuación más alta es Engineering Quality (96/100) y la más baja, Security (62/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

79
global / 100
Bueno

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

79
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

TektonOrganización
1421 seguidores24 repositorios públicosdesde feb 2019

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/openshift-pipelines/pipelines-as-codeapunta a otro repositorio; no se puntúav0.49.0-113hace 15 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

95Excelente · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
35.3/36Cadencia de commits — 51/52 semanas con commits
18/18Volumen de commits — 575 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year575
human_commit_share0,9
days_since_last_push0
active_weeks_last_year51
Cómo se puntúa
27/27Publica versiones — 100 versiones publicadas
36/36Recencia de las versiones — última versión hace 4 días
27/27Cadencia de publicación — una versión cada ~5,8 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count100
latest_release_tagv0.48.1
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases5,8

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

75Bueno · 18% del índice global
Cómo se puntúa
37.4/60Estrellas — 203 estrellas
17.7/25Forks — 135 forks
5/15Observadores — 9 observadores
Datos de entrada utilizados
forks135
stars203
watchers9
growth_stateorganic
growth_factor_pct100
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

65Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
5/22.5Distribución de commits — el principal contribuyente firma el 78% de los commits
13.5/13.5Amplitud de contribuyentes — 59 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 33 contributing companies or organizations
Datos de entrada utilizados
bus_factor1
contributors_sampled59
top_contributor_share0,776
Cómo se puntúa
41.1/46.8Resolución de issues — 88% de issues cerradas
34/38.3Aceptación de PR — 2014/2266 PR decididos fusionados
12/15OpenSSF Scorecard: Code-Review — Found 17/20 approved changesets -- score normalized to 8
Datos de entrada utilizados
merged_prs2014
open_issues70
closed_issues515
issue_closed_ratio0,88
closed_unmerged_prs252
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
22.7/25Alcance del propietario — 1421 seguidores de tektoncd
22.2/25Trayectoria — 24 repos públicos, cuenta de ~7 años
Datos de entrada utilizados
followers1421
owner_typeOrganization
is_verified
owner_logintektoncd
public_repos24
account_age_days2715

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

96Excelente · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 3 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yaml, .golangci.yml, .pylintrc
9.6/9.6Hooks de pre-commit
6.4/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
Datos de entrada utilizados
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

Documentación

100Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://pipelinesascode.com
10/10Descripción del repositorio
10/10Topics — 11 topics
10/10Wiki
Datos de entrada utilizados
topicstekton-pipelines, tekton, github, pipeline, kubernetes, continuous-delivery, pipelines-as-code, gitlab, ci, bitbucket, gitops
has_wiki
homepagehttps://pipelinesascode.com
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

62Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6/7.5Code-Review — Found 17/20 approved changesets -- score normalized to 8
2.5/2.5Contributors — project has 33 contributing companies or organizations
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
6/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,7
Excluidos de la puntuación (sin datos o no aplicable): packaging. Los pesos restantes se han renormalizado.
Cómo se puntúa
26.6/35Dependencias directas libres de avisos conocidos — 1 afectados: github.com/tektoncd/pipeline v1.14.0 (unknown)
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
37.2/40Sin avisos pendientes — 1 paquete(s) con avisos sin atender más allá de 90 días; el más antiguo publicado hace 700 días
Datos de entrada utilizados
sourceosv
advisories4
affected_packages3
assessed_packages156
unassessed_packages7
affected_by_severitycritical 1, unknown 2
direct_affected_packages1
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos. Los pesos restantes se han renormalizado. Se cotejaron 156 dependencias resueltas con OSV. 7 no pudieron evaluarse: sin versión resuelta, ecosistema no admitido o fuera de la lista de paquetes informada. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

96Excelente · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
15/15Documentación legible por máquinas (llms.txt) — llms.txt presente
40/40Historial de commits legible — 90 de 90 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
agent_instruction_max_bytes12.245
Cómo se puntúa
18/18Arranque con un solo comando — Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yaml, .golangci.yml, .pylintrc
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 26 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 10 de los últimos 100 commits son actualizaciones automáticas de dependencias
7/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0,26
toolchain_manifestsdocs/go.mod, go.mod
dependency_bot_commit_share0,1
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.7/55Tamaños de archivo manejables — 3/518 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes92.818
source_files_sampled518
oversized_source_files3
Cómo se puntúa
40/40Esquema de API (OpenAPI/GraphQL/proto) — vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto
0/20Servidor MCP
40/40Ejemplos ejecutables — samples
Datos de entrada utilizados
example_dirssamples
has_mcp_signalno
api_schema_filesvendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto

Datos clave

203estrellas de GitHub
59contribuidores
575commits en los últimos 12 meses
0días desde el último push
100versiones publicadas
1factor bus
70issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring

Más detalle

Historial de estrellas y forks 203 ★ / 135 ⇿
203Estrellas
135Forks
100Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

0408012016020024020312962021-042023-112026-07
Mayor 0Menor 34Parche 66

Cada punto abarca 5 días.

OpenSSF Scorecard 5.7 / 10
5.7agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-22 02:12 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
8Code-ReviewFound 17/20 approved changesets -- score normalized to 8
10Contributorsproject has 33 contributing companies or organizations
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
8Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Dependencias directas 54
RegistroPaqueteRestricción de versiónManifiesto
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0go.mod
Gogithub.com/AlecAivazis/survey/v2v2.3.7go.mod
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0go.mod
Gogithub.com/chzyer/readlinev1.5.1go.mod
Gogithub.com/cloudevents/sdk-go/v2v2.16.2go.mod
Gogithub.com/fvbommel/sortorderv1.1.0go.mod
Gogithub.com/gobwas/globv0.2.3go.mod
Gogithub.com/google/cel-gov0.29.2go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246go.mod
Gogithub.com/google/go-github/v84v84.0.0go.mod
Gogithub.com/google/go-github/v85v85.0.0go.mod
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16bgo.mod
Gogithub.com/jenkins-x/go-scmv1.15.31go.mod
Gogithub.com/jonboulle/clockworkv0.5.0go.mod
Gogithub.com/juju/ansitermv1.0.0go.mod
Gogithub.com/ktrysmt/go-bitbucketv0.10.0go.mod
Gogithub.com/mattn/go-colorablev0.1.15go.mod
Gogithub.com/mattn/go-isattyv0.0.23go.mod
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957dgo.mod
Gogithub.com/mitchellh/mapstructurev1.5.0go.mod
Gogithub.com/pkg/errorsv0.9.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tektoncd/pipelinev1.14.0go.mod
Gogitlab.com/gitlab-org/api/client-gov1.46.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/syncv0.22.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogopkg.in/yaml.v2v2.4.0go.mod
Gogotest.tools/v3v3.5.2go.mod
Gok8s.io/apiv0.36.2go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gok8s.io/client-gov0.36.2go.mod
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5go.mod
Goknative.dev/eventingv0.49.2go.mod
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dcgo.mod
Gosigs.k8s.io/yamlv1.6.0go.mod
Gogithub.com/golang-jwt/jwt/v4v4.5.2go.mod
Gogithub.com/prometheus/client_modelv0.6.2go.mod
Gogithub.com/prometheus/commonv0.69.0go.mod
Gogolang.org/x/termv0.45.0go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaago.mod
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afgo.mod
Gok8s.io/klog/v2v2.140.0go.mod
Todas las dependencias 163

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 54 paquetes directos y 109 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0directa
Gogithub.com/alecaivazis/survey/v2v2.3.7directa
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0directa
Gogithub.com/chzyer/readlinev1.5.1directa
Gogithub.com/cloudevents/sdk-go/v2v2.16.2directa
Gogithub.com/fvbommel/sortorderv1.1.0directa
Gogithub.com/gobwas/globv0.2.3directa
Gogithub.com/golang-jwt/jwt/v4v4.5.2directa
Gogithub.com/google/cel-gov0.29.2directa
Gogithub.com/google/go-cmpv0.7.0directa
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246directa
Gogithub.com/google/go-github/v84v84.0.0directa
Gogithub.com/google/go-github/v85v85.0.0directa
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16bdirecta
Gogithub.com/jenkins-x/go-scmv1.15.31directa
Gogithub.com/jonboulle/clockworkv0.5.0directa
Gogithub.com/juju/ansitermv1.0.0directa
Gogithub.com/ktrysmt/go-bitbucketv0.10.0directa
Gogithub.com/mattn/go-colorablev0.1.15directa
Gogithub.com/mattn/go-isattyv0.0.23directa
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957ddirecta
Gogithub.com/mitchellh/mapstructurev1.5.0directa
Gogithub.com/pkg/errorsv0.9.1directa
Gogithub.com/prometheus/client_modelv0.6.2directa
Gogithub.com/prometheus/commonv0.69.0directa
Gogithub.com/spf13/cobrav1.10.2directa
Gogithub.com/stretchr/testifyv1.11.1directa
Gogithub.com/tektoncd/pipelinev1.14.0directa
Gogitlab.com/gitlab-org/api/client-gov1.46.0directa
Gogo.opentelemetry.io/otelv1.44.0directa
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0directa
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0directa
Gogo.opentelemetry.io/otel/metricv1.44.0directa
Gogo.opentelemetry.io/otel/sdkv1.44.0directa
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0directa
Gogo.opentelemetry.io/otel/tracev1.44.0directa
Gogo.uber.org/zapv1.28.0directa
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90directa
Gogolang.org/x/oauth2v0.36.0directa
Gogolang.org/x/syncv0.22.0directa
Gogolang.org/x/termv0.45.0directa
Gogolang.org/x/textv0.40.0directa
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaadirecta
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afdirecta
Gogopkg.in/yaml.v2v2.4.0directa
Gogotest.tools/v3v3.5.2directa
Gok8s.io/apiv0.36.2directa
Gok8s.io/apimachineryv0.36.2directa
Gok8s.io/client-gov0.36.2directa
Gok8s.io/klog/v2v2.140.0directa
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5directa
Goknative.dev/eventingv0.49.2directa
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dcdirecta
Gosigs.k8s.io/yamlv1.6.0directa
Gocel.dev/exprv0.25.1indirecta
Gogithub.com/42wim/httpsigv1.2.4indirecta
Gogithub.com/andybalholm/cascadiav1.3.3indirecta
Gogithub.com/antlr/antlr4/runtime/go/antlrv1.4.10indirecta
Gogithub.com/antlr4-go/antlr/v4v4.13.1indirecta
Gogithub.com/beorn7/perksv1.0.1indirecta
Gogithub.com/blang/semver/v4v4.0.0indirecta
Gogithub.com/blendle/zapdriverv1.3.1indirecta
Gogithub.com/cenkalti/backoff/v5v5.0.3indirecta
Gogithub.com/cert-manager/cert-managerv1.20.1indirecta
Gogithub.com/cespare/xxhash/v2v2.3.0indirecta
Gogithub.com/cloudevents/sdk-go/observability/opentelemetry/v2v2.16.2indirecta
Gogithub.com/cloudevents/sdk-go/sql/v2v2.16.2indirecta
Gogithub.com/coreos/go-oidc/v3v3.18.0indirecta
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirecta
Gogithub.com/davidmz/go-pageantv1.0.2indirecta
Gogithub.com/emicklei/go-restful/v3v3.13.0indirecta
Gogithub.com/evanphx/json-patch/v5v5.9.11indirecta
Gogithub.com/felixge/httpsnoopv1.0.4indirecta
Gogithub.com/fxamacker/cbor/v2v2.9.1indirecta
Gogithub.com/go-fed/httpsigv1.1.1-0.20201223112313-55836744818eindirecta
Gogithub.com/go-jose/go-jose/v3v3.0.5indirecta
Gogithub.com/go-jose/go-jose/v4v4.1.4indirecta
Gogithub.com/go-logr/logrv1.4.3indirecta
Gogithub.com/go-logr/stdrv1.2.2indirecta
Gogithub.com/go-logr/zaprv1.3.0indirecta
Gogithub.com/go-openapi/errorsv0.22.7indirecta
Gogithub.com/go-openapi/jsonpointerv0.22.5indirecta
Gogithub.com/go-openapi/jsonreferencev0.21.5indirecta
Gogithub.com/go-openapi/strfmtv0.26.1indirecta
Gogithub.com/go-openapi/swagv0.25.5indirecta
Gogithub.com/go-openapi/swag/cmdutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/convv0.25.5indirecta
Gogithub.com/go-openapi/swag/fileutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/jsonnamev0.25.5indirecta
Gogithub.com/go-openapi/swag/jsonutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/loadingv0.25.5indirecta
Gogithub.com/go-openapi/swag/manglingv0.25.5indirecta
Gogithub.com/go-openapi/swag/netutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/stringutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/typeutilsv0.25.5indirecta
Gogithub.com/go-openapi/swag/yamlutilsv0.25.5indirecta
Gogithub.com/go-viper/mapstructure/v2v2.5.0indirecta
Gogithub.com/google/gnostic-modelsv0.7.1indirecta
Gogithub.com/google/go-querystringv1.2.0indirecta
Gogithub.com/google/uuidv1.6.0indirecta
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0indirecta
Gogithub.com/hashicorp/go-cleanhttpv0.5.2indirecta
Gogithub.com/hashicorp/go-retryablehttpv0.7.8indirecta
Gogithub.com/hashicorp/go-versionv1.9.0indirecta
Gogithub.com/hashicorp/golang-lruv1.0.2indirecta
Gogithub.com/imfing/hextrav0.12.0indirecta
Gogithub.com/inconshreveable/mousetrapv1.1.0indirecta
Gogithub.com/json-iterator/gov1.1.12indirecta
Gogithub.com/kballard/go-shellquotev0.0.0-20180428030007-95032a82bc51indirecta
Gogithub.com/kelseyhightower/envconfigv1.4.0indirecta
Gogithub.com/lunixbochs/vtcleanv1.0.0indirecta
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirecta
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31eeindirecta
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirecta
Gogithub.com/oklog/ulid/v2v2.1.1indirecta
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirecta
Gogithub.com/prometheus/client_golangv1.23.2indirecta
Gogithub.com/prometheus/otlptranslatorv1.0.0indirecta
Gogithub.com/prometheus/procfsv0.20.1indirecta
Gogithub.com/puerkitobio/goqueryv1.12.0indirecta
Gogithub.com/rickb777/datev1.22.0indirecta
Gogithub.com/rickb777/pluralv1.4.10indirecta
Gogithub.com/robfig/cron/v3v3.0.1indirecta
Gogithub.com/spf13/pflagv1.0.10indirecta
Gogithub.com/x448/float16v0.8.4indirecta
Gogithub.com/xlzd/gotpv0.1.0indirecta
Gogo.opentelemetry.io/auto/sdkv1.2.1indirecta
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0indirecta
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0indirecta
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0indirecta
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0indirecta
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirecta
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0indirecta
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0indirecta
Gogo.opentelemetry.io/proto/otlpv1.10.0indirecta
Gogo.uber.org/atomicv1.11.0indirecta
Gogo.uber.org/automaxprocsv1.6.0indirecta
Gogo.uber.org/multierrv1.11.0indirecta
Gogo.yaml.in/yaml/v2v2.4.4indirecta
Gogo.yaml.in/yaml/v3v3.0.4indirecta
Gogolang.org/x/cryptov0.53.0indirecta
Gogolang.org/x/netv0.56.0indirecta
Gogolang.org/x/sysv0.47.0indirecta
Gogolang.org/x/timev0.15.0indirecta
Gogomodules.xyz/jsonpatch/v2v2.5.0indirecta
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaaindirecta
Gogoogle.golang.org/grpcv1.81.1indirecta
Gogopkg.in/evanphx/json-patch.v4v4.13.0indirecta
Gogopkg.in/inf.v0v0.9.1indirecta
Gogopkg.in/yaml.v3v3.0.1indirecta
Gok8s.io/apiextensions-apiserverv0.36.2indirecta
Gok8s.io/kube-openapiv0.0.0-20260330154417-16be699c7b31indirecta
Gosigs.k8s.io/gateway-apiv1.5.1indirecta
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730indirecta
Gosigs.k8s.io/randfillv1.0.0indirecta
Gosigs.k8s.io/structured-merge-diff/v6v6.3.2indirecta
npm@axe-core/playwright^4.10.1indirecta
npm@playwright/test^1.49.1indirecta
npm@tailwindcss/postcss^4.1.18indirecta
npmpostcss-cli^11.0.1indirecta
npmprettier^3.8.0indirecta
npmprettier-plugin-go-template^0.0.15indirecta
npmtailwindcss^4.1.18indirecta
Avisos de dependencias 3

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 156 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 3 tienen avisos conocidos, de los cuales 1 son directas. 7 no pudieron evaluarse: sin versión resuelta, ecosistema no admitido, o fuera de la lista de paquetes informada.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
google.golang.org/grpcv1.81.1indirectacrítica11.82.1
github.com/tektoncd/pipelinev1.14.0directadesconocida2
golang.org/x/cryptov0.53.0indirectadesconocida1

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "tekton-pipelines",
        "tekton",
        "github",
        "pipeline",
        "kubernetes",
        "continuous-delivery",
        "pipelines-as-code",
        "gitlab",
        "ci",
        "bitbucket",
        "gitops"
      ],
      "is_fork": false,
      "size_kb": 78996,
      "has_wiki": true,
      "homepage": "https://pipelinesascode.com",
      "languages": {
        "Go": 3487952,
        "Shell": 88231,
        "Python": 31194,
        "Makefile": 9406,
        "Go Template": 11587
      },
      "pushed_at": "2026-07-21T10:21:44Z",
      "created_at": "2021-04-06T13:26:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T10:21:49Z",
      "description": "Pipelines-as-Code for Tekton",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://tekton.dev",
      "name": "Tekton",
      "type": "Organization",
      "login": "tektoncd",
      "company": null,
      "location": null,
      "followers": 1421,
      "avatar_url": "https://avatars.githubusercontent.com/u/47602533?v=4",
      "created_at": "2019-02-13T14:53:43Z",
      "is_verified": null,
      "public_repos": 24,
      "account_age_days": 2715
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.48.1",
          "kind": "patch",
          "published_at": "2026-07-17T13:48:26Z"
        },
        {
          "tag": "v0.42.3",
          "kind": "patch",
          "published_at": "2026-07-17T13:39:45Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2026-07-06T12:59:38Z"
        },
        {
          "tag": "v0.42.2",
          "kind": "patch",
          "published_at": "2026-06-15T07:19:37Z"
        },
        {
          "tag": "v0.37.8",
          "kind": "patch",
          "published_at": "2026-06-12T13:43:39Z"
        },
        {
          "tag": "v0.39.7",
          "kind": "patch",
          "published_at": "2026-06-09T18:31:33Z"
        },
        {
          "tag": "v0.42.1",
          "kind": "patch",
          "published_at": "2026-06-08T16:18:26Z"
        },
        {
          "tag": "v0.39.6",
          "kind": "patch",
          "published_at": "2026-06-08T14:41:54Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2026-06-04T16:28:32Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2026-05-26T08:24:42Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2026-05-06T11:27:46Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2026-04-08T08:38:24Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-03-31T18:49:00Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:28:22Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-02-23T14:42:23Z"
        },
        {
          "tag": "v0.37.7",
          "kind": "patch",
          "published_at": "2026-02-23T14:00:10Z"
        },
        {
          "tag": "v0.39.5",
          "kind": "patch",
          "published_at": "2026-02-19T18:57:07Z"
        },
        {
          "tag": "v0.37.6",
          "kind": "patch",
          "published_at": "2026-02-19T14:43:04Z"
        },
        {
          "tag": "v0.37.5",
          "kind": "patch",
          "published_at": "2026-01-29T15:13:18Z"
        },
        {
          "tag": "v0.39.4",
          "kind": "patch",
          "published_at": "2026-01-29T15:14:58Z"
        },
        {
          "tag": "v0.41.1",
          "kind": "patch",
          "published_at": "2026-01-29T10:33:18Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-01-20T14:11:55Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2025-12-19T06:49:11Z"
        },
        {
          "tag": "v0.39.3",
          "kind": "patch",
          "published_at": "2025-12-15T17:36:46Z"
        },
        {
          "tag": "v0.37.4",
          "kind": "patch",
          "published_at": "2025-12-15T09:42:51Z"
        },
        {
          "tag": "v0.35.4",
          "kind": "patch",
          "published_at": "2025-12-04T04:41:54Z"
        },
        {
          "tag": "v0.39.2",
          "kind": "patch",
          "published_at": "2025-11-19T11:02:58Z"
        },
        {
          "tag": "v0.37.3",
          "kind": "patch",
          "published_at": "2025-11-18T08:39:26Z"
        },
        {
          "tag": "v0.39.1",
          "kind": "patch",
          "published_at": "2025-11-18T07:41:53Z"
        },
        {
          "tag": "v0.37.2",
          "kind": "patch",
          "published_at": "2025-11-10T04:40:32Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2025-11-04T17:28:24Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2025-10-01T09:30:13Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2025-09-26T06:21:33Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2025-08-12T11:40:15Z"
        },
        {
          "tag": "v0.35.3",
          "kind": "patch",
          "published_at": "2025-07-16T18:29:05Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2025-07-04T16:53:16Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2025-06-26T15:30:13Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2025-06-04T13:07:41Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2025-05-26T15:19:51Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2025-05-06T13:43:40Z"
        },
        {
          "tag": "v0.33.2",
          "kind": "patch",
          "published_at": "2025-05-02T08:04:29Z"
        },
        {
          "tag": "v0.33.1",
          "kind": "patch",
          "published_at": "2025-04-16T10:34:37Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2025-02-14T14:28:54Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2025-01-21T10:35:04Z"
        },
        {
          "tag": "v0.28.2",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:58Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:36Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2024-12-17T10:56:53Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2024-11-27T11:51:15Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2024-11-08T16:55:33Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2024-10-31T16:23:11Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2024-09-19T17:40:55Z"
        },
        {
          "tag": "v0.27.2",
          "kind": "patch",
          "published_at": "2024-07-05T11:31:26Z"
        },
        {
          "tag": "v0.27.1",
          "kind": "patch",
          "published_at": "2024-06-10T15:39:31Z"
        },
        {
          "tag": "v0.24.7",
          "kind": "patch",
          "published_at": "2024-05-30T09:57:00Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2024-05-06T15:20:57Z"
        },
        {
          "tag": "v0.24.6",
          "kind": "patch",
          "published_at": "2024-05-06T14:39:36Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2024-04-18T11:57:55Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2024-03-25T15:21:09Z"
        },
        {
          "tag": "v0.24.5",
          "kind": "patch",
          "published_at": "2024-03-22T14:37:32Z"
        },
        {
          "tag": "v0.24.4",
          "kind": "patch",
          "published_at": "2024-03-21T14:02:29Z"
        },
        {
          "tag": "v0.24.3",
          "kind": "patch",
          "published_at": "2024-03-19T16:23:42Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2024-03-12T13:01:33Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2024-02-14T16:31:12Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2024-02-05T14:01:16Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2024-01-09T09:51:56Z"
        },
        {
          "tag": "v0.22.6",
          "kind": "patch",
          "published_at": "2024-01-02T12:13:30Z"
        },
        {
          "tag": "v0.22.5",
          "kind": "patch",
          "published_at": "2023-12-15T14:02:13Z"
        },
        {
          "tag": "v0.22.4",
          "kind": "patch",
          "published_at": "2023-11-23T10:10:32Z"
        },
        {
          "tag": "v0.22.3",
          "kind": "patch",
          "published_at": "2023-11-21T12:25:21Z"
        },
        {
          "tag": "v0.22.2",
          "kind": "patch",
          "published_at": "2023-11-16T08:22:54Z"
        },
        {
          "tag": "v0.22.1",
          "kind": "patch",
          "published_at": "2023-11-13T10:57:32Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2023-11-10T09:05:21Z"
        },
        {
          "tag": "v0.21.5",
          "kind": "patch",
          "published_at": "2023-10-31T14:38:00Z"
        },
        {
          "tag": "v0.21.4",
          "kind": "patch",
          "published_at": "2023-10-20T07:48:16Z"
        },
        {
          "tag": "v0.17.7",
          "kind": "patch",
          "published_at": "2023-10-20T07:28:36Z"
        },
        {
          "tag": "v0.19.6",
          "kind": "patch",
          "published_at": "2023-10-20T09:04:23Z"
        },
        {
          "tag": "v0.17.6",
          "kind": "patch",
          "published_at": "2023-10-18T15:19:51Z"
        },
        {
          "tag": "v0.19.5",
          "kind": "patch",
          "published_at": "2023-10-18T14:48:27Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2023-10-17T11:10:03Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2023-10-10T12:49:07Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2023-09-26T11:34:53Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2023-09-13T18:01:46Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2023-08-25T06:56:16Z"
        },
        {
          "tag": "v0.19.4",
          "kind": "patch",
          "published_at": "2023-08-04T08:37:21Z"
        },
        {
          "tag": "v0.19.3",
          "kind": "patch",
          "published_at": "2023-08-01T15:58:54Z"
        },
        {
          "tag": "v0.17.5",
          "kind": "patch",
          "published_at": "2023-08-01T14:00:28Z"
        },
        {
          "tag": "v0.17.4",
          "kind": "patch",
          "published_at": "2023-06-09T12:03:37Z"
        },
        {
          "tag": "v0.19.2",
          "kind": "patch",
          "published_at": "2023-06-08T14:05:48Z"
        },
        {
          "tag": "v0.19.1",
          "kind": "patch",
          "published_at": "2023-05-24T15:19:57Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2023-05-04T09:10:44Z"
        },
        {
          "tag": "v0.15.6",
          "kind": "patch",
          "published_at": "2023-04-19T09:46:58Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2023-04-18T13:34:40Z"
        },
        {
          "tag": "v0.17.3",
          "kind": "patch",
          "published_at": "2023-04-18T11:26:19Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2023-03-30T12:31:01Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2023-03-08T15:15:55Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2023-03-02T14:50:12Z"
        },
        {
          "tag": "v0.15.5",
          "kind": "patch",
          "published_at": "2023-02-06T11:46:56Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2023-02-06T10:59:31Z"
        },
        {
          "tag": "v0.15.4",
          "kind": "patch",
          "published_at": "2023-02-06T11:01:40Z"
        },
        {
          "tag": "v0.15.3",
          "kind": "patch",
          "published_at": "2023-01-19T11:50:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
          "body": "Corrected the default container image path for the controller in the\nmulti-controller documentation to point to the correct GitHub Container\nRegistry repository.\n\nFixes #2559\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update controller image path in multi-controller docs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-21T10:21:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4dfe8e76d8674cb78bc70bd5b84201f05799323",
          "body": "When updating a Bitbucket Cloud token via update-token, also\nprompt for the Atlassian account email and update\ngit_provider.user on the Repository CR. Without this, tokens\nrotated via the CLI leave a stale username that causes 401\nerrors on all provider API calls.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cli): set BB Cloud email in update-token",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-21T07:54:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "558561804964b529a161aea871788868687b0378",
          "body": "this deletes the gemini config from PaC repo\nbecause gemini code review is decommisioned and\nit is no longer needed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: delete gemini config from repo",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-20T18:43:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0feb33f9f5b2ead03cc2d510df497577b6ebee14",
          "body": "Replace testify/assert with gotest.tools/v3/assert in\ninfo_test.go and task_status_test.go to match the project's\nstandard assertion library and eliminate mixed usage.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "test: use gotest.tools/v3/assert consistently",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f1fe585601252cf88ded8a2487dde0cb25fdb3",
          "body": "Tekton Hub has been shut down and is no longer supported in\nOSP 1.24. Remove all TektonHub-specific code, configuration,\ntests, and documentation, leaving only Artifact Hub integration.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(hub): remove Tekton Hub support",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6e3f736a86b0e89103b84dfda95e5999075a0c72",
          "body": "Added logic to extract and display error messages from waiting container\nstates, which occur when secrets or other configuration issues prevent\npod creation. This allows users to see the actual error (e.g., \"secret\nnot found\") in the pipeline failure output instead of just a generic\nreason code. Als\n[…]\ns to include container creation and pod creation errors.\n\nFixes #2751\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12208\nCo-Authored-By: Gemini\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: capture container creation error messages in logs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-20T10:08:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad947f41d3d277edd7b761a030d5911dc3cc72c5",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\n\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/setup-go in the github-actions group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:25:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d121ae3e51f0ffdcdcd3391a674b6877a7af0ec",
          "body": "Bumps the go-dependencies group with 1 update: [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty).\n\n\nUpdates `github.com/mattn/go-isatty` from 0.0.22 to 0.0.23\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)\n\n---\nupdated-dependencies:\n- dependency-name: github\n[…]\n dependency-version: 0.0.23\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump github.com/mattn/go-isatty in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e25db4412aa0a70b220da6dc1e2a268b386c7131",
          "body": "Enabled verbose JSON logging with connection timeouts and retries for\ngosmee clients to make end-to-end test failures easier to debug.\nIsolated Gitea and GitHub Enterprise webhook client logs into their\nown directories and files to prevent them from overwriting or\nappending to shared main logs. Upda\n[…]\non script to\ngather these new logs, capture internal Kubernetes gosmee deployment\ndetails when available, and redact the newly added webhook URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Improve gosmee client debugging for end-to-end tests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:11:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a054817abb339b0eef99e76aab00ed42bd571d89",
          "body": "Updated the AI code reviewer prompt to provide more detailed guidance on\nreview standards. Enhanced instructions to clarify what constitutes\nactionable findings versus nits, added explicit severity level\ndefinitions for consistent issue categorization, and improved guidance\non when and how to provid\n[…]\nuggestions. These changes aim to\nproduce more focused and useful pull request reviews by setting clearer\nexpectations for the reviewer's behavior.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: refine paco code review prompt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f314275a165afc0641f3e6cef98bbecf0e51134",
          "body": "Extend Paco's structured review response with a difficulty rating, a\nshort explanation, and a security-sensitivity flag. Explain the rating\ncriteria in the model prompt so scores account for change size,\ncomplexity, risk, and blast radius while keeping summary-only runs\nconsistent with full reviews.\n[…]\nthe review instructions to suppress subjective formatting,\nnaming, and phrasing nits unless they affect correctness, security, or\nmaintainability.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: score review difficulty and other paco impro",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad2dcdb267f0d0b5ad99f3366bb4365d277c2fe0",
          "body": "Added an automated code review pipeline powered by AI to analyze pull\nrequest diffs against project-specific guidelines. This was done to help\ndevelopers catch bugs, style violations, and security flaws early by\nposting inline comments and a persistent overview summary directly onto\nGitHub pull requests.\n\nThis using opencode cli backend (but thats an implementation detail) and\nsupport custom review rules via a .tekton/ai/REVIEW.md file.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Introduce Paco AI code review",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T08:34:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c47b6e5245b6f115934cc6e4a889e60909dab1",
          "body": "Remove the Status []RepositoryRunStatus field from the Repository\nCR to eliminate informer cache churn caused by updating the CR on\nevery PipelineRun completion. CLI commands now query PipelineRuns\ndirectly via label selectors instead of reading repo status.\n\n- Delete updateRepoRunStatus reconciler \n[…]\n ShowLastSHA, ShowStatus, ShowLastAge\n- Update deepcopy, test helpers, informer transform, golden files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "refactor: remove Repository CR pipelinerun_status field",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T07:18:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6a391687b88008a8b4cc264077508b7a1c8181c",
          "body": "Replace IsCollaborator (which returns true for read-only collaborators)\nwith CollaboratorPermission to verify the sender has write or admin\nor owner access before allowing pipeline runs. Also fix\nCreateForkPullRequest to grant access to SecondUserName instead of\nTargetRefName.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitea): check write/admin permission instead of collaborator only",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T06:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84829463a99d791164a3ef8f7f5dc1cd00fc6766",
          "body": "Adds TestOTelMetrics, a consolidated e2e test for the OC→OTel metrics\nmigration in Pipelines-as-Code (PR #2567). The test scrapes two pods:\n\nController (app.kubernetes.io/name=controller):\n- Asserts http_client_* metrics from knative k8s client OTel instrumentation\n- Asserts go_* runtime metrics\n- C\n[…]\ne metrics\n\nVerified locally with PAC controller and watcher deployed to kind via ko.\n\nRelates to tektoncd/pipelines-as-code#2567\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add e2e test for OpenCensus to OpenTelemetry metrics migration",
          "author_name": "Khurram Baig",
          "author_login": "khrm",
          "committed_at": "2026-07-16T04:12:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69c4496b1d39ca6d22eff42a499bd7626e40e949",
          "body": "Add missing unit tests for low-coverage packages identified via\ncodecov analysis: params/clients, cli, bootstrap, pipelinerunmetrics,\nwebhook, and llm/llm-context. Also exclude test-helper packages from\ncodecov accounting and add a codecov badge to README.\n\nCoverage improvements:\n- params/clients: 1\n[…]\n: 39.6% -> 81.3%\n- webhook: 47.9% -> 70.9%\n- llm: 46.8% -> 57.9%\n- llm/context: 38.8% -> 77.5%\n\nOverall project statement coverage: 65.6% -> 68.3%\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: raise unit test coverage across packages",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T13:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5438a1e06ea50062a79fe8fcd52f456a1b974a46",
          "body": "The warning about the old profiling.enable key is migration\nguidance that describes historical state rather than current\nbehavior. Since the old key no longer works, only the current\nruntime-profiling key needs to be documented.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "docs(profiling): remove deprecated key callout",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-15T09:04:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35ee9df55f472c448f203fb60b566fbc27efd06f",
          "body": "The Gitea cancel run test used a hardcoded sleep before sending the\ncancel comment. This caused test failures when the webhook relay took\nlonger than expected to deliver the event, sending the cancel command\nbefore the pipeline run existed. Replaced the sleep with a check that\nwaits for the pipeline run to be created first.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Wait for pipelinerun to be created before cancellation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T07:32:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "85b606bb30f6b42d645cd79526dfd5ceba629f88",
          "body": "The apiextensions-apiserver indirect dependency is updated\nfrom v0.35.6 to v0.36.2 along with the corresponding\nk8s.io/apiserver transitive dependency. The vendored files\nreflect upstream changes including a new StorageMigrating\ncondition type and the removal of the deprecated\nprotomessage compatibility shim.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: bump k8s.io/apiextensions-apiserver to v0.36.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c6483e2865399ae6794a5a3f57f2fac628bdd93",
          "body": "Bumps the go-dependencies group with 1 update: [k8s.io/client-go](https://github.com/kubernetes/client-go).\n\n\nUpdates `k8s.io/client-go` from 0.35.6 to 0.36.2\n- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/kubernetes/client-go/compare/v\n[…]\n dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump k8s.io/client-go in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e845ef225649de5ab631288562795a1c4037e83",
          "body": "rh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "refractor: split gitea_test.go into focused files",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-07-10T07:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85cad747dee15d9847c04cec0d79a4c4fab5789a",
          "body": null,
          "is_bot": false,
          "headline": "fix: bump knative.dev/pkg and semconv to fix otel schema panic",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fe2198bfa19188481c1a166b368df68055fc1e2",
          "body": "Dependabot generates automated commit messages that often violate line\nlength or body formatting rules. Added a check to bypass commit\nvalidation for dependabot pull requests, allowing these automated\nupdates to proceed without linting failures.",
          "is_bot": false,
          "headline": "ci: skip commit validation on dependabot PRs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c421e079e553bbf0b3fcdf7291fca29ee66e6b7",
          "body": null,
          "is_bot": false,
          "headline": "ci: ignore go-github and ghinstallation in dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b3981bc20b55759649f413d515452f7161b029b",
          "body": "Bumps the go-dependencies group with 15 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/bradleyfalzon/ghinstallation/v2](https://github.com/bradleyfalzon/ghinstallation) | `2.18.0` | `2.19.0` |\n| [github.com/google/cel-go](https://github.com/google/cel-go) | `0.28.1` | `0.29.2` |\n[…]\nx: pin ghinstallation to v2.18.0\n\nDowngraded ghinstallation from v2.19.0 to v2.18.0 and removed the unused\ngo-github v88 dependency that was pulled in transitively.\n\nfix: pin ghinstallation to v2.18.0",
          "is_bot": true,
          "headline": "ci: bump the go-dependencies group with 15 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "717f163e6fd3bfef22bd51108202c1049050bd7e",
          "body": "Added Go module tracking to the Dependabot configuration to keep Go\ndependencies updated. Since we can now group these updates together, we\ncan prevent an excessive number of pull requests.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Readd Go module updates in Dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T12:38:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "912f4e6b3b4147f4143f45e9cedbf2e767f562fd",
          "body": "- Update Go version from 1.26.4 to 1.26.5 in go.mod\n- Addresses crypto/tls Encrypted Client Hello privacy leak\n- CVE-2026-42505 / GO-2026-5856 fixed in go1.26.5\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-42505 - update Go to 1.26.5",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-09T11:50:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a8413915cd80a6217b6eb3d50018b449082550a",
          "body": "The test waited on the PR head SHA status which is already green from\nthe pull_request run, then slept 5s; a delayed push webhook made\nGetStandardParams fail fatally on its first iteration with zero push\npipelineruns.\n\nWait for both pipelineruns to succeed after the merge and make\nGetStandardParams \n[…]\nhecking helper is patient\nenough to retry while things are still warming up, instead of quitting\nat the first empty result.\n\nAI-assisted-by: Cursor\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(e2e): wait for push pipelinerun in gitea params test",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T11:47:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e270e68e403cf5f937f48e6e5ea73ea663818888",
          "body": "The GitLab token auto-rotation feature revoked the old token via the\nself-rotate API before making the first Kubernetes API call that\ncould fail with a permission error. If the subsequent Secret update\nfailed, the old token was already revoked and the new token was\ndiscarded, irrecoverably destroyin\n[…]\n the\nrotation is aborted with a clear error while the old token is still\nvalid, so nothing is lost.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): verify write access before rotating token",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T08:23:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73cb521a48abeca491396811ac795e5a0039ece2",
          "body": "Document that provider code must use v.Logger instead of\nrun.Clients.Log, since the provider logger carries standard\ncontext variables (provider, repository, event-id). This\nprevents regressions of the pattern fixed in the recent\nprovider logging commits.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: add provider logginf guidance to AGENTS.md",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b89b22edfa4ae5a6c296b11b8a39e6c01cd7caab",
          "body": "The token auto-rotation logging in the GitLab provider's\nsetClient was still using run.Clients.Log instead of the\nprovider's own logger. This logger lacks the standard context\nvariables (provider, repository, event-id) that v.Logger\ncarries.\n\nFollow-up-to: https://github.com/tektoncd/pipelines-as-code/pull/2827\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(provider): use provider logger in gitlab setClient",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "939d30a4365440484d4319046065af596601a37a",
          "body": "The run.CLients.Log logger is created early and does not have the\nstandard context variables. The provider logger is used primarily and\nwhile technically possible because pointers, provider.Logger == nil is\nan illegal state.\n\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(provider): always use log using Provider logger",
          "author_name": "Andrew Thorp",
          "author_login": "aThorp96",
          "committed_at": "2026-07-07T13:08:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e62d212d539ff389a82f4ca257aa9a7655cf042",
          "body": "Complete the refactor started in 39271f36a which removed the wait\nhelpers polling the deprecated Repository CR Status field. Three\nloose ends were left behind and are tied off here.\n\nFix zero-minimum wait semantics. The removed helpers compared with\n\">\" so MinNumberStatus: 0 meant \"wait for one\". Th\n[…]\nross 22\nE2E test files are deleted.\n\nValidated with go test ./test/pkg/wait and a compile of the e2e\ntagged test package.\n\nAssisted-by: Claude Code\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "refactor(e2e): finish Repository.Status removal in waits",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-07T11:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39271f36a191962287f27270b75ebc52084c3f84",
          "body": "The Repository CR's Status field is deprecated and will be removed.\nThis refactors E2E test wait helpers to use PipelineRun objects directly\ninstead of polling Repository.Status:\n\n- Remove UntilRepositoryUpdated and UntilRepositoryHasStatusReason\n- Remove FailOnRepoCondition from wait.Opts\n- Modify \n[…]\ninstead\n  of repo.Status fields\n- Migrate all ~40 call sites across 20 test files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(e2e): remove reliance on Repository.Status in wait functions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-07T07:39:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1433ee8668857940524d58b6c8510d4d8552d7b8",
          "body": "Add Forgejo to the webhook setup used by `tkn pac create repo` and\n`tkn pac webhook add`. Create the repository webhook and store the\ntoken and webhook secret for runtime use.\n\nHandle repository URLs with `.git` suffixes, trailing slashes,\ninstance subpaths, and SSH forms without blocking manual set\n[…]\noken permission is needed and clarify when the CLI\ncreates the provider secret.\n\nFixes #2755.\n\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>\nSigned-off-by: Katie Mulliken <mulliken@redhat.com>",
          "is_bot": false,
          "headline": "feat(webhook): add Forgejo CLI setup",
          "author_name": "Katie Mulliken",
          "author_login": "SecKatie",
          "committed_at": "2026-07-06T12:02:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0badfa041319b55f201e956df9ecf152923581f",
          "body": "Pipelines-as-Code automatically rotated GitLab access tokens to\nprevent pipeline failures caused by expired credentials. Expiring\ntokens were replaced with new tokens and updated in the corresponding\nKubernetes Secret, reducing manual maintenance. Shared secrets from the\nglobal repository were exclu\n[…]\ns. This behavior is disabled\nby default but could be turned on via repository configuration.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-11153\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Implement automatic GitLab access rotation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T11:22:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bd2cc1be180b32ada848ab65d1090d32e6bf1a2",
          "body": "Removed the testrr integration, including the upload script, CI\nenvironment variables, and documentation. The testrr service is no\nlonger used to track test results from Tekton and GitHub Actions.\n\nIt was never really used and created a lot of resources waste, so we are\nremoving it to simplify our CI/CD pipeline and reduce unnecessary\ndependencies.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Remove testrr test reporting from the CI environment",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T09:04:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27ac5d7e2567f21b5ae281fa54db0fcc89dd3c80",
          "body": "The reconciler is a shared controller object. It can work on more than one\nPipelineRun at the same time. Some values it used while loading Git provider\ncredentials were stored on that shared object, even though they only belonged\nto the PipelineRun currently being processed.\n\nThat could let one Pipe\n[…]\non. Also copy Repository objects before merging global settings, so\nwe do not modify objects that came from the shared informer cache.\n\nFixes #2824\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): avoid shared state",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T13:29:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63e8059d17c3fde3e60fd1dc07b48b260d9996a5",
          "body": "Updated the documentation and scaffolding templates to clarify task\nresolution behaviors. Explicitly distinguished annotation-based task\ninlining from native Tekton Hub resolver syntax because combining them\ncaused configuration errors. Replaced outdated git-clone catalog URLs\nwith the correct Artifact Hub links to ensure accurate references.\n\nFixes #2814\nAI-assisted-by: OpenAI ChatGPT\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Clarify task resolution in the pipeline documentation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T07:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccba1d5ca7a56c0eb66c102420bb553c8581f48b",
          "body": "this commit reverts a github link in docs from using\nmain branch to point to a specific commit to make\npermalink lint happy.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: use commit sha to prevent permalint lint error",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e30e597f4318d7438df004401802772ff56e6429",
          "body": "Label removal events on GitLab merge requests were incorrectly triggering\npipeline runs. The hasOnlyLabelsChanged check used an OR condition that\nmatched both additions and removals. Changed to compare current vs previous\nlabel count so only label additions are processed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): discard label removal events on merge requests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a7f21344bdf3ab247c8759fdcbefff42f8a62fc",
          "body": "- Upgrade github.com/tektoncd/pipeline from v1.13.1 to v1.14.0\n- Fixes GHSA-cv4x-93xx-wgfj / CVE-2026-33022: controller panic via long\n  resolver name in TaskRun/PipelineRun (GenerateDeterministicNameFromSpec)\n- Fixes GO-2023-1901: Pipelines do not validate child UIDs\n- Co-upgrade transitive deps pu\n[…]\n,text} minor bumps\n- Ran: go mod tidy && go mod verify && go mod vendor\n\nResolves: SRVKP-11100\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-33022 - upgrade tektoncd/pipeline v1.13.1 → v1.14.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-03T05:20:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03cd060cbf610d5343af4d10e8bbf0e3d66279e6",
          "body": "Added a Go formatting check to the linting process using gofumpt.\nIntegrated this verification step into the local Makefile lint target\nand the automated Tekton CI pipeline to ensure consistent code style\nacross the repository.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Enforce Go code formatting checks in lint pipeline",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T13:42:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8966a5331f743fe9e68d2262da1234b2391e4cb",
          "body": "Code was reformatted using fumpt to improve consistency with Go\nformatting standards. This includes adjusting line breaks in function\ncalls and adding parentheses for better readability where function\narguments span multiple lines. chore: reformat files with make fumpt",
          "is_bot": false,
          "headline": "chore: reformat code with fumpt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T08:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dfcd60091c46844449e91a38bf38b76bea56c47",
          "body": "Switch Bitbucket Cloud setup away from app-password language and\nmake the CLI collect the Atlassian account email used for API token\nauthentication. Webhook creation now uses that email with the scoped\nAPI token instead of authenticating with the repository owner.\n\nKeep Repository CRD shape unchange\n[…]\nthe CLI auth flow, token rotation prompt, and generated git auth\nsecret behavior.\n\nFixes #2818\nJira https://redhat.atlassian.net/browse/SRVKP-12685\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: bitbucket API tokens instead of app-passwords",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T15:55:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fdee04551602b8af9ef267e121863f045c256e5",
          "body": "Addresses SRVKP-12311 by moving unit coverage publishing to a\ndedicated GitHub Actions workflow. The workflow runs on pull requests,\npushes to main, and manual dispatch, then uploads coverage with the\nunit-tests flag through Codecov OIDC.\n\nRemove the older Tekton Codecov uploader steps that relied o\n[…]\no longer suggests Codecov coverage ownership.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12311\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: add codecov oidc upload",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T09:33:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d51949f5027d41d9e8941ffa651a541acd8188f",
          "body": "Explain that disabling GitLab PipelineRun status comments does not\nhide validation errors from PipelineRuns in the `.tekton/` directory.\nThis keeps the note in normal prose instead of an info callout, so\nthe GitLab guide reads as a continuous troubleshooting section.\n\nSigned-off-by: Estee Cohen <estherco@post.bgu.ac.il>\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: clarify GitLab comment strategy behavior",
          "author_name": "Estee Cohen",
          "author_login": "EsteeCohen",
          "committed_at": "2026-07-01T09:16:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc50929a53e9d07fda018ac73bd6f899a31310d",
          "body": null,
          "is_bot": false,
          "headline": "fix(llm): run default AI roles on completed PipelineRuns",
          "author_name": "BoseKarthikeyan",
          "author_login": "BoseKarthikeyan",
          "committed_at": "2026-06-30T09:21:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d2cde6492c70ac4f983f6fede548dd138c5d73b",
          "body": "Knative's config-observability ConfigMap only exposes a flat\ntracing-sampling-rate, so at fractional rates each service in the chain\nrolls independently — PaC can drop a trace while Tekton keeps it, leaving\nexecution spans whose parent_spanID points at nothing. Switching to the\nOTel SDK opens up OTE\n[…]\nonally not honored per Konflux-CI\nADR 0061. otlptracegrpc and otlptracehttp promoted from indirect to direct\ndependencies.\n\nAssisted-by: Claude Code\nSigned-off-by: Josiah England <jengland@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): direct OTel SDK setup for chain-coherent sampling",
          "author_name": "Josiah England",
          "author_login": "ci-operator",
          "committed_at": "2026-06-30T05:31:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1a2f48ed544837c80ea38487d1ed728df82c819",
          "body": "Replace duplicate 404 and non-404 error subtests with a\ntable-driven test to satisfy the dupl linter.\n\nFixes https://github.com/tektoncd/pipelines-as-code/issues/2653\n\nrh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "fix: downgrade 404 API responses from error to debug log level",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-06-29T14:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74939ef42af88d708302559927406a59c7f16bbb",
          "body": "Reduce PR noise by grouping all GitHub Actions dependency updates into a\nsingle consolidated pull request, improving workflow efficiency.",
          "is_bot": false,
          "headline": "chore: Configure Dependabot to group GitHub Actions updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-29T08:16:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f045c6cf34367dbc09d0e0da9cdd72f9610b76d",
          "body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\ns:\n- dependency-name: actions/cache\n  dependency-version: 6.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/cache from 5.0.5 to 6.1.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa462865bb55ec617868b0f23451bc03ebcd0452",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n  dependency-version: 6.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a781dbea31c5b894d6419b95df9fd2eb6f2cb1d",
          "body": "Bumps [ko-build/setup-ko](https://github.com/ko-build/setup-ko) from 0.9 to 0.10.\n- [Release notes](https://github.com/ko-build/setup-ko/releases)\n- [Commits](https://github.com/ko-build/setup-ko/compare/d006021bd0c28d1ce33a07e7943d48b079944c8d...61b4d1d396f5b2e7d6bb6fefdce3dc38d1a13445)\n\n---\nupdate\n[…]\ndependency-name: ko-build/setup-ko\n  dependency-version: '0.10'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ko-build/setup-ko from 0.9 to 0.10",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82843027ab11abb03ce42f4603361cc3718e9ee9",
          "body": "Cache ListOrgTeams API responses per organization to avoid\nredundant API calls when checking policy for the same org\nacross multiple allowed teams evaluations.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "feat(forgejo): cache org teams in policy check",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-26T13:57:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "181a27faf760794cb3104995f0dcc88c12cb6be9",
          "body": "this allows e2e workflow run on any changes in hack/\ndirectory as there are all the script used across\nworkflow file.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore(ci): allow e2e workflow run hack/* changes",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ac13de68283c7aade7524100f9ba0f980f6569",
          "body": "Use per-resource kubectl get with --- separators when collecting\npipelineruns, repositories, and configmaps in CI log artifacts so\neach resource is a distinct YAML document.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): separate collected resources with YAML document markers",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fb79c78fc4bb95b6aafeac654f2ab76cebcdf1e",
          "body": "Add table-driven unit tests for pkg/provider/gitea/parse_payload.go:\n\n- TestParsePayloadPullRequest covers the opened, synchronized, label_updated\n  and closed actions (event type, trigger target and label extraction).\n- TestParsePayloadPush covers the head_commit path and the before-SHA fallback.\n-\n[…]\noad helper builds the request and calls ParsePayload, and\nprPayload builds pull_request webhook bodies.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Kshitiz Jain <kshitizj@gmail.com>",
          "is_bot": false,
          "headline": "test(gitea): add unit tests for parse_payload",
          "author_name": "Kshitiz Jain",
          "author_login": "kshitizj03",
          "committed_at": "2026-06-25T09:21:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fff1dac7fad8183449d7521d3a6c0e797b06efe6",
          "body": "Tekton workspaces are shallow detached-HEAD clones; remote tracking\nrefs like origin/main are not available after git fetch -a --tags.\nUsing {{revision}} (the triggering commit SHA) matches the pattern\nalready used in .tekton/release-pipeline.yaml.",
          "is_bot": false,
          "headline": "fix: use revision instead of origin/main for nightly branch checkout",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-23T13:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f765bcb26a4da9fd5cd13137179450683953f56",
          "body": "actions/checkout v7 now refuses to fetch fork pull request code in\npull_request_target workflows by default to prevent pwn request\nattacks. Add allow-unsafe-pr-checkout: true to the e2e workflow\ncheckout step that needs to build and test fork PR code with\nrepository secrets.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): allow checkout of fork PR code in pull_request_target workflow",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-23T11:27:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6554d32b4a9b867c0d3ecc9b902e2b5b358ce38c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T08:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20a29a92b595e6e1c7794d1f9d0771b9554eb14f",
          "body": "Value.Emit() is deprecated in the updated OpenTelemetry SDK;\nreplace with Value.String() to resolve linter warning.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): use String instead of deprecated Emit",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d39d0d9b0924b8133e16d99d3e5997e1ef058b5",
          "body": "- Update github.com/tektoncd/pipeline from v1.11.1 to v1.13.1\n- Co-upgrades: cel-go v0.28.1, go-scm v1.15.22, otel v1.44.0,\n  zap v1.28.0, k8s.io/* v0.35.5, grpc v1.81.1\n\nCVE-2026-33022 (GHSA-cv4x-93xx-wgfj, CVSS 6.5 Medium):\nTekton Pipelines controller panic via long resolver name in\nGenerateDeterm\n[…]\nIs (pkg/apis, pkg/client) and does not run the\nTekton controller binary.\n\nResolves: SRVKP-9042\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump tektoncd/pipeline to v1.13.1",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ad17d4501ebcc8021b929c13ae397fcff5c8554",
          "body": "Updated the Homebrew installation documentation to include instructions\nfor trusting the tap to support newer Homebrew versions. Added steps\nto handle macOS Gatekeeper blocking the binary on first run, and\ndefined corresponding caveats in the release configuration.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update homebrew installation instructions for tap trust",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-22T11:19:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3dcf4ae3040e688935b84886bb4d6bbd9f6498a5",
          "body": "this commits adds a reason in log message that why the\nPipelineRun is cancelled so to make it clear to users.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "refactor: enhance log message for cancel-in-progress",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-19T15:22:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c38b0283fe109f5d9dcdfc9a215e07788e112a6c",
          "body": "Addresses Go stdlib vulnerabilities that require upgrading the compiler\ntoolchain from Go 1.25.11 to Go 1.26.4.\n\nCVEs fixed:\n- CVE-2026-27137 (GO-2026-4599): Incorrect email constraints in crypto/x509\n- CVE-2026-27138 (GO-2026-4600): Panic in name constraint checking in crypto/x509\n- CVE-2026-25679 \n[…]\n these fixes require Go 1.26.x.\nNo dependency changes: go.sum unchanged, go mod verify passes.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): upgrade Go from 1.25.11 to 1.26.4 to fix 23 stdlib CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-18T13:37:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c0fabcc29f8a87bf2cb7169d2914b8321bbe684",
          "body": "Replaced the local HTTP-based git-clone stepaction with the official\nTekton Hub resolver across Tekton workflows. Removed the redundant\nlocal stepaction definition file to keep configuration centralized.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Use git-clone artifacthub stepactions",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeb85ab653e95a4ddac059a2909cc41468097d36",
          "body": "Preserves the error chain for errors.Is/errors.As callers.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: use %w instead of %s for error wrapping in DetectPacInstallation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc818de1b009f8c117952eb651a783143c56e605",
          "body": "Add notes to the configmap and docs clarifying that\ncustom-console-url-pr-details, custom-console-url-namespace,\nand custom-console-url-pr-tasklog must all be configured when\ncustom-console-url is set. Also document console URL precedence\norder and add the missing custom-console-url-namespace example.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(consoleui): document required custom console settings",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T05:22:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52fd4ae9ff914eb88fda2013ec33f611b1726f15",
          "body": "Upgrade golang.org/x/crypto from v0.50.0 to v0.52.0 to address the\nfollowing vulnerabilities in the SSH package:\n\n- CVE-2026-42508 (GO-2026-5021): auth bypass via unenforced @revoked status in ssh/knownhosts\n- CVE-2026-39833 (GO-2026-5005): key constraints not enforced in ssh/agent\n- CVE-2026-39832 \n[…]\n3.0\n- golang.org/x/text: v0.36.0 → v0.37.0\n\nAll fixed in v0.52.0 (minimum safe patch version).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/crypto v0.50.0 → v0.52.0 to fix 13 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T03:54:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3180f7ca1db2856ddcc1f1e968c414d0cb89a812",
          "body": "this commit fixes the linting issues after a new\nvale release changes the rule I guess.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): linting issue after new release",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-16T12:59:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6035f789cdf72090f5b6a58e3dece394323c3bf",
          "body": "Upgrade go directive in go.mod from go1.25.7 to go1.25.11 to address\nthe following Go standard library vulnerabilities:\n\n- CVE-2026-42507 (GO-2026-5039): arbitrary inputs in errors without escaping in net/textproto\n- CVE-2026-42504 (GO-2026-5038): quadratic complexity in mime.WordDecoder.DecodeHeade\n[…]\not escaped in html/template\n\nAll fixed in go1.25.11 (minimum safe patch in the go1.25.x line).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade Go stdlib to go1.25.11 to fix 16 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:04:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f06dcf55cf3d3f83af65ac8fc9733448b545a4f5",
          "body": "Upgrade golang.org/x/net from v0.53.0 to v0.55.0 to address the\nfollowing vulnerabilities in golang.org/x/net:\n\n- CVE-2026-39821 (GO-2026-5026): failure to reject ASCII-only Punycode-encoded labels\n- CVE-2026-42506 (GO-2026-5025): incorrect handling of namespaced elements in foreign content\n- CVE-20\n[…]\n/text: v0.36.0 → v0.37.0\n\nNote: A separate PR upgrades x/crypto to v0.52.0 to fix 13 SSH CVEs.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/net v0.53.0 → v0.55.0 to fix 6 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:03:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbd582d0eef060094da1bbac907a1d6764b210df",
          "body": "… in the set client",
          "is_bot": false,
          "headline": "feat(bitbucketdatacenter): allow service accounts to not require user…",
          "author_name": "Ruben Rodrigues",
          "author_login": "Ru13en",
          "committed_at": "2026-06-09T18:56:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe709aecfe20b4da430a686463f655b4e1ebefac",
          "body": "gosmee v0.31.1 fixed an inverted TLS flag (InsecureSkipVerify was\nnegated), so the flag now works correctly. Restore it for e2e tests\nthat use self-signed minica certificates and unpin the version to\npick up the security fixes in v0.31.1+.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): restore --insecure-skip-tls-verify and unpin gosmee version",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T15:08:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f9c939d7369a9d246ced54404e90642a2d963655",
          "body": "The e2e workflow now installs the minica CA certificate into the system\ntrust store, so gosmee no longer needs to skip TLS verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): remove --insecure-skip-tls-verify flag from gosmee client",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T12:01:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ce4774d3f94b07ecc723a920d8312412d730a091",
          "body": "we've seen some failure in E2E test which could\nbe surfaced due to recent gosmee release so using\nv0.31.0 version to see the affect.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: stick gosmee version to v0.31.0",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T11:22:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85f323a53088693acf3e403ff9b6219ce346cc9c",
          "body": "Update release notes format reference to use the new\nTekton Github org name as well as product name,\nreplacing openshift-pipelines and OpenShift references.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(release-notes): update org and branding refs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-09T08:56:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70faf9f9220253a15f9d71058faeb11097824a78",
          "body": "Gosmee starts before startpaac generates minica certs and before\nupdate-ca-certificates runs. Even after the CA is installed, the\nalready-running gosmee process doesn't pick it up since Go loads\nthe cert pool at startup. This only affects the downstream\nconnection to the PAC controller inside the ephemeral CI cluster,\nnot the upstream SSE connection or any git provider connections.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): skip TLS verification for gosmee client in e2e tests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-08T12:23:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5bee3b79913be2d55892b4b1dc7306301701e88b",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 6.0.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-07T11:12:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "402d5c7eeece881cb082ec68e9e8b61709e39ace",
          "body": "Removed logic that blindly accepted the X-GitHub-Enterprise-Host header\nand now validate that it matches the repository URL in the webhook payload.\nAdded webhook signature verification before token generation to ensure\nthe payload hasn't been tampered with. This prevents an attacker from\nredirecting token requests to their own server by forging the Enterprise\nHost header.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: prevent GitHub Enterprise header hijacking in app token requests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-04T15:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee5d9b0a55afcd66b09ebce0d9d58d30c050cdb5",
          "body": "Use DeepCopy when reusing cached Pipeline and Task objects across\nPipelineRuns. Without this, inlineTasks mutates the cached\noriginal, contaminating subsequent runs that reference the same\nremote pipeline.\n\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(resolve): deep-copy cached resources before inlining",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "001782829e82b83ecb3da903f5a024ca0826b64c",
          "body": "Scope GitHub App installation tokens so they cannot access\nrepositories beyond the triggering one.  Normal webhooks now\nextract the repository ID from the payload and pass it to\nInstallationTokenOptions.  Incoming webhooks lack a payload\nrepo ID, so a new RepositoryNames field lets SetClient scope\nt\n[…]\npe providers and extend SetClient's\nfallback to reissue a scoped token when either field is set.\n\nCo-Authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(github): scope App token to triggering repo",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd262aa3b7ad12ea664f9d654351a8766f2c1306",
          "body": "this updates the message about deprecation of secret passing\nin URL query parameters so which would be removed in future\nrelease.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: update incoming webhook legacy params deprecation message",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-04T11:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c03760fd7181c2b5da1e4ce4356279bf322a7ae",
          "body": "Signed-off-by: Shubham Bhardwaj <shubbhar@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): redact query string from incoming webhook log",
          "author_name": "Shubham Bhardwaj",
          "author_login": "infernus01",
          "committed_at": "2026-06-03T15:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "223e39c0ec6d784114d566364a7c6eb99964172a",
          "body": "The notify-slack script looked for e2e-test-output.log which was\nnever produced by gotestsum. Switch to parsing e2e-test-output.json\nusing jq so scheduled run failures are reported to Slack.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): parse JSON test output for Slack notifications",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-03T11:45:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "885427460c5323b1267bd10eccbcd59a29baa1bf",
          "body": "The pipelines-as-code-controller ServiceAccount had cluster-wide delete\npermission on secrets that was never used in the codebase. This change\nremoves the unused permission to follow the principle of least privilege.\n\nThe controller only requires 'get' permission on secrets for:\n- Incoming webhook v\n[…]\nate, delete) for managing the\nlifecycle of pac-gitauth-* secrets.\n\nVerification:\n- All unit tests pass (2816 tests)\n- Linting passes\n- Watcher permissions unchanged\n- No functional impact\n\nFixes #2743",
          "is_bot": false,
          "headline": "fix: remove unused secrets/delete permission from controller",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-03T06:58:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d0454b7d2cd8ddef53fc8c6b147851b053acff2",
          "body": "Bumps [mxschmitt/action-tmate](https://github.com/mxschmitt/action-tmate) from 3.23 to 3.24.\n- [Release notes](https://github.com/mxschmitt/action-tmate/releases)\n- [Changelog](https://github.com/mxschmitt/action-tmate/blob/master/RELEASE.md)\n- [Commits](https://github.com/mxschmitt/action-tmate/com\n[…]\ndency-name: mxschmitt/action-tmate\n  dependency-version: '3.24'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump mxschmitt/action-tmate from 3.23 to 3.24",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T14:47:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67cfa525176645dee0e19297584436c0526f6183",
          "body": "Replace the obsolete profiling.enable ConfigMap key with\nruntime-profiling (enabled/disabled). Remove the K_METRICS_CONFIG\ncontroller section since the controller now uses ConfigMap-based\nobservability via the eventing adapter. Document that controller\nprofiling requires a pod restart as the adapter\n[…]\nconfig once\nat startup. Add CONFIG_OBSERVABILITY_NAME prerequisite for the\nwebhook.\n\nFixes #2633\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(profiling): update guide for OTel migration",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3811249c246b4084b1f2e337069c0ccf412ac516",
          "body": "Update knative/eventing to v0.49.0 which includes the pprof server\nfix (knative/eventing#9008). Also bumps k8s.io to v0.35.4,\nknative/pkg, and golang.org/x dependencies.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump knative/eventing to v0.49.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bb2f82a9cfac342fe22a948cc7b7c035d9ec4a3",
          "body": "Add configurable TLS settings for the PAC controller via\ndeployment environment variables. This allows the Tekton Operator\nto propagate TLS configuration (min version, cipher suites, curve\npreferences) to the controller without code changes.\n\n- Add pkg/tlsconfig package for parsing TLS configuration\n[…]\n_CURVE_PREFERENCES env vars to the controller deployment\n  with secure defaults matching Tekton Results\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "feat: add TLS configuration support",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-28T12:49:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dac4d6d836a59f2ec81cb3d5f0f132227b9c102",
          "body": "Deprecated the Tekton Hub catalog integration across documentation,\nconfiguration settings, and resource resolution. Added deprecation\nwarnings via logger messages, Kubernetes events on Repository CRs,\nand automated comments on pull requests when resources were resolved\nfrom Tekton Hub catalogs. Thi\n[…]\nnge prepared users for the complete\nremoval of Tekton Hub support in a future release, encouraging them\nto migrate to Artifact Hub or remote URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Add deprecation warnings for Tekton Hub integration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-28T12:06:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69fa323d60c2436976059296b33993a03ecd5553",
          "body": "When a version tag (e.g. v0.47.0) is pushed, the container workflow's\ntag sanitization converts dots to dashes producing v0-47-0 images.\nThe release pipeline generates release.yaml referencing v0.47.0\n(with dots), causing a mismatch where manifests point to nonexistent\nimage tags.\n\nAdd a condition for refs/tags/v* that uses the tag name as-is, since\nDocker image tags support dots.\n\nCloses #2741",
          "is_bot": false,
          "headline": "fix(release): preserve dots in image tags for version tag pushes",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-27T08:37:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32820cbb4c98d6b66e40e5445c20e5f85459e678",
          "body": "Enable Gitea/Forgejo provider to resolve remote taskRef URLs using\nthe provider's authenticated API instead of returning \"not\nsupported\". Supports branch, tag, and commit SHA URL formats.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gitea): implement GetTaskURI for remote task resolution",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-27T08:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "529a725ac61ca5c4e0a0e35408e36c16fe238e33",
          "body": "When a merge request originates from a fork the bot cannot access,\npost an informative comment on the MR explaining the issue. Uses\nCreateComment with an update marker to prevent duplicate comments\non reconciler retries.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitlab): post MR comment on inaccessible fork",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-25T10:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c7b0e06e41e7d3834292bd66e13dee95f195c9d",
          "body": "The watcher observes PipelineRun status but does not own it.\nDisable generated status synchronization so informer cache\ntransforms cannot trigger UpdateStatus calls against the\nPipelineRun /status subresource.\n\nThis avoids forbidden errors on clusters where the watcher\nonly has metadata and spec-level PipelineRun permissions.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): skip watcher status updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T11:46:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b9a6f1842eb647014055bb183f76fb724f0b3d6",
          "body": "The gomodguard_v2 linter was introduced in v2.12.0 but the CI\nimage was still on v2.10.1, causing lint failures with unknown\nlinter error.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "ci: update golangci-lint to v2.12.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-20T10:09:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9db1feca2d2b030a3f08ffac7f1710928f5d11f8",
          "body": "Updated gomodguard to gomodguard_v2 for the latest linter\nversion. Also disabled the inline check in govet to reduce\nfalse positives during code analysis.\n\nError was:\n\nlevel=warning msg=\"The linter 'gomodguard' is deprecated (since v2.12.0)\ndue to: new major version. Replaced by gomodguard_v2.\" leve\n[…]\nta) ^\ntest/pkg/configmap/configmap.go:22:11: inline: cannot inline: type\nparameter inference is not yet supported (govet) maps.Copy(newData,\ndata)\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: update golangci linter configuration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T03:18:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "445941b2cc745ff67afc9fcc9549a3b66a011b74",
          "body": "Previously, CEL expressions in Pipelines-as-Code only had access to\nthe core CEL operators, which limited users to basic comparisons and\nlogical expressions. Functions like join(), replace(), substring(),\nand other string/list manipulation operations were unavailable,\nforcing users to work around th\n[…]\nparison, since the output is a single\ndynamic file path that varies per test run.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cel): enable string and list extension functions in CEL expressions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T15:07:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f841d2d728d228f4008fa0cb336793e5a182cd74",
          "body": "When a pull request is merged in Bitbucket Data Center, the resulting\npush event contains a merge commit that reports no file changes. This\ncaused on-path-change and on-cel-expression filters to silently skip\nPipelineRuns because the changed files list was always empty.\n\nThe fix detects merge commit\n[…]\n for on-path-change annotation surviving a PR merge push\n- Add unit tests for getMergeCommitChanges and merge commit GetFiles path\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bitbucket-datacenter): detect changes on merged PR push",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T10:57:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 575,
      "latest_release_at": "2026-07-17T13:48:26Z",
      "latest_release_tag": "v0.48.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 51,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 5.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/openshift-pipelines/pipelines-as-code",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": false,
          "registry_url": "https://pkg.go.dev/github.com/openshift-pipelines/pipelines-as-code",
          "is_deprecated": false,
          "latest_version": "v0.49.0",
          "repository_url": "https://github.com/openshift-pipelines/pipelines-as-code",
          "versions_count": 113,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-06T12:02:19Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 15
        }
      ]
    },
    "popularity": {
      "forks": 135,
      "stars": 203,
      "watchers": 9,
      "fork_history": {
        "days": [
          {
            "date": "2021-04-06",
            "count": 1
          },
          {
            "date": "2021-04-22",
            "count": 1
          },
          {
            "date": "2021-05-20",
            "count": 1
          },
          {
            "date": "2021-07-01",
            "count": 1
          },
          {
            "date": "2021-08-12",
            "count": 1
          },
          {
            "date": "2021-08-16",
            "count": 1
          },
          {
            "date": "2021-08-29",
            "count": 1
          },
          {
            "date": "2021-09-14",
            "count": 1
          },
          {
            "date": "2021-10-14",
            "count": 1
          },
          {
            "date": "2021-11-11",
            "count": 1
          },
          {
            "date": "2021-11-15",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-11-29",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-21",
            "count": 1
          },
          {
            "date": "2022-01-26",
            "count": 1
          },
          {
            "date": "2022-02-07",
            "count": 1
          },
          {
            "date": "2022-02-15",
            "count": 1
          },
          {
            "date": "2022-03-11",
            "count": 1
          },
          {
            "date": "2022-03-24",
            "count": 1
          },
          {
            "date": "2022-03-25",
            "count": 1
          },
          {
            "date": "2022-04-04",
            "count": 2
          },
          {
            "date": "2022-04-07",
            "count": 1
          },
          {
            "date": "2022-04-18",
            "count": 1
          },
          {
            "date": "2022-06-08",
            "count": 1
          },
          {
            "date": "2022-06-09",
            "count": 2
          },
          {
            "date": "2022-07-07",
            "count": 1
          },
          {
            "date": "2022-07-16",
            "count": 1
          },
          {
            "date": "2022-08-17",
            "count": 1
          },
          {
            "date": "2022-08-30",
            "count": 1
          },
          {
            "date": "2022-10-05",
            "count": 1
          },
          {
            "date": "2022-10-16",
            "count": 1
          },
          {
            "date": "2022-11-01",
            "count": 1
          },
          {
            "date": "2022-11-18",
            "count": 1
          },
          {
            "date": "2023-01-06",
            "count": 1
          },
          {
            "date": "2023-01-11",
            "count": 1
          },
          {
            "date": "2023-01-13",
            "count": 1
          },
          {
            "date": "2023-01-19",
            "count": 1
          },
          {
            "date": "2023-02-14",
            "count": 1
          },
          {
            "date": "2023-03-09",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 1
          },
          {
            "date": "2023-03-26",
            "count": 2
          },
          {
            "date": "2023-03-29",
            "count": 2
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-26",
            "count": 1
          },
          {
            "date": "2023-05-03",
            "count": 1
          },
          {
            "date": "2023-05-17",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-12",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-10-15",
            "count": 1
          },
          {
            "date": "2023-10-25",
            "count": 1
          },
          {
            "date": "2023-11-06",
            "count": 1
          },
          {
            "date": "2023-11-16",
            "count": 1
          },
          {
            "date": "2023-12-07",
            "count": 1
          },
          {
            "date": "2023-12-13",
            "count": 1
          },
          {
            "date": "2024-02-04",
            "count": 1
          },
          {
            "date": "2024-03-14",
            "count": 1
          },
          {
            "date": "2024-03-22",
            "count": 2
          },
          {
            "date": "2024-04-08",
            "count": 1
          },
          {
            "date": "2024-06-04",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-06-28",
            "count": 1
          },
          {
            "date": "2024-07-02",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-10-15",
            "count": 1
          },
          {
            "date": "2024-11-26",
            "count": 1
          },
          {
            "date": "2024-11-28",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-03",
            "count": 1
          },
          {
            "date": "2024-12-27",
            "count": 1
          },
          {
            "date": "2025-01-03",
            "count": 1
          },
          {
            "date": "2025-01-18",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-01-30",
            "count": 2
          },
          {
            "date": "2025-02-06",
            "count": 1
          },
          {
            "date": "2025-02-11",
            "count": 1
          },
          {
            "date": "2025-02-23",
            "count": 1
          },
          {
            "date": "2025-02-28",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 1
          },
          {
            "date": "2025-03-20",
            "count": 1
          },
          {
            "date": "2025-04-15",
            "count": 1
          },
          {
            "date": "2025-05-08",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-06-05",
            "count": 1
          },
          {
            "date": "2025-06-13",
            "count": 1
          },
          {
            "date": "2025-06-20",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          },
          {
            "date": "2025-07-20",
            "count": 1
          },
          {
            "date": "2025-08-04",
            "count": 1
          },
          {
            "date": "2025-08-10",
            "count": 1
          },
          {
            "date": "2025-09-30",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-11-21",
            "count": 1
          },
          {
            "date": "2025-12-17",
            "count": 1
          },
          {
            "date": "2026-01-17",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-19",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-18",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-05-13",
            "count": 2
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 1
          },
          {
            "date": "2026-06-18",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 129,
        "total_forks": 135
      },
      "star_history": {
        "days": [
          {
            "date": "2021-05-27",
            "count": 2
          },
          {
            "date": "2021-06-07",
            "count": 1
          },
          {
            "date": "2021-06-25",
            "count": 1
          },
          {
            "date": "2021-06-29",
            "count": 1
          },
          {
            "date": "2021-07-03",
            "count": 1
          },
          {
            "date": "2021-07-04",
            "count": 1
          },
          {
            "date": "2021-07-05",
            "count": 1
          },
          {
            "date": "2021-07-06",
            "count": 2
          },
          {
            "date": "2021-09-01",
            "count": 1
          },
          {
            "date": "2021-09-08",
            "count": 1
          },
          {
            "date": "2021-09-19",
            "count": 1
          },
          {
            "date": "2021-09-21",
            "count": 1
          },
          {
            "date": "2021-10-13",
            "count": 1
          },
          {
            "date": "2021-10-26",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 2
          },
          {
            "date": "2021-11-23",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-12-09",
            "count": 1
          },
          {
            "date": "2021-12-10",
            "count": 2
          },
          {
            "date": "2021-12-15",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-08",
            "count": 1
          },
          {
            "date": "2022-01-11",
            "count": 1
          },
          {
            "date": "2022-02-08",
            "count": 1
          },
          {
            "date": "2022-03-01",
            "count": 1
          },
          {
            "date": "2022-03-04",
            "count": 1
          },
          {
            "date": "2022-03-08",
            "count": 1
          },
          {
            "date": "2022-03-16",
            "count": 1
          },
          {
            "date": "2022-03-17",
            "count": 1
          },
          {
            "date": "2022-04-01",
            "count": 1
          },
          {
            "date": "2022-04-08",
            "count": 1
          },
          {
            "date": "2022-04-11",
            "count": 1
          },
          {
            "date": "2022-04-12",
            "count": 1
          },
          {
            "date": "2022-04-19",
            "count": 1
          },
          {
            "date": "2022-04-27",
            "count": 1
          },
          {
            "date": "2022-04-29",
            "count": 1
          },
          {
            "date": "2022-05-13",
            "count": 1
          },
          {
            "date": "2022-05-14",
            "count": 1
          },
          {
            "date": "2022-05-17",
            "count": 1
          },
          {
            "date": "2022-05-25",
            "count": 1
          },
          {
            "date": "2022-06-10",
            "count": 1
          },
          {
            "date": "2022-06-14",
            "count": 1
          },
          {
            "date": "2022-06-22",
            "count": 1
          },
          {
            "date": "2022-06-25",
            "count": 1
          },
          {
            "date": "2022-07-14",
            "count": 1
          },
          {
            "date": "2022-07-21",
            "count": 1
          },
          {
            "date": "2022-08-05",
            "count": 1
          },
          {
            "date": "2022-08-07",
            "count": 1
          },
          {
            "date": "2022-08-23",
            "count": 1
          },
          {
            "date": "2022-10-19",
            "count": 1
          },
          {
            "date": "2022-11-05",
            "count": 1
          },
          {
            "date": "2022-12-13",
            "count": 1
          },
          {
            "date": "2022-12-14",
            "count": 1
          },
          {
            "date": "2022-12-29",
            "count": 1
          },
          {
            "date": "2023-01-17",
            "count": 1
          },
          {
            "date": "2023-01-27",
            "count": 2
          },
          {
            "date": "2023-02-03",
            "count": 1
          },
          {
            "date": "2023-02-06",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-02-16",
            "count": 1
          },
          {
            "date": "2023-03-01",
            "count": 1
          },
          {
            "date": "2023-03-15",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 2
          },
          {
            "date": "2023-03-28",
            "count": 1
          },
          {
            "date": "2023-04-08",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-12",
            "count": 1
          },
          {
            "date": "2023-04-15",
            "count": 1
          },
          {
            "date": "2023-04-21",
            "count": 1
          },
          {
            "date": "2023-04-24",
            "count": 1
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-30",
            "count": 1
          },
          {
            "date": "2023-05-02",
            "count": 1
          },
          {
            "date": "2023-05-25",
            "count": 1
          },
          {
            "date": "2023-05-31",
            "count": 1
          },
          {
            "date": "2023-06-01",
            "count": 1
          },
          {
            "date": "2023-06-08",
            "count": 1
          },
          {
            "date": "2023-06-20",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-04",
            "count": 1
          },
          {
            "date": "2023-07-08",
            "count": 1
          },
          {
            "date": "2023-07-13",
            "count": 1
          },
          {
            "date": "2023-07-24",
            "count": 1
          },
          {
            "date": "2023-08-28",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-20",
            "count": 1
          },
          {
            "date": "2023-09-25",
            "count": 2
          },
          {
            "date": "2023-10-03",
            "count": 1
          },
          {
            "date": "2023-10-30",
            "count": 1
          },
          {
            "date": "2023-11-10",
            "count": 1
          },
          {
            "date": "2023-12-08",
            "count": 1
          },
          {
            "date": "2023-12-19",
            "count": 1
          },
          {
            "date": "2023-12-21",
            "count": 1
          },
          {
            "date": "2023-12-28",
            "count": 1
          },
          {
            "date": "2024-01-02",
            "count": 1
          },
          {
            "date": "2024-01-19",
            "count": 1
          },
          {
            "date": "2024-02-07",
            "count": 2
          },
          {
            "date": "2024-02-20",
            "count": 1
          },
          {
            "date": "2024-02-26",
            "count": 1
          },
          {
            "date": "2024-02-28",
            "count": 1
          },
          {
            "date": "2024-03-11",
            "count": 1
          },
          {
            "date": "2024-03-27",
            "count": 1
          },
          {
            "date": "2024-04-02",
            "count": 1
          },
          {
            "date": "2024-04-09",
            "count": 2
          },
          {
            "date": "2024-04-25",
            "count": 1
          },
          {
            "date": "2024-05-06",
            "count": 1
          },
          {
            "date": "2024-05-08",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-18",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-07-21",
            "count": 1
          },
          {
            "date": "2024-08-02",
            "count": 1
          },
          {
            "date": "2024-08-08",
            "count": 1
          },
          {
            "date": "2024-08-13",
            "count": 1
          },
          {
            "date": "2024-09-27",
            "count": 1
          },
          {
            "date": "2024-10-16",
            "count": 1
          },
          {
            "date": "2024-10-20",
            "count": 1
          },
          {
            "date": "2024-10-27",
            "count": 1
          },
          {
            "date": "2024-10-28",
            "count": 1
          },
          {
            "date": "2024-11-10",
            "count": 1
          },
          {
            "date": "2024-11-15",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-25",
            "count": 1
          },
          {
            "date": "2025-01-09",
            "count": 2
          },
          {
            "date": "2025-02-07",
            "count": 1
          },
          {
            "date": "2025-02-12",
            "count": 4
          },
          {
            "date": "2025-02-13",
            "count": 2
          },
          {
            "date": "2025-02-24",
            "count": 1
          },
          {
            "date": "2025-02-26",
            "count": 1
          },
          {
            "date": "2025-03-19",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-04-23",
            "count": 1
          },
          {
            "date": "2025-05-21",
            "count": 2
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-30",
            "count": 1
          },
          {
            "date": "2025-06-07",
            "count": 1
          },
          {
            "date": "2025-06-11",
            "count": 4
          },
          {
            "date": "2025-07-01",
            "count": 2
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-08-30",
            "count": 1
          },
          {
            "date": "2025-10-10",
            "count": 1
          },
          {
            "date": "2025-10-11",
            "count": 1
          },
          {
            "date": "2025-10-22",
            "count": 1
          },
          {
            "date": "2025-11-07",
            "count": 1
          },
          {
            "date": "2025-11-19",
            "count": 1
          },
          {
            "date": "2025-11-26",
            "count": 1
          },
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-01-30",
            "count": 1
          },
          {
            "date": "2026-02-03",
            "count": 1
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-08",
            "count": 1
          },
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-02-10",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-01",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-14",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 1
          },
          {
            "date": "2026-04-23",
            "count": 1
          },
          {
            "date": "2026-04-26",
            "count": 1
          },
          {
            "date": "2026-05-02",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 2
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-30",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 2
          },
          {
            "date": "2026-07-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 203,
        "total_stars": 203
      },
      "open_issues_and_prs": 80
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "samples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
        "vendor/github.com/emicklei/go-restful/v3/Makefile",
        "vendor/github.com/felixge/httpsnoop/Makefile",
        "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
        "vendor/github.com/juju/ansiterm/Makefile",
        "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
        "vendor/github.com/munnerz/goautoneg/Makefile",
        "vendor/github.com/pkg/errors/Makefile",
        "vendor/github.com/prometheus/procfs/Makefile",
        "vendor/github.com/spf13/cobra/Makefile",
        "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
        "vendor/go.opentelemetry.io/otel/Makefile",
        "vendor/go.uber.org/atomic/Makefile",
        "vendor/go.uber.org/multierr/Makefile",
        "vendor/go.uber.org/zap/Makefile",
        "vendor/google.golang.org/grpc/Makefile",
        "vendor/sigs.k8s.io/json/Makefile"
      ],
      "api_schema_files": [
        "vendor/github.com/google/gnostic-models/extensions/extension.proto",
        "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
        "vendor/k8s.io/api/admission/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
        "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
        "vendor/k8s.io/api/apps/v1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta2/generated.proto",
        "vendor/k8s.io/api/authentication/v1/generated.proto",
        "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
        "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
        "vendor/k8s.io/api/authorization/v1/generated.proto",
        "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v2/generated.proto",
        "vendor/k8s.io/api/batch/v1/generated.proto",
        "vendor/k8s.io/api/batch/v1beta1/generated.proto",
        "vendor/k8s.io/api/certificates/v1/generated.proto",
        "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
        "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
        "vendor/k8s.io/api/coordination/v1/generated.proto",
        "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
        "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
        "vendor/k8s.io/api/core/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
        "vendor/k8s.io/api/events/v1/generated.proto",
        "vendor/k8s.io/api/events/v1beta1/generated.proto",
        "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
        "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
        "vendor/k8s.io/api/networking/v1/generated.proto",
        "vendor/k8s.io/api/networking/v1beta1/generated.proto",
        "vendor/k8s.io/api/node/v1/generated.proto",
        "vendor/k8s.io/api/node/v1alpha1/generated.proto",
        "vendor/k8s.io/api/node/v1beta1/generated.proto",
        "vendor/k8s.io/api/policy/v1/generated.proto",
        "vendor/k8s.io/api/policy/v1beta1/generated.proto",
        "vendor/k8s.io/api/rbac/v1/generated.proto",
        "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
        "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1/generated.proto",
        "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
        "vendor/k8s.io/api/resource/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1beta2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1/generated.proto",
        "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
        "vendor/k8s.io/api/storage/v1/generated.proto",
        "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
        "vendor/k8s.io/api/storage/v1beta1/generated.proto",
        "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
        "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 92818,
      "source_files_sampled": 518,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
        "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 12245
    },
    "dependencies": {
      "manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2023-1901",
              "GO-2026-4730"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": 700
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 2,
          "critical": 1
        },
        "advisory_count": 4,
        "affected_count": 3,
        "assessed_count": 156,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 7,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.0"
        },
        {
          "name": "github.com/AlecAivazis/survey/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.3.7"
        },
        {
          "name": "github.com/bradleyfalzon/ghinstallation/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.18.0"
        },
        {
          "name": "github.com/chzyer/readline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/cloudevents/sdk-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.16.2"
        },
        {
          "name": "github.com/fvbommel/sortorder",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/gobwas/glob",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.3"
        },
        {
          "name": "github.com/google/cel-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.29.2"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/scrape",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260403152401-96a365122246"
        },
        {
          "name": "github.com/google/go-github/v84",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v84.0.0"
        },
        {
          "name": "github.com/google/go-github/v85",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v85.0.0"
        },
        {
          "name": "github.com/hako/durafmt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20210608085754-5c1018a4e16b"
        },
        {
          "name": "github.com/jenkins-x/go-scm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.15.31"
        },
        {
          "name": "github.com/jonboulle/clockwork",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.0"
        },
        {
          "name": "github.com/juju/ansiterm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ktrysmt/go-bitbucket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.10.0"
        },
        {
          "name": "github.com/mattn/go-colorable",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.15"
        },
        {
          "name": "github.com/mattn/go-isatty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.23"
        },
        {
          "name": "github.com/mgutz/ansi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200706080929-d51e80ef957d"
        },
        {
          "name": "github.com/mitchellh/mapstructure",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/pkg/errors",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tektoncd/pipeline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.0"
        },
        {
          "name": "gitlab.com/gitlab-org/api/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.46.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260312153236-7ab1446f8b90"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "gopkg.in/yaml.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.4.0"
        },
        {
          "name": "gotest.tools/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.5.2"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260319190234-28399d86e0b5"
        },
        {
          "name": "knative.dev/eventing",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.2"
        },
        {
          "name": "knative.dev/pkg",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260622140654-39ebae2ee2dc"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/golang-jwt/jwt/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.5.2"
        },
        {
          "name": "github.com/prometheus/client_model",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.2"
        },
        {
          "name": "github.com/prometheus/common",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260526163538-3dc84a4a5aaa"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
        },
        {
          "name": "k8s.io/klog/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.140.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
            "direct": true,
            "version": "v3.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecaivazis/survey/v2",
            "direct": true,
            "version": "v2.3.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bradleyfalzon/ghinstallation/v2",
            "direct": true,
            "version": "v2.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chzyer/readline",
            "direct": true,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/v2",
            "direct": true,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fvbommel/sortorder",
            "direct": true,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": true,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v4",
            "direct": true,
            "version": "v4.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": true,
            "version": "v0.29.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/scrape",
            "direct": true,
            "version": "v0.0.0-20260403152401-96a365122246",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v84",
            "direct": true,
            "version": "v84.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v85",
            "direct": true,
            "version": "v85.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hako/durafmt",
            "direct": true,
            "version": "v0.0.0-20210608085754-5c1018a4e16b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jenkins-x/go-scm",
            "direct": true,
            "version": "v1.15.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jonboulle/clockwork",
            "direct": true,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/juju/ansiterm",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ktrysmt/go-bitbucket",
            "direct": true,
            "version": "v0.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": true,
            "version": "v0.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": true,
            "version": "v0.0.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgutz/ansi",
            "direct": true,
            "version": "v0.0.0-20200706080929-d51e80ef957d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": true,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "ecosystem": "go"
          },
          {
            "name": "gitlab.com/gitlab-org/api/client-go",
            "direct": true,
            "version": "v1.46.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": true,
            "version": "v1.28.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20260312153236-7ab1446f8b90",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": true,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.12-0.20260120151049-f2248ac996af",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": true,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gotest.tools/v3",
            "direct": true,
            "version": "v3.5.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": true,
            "version": "v2.140.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": true,
            "version": "v0.0.0-20260319190234-28399d86e0b5",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/eventing",
            "direct": true,
            "version": "v0.49.2",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/pkg",
            "direct": true,
            "version": "v0.0.0-20260622140654-39ebae2ee2dc",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/42wim/httpsig",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/andybalholm/cascadia",
            "direct": false,
            "version": "v1.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr/antlr4/runtime/go/antlr",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blang/semver/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blendle/zapdriver",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cert-manager/cert-manager",
            "direct": false,
            "version": "v1.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/observability/opentelemetry/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/sql/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-oidc/v3",
            "direct": false,
            "version": "v3.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davidmz/go-pageant",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/evanphx/json-patch/v5",
            "direct": false,
            "version": "v5.9.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-fed/httpsig",
            "direct": false,
            "version": "v1.1.1-0.20201223112313-55836744818e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/zapr",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/errors",
            "direct": false,
            "version": "v0.22.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.22.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/strfmt",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/cmdutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/conv",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/fileutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonname",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/loading",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/mangling",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/netutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/stringutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/typeutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/yamlutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cleanhttp",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-retryablehttp",
            "direct": false,
            "version": "v0.7.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-version",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/imfing/hextra",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kballard/go-shellquote",
            "direct": false,
            "version": "v0.0.0-20180428030007-95032a82bc51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kelseyhightower/envconfig",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lunixbochs/vtclean",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": false,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/puerkitobio/goquery",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/date",
            "direct": false,
            "version": "v1.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/plural",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/robfig/cron/v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xlzd/gotp",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": false,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/automaxprocs",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "gomodules.xyz/jsonpatch/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": false,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20260330154417-16be699c7b31",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api",
            "direct": false,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.2",
            "ecosystem": "go"
          },
          {
            "name": "@axe-core/playwright",
            "direct": false,
            "version": "^4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "^1.49.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/postcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          },
          {
            "name": "postcss-cli",
            "direct": false,
            "version": "^11.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "^3.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "prettier-plugin-go-template",
            "direct": false,
            "version": "^0.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 163,
        "direct_count": 54,
        "indirect_count": 109
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 2014,
        "open_issues": 70,
        "closed_ratio": 0.88,
        "closed_issues": 515,
        "closed_unmerged_prs": 252
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "chmouel",
          "commits": 2290,
          "avatar_url": "https://avatars.githubusercontent.com/u/98980?v=4"
        },
        {
          "type": "User",
          "login": "zakisk",
          "commits": 223,
          "avatar_url": "https://avatars.githubusercontent.com/u/49492007?v=4"
        },
        {
          "type": "User",
          "login": "savitaashture",
          "commits": 107,
          "avatar_url": "https://avatars.githubusercontent.com/u/9441662?v=4"
        },
        {
          "type": "User",
          "login": "theakshaypant",
          "commits": 84,
          "avatar_url": "https://avatars.githubusercontent.com/u/16561942?v=4"
        },
        {
          "type": "User",
          "login": "piyush-garg",
          "commits": 31,
          "avatar_url": "https://avatars.githubusercontent.com/u/19270240?v=4"
        },
        {
          "type": "User",
          "login": "aThorp96",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/28596783?v=4"
        },
        {
          "type": "User",
          "login": "sm43",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/55777192?v=4"
        },
        {
          "type": "User",
          "login": "PuneetPunamiya",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/32545638?v=4"
        },
        {
          "type": "User",
          "login": "vdemeester",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/6508?v=4"
        },
        {
          "type": "User",
          "login": "infernus01",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/89133323?v=4"
        }
      ],
      "contributors_sampled": 59,
      "top_contributor_share": 0.776
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "codecov.yaml",
        "container.yaml",
        "e2e.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml",
        ".golangci.yml",
        ".pylintrc"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 8,
            "reason": "Found 17/20 approved changesets -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 33 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 8,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
        "ran_at": "2026-07-22T02:12:12Z",
        "aggregate_score": 5.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T13:36:38Z",
      "oldest_open_prs": [
        {
          "number": 2655,
          "created_at": "2026-04-08T09:02:29Z",
          "last_comment_at": "2026-07-16T11:44:33Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2848,
          "created_at": "2026-07-10T19:24:17Z",
          "last_comment_at": "2026-07-21T07:29:37Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2854,
          "created_at": "2026-07-15T12:23:38Z",
          "last_comment_at": "2026-07-15T18:09:09Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2856,
          "created_at": "2026-07-16T08:41:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2859,
          "created_at": "2026-07-16T11:10:41Z",
          "last_comment_at": "2026-07-21T06:28:58Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2867,
          "created_at": "2026-07-21T11:07:16Z",
          "last_comment_at": "2026-07-21T11:07:40Z",
          "last_comment_author": "pipelines-as-code"
        },
        {
          "number": 2868,
          "created_at": "2026-07-21T11:09:17Z",
          "last_comment_at": "2026-07-21T11:47:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2869,
          "created_at": "2026-07-21T12:56:50Z",
          "last_comment_at": "2026-07-21T13:02:50Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2870,
          "created_at": "2026-07-21T13:02:08Z",
          "last_comment_at": "2026-07-21T13:14:09Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 2871,
          "created_at": "2026-07-21T13:30:25Z",
          "last_comment_at": "2026-07-21T13:33:08Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-21T10:21:44Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 508,
          "created_at": "2022-04-01T13:59:38Z",
          "last_comment_at": "2026-02-26T11:40:23Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 724,
          "created_at": "2022-06-09T08:42:43Z",
          "last_comment_at": "2025-10-15T09:37:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 732,
          "created_at": "2022-06-20T06:56:49Z",
          "last_comment_at": "2026-02-26T11:40:05Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 780,
          "created_at": "2022-08-01T15:57:45Z",
          "last_comment_at": "2026-02-26T11:39:49Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 790,
          "created_at": "2022-08-09T12:42:02Z",
          "last_comment_at": "2026-02-26T11:40:07Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 828,
          "created_at": "2022-09-09T12:32:05Z",
          "last_comment_at": "2026-02-26T11:40:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 924,
          "created_at": "2022-10-17T13:23:32Z",
          "last_comment_at": "2026-02-26T11:40:19Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 933,
          "created_at": "2022-10-20T10:25:52Z",
          "last_comment_at": "2026-02-26T11:40:43Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 934,
          "created_at": "2022-10-20T10:29:41Z",
          "last_comment_at": "2026-02-26T11:40:18Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 998,
          "created_at": "2022-11-21T07:04:20Z",
          "last_comment_at": "2026-02-26T11:40:36Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1049,
          "created_at": "2022-12-05T12:02:37Z",
          "last_comment_at": "2026-02-26T15:23:46Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1070,
          "created_at": "2022-12-12T15:15:51Z",
          "last_comment_at": "2026-02-26T11:51:25Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1098,
          "created_at": "2023-01-05T11:28:07Z",
          "last_comment_at": "2026-02-26T11:40:08Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1112,
          "created_at": "2023-01-19T11:18:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1152,
          "created_at": "2023-02-14T11:04:32Z",
          "last_comment_at": "2026-02-26T11:51:20Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1227,
          "created_at": "2023-04-12T07:07:13Z",
          "last_comment_at": "2026-02-26T11:41:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1235,
          "created_at": "2023-04-13T14:52:59Z",
          "last_comment_at": "2026-02-26T13:50:34Z",
          "last_comment_author": "tekton-pac-bot"
        },
        {
          "number": 1237,
          "created_at": "2023-04-17T09:46:26Z",
          "last_comment_at": "2026-02-26T11:40:55Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1246,
          "created_at": "2023-04-22T12:57:18Z",
          "last_comment_at": "2026-02-26T11:42:27Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1291,
          "created_at": "2023-05-18T07:12:16Z",
          "last_comment_at": "2026-03-06T10:32:53Z",
          "last_comment_author": "mikem-of"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/tektoncd/pipelines-as-code",
    "host": "github.com",
    "name": "pipelines-as-code",
    "owner": "tektoncd"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 79,
      "inputs": {
        "security": 62,
        "vitality": 95,
        "community": 75,
        "governance": 65,
        "engineering": 96
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 95,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 575,
              "human_commit_share": 0.9,
              "days_since_last_push": 0,
              "active_weeks_last_year": 51
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "51/52 weeks with commits",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "575 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 575
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.48.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 5.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 75,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "forks": 135,
              "stars": 203,
              "watchers": 9,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "203 stars",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 203
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "135 forks",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "9 watchers",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 65,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 59,
              "top_contributor_share": 0.776
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 78% of commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 78
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "59 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 59
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "merged_prs": 2014,
              "open_issues": 70,
              "closed_issues": 515,
              "issue_closed_ratio": 0.88,
              "closed_unmerged_prs": 252
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "88% of issues closed",
                "points": 41.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 88
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2014/2266 decided PRs merged",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2014,
                      "decided": 2266
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 12,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "followers": 1421,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "tektoncd",
              "public_repos": 24,
              "account_age_days": 2715
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,421 followers of tektoncd",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1421,
                      "login": "tektoncd"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "24 public repos, account ~7 yr old",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 24
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 96,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "tekton-pipelines",
                "tekton",
                "github",
                "pipeline",
                "kubernetes",
                "continuous-delivery",
                "pipelines-as-code",
                "gitlab",
                "ci",
                "bitbucket",
                "gitops"
              ],
              "has_wiki": true,
              "homepage": "https://pipelinesascode.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pipelinesascode.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "11 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 156 resolved dependencies against OSV; 7 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 156
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 7
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "source": "osv",
              "advisories": 4,
              "affected_packages": 3,
              "assessed_packages": 156,
              "unassessed_packages": 7,
              "affected_by_severity": "critical 1, unknown 2",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: github.com/tektoncd/pipeline v1.14.0 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "github.com/tektoncd/pipeline v1.14.0 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 700 days ago",
                "points": 37.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 700
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 156,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 17
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 96,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
                "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 12245
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 90 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
                "vendor/github.com/emicklei/go-restful/v3/Makefile",
                "vendor/github.com/felixge/httpsnoop/Makefile",
                "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
                "vendor/github.com/juju/ansiterm/Makefile",
                "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
                "vendor/github.com/munnerz/goautoneg/Makefile",
                "vendor/github.com/pkg/errors/Makefile",
                "vendor/github.com/prometheus/procfs/Makefile",
                "vendor/github.com/spf13/cobra/Makefile",
                "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
                "vendor/go.opentelemetry.io/otel/Makefile",
                "vendor/go.uber.org/atomic/Makefile",
                "vendor/go.uber.org/multierr/Makefile",
                "vendor/go.uber.org/zap/Makefile",
                "vendor/google.golang.org/grpc/Makefile",
                "vendor/sigs.k8s.io/json/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.26,
              "toolchain_manifests": [
                "docs/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.1
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "26 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 26,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "10 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 92818,
              "source_files_sampled": 518,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/518 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 518,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "vendor/github.com/google/gnostic-models/extensions/extension.proto",
                "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
                "vendor/k8s.io/api/admission/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
                "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
                "vendor/k8s.io/api/apps/v1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta2/generated.proto",
                "vendor/k8s.io/api/authentication/v1/generated.proto",
                "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
                "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
                "vendor/k8s.io/api/authorization/v1/generated.proto",
                "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v2/generated.proto",
                "vendor/k8s.io/api/batch/v1/generated.proto",
                "vendor/k8s.io/api/batch/v1beta1/generated.proto",
                "vendor/k8s.io/api/certificates/v1/generated.proto",
                "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
                "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
                "vendor/k8s.io/api/coordination/v1/generated.proto",
                "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
                "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
                "vendor/k8s.io/api/core/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
                "vendor/k8s.io/api/events/v1/generated.proto",
                "vendor/k8s.io/api/events/v1beta1/generated.proto",
                "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
                "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
                "vendor/k8s.io/api/networking/v1/generated.proto",
                "vendor/k8s.io/api/networking/v1beta1/generated.proto",
                "vendor/k8s.io/api/node/v1/generated.proto",
                "vendor/k8s.io/api/node/v1alpha1/generated.proto",
                "vendor/k8s.io/api/node/v1beta1/generated.proto",
                "vendor/k8s.io/api/policy/v1/generated.proto",
                "vendor/k8s.io/api/policy/v1beta1/generated.proto",
                "vendor/k8s.io/api/rbac/v1/generated.proto",
                "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
                "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1/generated.proto",
                "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
                "vendor/k8s.io/api/resource/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1beta2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1/generated.proto",
                "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
                "vendor/k8s.io/api/storage/v1/generated.proto",
                "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
                "vendor/k8s.io/api/storage/v1beta1/generated.proto",
                "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
                "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T02:12:45.089451Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tektoncd/pipelines-as-code.svg",
  "full_name": "tektoncd/pipelines-as-code",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.26.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.