Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-29 14:57 UTC

BARGHEST-ngo / tailscale-patched

Customised Tailscale for MESH

GoBSD-3-Clause★ 0 stars⑂ 0 forkssince Jun 2026View on GitHub ↗

BARGHEST-ngo/tailscale-patched holds a health index of 67 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (80/100) and lowest on Community & Adoption (40/100). It was last updated 9 days ago. 3 contributors account for most of its recent work.

67
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

67
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

BARGHESTOrganization
31 followers10 public repossince Mar 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gotailscale.comv1.102.0-2325 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

79Good · 22% of overall
How it's scored
28.8/36Push recency — last push 9 days ago
31.8/36Commit cadence — 46/52 weeks with commits
18/18Commit volume — 1,292 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year1,292
human_commit_share1
days_since_last_push9
active_weeks_last_year46
How it's scored
16.2/27Ships releases — 95 version tags (no GitHub releases)
27/36Release recency — latest release 165 days ago
27/27Release cadence — a release every ~8.8 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count95
latest_release_tagv1.94.2
releases_from_tagsyes
days_since_latest_release165
mean_days_between_releases8.8
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

40At risk · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

85Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (BSD-3-Clause)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

74Good · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
14.2/22.5Commit distribution — top contributor authored 37% of commits
13.5/13.5Contributor breadth — 99 contributors
10/10OpenSSF Scorecard: Contributors — project has 33 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled99
top_contributor_share0.367
How it's scored
0/46.8Issue resolution — no issues or no data
38.2/38.3PR acceptance — 7/7 decided PRs merged
3/15OpenSSF Scorecard: Code-Review — Found 6/22 approved changesets -- score normalized to 2
Inputs used
merged_prs7
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
10.8/25Owner reach — 31 followers of BARGHEST-ngo
10.3/25Track record — 10 public repos, account ~1 yr old
Inputs used
followers31
owner_typeOrganization
is_verified
owner_loginBARGHEST-ngo
public_repos10
account_age_days496
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 5 days ago
20/20Version history — 232 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagestailscale.com
ecosystemsgo
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

80Good · 20% of overall
How it's scored
24/24CI workflows — 20 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
4.5/7.5Binary-Artifacts — binaries present in source code
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 6/22 approved changesets -- score normalized to 2
2.5/2.5Contributors — project has 33 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 97 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.6
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

66Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 89 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.89
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — client/web/tsconfig.json, cmd/tsconnect/tsconfig.json
10/10Reproducible environment — Dockerfile, Nix, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
5/8Automated maintenance — dependency automation configured, none observed in the sampled commits
7/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
Inputs used
has_nixyes
has_testsyes
lockfilesCargo.lock, go.sum, yarn.lock
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configsclient/web/tsconfig.json, cmd/tsconnect/tsconfig.json
agent_commit_share0
toolchain_manifestsgo.mod, tool/goexe/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
54.4/55Manageable file sizes — 23/2,180 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes276,136
source_files_sampled2,180
oversized_source_files23
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — example, examples
Inputs used
example_dirsexample, examples
has_mcp_signalno
api_schema_files

Key facts

0GitHub stars
99contributors
1,292commits, last 12 months
9days since last push
95releases
3bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 5.6 / 10
5.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-29 14:56 UTC

6Binary-Artifactsbinaries present in source code
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 6/22 approved changesets -- score normalized to 2
10Contributorsproject has 33 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities97 existing vulnerabilities detected
Direct dependencies 156
RegistryPackageVersion constraintManifest
Gofilippo.io/mkcertv1.4.4go.mod
Gofyne.io/systrayv1.11.1-0.20250812065214-4856ac3adc3cgo.mod
Gogithub.com/BARGHEST-ngo/amnezia-wireguard-gov0.2.0-alpha.2go.mod
Gogithub.com/BARGHEST-ngo/androidqf_meshv0.2.0go.mod
Gogithub.com/Kodeworks/golang-image-icov0.0.0-20141118225523-73f0f4cfade9go.mod
Gogithub.com/akutz/memconnv0.1.0go.mod
Gogithub.com/alexbrainman/sspiv0.0.0-20231016080023-1a75b4708caago.mod
Gogithub.com/andybalholm/brotliv1.1.0go.mod
Gogithub.com/atotto/clipboardv0.1.4go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.41.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.29.5go.mod
Gogithub.com/aws/aws-sdk-go-v2/feature/s3/managerv1.17.58go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.75.3go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/ssmv1.44.7go.mod
Gogithub.com/axiomhq/hyperloglogv0.0.0-20240319100328-84253e514e02go.mod
Gogithub.com/botherder/go-savetimev1.5.0go.mod
Gogithub.com/bradfitz/go-tool-cachev0.0.0-20260216153636-9e5201344fe5go.mod
Gogithub.com/bradfitz/monogokv0.0.0-20260429173803-229ef7981a6bgo.mod
Gogithub.com/bramvdbogaerde/go-scpv1.4.0go.mod
Gogithub.com/cilium/ebpfv0.16.0go.mod
Gogithub.com/coder/websocketv1.8.12go.mod
Gogithub.com/coreos/go-iptablesv0.7.1-0.20240112124308-65c67c9f46e6go.mod
Gogithub.com/coreos/go-systemdv0.0.0-20191104093116-d3cd4ed1dbcfgo.mod
Gogithub.com/creachadair/mdsv0.25.9go.mod
Gogithub.com/creachadair/msyncv0.7.1go.mod
Gogithub.com/creachadair/taskgroupv0.13.2go.mod
Gogithub.com/creack/ptyv1.1.24go.mod
Gogithub.com/dblohm7/wingoesv0.0.0-20240119213807-a09d6be7affago.mod
Gogithub.com/digitalocean/go-smbiosv0.0.0-20180907143718-390a4f403a8ego.mod
Gogithub.com/distribution/referencev0.6.0go.mod
Gogithub.com/djherbis/timesv1.6.0go.mod
Gogithub.com/dsnet/tryv0.0.3go.mod
Gogithub.com/elastic/crd-ref-docsv0.0.12go.mod
Gogithub.com/evanw/esbuildv0.19.11go.mod
Gogithub.com/fogleman/ggv1.3.0go.mod
Gogithub.com/frankban/quicktestv1.14.6go.mod
Gogithub.com/fxamacker/cbor/v2v2.9.0go.mod
Gogithub.com/gaissmai/bartv0.26.1go.mod
Gogithub.com/go-json-experiment/jsonv0.0.0-20250813024750-ebf49471dcedgo.mod
Gogithub.com/go-logr/zaprv1.3.0go.mod
Gogithub.com/go-ole/go-olev1.3.0go.mod
Gogithub.com/go4org/hashtriemapv0.0.0-20251130024219-545ba229f689go.mod
Gogithub.com/go4org/plan9netshellv0.0.0-20250324183649-788daa080737go.mod
Gogithub.com/godbus/dbus/v5v5.1.1-0.20230522191255-76236955d466go.mod
Gogithub.com/gokrazy/breakglassv0.0.0-20251229072214-9dbc0478d486go.mod
Gogithub.com/gokrazy/gokrazyv0.0.0-20260418085648-c38c3134b8a7go.mod
Gogithub.com/gokrazy/kernel.arm64v0.0.0-20260403054012-807489e0272ago.mod
Gogithub.com/gokrazy/serial-busyboxv0.0.0-20250119153030-ac58ba7574e7go.mod
Gogithub.com/golang/groupcachev0.0.0-20241129210726-2c02b8208cf8go.mod
Gogithub.com/golang/snappyv0.0.4go.mod
Gogithub.com/golangci/golangci-lintv1.57.1go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-containerregistryv0.21.5go.mod
Gogithub.com/google/go-tpmv0.9.4go.mod
Gogithub.com/google/gopacketv1.1.19go.mod
Gogithub.com/google/nftablesv0.2.1-0.20240414091927-5e242ec57806go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/goreleaser/nfpm/v2v2.33.1go.mod
Gogithub.com/hashicorp/go-hclogv1.6.2go.mod
Gogithub.com/hashicorp/raftv1.7.2go.mod
Gogithub.com/hashicorp/raft-boltdb/v2v2.3.1go.mod
Gogithub.com/hdevalence/ed25519consensusv0.2.0go.mod
Gogithub.com/huin/goupnpv1.3.0go.mod
Gogithub.com/i582/cfmtv1.4.0go.mod
Gogithub.com/illarion/gonotify/v3v3.0.2go.mod
Gogithub.com/inetaf/tcpproxyv0.0.0-20250203165043-ded522cbd03fgo.mod
Gogithub.com/insomniacslk/dhcpv0.0.0-20231206064809-8c70d406f6d2go.mod
Gogithub.com/jellydator/ttlcache/v3v3.1.0go.mod
Gogithub.com/jsimonetti/rtnetlinkv1.4.0go.mod
Gogithub.com/kballard/go-shellquotev0.0.0-20180428030007-95032a82bc51go.mod
Gogithub.com/kdomanski/iso9660v0.4.0go.mod
Gogithub.com/klauspost/compressv1.18.5go.mod
Gogithub.com/kortschak/wolv0.0.0-20200729010619-da482cc4850ago.mod
Gogithub.com/mattn/go-colorablev0.1.13go.mod
Gogithub.com/mattn/go-isattyv0.0.20go.mod
Gogithub.com/mdlayher/genetlinkv1.3.2go.mod
Gogithub.com/mdlayher/netlinkv1.7.3-0.20250113171957-fbb4dce95f42go.mod
Gogithub.com/mdlayher/sdnotifyv1.0.0go.mod
Gogithub.com/miekg/dnsv1.1.58go.mod
Gogithub.com/mitchellh/go-psv1.0.0go.mod
Gogithub.com/peterbourgon/ff/v3v3.4.0go.mod
Gogithub.com/pires/go-proxyprotov0.8.1go.mod
Gogithub.com/pkg/errorsv0.9.1go.mod
Gogithub.com/pkg/sftpv1.13.6go.mod
Gogithub.com/prometheus/client_golangv1.23.0go.mod
Gogithub.com/prometheus/commonv0.65.0go.mod
Gogithub.com/prometheus/prometheusv0.49.2-0.20240125131847-c3b8ef1694ffgo.mod
Gogithub.com/robert-nix/ansihtmlv1.0.1go.mod
Gogithub.com/safchain/ethtoolv0.3.0go.mod
Gogithub.com/skip2/go-qrcodev0.0.0-20200617195104-da1b6568686ego.mod
Gogithub.com/studio-b12/gowebdavv0.9.0go.mod
Gogithub.com/tailscale/certstorev0.1.1-0.20260409135935-3638fb84b77dgo.mod
Gogithub.com/tailscale/depawarev0.0.0-20251001183927-9c2ad255ef3fgo.mod
Gogithub.com/tailscale/glidersshv0.3.4-0.20260330083525-c1389c70ff89go.mod
Gogithub.com/tailscale/goexpectv0.0.0-20210902213824-6e8c725cea41go.mod
Gogithub.com/tailscale/gokrazy-kernelv0.0.0-20240728225134-3d23beabda2ego.mod
Gogithub.com/tailscale/golang-x-cryptov0.0.0-20250404221719-a5573b049869go.mod
Gogithub.com/tailscale/hujsonv0.0.0-20260302212456-ecc657c15afdgo.mod
Gogithub.com/tailscale/mkctrv0.0.0-20260107121656-ea857e3e500bgo.mod
Gogithub.com/tailscale/netlinkv1.1.1-0.20240822203006-4d49adab4de7go.mod
Gogithub.com/tailscale/peercredv0.0.0-20250107143737-35a0c7bd7edcgo.mod
Gogithub.com/tailscale/setecv0.0.0-20251203133219-2ab774e4129ago.mod
Gogithub.com/tailscale/ts-gokrazyv0.0.0-20260429180033-fe741c6deb44go.mod
Gogithub.com/tailscale/web-client-prebuiltv0.0.0-20250124233751-d4cd19a26976go.mod
Gogithub.com/tailscale/wfv0.0.0-20240214030419-6fbb0a674ee6go.mod
Gogithub.com/tailscale/xnetv0.0.0-20240729143630-8497ac4dab2ego.mod
Gogithub.com/tc-hib/winresv0.2.1go.mod
Gogithub.com/tcnksm/go-httpstatv0.2.0go.mod
Gogithub.com/toqueteos/webbrowserv1.2.0go.mod
Gogithub.com/u-root/u-rootv0.14.0go.mod
Gogithub.com/vishvananda/netnsv0.0.5go.mod
Gogo.uber.org/zapv1.27.0go.mod
Gogo4.org/memv0.0.0-20240501181205-ae6ca9944745go.mod
Gogo4.org/netipxv0.0.0-20231129151722-fdeea329fbbago.mod
Gogolang.org/x/cryptov0.50.0go.mod
Gogolang.org/x/expv0.0.0-20250620022241-b7579e27df2bgo.mod
Gogolang.org/x/modv0.35.0go.mod
Gogolang.org/x/netv0.53.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/syncv0.20.0go.mod
Gogolang.org/x/sysv0.43.0go.mod
Gogolang.org/x/termv0.42.0go.mod
Gogolang.org/x/timev0.12.0go.mod
Gogolang.org/x/toolsv0.44.0go.mod
Gogolang.zx2c4.com/wintunv0.0.0-20230126152724-0fa3db229ce2go.mod
Gogolang.zx2c4.com/wireguard/windowsv0.5.3go.mod
Gogopkg.in/square/go-jose.v2v2.6.0go.mod
Gogvisor.dev/gvisorv0.0.0-20260224225140-573d5e7127a8go.mod
Gohelm.sh/helm/v3v3.19.0go.mod
Gohonnef.co/go/toolsv0.7.0go.mod
Gok8s.io/apiv0.34.0go.mod
Gok8s.io/apimachineryv0.34.0go.mod
Gok8s.io/apiserverv0.34.0go.mod
Gok8s.io/client-gov0.34.0go.mod
Gosigs.k8s.io/controller-runtimev0.19.4go.mod
Gosigs.k8s.io/controller-toolsv0.17.0go.mod
Gosigs.k8s.io/kindv0.30.0go.mod
Gosigs.k8s.io/yamlv1.6.0go.mod
Gosoftware.sslmate.com/src/go-pkcs12v0.4.0go.mod
Gotailscale.com/client/tailscale/v2v2.9.0go.mod
Gogithub.com/AlekSi/pointerv1.2.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.16.27go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.41.5go.mod
Gogithub.com/aws/smithy-gov1.24.0go.mod
Gogithub.com/fatih/colorv1.18.0go.mod
Gogithub.com/fsnotify/fsnotifyv1.9.0go.mod
Gogithub.com/gorilla/csrfv1.7.3go.mod
Gogithub.com/mdlayher/socketv0.5.0go.mod
Gogithub.com/prometheus/client_modelv0.6.2go.mod
Gogithub.com/sourcegraph/go-diffv0.7.0go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tailscale/go-winiov0.0.0-20231025203758-c4f33415bf55go.mod
Gogithub.com/ulikunitz/xzv0.5.15go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gok8s.io/apiextensions-apiserverv0.34.0go.mod
Gok8s.io/utilsv0.0.0-20250604170112-4c0f3b243397go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 45869,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "C": 249384,
        "Go": 14742410,
        "CSS": 26022,
        "Lua": 6882,
        "Nix": 9998,
        "HTML": 38464,
        "Rust": 16854,
        "Shell": 89594,
        "Swift": 56179,
        "Makefile": 10304,
        "Dockerfile": 8363,
        "JavaScript": 3381,
        "PowerShell": 19244,
        "TypeScript": 163473,
        "Go Template": 489
      },
      "pushed_at": "2026-07-20T14:45:57Z",
      "created_at": "2026-06-10T08:43:11Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T13:58:40Z",
      "description": "Customised Tailscale for MESH",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "BSD-3-Clause",
      "default_branch": "main",
      "license_spdx_raw": "BSD-3-Clause",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://barghest.asia",
      "name": "BARGHEST",
      "type": "Organization",
      "login": "BARGHEST-ngo",
      "company": null,
      "location": null,
      "followers": 31,
      "avatar_url": "https://avatars.githubusercontent.com/u/204176000?v=4",
      "created_at": "2025-03-20T10:25:46Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 496
    },
    "license": {
      "state": "standard",
      "spdx_id": "BSD-3-Clause",
      "raw_spdx": "BSD-3-Clause",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.95.0-pre",
          "kind": "prerelease",
          "published_at": "2026-01-14T22:19:17Z"
        },
        {
          "tag": "v1.94.2",
          "kind": "patch",
          "published_at": "2026-02-13T19:41:21Z"
        },
        {
          "tag": "v1.94.1",
          "kind": "patch",
          "published_at": "2026-01-22T18:44:55Z"
        },
        {
          "tag": "v1.94.0",
          "kind": "minor",
          "published_at": "2026-01-14T20:55:28Z"
        },
        {
          "tag": "v1.93.0-pre",
          "kind": "prerelease",
          "published_at": "2025-11-26T20:49:52Z"
        },
        {
          "tag": "v1.92.5",
          "kind": "patch",
          "published_at": "2026-01-06T18:15:04Z"
        },
        {
          "tag": "v1.92.4",
          "kind": "patch",
          "published_at": "2025-12-18T10:30:54Z"
        },
        {
          "tag": "v1.92.3",
          "kind": "patch",
          "published_at": "2025-12-16T20:11:52Z"
        },
        {
          "tag": "v1.92.2",
          "kind": "patch",
          "published_at": "2025-12-10T18:24:06Z"
        },
        {
          "tag": "v1.92.1",
          "kind": "patch",
          "published_at": "2025-12-05T15:51:26Z"
        },
        {
          "tag": "v1.92.0",
          "kind": "minor",
          "published_at": "2025-11-26T20:35:58Z"
        },
        {
          "tag": "v1.91.0-pre",
          "kind": "prerelease",
          "published_at": "2025-10-20T16:11:05Z"
        },
        {
          "tag": "v1.90.9",
          "kind": "patch",
          "published_at": "2025-11-25T16:12:16Z"
        },
        {
          "tag": "v1.90.8",
          "kind": "patch",
          "published_at": "2025-11-18T18:31:30Z"
        },
        {
          "tag": "v1.90.7",
          "kind": "patch",
          "published_at": "2025-11-18T17:32:04Z"
        },
        {
          "tag": "v1.90.6",
          "kind": "patch",
          "published_at": "2025-10-31T21:18:03Z"
        },
        {
          "tag": "v1.90.5",
          "kind": "patch",
          "published_at": "2025-10-30T17:38:25Z"
        },
        {
          "tag": "v1.90.4",
          "kind": "patch",
          "published_at": "2025-10-28T18:29:24Z"
        },
        {
          "tag": "v1.90.3",
          "kind": "patch",
          "published_at": "2025-10-27T16:15:14Z"
        },
        {
          "tag": "v1.90.2",
          "kind": "patch",
          "published_at": "2025-10-24T16:49:00Z"
        },
        {
          "tag": "v1.90.1",
          "kind": "patch",
          "published_at": "2025-10-23T16:06:03Z"
        },
        {
          "tag": "v1.90.0",
          "kind": "minor",
          "published_at": "2025-10-20T16:01:07Z"
        },
        {
          "tag": "v1.89.0-pre",
          "kind": "prerelease",
          "published_at": "2025-09-11T18:19:17Z"
        },
        {
          "tag": "v1.88.4",
          "kind": "patch",
          "published_at": "2025-10-14T17:45:00Z"
        },
        {
          "tag": "v1.88.3",
          "kind": "patch",
          "published_at": "2025-09-25T13:04:46Z"
        },
        {
          "tag": "v1.88.2",
          "kind": "patch",
          "published_at": "2025-09-17T17:13:08Z"
        },
        {
          "tag": "v1.88.1",
          "kind": "patch",
          "published_at": "2025-09-11T19:13:06Z"
        },
        {
          "tag": "v1.88.0",
          "kind": "minor",
          "published_at": "2025-09-11T17:33:53Z"
        },
        {
          "tag": "v1.87.0-pre",
          "kind": "prerelease",
          "published_at": "2025-07-24T18:25:57Z"
        },
        {
          "tag": "v1.86.5",
          "kind": "patch",
          "published_at": "2025-08-22T16:30:19Z"
        },
        {
          "tag": "v1.86.4",
          "kind": "patch",
          "published_at": "2025-08-07T16:46:29Z"
        },
        {
          "tag": "v1.86.3",
          "kind": "patch",
          "published_at": "2025-08-07T15:18:21Z"
        },
        {
          "tag": "v1.86.2",
          "kind": "patch",
          "published_at": "2025-07-29T16:56:20Z"
        },
        {
          "tag": "v1.86.1",
          "kind": "patch",
          "published_at": "2025-07-25T17:54:40Z"
        },
        {
          "tag": "v1.86.0",
          "kind": "minor",
          "published_at": "2025-07-24T18:11:13Z"
        },
        {
          "tag": "v1.85.0-pre",
          "kind": "prerelease",
          "published_at": "2025-05-21T19:27:32Z"
        },
        {
          "tag": "v1.84.3",
          "kind": "patch",
          "published_at": "2025-06-26T16:26:38Z"
        },
        {
          "tag": "v1.84.2",
          "kind": "patch",
          "published_at": "2025-06-09T21:39:17Z"
        },
        {
          "tag": "v1.84.1",
          "kind": "patch",
          "published_at": "2025-05-29T17:40:49Z"
        },
        {
          "tag": "v1.84.0",
          "kind": "minor",
          "published_at": "2025-05-21T19:10:03Z"
        },
        {
          "tag": "v1.83.0-pre",
          "kind": "prerelease",
          "published_at": "2025-03-26T13:29:38Z"
        },
        {
          "tag": "v1.82.5",
          "kind": "patch",
          "published_at": "2025-04-17T19:01:26Z"
        },
        {
          "tag": "v1.82.4",
          "kind": "patch",
          "published_at": "2025-04-11T17:52:10Z"
        },
        {
          "tag": "v1.82.3",
          "kind": "patch",
          "published_at": "2025-04-11T16:32:59Z"
        },
        {
          "tag": "v1.82.2",
          "kind": "patch",
          "published_at": "2025-04-10T19:53:40Z"
        },
        {
          "tag": "v1.82.0",
          "kind": "minor",
          "published_at": "2025-03-26T19:50:33Z"
        },
        {
          "tag": "v1.81.0-pre",
          "kind": "prerelease",
          "published_at": "2025-01-30T21:04:29Z"
        },
        {
          "tag": "v1.80.3",
          "kind": "patch",
          "published_at": "2025-03-03T20:05:20Z"
        },
        {
          "tag": "v1.80.2",
          "kind": "patch",
          "published_at": "2025-02-12T18:31:52Z"
        },
        {
          "tag": "v1.80.1",
          "kind": "patch",
          "published_at": "2025-02-06T18:38:55Z"
        },
        {
          "tag": "v1.80.0",
          "kind": "minor",
          "published_at": "2025-01-30T20:52:55Z"
        },
        {
          "tag": "v1.79.0-pre",
          "kind": "prerelease",
          "published_at": "2024-12-06T17:25:12Z"
        },
        {
          "tag": "v1.78.3",
          "kind": "patch",
          "published_at": "2024-12-11T20:26:51Z"
        },
        {
          "tag": "v1.78.2",
          "kind": "patch",
          "published_at": "2024-12-11T18:06:06Z"
        },
        {
          "tag": "v1.78.1",
          "kind": "patch",
          "published_at": "2024-12-05T23:51:23Z"
        },
        {
          "tag": "v1.78.0",
          "kind": "minor",
          "published_at": "2024-12-05T19:16:48Z"
        },
        {
          "tag": "v1.77.0-pre",
          "kind": "prerelease",
          "published_at": "2024-10-10T18:34:14Z"
        },
        {
          "tag": "v1.76.6",
          "kind": "patch",
          "published_at": "2024-11-04T20:07:36Z"
        },
        {
          "tag": "v1.76.3",
          "kind": "patch",
          "published_at": "2024-10-21T15:10:38Z"
        },
        {
          "tag": "v1.76.1",
          "kind": "patch",
          "published_at": "2024-10-15T18:20:59Z"
        },
        {
          "tag": "v1.76.0",
          "kind": "minor",
          "published_at": "2024-10-10T18:11:51Z"
        },
        {
          "tag": "v1.75.0-pre",
          "kind": "prerelease",
          "published_at": "2024-09-12T20:19:46Z"
        },
        {
          "tag": "v1.74.1",
          "kind": "patch",
          "published_at": "2024-09-18T18:54:26Z"
        },
        {
          "tag": "v1.74.0",
          "kind": "minor",
          "published_at": "2024-09-12T19:58:22Z"
        },
        {
          "tag": "v1.73.0-pre",
          "kind": "prerelease",
          "published_at": "2024-08-19T17:17:29Z"
        },
        {
          "tag": "v1.72.1",
          "kind": "patch",
          "published_at": "2024-08-22T16:21:32Z"
        },
        {
          "tag": "v1.72.0",
          "kind": "minor",
          "published_at": "2024-08-19T17:07:21Z"
        },
        {
          "tag": "v1.71.0-pre",
          "kind": "prerelease",
          "published_at": "2024-07-17T17:27:05Z"
        },
        {
          "tag": "v1.70.0",
          "kind": "minor",
          "published_at": "2024-07-17T17:11:59Z"
        },
        {
          "tag": "v1.69.0-pre",
          "kind": "prerelease",
          "published_at": "2024-06-12T17:16:33Z"
        },
        {
          "tag": "v1.68.2",
          "kind": "patch",
          "published_at": "2024-07-02T18:23:20Z"
        },
        {
          "tag": "v1.68.1",
          "kind": "patch",
          "published_at": "2024-06-14T11:47:24Z"
        },
        {
          "tag": "v1.68.0",
          "kind": "minor",
          "published_at": "2024-06-12T17:03:59Z"
        },
        {
          "tag": "v1.67.0-pre",
          "kind": "prerelease",
          "published_at": "2024-05-08T21:00:17Z"
        },
        {
          "tag": "v1.66.4",
          "kind": "patch",
          "published_at": "2024-05-21T00:28:00Z"
        },
        {
          "tag": "v1.66.3",
          "kind": "patch",
          "published_at": "2024-05-14T21:16:13Z"
        },
        {
          "tag": "v1.66.2",
          "kind": "patch",
          "published_at": "2024-05-14T20:44:56Z"
        },
        {
          "tag": "v1.66.1",
          "kind": "patch",
          "published_at": "2024-05-09T20:21:31Z"
        },
        {
          "tag": "v1.66.0",
          "kind": "minor",
          "published_at": "2024-05-08T20:52:24Z"
        },
        {
          "tag": "v1.65.0-pre",
          "kind": "prerelease",
          "published_at": "2024-04-11T18:00:11Z"
        },
        {
          "tag": "v1.64.2",
          "kind": "patch",
          "published_at": "2024-04-17T13:08:36Z"
        },
        {
          "tag": "v1.64.1",
          "kind": "patch",
          "published_at": "2024-04-15T17:10:28Z"
        },
        {
          "tag": "v1.64.0",
          "kind": "minor",
          "published_at": "2024-04-11T17:29:54Z"
        },
        {
          "tag": "v1.63.0-pre",
          "kind": "prerelease",
          "published_at": "2024-03-13T14:51:52Z"
        },
        {
          "tag": "v1.62.1",
          "kind": "patch",
          "published_at": "2024-03-26T19:40:57Z"
        },
        {
          "tag": "v1.62.0",
          "kind": "minor",
          "published_at": "2024-03-13T14:35:30Z"
        },
        {
          "tag": "v1.61.0-pre",
          "kind": "prerelease",
          "published_at": "2024-02-15T23:24:49Z"
        },
        {
          "tag": "v1.60.1",
          "kind": "patch",
          "published_at": "2024-02-29T03:37:44Z"
        },
        {
          "tag": "v1.60.0",
          "kind": "minor",
          "published_at": "2024-02-15T20:08:20Z"
        },
        {
          "tag": "v1.58.2",
          "kind": "patch",
          "published_at": "2024-01-23T21:54:48Z"
        },
        {
          "tag": "v1.58.1",
          "kind": "patch",
          "published_at": "2024-01-23T18:18:58Z"
        },
        {
          "tag": "v1.58.0",
          "kind": "minor",
          "published_at": "2024-01-18T20:04:42Z"
        },
        {
          "tag": "v1.56.1",
          "kind": "patch",
          "published_at": "2023-12-15T19:21:33Z"
        },
        {
          "tag": "v1.56.0",
          "kind": "minor",
          "published_at": "2023-12-13T19:58:42Z"
        },
        {
          "tag": "v1.44.3",
          "kind": "patch",
          "published_at": "2024-01-05T22:33:30Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "96abef288847c5b4ce4869c8c18a828c31f37bb9",
          "body": "Bug/leak local rfc1918 addresses",
          "is_bot": false,
          "headline": "Merge pull request #7 from BARGHEST-ngo/bug/leak-local-rfc1918-addresses",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-07-20T13:57:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "329986aad14565d459b1d928a5686c21d825b3cb",
          "body": null,
          "is_bot": false,
          "headline": "add TestLANAddr",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-07-20T13:06:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6293878c903ea36e555884739a38d9b64d03a539",
          "body": null,
          "is_bot": false,
          "headline": "filter private LAN addresses",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-07-20T12:52:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9571649c558c05ebc8d87f13502cad30bb495cd1",
          "body": "fix: change stun software attr from tailnode",
          "is_bot": false,
          "headline": "Merge pull request #6 from BARGHEST-ngo/fix/change-stun-software-attr",
          "author_name": "shockham",
          "author_login": "shockham",
          "committed_at": "2026-07-20T11:57:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "027afddec4cd650943e7c460a2404528c5a042c8",
          "body": null,
          "is_bot": false,
          "headline": "fix: change stun software attr from tailnode",
          "author_name": "shockham",
          "author_login": "shockham",
          "committed_at": "2026-07-20T10:54:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3d80563fd00eef201d5c84c1b8a91c4f732e4ac",
          "body": "…njection\n\nsanitize peer OS name",
          "is_bot": false,
          "headline": "Merge pull request #5 from BARGHEST-ngo/bug/sanitize-ansi-character-i…",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-07-20T09:48:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad8f19af11af9f34fa3cf41f2bf4a5ab28927eb5",
          "body": null,
          "is_bot": false,
          "headline": "sanitize peer OS name",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-07-20T09:08:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0eb7a7af7a6e1c22cb0460ec7e003be10e3ab3bf",
          "body": "fix: ANSI escape fix",
          "is_bot": false,
          "headline": "Merge pull request #4 from BARGHEST-ngo/fix/meshstatus-ansi-injection",
          "author_name": "Ovi",
          "author_login": "0x0v1",
          "committed_at": "2026-06-18T15:45:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "191a42dfe19ecea1cdf40e158ff2b7ba4d6eed55",
          "body": null,
          "is_bot": false,
          "headline": "fix: ANSI escape fix",
          "author_name": "Ovi",
          "author_login": "0x0v1",
          "committed_at": "2026-06-18T14:55:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22b649ecf789275ac60a7946d00020cfac84af0a",
          "body": "fix: re-advertise endpoints on node-key change",
          "is_bot": false,
          "headline": "Merge pull request #3 from BARGHEST-ngo/fix/republish-on-rekey",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-16T10:13:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da220baaaaf9cde2092134ab3720d4b7f1b8bf93",
          "body": null,
          "is_bot": false,
          "headline": "Merge pull request #2 from BARGHEST-ngo/disable-scheduled-actions",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-12T09:51:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b682d09ddc7f52de9487864eef29332ad0907021",
          "body": null,
          "is_bot": false,
          "headline": "fix: re-advertise endpoints on node-key change",
          "author_name": "Ovi",
          "author_login": "0x0v1",
          "committed_at": "2026-06-11T16:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ceef8ba58972cd55e383bda874dd6c04107d059",
          "body": null,
          "is_bot": false,
          "headline": "disable various scheduled actions",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-11T14:07:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab574d4c0252ee0f2bebbc3d9828bcbc3b415155",
          "body": "Disable scheduled runs in natlab-test.yml",
          "is_bot": false,
          "headline": "Merge pull request #1 from BARGHEST-ngo/disable-cron-jobs",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-11T10:09:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de9680fe5020b5319a4a65f8a8f565cceb5bdfc9",
          "body": "Comment out the schedule trigger in the GitHub Actions workflow.",
          "is_bot": false,
          "headline": "Disable scheduled runs in natlab-test.yml",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-11T09:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edfc235e37f0fbe79bfe6a43072625d49d8b3c4e",
          "body": "Merge upstream",
          "is_bot": false,
          "headline": "Merge pull request #3 from BARGHEST-ngo/merge-upstream",
          "author_name": "DWoodhouse22",
          "author_login": "DWoodhouse22",
          "committed_at": "2026-06-02T11:37:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a1a70a811461003aee6b562e9d7eeb6f7d6cfcd",
          "body": null,
          "is_bot": false,
          "headline": "remove defunct test helper",
          "author_name": "devtimber",
          "author_login": "devtimber",
          "committed_at": "2026-05-13T15:23:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc9f5c50f47d608146b1efff02c48552381a334a",
          "body": null,
          "is_bot": false,
          "headline": "merge mesh branch & resolve post-merge build errors after upstream sync",
          "author_name": "devtimber",
          "author_login": "devtimber",
          "committed_at": "2026-05-13T12:26:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f47539e79614898317636cc1c0f55b77d3bdebc0",
          "body": null,
          "is_bot": false,
          "headline": "resolve merge conflicts",
          "author_name": "devtimber",
          "author_login": "devtimber",
          "committed_at": "2026-05-13T09:49:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6467f0d0673652e8d3cca1384b8571fad0c0c29f",
          "body": "This fixes a log message where ipn/ipnlocal.shouldUseOneCGNATRoute\nwould claim that an android machines was actually macOS.\n\nUpdates #cleanup\nUpdates #19652\n\nSigned-off-by: Simon Law <sfllaw@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal: fix minor typo in shouldUseOneCGNATRoute (#19719)",
          "author_name": "Simon Law",
          "author_login": "sfllaw",
          "committed_at": "2026-05-13T04:55:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b729795c30f3f408b3caa983713eec1136d74ff",
          "body": "Replace the process-global Server.mu lookup in the packet send hot path\nwith a global hashtriemap mirror of local clientSet entries. The\nauthoritative clients map remains guarded by Server.mu; clientsAtomic is\nonly a lock-free fast path for active local clients.\n\nMisses, stale inactive client sets, \n[…]\ndates #3560 (very indirectly, historically)\nUpdates #19713 (as an alternative to that PR)\n\nChange-Id: Ifb72e5c9854ad00e938cd24c6ab9c27312f297e8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "derp/derpserver: use hashtriemap for peer lookup",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-12T23:08:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72578de0330c3a3150240b4f087033111e1f4b2e",
          "body": "…services\n\nAdds two new cap resolution methods alongside the existing PeerCaps:\n\nPeerCapsForService(src netip.Addr, svcName tailcfg.ServiceName) resolves\nthe service name to its VIP addresses via the node's service IP mappings\nand returns caps scoped to that service. Exposed on /v0/whois via the\nsvc\n[…]\nhe existing PeerCaps/WhoIs path is\nunchanged: without a service parameter, WhoIs returns only host-level\ncaps.\n\nUpdates tailscale/corp#41632\n\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/{ipnlocal,localapi},client/local: add per-dst cap resolution for …",
          "author_name": "Adriano Sela Aviles",
          "author_login": "adrianosela",
          "committed_at": "2026-05-12T22:50:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad8ead9c94a0dd66396528b23728b24e366d0942",
          "body": "Fixes #12778\n\nChange-Id: If9f8b299cef0cb68f93b344845b5c6a5b7554d2c\nSigned-off-by: DeedleFake <deedlefake@users.noreply.github.com>",
          "is_bot": false,
          "headline": "cmd/tailscale/cli: add RunWithContext",
          "author_name": "DeedleFake",
          "author_login": "DeedleFake",
          "committed_at": "2026-05-12T19:27:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f48567bf1933273b023c2f60e04babbecb68ae5",
          "body": "…onnectivity (#19699)\n\nAdd new clientmetric counters for establishing contact with peers while using\ncached network map data. To do this, instrument the magicsock.Conn with a bit\nto indicate whether its peer data came from a cached netmap. If so, there are\ntwo conditions we will count as establishin\n[…]\n caching tests.\n\nUpdates https://github.com/tailscale/projects/issues/13\nUpdates #12639\n\nChange-Id: Ie8cf3244ac8af4f5bcfe4d0d944078da2ba08990\nSigned-off-by: M. J. Fromberger <fromberger@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal,wgengine/magicsock: add basic counters for cached peer c…",
          "author_name": "M. J. Fromberger",
          "author_login": "creachadair",
          "committed_at": "2026-05-12T19:01:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "120bfcf1cc3bdfcc7b5d78b12e725d161bb7f05f",
          "body": "…d cache type name\n\nTwo changes that share the same intent of reducing per-T duplication\nin code that doesn't actually depend on T:\n\n1. Hoist the non-generic portion of newSubscriberFunc[T] into a\n   newSubscriberFuncCore() helper. The hoisted work is the time\n   timer setup, the subscriberFuncCore \n[…]\n7.6%) because the dispatch hot\npath no longer allocates a string on every event.\n\nUpdates #12614\n\nChange-Id: Ib3a3d6796785e16506330ec034e1144580d467a3\nSigned-off-by: James Tucker <james@tailscale.com>",
          "is_bot": false,
          "headline": "util/eventbus: extract non-generic SubscriberFunc constructor body an…",
          "author_name": "James Tucker",
          "author_login": "raggi",
          "committed_at": "2026-05-12T18:16:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e37e12167e6c63c6522e387f0a2dfcbfaffc7e3",
          "body": "Use internal go modules",
          "is_bot": false,
          "headline": "Merge pull request #2 from BARGHEST-ngo/feature/no-mesh-patch",
          "author_name": "Ovi",
          "author_login": "0x0v1",
          "committed_at": "2026-05-12T15:13:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "758ebe98394d92f02831498eb58456030a7dc2ab",
          "body": "macOS limits Unix socket paths to 104 bytes. The Go test TempDir\npath (e.g. /var/folders/.../TestDirectConnection...679197086/001/)\neasily exceeds that, causing \"bind: invalid argument\". Create a\nshort /tmp/vmtest* directory for all socket files (vnet, QMP,\ndgram) so the paths stay well under the limit on every platform.\n\nUpdates #13038\n\nChange-Id: I721d24561d1766aaa964692bc77f40a131aa9455\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: use short paths for Unix sockets",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-12T04:54:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4c5613156dd382235929e5fb6de8f8088095614",
          "body": "startCloudQEMU hardcoded -machine q35,accel=kvm and -cpu host,\nwhich fails on any host without KVM (notably macOS). Replace\nwith a qemuAccelArgs helper that probes /dev/kvm and falls back\nto QEMU's TCG software emulation, matching the pattern already\nused by tstest/integration/nat. Also wire the helper into\nstartGokrazyQEMU so gokrazy VMs pick up KVM when available.\n\nUpdates #13038\n\nChange-Id: I7745518db823279b1880957bb14ca2ffdaab4c50\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: don't require KVM; use TCG on macOS",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-12T02:18:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e062b46984a2a8e02881617a7105593da70924a5",
          "body": "The natlab vmtest suite (tstest/natlab/vmtest) and the integration nat\ntests are gated behind --run-vm-tests because they need KVM and are\nslow. Until now nothing in CI exercised them apart from a single\ncanary TestEasyEasy run on every PR.\n\nAdd .github/workflows/natlab-test.yml that runs the full o\n[…]\nt only fires after 10s, so a truly stuck agent connection still\nsurfaces.\n\nUpdates #13038\n\nChange-Id: I4582098d8865200fd5a73a9b696942319ccf3bf0\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab, .github/workflows: add opt-in natlab CI workflow",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-12T00:14:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4eec4423b42a22e5331e99240baa75fd3d6b6f3b",
          "body": "…ic core\n\nMirrors the same refactor previously applied to SubscriberFunc:\n\n  - Publisher[T]: a thin user-facing facade. Holds a pointer to a\n    non-generic publisherCore and exposes Publish/Close/ShouldPublish.\n  - publisherCore: a non-generic struct that owns the *Client back-\n    pointer, stop fl\n[…]\n within noise\n(2018 -> 2038 ns/op at -benchtime=2s) and all eventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I61979c2bf95d2a711c2321e6e0b4b7d15980e9f5\nSigned-off-by: James Tucker <james@tailscale.com>",
          "is_bot": false,
          "headline": "util/eventbus: move Publisher publisher-interface impl to a non-gener…",
          "author_name": "James Tucker",
          "author_login": "raggi",
          "committed_at": "2026-05-11T21:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d72cde1a6ba0c9559fa20d72f1d362427a11b71f",
          "body": "…-generic core\n\nSplits SubscriberFunc[T] into:\n\n  - SubscriberFunc[T]: a thin user-facing facade that holds only a\n    pointer to a non-generic core. It exposes Close() to user code,\n    which forwards to the core.\n  - subscriberFuncCore: a non-generic struct that owns all the\n    subscriber state (\n[…]\ns within noise\n(1955 -> 1941 ns/op on the test box) and all eventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I646b3b05fd8d95f9afead59bfd0f69cd18b7a709\nSigned-off-by: James Tucker <james@tailscale.com>",
          "is_bot": false,
          "headline": "util/eventbus: move SubscriberFunc subscriber-interface impl to a non…",
          "author_name": "James Tucker",
          "author_login": "raggi",
          "committed_at": "2026-05-11T19:14:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ead5ce65a3d7a50e8ce07cce3c746aadbeaa9a55",
          "body": "There is a 30-second timeout set on client TLS connections but the handshake was\ncalled on the wrong connection and so the timeout was never used in practice.\n\nSigned-off-by: Francois Marier <francois@fmarier.org>",
          "is_bot": false,
          "headline": "cmd/pgproxy: fix client TLS handshake timeout",
          "author_name": "Francois Marier",
          "author_login": "fmarier",
          "committed_at": "2026-05-11T18:12:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f45a6a9d8e180373414d42246914a2fb0af0a0c",
          "body": "Make it possible to remove the least recently used expired address\nassignment from addrAssignments.\nBefore checking out a new address from the IP pools, return a handful of\nexpired addresses.\n\nUpdates tailscale/corp#39975\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
          "is_bot": false,
          "headline": "feature/conn25: return expired assignments to address pools",
          "author_name": "Fran Bull",
          "author_login": "franbull",
          "committed_at": "2026-05-08T21:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82346f388249b7f45355efdb13984d7ca3b5b74b",
          "body": "Updates tailscale/corp#39975\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
          "is_bot": false,
          "headline": "feature/conn25: move addrAssignments to their own file",
          "author_name": "Fran Bull",
          "author_login": "franbull",
          "committed_at": "2026-05-08T21:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "469d356ed899c0a097e6bcb7907fea819dcf3cba",
          "body": "…9660)\n\nWhen a peer is not able to connect to control after a restart and is\nusing a cached netmap, that nodes should be able to connect to another\npeer in its tailnet (given that the home DERP of that peer has not\nchanged in the meantime).\n\nAdd test that starts two peers and connects them to a tail\n[…]\nrt it. Verify that the connection between the two ends up direct.\n\nAdds facilities for expecting a certain path type between nodes.\n\nUpdates: #19597\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: add test for direct conn with cached netmap (#1…",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-05-08T20:57:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee2378b141f6c0365738e64d0057778fd7244d1a",
          "body": "If a DNS query for a domain that should be routed through a connector\nresults in CNAME records in the response, collapse the CNAME chain to an\nA/AAAA record for the domain -> magic IP.\n\nFixes tailscale/corp#39978\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
          "is_bot": false,
          "headline": "feature/conn25: follow CNAMEs when rewriting DNS response",
          "author_name": "Fran Bull",
          "author_login": "franbull",
          "committed_at": "2026-05-08T15:12:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24eb15744857437e41ea2eec7394ae9da8f72e3e",
          "body": "Updates tailscale/corp#41490\n\nChange-Id: I35b67bdbcd71468fea03b033b17aeefe1319dc45\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "go.toolchain.rev: bump to Go 1.26.3",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-07T22:33:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6ffc0d9865f9a8bbc3902c6c8f8d73731b96387",
          "body": "The `CreateStateForTest` helper reduces boilerplate in cases where the test\nonly cares about the trusted keys and not the disablement values (and makes\nit more obvious where the disablement values are meaningful).\n\nThe `setupChonkStorage` helper reduces the boilerplate when creating on-disk\nTKA stor\n[…]\nduces the boilerplate when setting up a\n`LocalBackend` instance in the IPN tests.\n\nUpdates #cleanup\n\nChange-Id: Iacfba1be5f7fab208eec11e4369d63c7d7519da5\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "tka,ipn: reduce boilerplate in Tailnet Lock tests",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-05-07T20:49:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "495d3acc7b7337131b94aaa28bdbd68d34e7f599",
          "body": "Re-exec the test binary as a thin wrapper that holds a pipe inherited\nfrom the test. When the test goes away (any reason, including SIGKILL,\npanic, or OOM), the kernel closes the pipe write end; the wrapper sees\nEOF and SIGKILLs itself, taking QEMU and its children with it.\n\nUpdates #13038\n\nChange-Id: Ib2151098193551396c1d7bb51b07da3bd6b2cfb4\n\nSigned-off-by: Fernando Serboncini <fserb@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: kill QEMU when test process dies (#19676)",
          "author_name": "Fernando Serboncini",
          "author_login": "fserb",
          "committed_at": "2026-05-07T20:14:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76248a68b2668081640fe7c043dc1c58e21495f9",
          "body": "Running all vmtests in tstest/natlab/vmtest locally was breaking later\ntasks in the queue. The goroutine dump on timeout had goroutines hanging\naround for 9 minutes, meaning that something was not getting cleaned up.\n\n  goroutine 262 [select, 9 minutes]:\n  gvisor.dev/gvisor/pkg/tcpip/adapters/gonet.\n[…]\n) to gonet TCP connections when the test ends\n(inspired by ServeUnixConn()), and wait for them to shut down before\nexiting the test.\n\nUpdates #13038\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vnet: close gonet sockets when test is done (#19677)",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-05-07T18:57:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "223cf5cb2486c40a8b18be6b59df7045655e573d",
          "body": null,
          "is_bot": false,
          "headline": "Replace androidqf and wireguard",
          "author_name": "devtimber",
          "author_login": "devtimber",
          "committed_at": "2026-05-07T11:56:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33b9579c21d5c5841a38b3e18159ac8ff44943be",
          "body": "…e (#19662)\n\nFixes: #14927\n\nSigned-off-by: Hazel T <hazel@tailscale.com>",
          "is_bot": false,
          "headline": "scripts/installer.sh: add openSUSE Slowroll as a Tumbleweed derivativ…",
          "author_name": "Hazel T",
          "author_login": "KannaDev",
          "committed_at": "2026-05-07T11:43:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76712b32d9179843f301e431ebae634da2cd1c0d",
          "body": "Updates #cleanup\n\nSigned-off-by: Erisa A <erisa@tailscale.com>",
          "is_bot": false,
          "headline": ".github: install ca-certificates on Kali to fix installer tests (#19673)",
          "author_name": "Erisa A",
          "author_login": "Erisa",
          "committed_at": "2026-05-07T11:20:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0def0f19bdf150192efe22bca92b6b2649d1eb83",
          "body": "…helper\n\nThe (*SubscriberFunc[T]).dispatch method body — a ~40-line select\nloop with slow-subscriber timer, snapshot handling, ctx-cancel\ndraining, and a CI stack-dump branch — was previously fully\nduplicated by the Go compiler for every distinct GC shape of T.\nNone of that body actually depends on \n[…]\nlocs/op, 144 B/op as the prior eventbus implementation. All\neventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I85f933f50f58cd25bbfe5cc46bdda7aab22f0bf7\nSigned-off-by: James Tucker <james@tailscale.com>",
          "is_bot": false,
          "headline": "util/eventbus: extract SubscriberFunc.dispatch loop to a non-generic …",
          "author_name": "James Tucker",
          "author_login": "raggi",
          "committed_at": "2026-05-07T01:56:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87a74c3aa2ea1cebdc6db64e6e390849da457313",
          "body": "The tailscale.com/wif package brings in the AWS SDK\n(github.com/aws/aws-sdk-go-v2/{config,sts,...} and github.com/aws/smithy-go)\nto support fetching ID tokens from AWS IMDS for workload identity\nfederation. Until now, tsnet pulled this in unconditionally via\nfeature/condregister/identityfederation, \n[…]\n, so it shouldn't be\nsubject to the ts_omit_identityfederation build tag.\n\nUpdates #12614\n\nChange-Id: I70599f2bdd4d3666b26a859d5b76caa5d6b94507\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tsnet: make workload identity federation opt-in",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-07T01:43:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "daddb14b8f293ded2489f54bf8b2f335bf0020a0",
          "body": "When HTTPS is explicitly disabled (HTTPSPort == NoPort), the JS WebSocket\ndialer should use ws:// instead of wss://. This matches the behavior of\nthe non-JS client and fixes connections to development control servers\ne.g. http://localhost:31544.\n\nUpdates tailscale/corp#40944\n\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
          "is_bot": false,
          "headline": "control/controlhttp: use ws:// when HTTPSPort is NoPort in JS dialer",
          "author_name": "Adriano Sela Aviles",
          "author_login": "adrianosela",
          "committed_at": "2026-05-06T22:58:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d06cc56987d85662bdf2f8ed61fbabb71da93347",
          "body": "Per recent chat with @raggi about all this, I went and looked at this\ntest again.\n\nUpdates #cleanup\n\nChange-Id: Icb7d87b1ed2cebf481ee4e358a3aa603e63fb8a4\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine/magicsock: add more docs, checks to Test32bitAlignment",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-06T22:29:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15bb10dbce3a8ee7ddd4350df179ff73ccfbe52e",
          "body": "Commit 69c79cb9f (Sep 2025) moved awsstore and kubestore registration\nbehind condregister build tags so tsnet wouldn't pull in the AWS SDK\nand Kubernetes client by default. The accompanying TestDeps BadDeps\nentry was missed, so PR #19667 (which re-added those imports) wasn't\ncaught by the test.\n\nAdd\n[…]\no packages to BadDeps so future regressions fail the test.\n\nUpdates #19667\nUpdates #12614\n\nChange-Id: I903b7c976e5e122cc0c0b956dc73740f5d474fac\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tsnet: ban awsstore and kubestore as deps in TestDeps",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-06T21:57:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b74eeda0556f1a7167e10224e3effb1fd4320a17",
          "body": "Include the unit (s) when printing the time taken to test each package.\n\nUpdates #cleanup\n\nSigned-off-by: Tom Proctor <tomhjp@users.noreply.github.com>",
          "is_bot": false,
          "headline": "cmd/testwrapper: print unit for package duration (#19663)",
          "author_name": "Tom Proctor",
          "author_login": "tomhjp",
          "committed_at": "2026-05-06T21:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c721189cef88d7726b188f7d61d52cf0e8cdfc52",
          "body": "Android rebuilds its VpnService interface when the VPN route\nconfiguration changes, which tears down long lived TCP connections\nthrough the tunnel. Use the same automatic OneCGNATRoute behavior as\nmacOS on Android, and prefer the single CGNAT route when no other\ninterface is using the CGNAT, falling back to fine grained peer routes\notherwise.\n\nUpdates tailscale/tailscale#19591\n\nSigned-off-by: kari <kari@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal: prefer one CGNAT route on Android (#19652)",
          "author_name": "kari-ts",
          "author_login": "kari-ts",
          "committed_at": "2026-05-06T02:11:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f844c8bc32f237bf21f83ce89923cafc6c830a00",
          "body": "The test goroutine read lockCnt immediately after Lock returned, racing\nwith Close: close(lk.closing) wakes lockSlow's select, whose deferred\nAdd(-2) on lockCnt can run before Close's CAS clears the LSB. When that\nhappens, lockCnt is briefly 1 (3 - 2) instead of 0 (1 + 2 - 2 - 1),\nproducing \"lockCnt\n[…]\ne Lock goroutine has finished, so both updates\nhave settled before we read.\n\nFixes #19647\n\nChange-Id: Ia67036ff73a1beb528cbd621460db9048f3066ad\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "util/winutil/gp: deflake TestGroupPolicyReadLockClose",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-05T21:02:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "872d79089ead823cf2e930b007d6aad312e05cd2",
          "body": "Signed-off-by: Jonathan Nobels <jonathan@tailscale.com>",
          "is_bot": false,
          "headline": "VERSION.txt: this is v1.99.0 (#19645)",
          "author_name": "Jonathan Nobels",
          "author_login": "barnstar",
          "committed_at": "2026-05-05T19:07:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa21b0c0082040892064a4d4af0aabdc78dde653",
          "body": "…9627)\n\nWhen an exit node was set before launching systray, the recommended row\nin exit nodes rendered as not selected even when the active exit node\nwas at the same location.\n\nThis looks to be two different things:\n\n- suggestExitNode takes its own suggestion into account, and not the\n  users active\n[…]\nnd mutated via .Check(), which for newly\n  created elements may be cached (such as when launching systray, with\n  an already active node).\n\nFixes #19626\n\nSigned-off-by: Evan Lowry <evan@tailscale.com>",
          "is_bot": false,
          "headline": "client/systray: fix recommended exit node not showing as selected (#1…",
          "author_name": "Evan Lowry",
          "author_login": "Lykathia",
          "committed_at": "2026-05-05T13:49:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eac531da8e22a87e18ca1f04e16e93bce1e50c04",
          "body": "This was originally hidden during the beta period in both `up` and `set`,\nthen when device posture went GA we unhid the flag in `set` but not in\n`up`.\n\nThis is confusing for users, because an error message can direct them to\nrun `tailscale up` with this flag if they've set it previously, but the\nhelp text won't tell them what it does.\n\nUpdates #5902\nUpdates #17972\n\nChange-Id: I9a31946f4b3bb411feed0f5a6449d7ff9a5ba9d3\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/tailscale/cli: unhide `--report posture` flag in `up`",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-05-05T09:12:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "883d4fd2cddf80cf860a10bd8e8b5e45cf00599e",
          "body": "… instead\n\nFixes #19633\nFixes #13760\n\nChange-Id: I0fa9423523a3a0fb1dfcde57de0f26e51723ff97\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine/netstack, net/ping: stop using pro-bing and use our net/ping…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-04T21:05:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81569e891fdcd71aabc0fb0ccd2238f6f805abea",
          "body": "The purpose of this package is to test the iOS dependency closure, but\nit had drifted from the actual import list of the ipn-go-bridge package\nin the corp repo (the Go side of the iOS / macOS app).\n\nUpdate the imports to match ipn-go-bridge's GOOS=ios import list,\nadding many missing packages includ\n[…]\ner-ping, so the iOS app already ships them.\nBut we should fix that later.\n\nUpdates #19633\n\nChange-Id: Ic50779fdb195685a2e8ccd7c513eee91b0feeaf8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/iosdeps: update import list to mirror ipn-go-bridge",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-04T21:05:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9bb7ca6116a90da553454614e497a8cb84faa8c0",
          "body": "Add a new vet checker that rejects variables, parameters, named\nreturn values, receivers, range/type-switch bindings, type\nparameters, struct fields, and constants named \"l\" (lowercase ell)\nor \"I\" (uppercase i). Both are hard to distinguish from the digit\n\"1\" and from each other in too many fonts.\n\n\n[…]\nstdata/ directories, which\nthe go tool ignores; they are not real packages.\n\nFixes #19631\n\nChange-Id: I71ad2fa990705f7a070406ebcdb8cefa7487d849\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/vet/lowerell, drive/driveimpl: forbid variables named \"l\" or \"I\"",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-04T21:03:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0cf899610c2ac62780826d8e3ba908ddcc3f2115",
          "body": "Added in 2022, this appears to be unused now.\n\nUpdates #cleanup\n\nSigned-off-by: Andrew Lytvynov <awly@tailscale.com>",
          "is_bot": false,
          "headline": "util/linuxfw/linuxfwtest: remove unused package (#19520)",
          "author_name": "Andrew Lytvynov",
          "author_login": "awly",
          "committed_at": "2026-05-04T19:33:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca2317439dcc543cce62d55fa7ebd794f5ebe34f",
          "body": "Signed-off-by: License Updater <noreply+license-updater@tailscale.com>",
          "is_bot": false,
          "headline": "licenses: update license notices",
          "author_name": "License Updater",
          "author_login": null,
          "committed_at": "2026-05-04T17:34:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce76f44df2592dbd9c97b27ef0c04d079be907d0",
          "body": "Which can be unfair around varying packet sizes.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
          "is_bot": false,
          "headline": "derp/derpserver: remove global rate limiter",
          "author_name": "Jordan Whited",
          "author_login": "jwhited",
          "committed_at": "2026-05-04T16:41:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29122506be064dbecfcb376d45a00106f762db26",
          "body": "Move HOOK_VERSION into the githook package and export it as\ngithook.HookVersion, so tailscale/corp can reference it via\nthe shared-code bump instead of having to bump HOOK_VERSION\nby hand.\n\nNew launcher.sh composes the wanted version from 2 sources:\nthe shared HOOK_VERSION and an optional repo local\n[…]\nisc/git_hook/HOOK_VERSION, for repo-specific config bumps.\n\nUpdates tailscale/corp#40381\n\nChange-Id: I7cf16889ba53cb564cc2df7dfd7588748f542c55\n\nSigned-off-by: Fernando Serboncini <fserb@tailscale.com>",
          "is_bot": false,
          "headline": "misc/git_hook: propagate shared HOOK_VERSION (#19476)",
          "author_name": "Fernando Serboncini",
          "author_login": "fserb",
          "committed_at": "2026-05-04T16:38:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "290a6cc03cb9ba59b4847a778c4bf9f382c52e21",
          "body": "…9202)\n\nInstalled SplitDNS routes are always treated as wildcard domains,\nso the domains that we pass to the local resolver should be normalized\nand have any leading *. wildcard prefix removed.\n\nWhen looking at DNS responses to see if the domain matches, we need to\nconsider both exact matches and wi\n[…]\n response should be rewritten, it is ignored\nif any of the matching apps for the domain are in the self-hosted apps set.\n\nFixes tailscale/corp#39272\n\nSigned-off-by: George Jones <george@tailscale.com>",
          "is_bot": false,
          "headline": "appc, feature/conn25: handle exact and wildcard domains correctly (#1…",
          "author_name": "George Jones",
          "author_login": "george-tailscale",
          "committed_at": "2026-05-01T21:33:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdf3419e7d5c851b9fe4c974d93ffb6f0da4820d",
          "body": "If another part of the client code registers a custom scheme with the\nforwarder, the forwarder will check resolver addresses to see if they\nmatch the scheme. If they do, the corresponding custom scheme handler\nwill be called to find the actual address for the resolver at this\nmoment. If the handler \n[…]\nwork that would like to make sure it sends DNS requests to the\ncurrent connector peer in a high availability configuration.\n\nUpdates tailscale/corp#39858\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
          "is_bot": false,
          "headline": "net/dns: add custom scheme resolvers",
          "author_name": "Fran Bull",
          "author_login": "franbull",
          "committed_at": "2026-05-01T21:01:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78126c5d9f8876fb4e98be4a786a01c9ed9ab983",
          "body": "Add a node capability to help determine if the desktop clients should\nshow services list/menu/section\n\nUpdates: https://github.com/tailscale/corp/issues/40900\n\nChange-Id: Ie34b3362f921d710173b2a0dd190354352bb26f0\n\nSigned-off-by: Rollie Ma <rollie@tailscale.com>",
          "is_bot": false,
          "headline": "tailcfg: add node capability for services in desktop clients (#19605)",
          "author_name": "Rollie Ma",
          "author_login": "waltzofpearls",
          "committed_at": "2026-05-01T19:07:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee10f9881c86e5f230c2af34ed0bfaa009697b03",
          "body": "also fixes memory leak with authKeyReissuing map on ProxyGroup\nreconciler authkey reissue.\n\nUpdates #19311\n\nSigned-off-by: chaosinthecrd <tom@tmlabs.co.uk>",
          "is_bot": false,
          "headline": "cmd/k8s-operator: add authkey reissuing to recorder reconciler (#19556)",
          "author_name": "Tom Meadows",
          "author_login": "ChaosInTheCRD",
          "committed_at": "2026-05-01T17:26:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ced30b0b6b6aa085cfbba5f5a9bbc0a52d480b3",
          "body": "Values get written into TKA state; secrets don't.\n\nUpdates #cleanup\n\nChange-Id: Ief9831dcb1102f584a33b2e71b611b38ca463724\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "tka: clarify that this limit is on disablement *values* not *secrets*",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-05-01T17:25:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f15a4f441621e537340234d63271d3cf4dffe4b5",
          "body": "There are only a couple endpoints that check peer capabilities. Keeping\npermission checks with the code that assumes they were performed, rather\nthan with the routing layer, feels easier to reason about.\n\nCheck that the caller is actually a peer and pass their capabilities via\na context value for ha\n[…]\nlers that want to check them.\n\nAlong with this, simplify the helper handler wrappers that are not\nneeded for most of the endpoints.\n\nUpdates #40851\n\nSigned-off-by: Andrew Lytvynov <awly@tailscale.com>",
          "is_bot": false,
          "headline": "client/web: move API permission checks into handlers (#19576)",
          "author_name": "Andrew Lytvynov",
          "author_login": "awly",
          "committed_at": "2026-05-01T16:01:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bbcb8650d418f699034cfc57216d2ad8ec7d3556",
          "body": "Stop opening an IPN bus subscription with NotifyInitialNetMap purely to\nread the current netmap once. Use the LocalAPI debug current-netmap\naction (added in 159cf8707) instead, which returns the current netmap\nsynchronously without subscribing to the bus.\n\nUpdates #12542\n\nChange-Id: I8aa2096d65aaea4dfe62634f03ce06b5470e0e51\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/tailscale/cli: fetch netmap via current-netmap debug action",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-01T14:53:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c3ed5ab32f29159301edd812d5948eef8602499",
          "body": "Move tailscaled's in-tree reactive users from of IPN bus Notify.NetMap\nupdates to the narrower Notify.SelfChange signal introduced earlier in\nthis series. Consumers that need additional state (peers, DNS config,\netc.) fetch it on demand via the LocalAPI.\n\nIt is a step toward the larger goal of not f\n[…]\nto the\nupcoming new Notify APIs, we'll remove ipn.Notify.NetMap entirely)\n\nUpdates #12542\n\nChange-Id: I51ea9d86bdca1909d6ac0e7d5bd3934a3a4e8516\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "all: migrate code off Notify.NetMap to Notify.SelfChange",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-01T13:51:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff9c3f0e003ebf7f351dcae7c14a6b770b6c9544",
          "body": "For testing the loading of netmap cache from disk, the cache needs to\nexist. The simple solution is to start two nodes and connect them to\ncontrol, with the netmap caching capability set. Then cut the connection\nto control, restart the nodes, and ping between them.\n\nThis tests that we can start from\n[…]\nstablish a connection between the nodes.\n\nFor now this is not testing how the nodes are able to talk to each other\n(DERP vs direct).\n\nUpdates #19597\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: add test loading netmap cache from disk (#19598)",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-05-01T13:46:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89a78dc9b733671bfc62d14377c6a7a4b7e1837d",
          "body": "Add a narrow LocalAPI accessor and matching client/LocalBackend method\nto look up a single peer's current full [tailcfg.Node] by NodeID, in\nO(1) time on the daemon side, without fetching the entire netmap.\n\nUseful for callers that need the latest state of a single peer (e.g.\nin response to a peer-mutation event on the IPN bus) without paying\nfor a full netmap fetch.\n\nUpdates #12542\n\nChange-Id: I1cb2d350e6ad846a5dabc1f5368dfc8121387f7c\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "client/local, ipn/localapi, ipn/ipnlocal: add PeerByID",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-05-01T13:20:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cac94f51cc71d15fdca91582487d7216d93aa172",
          "body": "Compacting on startup means nodes may compact at a different cadence\nbased on whether they're long-running or restarting frequently.\n\nWe already compact after every sync, which only occurs when the TKA\nstate has changed. Waiting for TKA changes to trigger compaction on\nnodes means compaction will occur more consistently across a tailnet.\n\nUpdates tailscale/corp#33537\n\nChange-Id: Ia0aa6d9e5e362e9ab08450fde69772841790d5b5\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal: don't compact TKA state on startup",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-05-01T12:27:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6c5d237429f3f7e865d757e5f5075a8c919bbbd",
          "body": "Add a new bus signal that lets reactive consumers (containerboot, kube\nagents, sniproxy, tsconsensus, etc.) react to self-node updates without\nhaving to subscribe to the full netmap. Today those consumers either\nwatch Notify.NetMap (which on large tailnets is expensive to encode and\nship per watcher\n[…]\nthe legacy NetMap emission to platforms whose host GUIs still\nrequire it.\n\nUpdates #12542\n\nChange-Id: I4441650b0e085d663eb6bf26a03748b7d961ca49\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "ipn, ipn/ipnlocal: add Notify.SelfChange",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T21:47:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f343fdc0cf1455f5550cb0d6c6a344848049306",
          "body": "Add two narrow LocalAPI accessors so callers don't have to subscribe to\nthe IPN bus and pull a full *netmap.NetworkMap just to read DNS-shaped\nfields:\n\n  - GET /localapi/v0/cert-domains returns DNS.CertDomains.\n  - GET /localapi/v0/dns-config returns the full tailcfg.DNSConfig.\n\nMigrate in-tree call\n[…]\nraveling on the IPN bus, so the bus payload can shrink in a\nlater change.\n\nUpdates #12542\n\nChange-Id: Ie10204e141d085fbac183b4cfe497226b670ad6c\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "client/local, ipn/localapi, all: add CertDomains and DNSConfig accessors",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T20:50:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "822299642b71ae381d2be1d46234fc48acf8ec5c",
          "body": "We have two sources of truth for configuration state: the node view\n(from the netmap/policy) and prefs (the --advertise-connector option).\nThese come with two independent update paths: onSelfChange for node view\nchanges and profileStateChange for pref changes.\n\nCentralize config on Conn25 so that on\n[…]\nonfig. See getIPSets() in this commit.\n\n - As of this commit, the connector doesn't need config-derived state at\n   all.\n\nFixes tailscale/corp#40872\n\nSigned-off-by: Michael Ben-Ami <mzb@tailscale.com>",
          "is_bot": false,
          "headline": "feature/conn25: centralize config on Conn25 with atomic access",
          "author_name": "Michael Ben-Ami",
          "author_login": "mzbenami",
          "committed_at": "2026-04-30T20:29:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "159cf8707a0293e58c6e23360240b9b62f72294f",
          "body": "…MapWithPeers\n\nAdd two narrower accessors alongside the existing\n[LocalBackend.NetMap], with docs that distinguish their semantics:\n\n  - NetMapNoPeers: cheap (returns the cached *netmap.NetworkMap with\n    a possibly-stale Peers slice). For callers that only read non-Peers\n    fields like SelfNode, \n[…]\nreaking up a larger change for\nreview; on its own it is a no-op refactor.\n\nUpdates #12542\n\nChange-Id: Idbb30707414f8da3149c44ca0273262708375b02\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal, all: split LocalBackend.NetMap into NetMapNoPeers / Net…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T18:14:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92179b1fc7ec203eaa9cb5f584f34ca36f25168c",
          "body": "Move the template, request handler, and HTTP/HTTPS server wiring out\nof package main and into a new cmd/hello/helloserver package so the\nserver can be embedded in other binaries. The main package now only\nconstructs a helloserver.Server with the production addresses and\ncalls Run.\n\nWhile here, drop \n[…]\nllbacks they enabled; the binary is\nonly run in production.\n\nUpdates tailscale/corp#32398\n\nChange-Id: Id1d38b981733334cafc596021130f36e1c1eed67\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/hello: split server into helloserver package",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T15:40:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "644c3224e923b4f2e10035672bdb2fe2b16a6830",
          "body": "This commit modifies the usage of the `egressservices.Configs` type\nwithin containerboot and the k8s operator.\n\nOriginally it was being thrown around as a pointer which is not required\nas maps are already pointers under the hood.\n\nSigned-off-by: David Bond <davidsbond93@gmail.com>",
          "is_bot": false,
          "headline": "cmd/{containerboot,k8s-operator}: don't return pointers to maps (#19593)",
          "author_name": "David Bond",
          "author_login": "davidsbond",
          "committed_at": "2026-04-30T15:11:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "815bb291c9cecacfaca5f884bd4a1702f1c0edf2",
          "body": "If a user passes --advertise-tags=foo,bar (with no colons in any\nsegment), automatically prepend \"tag:\" client-side so it goes on the\nwire as \"tag:foo,tag:bar\". Segments that already contain a colon are\nleft untouched and must be fully-qualified (\"tag:foo\"), which keeps\nthe door open for future colo\n[…]\nuto-qualifying tag names in advertise-tags and I hope I won't regret\nit :)\"\n\nUpdates #861\n\nChange-Id: I06935b0d3ae909894c95c9c2e185b7d6a219ff32\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/tailscale/cli: allow tag without \"tag:\" prefix in 'tailscale up'",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T14:13:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f343b496c3efef16b1d0dd4183a3d7624daba944",
          "body": "…mand peers\n\nReplace the UAPI text protocol-based wireguard configuration with\nwireguard-go's new direct callback API (SetPeerLookupFunc,\nSetPeerByIPPacketFunc, RemoveMatchingPeers, SetPrivateKey).\n\nInstead of computing a trimmed wireguard config ahead of time upon\ncontrol plane updates and pushing \n[…]\nPs to node public keys\nusing the existing nodeByAddr index.\n\nUpdates tailscale/corp#12345\n\nChange-Id: I4cba80979ac49a1231d00a01fdba5f0c2af95dd8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine, all: remove LazyWG, use wireguard-go callback API for on-de…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-30T02:46:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b313bffbe7e5fe31694f2127621c04790f2216fa",
          "body": "…stControl\n\nThe test was flaky under stress with \"AddRawMapResponse N: node not\nconnected\" failures. The root cause was in testcontrol's addDebugMessage:\nit conflated \"no streaming poll registered\" with \"wake-up channel buffer\nmomentarily full\". The single-slot updatesCh is just a lossy wake-up\nsign\n[…]\nn CI)\" stack\ndumps emitted by controlhttp.(*Dialer).forceNoise443 under CI.\n\nFixes #19583\n\nChange-Id: Ib2334376585e8d6562f000a0b71dea0117acb0ff\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "control/tsp, tstest/integration/testcontrol: deflake TestMapAgainstTe…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T23:11:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "978b6a81b286201d968dff19ae1afc98acf09d03",
          "body": "78627c1 introduced starting up and preserving the DERP server from\ncache, but also changed it so the initial ReSTUN would not fire when\nsetting the DERPMap.\n\nChange this so when not working from a cache, the ReSTUN will always\nfire during startup.\n\nUpdates #19585\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "ipn/ipnlocal: always ReSTUN when starting up without a cache (#19586)",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-04-29T22:56:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0a9728fe2abcb5219589915a116ba15afbec56f",
          "body": "As of 0e9f9e2bd it is possible to have an infinity per-client limit,\nwith finite global.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
          "is_bot": false,
          "headline": "derp/derpserver: fix Server.UpdateRateLimits docs",
          "author_name": "Jordan Whited",
          "author_login": "jwhited",
          "committed_at": "2026-04-29T21:43:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e9f9e2bd80712f2deec48930633813151614e92",
          "body": "This commit enables the operator to set a global rate limit without any\nper-client.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
          "is_bot": false,
          "headline": "derp/derpserver: support global rate limiting independent of per-client",
          "author_name": "Jordan Whited",
          "author_login": "jwhited",
          "committed_at": "2026-04-29T21:15:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15cba0a3f66fc2f5a481ec9d986f94e9a95d2935",
          "body": "Add a vmtest that brings up two gokrazy nodes A and B behind two\nOne2OneNAT networks (so direct UDP works in both directions and any\nslowness can't be blamed on NAT traversal), establishes a WireGuard\ntunnel A → B with TSMP, then rotates B's disco key four times and\nasserts that the data plane recov\n[…]\n retry transient\n  failures rather than fataling the test.\n\nUpdates #12639\nUpdates #13038\n\nChange-Id: I3644f27fc30e52990ba25a3983498cc582ddb958\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: add TestDiscoKeyChange",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T19:58:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22ff402da93f1487f9de72a413014500a39003cf",
          "body": "…utReSTUN\n\nCommit 78627c132f changed the signature of magicsock.Conn.SetDERPMap to\ntake an additional bool doReStun parameter. Avoid both the boolean\nparameter and the API signature change by restoring SetDERPMap to its\noriginal single-argument form and adding a new SetDERPMapWithoutReSTUN\nmethod for the cache-loading caller that wants to skip the post-set\nReSTUN.\n\nUpdates #19490\n\nChange-Id: I97d9e82156bfc546ccf59756d1ea52f039b5de06\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine/magicsock: restore SetDERPMap signature, add SetDERPMapWitho…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T19:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26c56338c68235956decad7459cea54e9099c991",
          "body": "…e7bd2da",
          "is_bot": false,
          "headline": "chore: Cumulative updates from MESH 5a0f75cb16c9a42a838bb759a3e194822…",
          "author_name": "Dan Staples",
          "author_login": "dismantl",
          "committed_at": "2026-04-29T18:45:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cd8bcc82734620931f6d2bc0cbe90c057e4439d",
          "body": "Updates: tailscale/corp#40648\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
          "is_bot": false,
          "headline": "tailcfg: extend services model for client application actions",
          "author_name": "Adriano Sela Aviles",
          "author_login": "adrianosela",
          "committed_at": "2026-04-29T18:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70f0b261b6f96192cd2a4e0974ee3bf8f6d7cbda",
          "body": "…log change\n\nWhen we switched to monogok in 371d6369cd25afb, we lost our gokrazy fork's\nchange to let the syslog be configured from the Linux cmdline.\n\nThat's sent upstream in gokrazy/gokrazy#275 but still in review. Meanwhile,\nrevert to a fork, while still keeping monogok. Monogok was updated to\nsu\n[…]\nthe log polling loop out of pending PR #19568\nand go ack to using syslog.\n\nUpdates #13038\n\nChange-Id: I36931ee8eecc40d6165ad036c6181dfb07b86ba2\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "go.mod, gokrazy: bump to fork of gokrazy/gokrazy init process for sys…",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T18:27:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01d0bdd25366a095ec5a07e14baaef438d309f2b",
          "body": "Expvars track count of rate limiters exceeding their threshold.\nCovers (1) global rate limiter and (2) total of local rate limiters.\n\nAlso publish optional rate-limit metrics during ExpVar() call\nif -rate-config is specified. Fixes current rate-limit metrics\nbeing published outside of \"derp\" in /debug/vars.\n\nUpdates tailscale/corp#38509\n\nChange-Id: Ic7f5a1e890d0d7d3d7b679daa4b5f8926a6a6964\nSigned-off-by: Alex Valiushko <alexvaliushko@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/derper,derp: add metrics for rate limit hits (#19560)",
          "author_name": "Alex Valiushko",
          "author_login": "illotum",
          "committed_at": "2026-04-29T17:29:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be7cce74ba97f2f31820168aed0ea4c8e73e3367",
          "body": "…ch (#19575)\n\nThe mismatch behaviour of falling back to a previous key could end up\nbreaking connections when the netmap update took longer than the 2\nseconds allowed in controlClient.auto for netmap updates, or if the\ncontrolClient context was canceled. This could end up breaking\nlegitimate updates\n[…]\nom control.\n\nInstead, log the event, and let the connection be reset to that of the\nkey as that is safer.\n\nIssue found by @bradfitz.\n\nUpdates #19574\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine/userspace: do not fall back to old key on tsmpLearned mismat…",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-04-29T17:23:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd6ae2fad4be801b3610358fc52c5df4bdcfd736",
          "body": "Two cloud-platform nodes (e.g. sr-a and sr-b in TestSiteToSite) boot in\nparallel via errgroup and both call ensureCompiled and the inline image\npreparation block, racing to Begin() the same shared *Step (which is\ndeduped by name in Env.Step). The second goroutine panics:\n\n    panic: Step \"Compile li\n[…]\ns Begin/work/End.\n\nFixes commit 02ffe5baa8ccb2b81c4cfba3b59653e2cff10e01.\n\nUpdates #13038\n\nChange-Id: If710bcc9e0aafebf0ad5b61553bae11458d976d7\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: serialize per-platform setup with sync.Once",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T16:54:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02ffe5baa8ccb2b81c4cfba3b59653e2cff10e01",
          "body": "Cache a pre-booted macOS VM snapshot on disk so subsequent test runs\nrestore from the snapshot instead of cold-booting. The snapshot is keyed\nby the Tart base image digest and a code version constant\n(macOSSnapshotCodeVersion); bumping either invalidates the cache.\n\nSnapshot preparation (one-time):\n\n[…]\ne\n- Fix Makefile: set -o pipefail so xcodebuild failures aren't swallowed\n\nUpdates #13038\n\nChange-Id: Icbab73b57af7df3ae96136fb49cda2536310f31b\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: add macOS VM snapshot caching for fast test starts",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T15:17:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b53550fe6fb11a5dce69ce61cee108c3607273a",
          "body": "…(#19565)\n\nUpon deciding to update the LastSeen timestamp, we weren't checking that the\nfield we are replacing into was non-nil. Rather than add an additional check,\njust allocate a fresh pointer for the updated time.\n\nUpdates #19564\n\nChange-Id: I589ebe65175fc7677c04a31dd6c4670e2531ee62\nSigned-off-by: M. J. Fromberger <fromberger@tailscale.com>",
          "is_bot": false,
          "headline": "control/controlclient: fix a nil-indirection bug in DERP key pruning …",
          "author_name": "M. J. Fromberger",
          "author_login": "creachadair",
          "committed_at": "2026-04-29T14:57:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a29e42135b793660e4e658aa4f2bc8155420de36",
          "body": "This commit modifies the `DNSConfig` resource to allow customisation of\nthe `spec.nodeSelector` field in the nameserver pods.\n\nCloses: https://github.com/tailscale/tailscale/issues/19419\n\nSigned-off-by: David Bond <davidsbond93@gmail.com>",
          "is_bot": false,
          "headline": "cmd/k8s-operator: add nodeSelector to `DNSConfig` resource (#19429)",
          "author_name": "David Bond",
          "author_login": "davidsbond",
          "committed_at": "2026-04-29T14:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cec06b8f2c65c832ed71a902481c80dbe80695c",
          "body": "When --vmtest-web is set, Host.app is launched with --screenshot-port 0\nto start a localhost HTTP server that captures the VZVirtualMachineView\ndisplay. The Go test harness parses the SCREENSHOT_PORT=<port> line from\nstdout, then polls every 2 seconds for JPEG thumbnails and pushes them\nover WebSock\n[…]\ny're large\nand only the latest matters, stored in NodeStatus.Screenshot).\n\nUpdates #13038\n\nChange-Id: I9bc67ddd1cc72948b33c555d4be3d8db06a41f6d\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
          "is_bot": false,
          "headline": "tstest/natlab/vmtest: add macOS VM screenshot streaming to web UI",
          "author_name": "Brad Fitzpatrick",
          "author_login": "bradfitz",
          "committed_at": "2026-04-29T14:48:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78627c132f6795ed85729bac97a4ed6bca1c8295",
          "body": "…#19491)\n\nWith netmap caching, the home DERP of the self node was neither saved to\nthe cache or loaded from it, making nodes not stick to a DERP when\nstarting without a connection to control.\n\nInstead, make sure that when a cache is available, load that cache,\nbefore looking for DERP servers. This i\n[…]\nished.\n\nMaking DERP only change when connected to control is handled by existing\ncode from f072d017bd8241675aa946a27fc1827f570435cb.\n\nUpdates #19490\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
          "is_bot": false,
          "headline": "wgengine/magicsock,ipn/ipnlocal: store and load homeDERP from cache (…",
          "author_name": "Claus Lensbøl",
          "author_login": "cmol",
          "committed_at": "2026-04-29T14:24:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1841a93ab2c30d6ce79af53d3ccf0b3d9f1c2897",
          "body": "…laky (again)\n\nThis test is still flaking on macOS, so mark it as such so we can track\nand investigate further.\n\nUpdates #7707\n\nChange-Id: I640da3c1068a90a9815caab2df9431bceb01f846\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "ssh/tailssh: mark TestSSHRecordingCancelsSessionsOnUploadFailure as f…",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-04-29T13:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb91bb842c189d0ebe7ea87e6744b5484f1f3511",
          "body": "Seamless key renewal has been the default in all clients since 1.90.\nWe retained the ability to disable it from the control plane as a\nprecaution, but we haven't seen any issues that require us to disable it.\n\nWe're now removing all the code for non-seamless key renewal, because we\ndon't expect to t\n[…]\nntested in the\nfield for three releases so might contain latent bugs!\n\nUpdates tailscale/corp#33042\n\nChange-Id: I4b80bf07a3a50298d1c303743484169accc8844b\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
          "is_bot": false,
          "headline": "all: remove everything related to non-seamless key renewal",
          "author_name": "Alex Chan",
          "author_login": "alexwlchan",
          "committed_at": "2026-04-29T09:03:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40088602c960a53961db129526b98d473373071a",
          "body": "Fixes #19566\n\nSigned-off-by: Noel O'Brien <noel@tailscale.com>",
          "is_bot": false,
          "headline": "cmd/hello: remove hello.ipn.dev (#19567)",
          "author_name": "Noel O'Brien",
          "author_login": "noelob",
          "committed_at": "2026-04-29T00:54:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 95,
      "commits_last_year": 1292,
      "latest_release_at": "2026-02-13T19:41:21Z",
      "latest_release_tag": "v1.94.2",
      "releases_from_tags": true,
      "days_since_last_push": 9,
      "active_weeks_last_year": 46,
      "days_since_latest_release": 165,
      "mean_days_between_releases": 8.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "tailscale.com",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": null,
          "registry_url": "https://pkg.go.dev/tailscale.com",
          "is_deprecated": false,
          "latest_version": "v1.102.0",
          "repository_url": null,
          "versions_count": 232,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-23T18:54:05Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [
        "example",
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "docs/k8s/Makefile",
        "gokrazy/Makefile",
        "tool/goexe/Makefile",
        "tstest/tailmac/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "client/web/tsconfig.json",
        "cmd/tsconnect/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod",
        "tool/goexe/Cargo.toml"
      ],
      "largest_source_bytes": 276136,
      "source_files_sampled": 2180,
      "oversized_source_files": 23,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "filippo.io/mkcert",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.4"
        },
        {
          "name": "fyne.io/systray",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1-0.20250812065214-4856ac3adc3c"
        },
        {
          "name": "github.com/BARGHEST-ngo/amnezia-wireguard-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0-alpha.2"
        },
        {
          "name": "github.com/BARGHEST-ngo/androidqf_mesh",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/Kodeworks/golang-image-ico",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20141118225523-73f0f4cfade9"
        },
        {
          "name": "github.com/akutz/memconn",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.0"
        },
        {
          "name": "github.com/alexbrainman/sspi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231016080023-1a75b4708caa"
        },
        {
          "name": "github.com/andybalholm/brotli",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/atotto/clipboard",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.41.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.29.5"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/feature/s3/manager",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.17.58"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/s3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.75.3"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/ssm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.7"
        },
        {
          "name": "github.com/axiomhq/hyperloglog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240319100328-84253e514e02"
        },
        {
          "name": "github.com/botherder/go-savetime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/bradfitz/go-tool-cache",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260216153636-9e5201344fe5"
        },
        {
          "name": "github.com/bradfitz/monogok",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260429173803-229ef7981a6b"
        },
        {
          "name": "github.com/bramvdbogaerde/go-scp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/cilium/ebpf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.16.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.12"
        },
        {
          "name": "github.com/coreos/go-iptables",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.1-0.20240112124308-65c67c9f46e6"
        },
        {
          "name": "github.com/coreos/go-systemd",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20191104093116-d3cd4ed1dbcf"
        },
        {
          "name": "github.com/creachadair/mds",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.25.9"
        },
        {
          "name": "github.com/creachadair/msync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.1"
        },
        {
          "name": "github.com/creachadair/taskgroup",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.2"
        },
        {
          "name": "github.com/creack/pty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.24"
        },
        {
          "name": "github.com/dblohm7/wingoes",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240119213807-a09d6be7affa"
        },
        {
          "name": "github.com/digitalocean/go-smbios",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20180907143718-390a4f403a8e"
        },
        {
          "name": "github.com/distribution/reference",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.0"
        },
        {
          "name": "github.com/djherbis/times",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/dsnet/try",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.3"
        },
        {
          "name": "github.com/elastic/crd-ref-docs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.12"
        },
        {
          "name": "github.com/evanw/esbuild",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.19.11"
        },
        {
          "name": "github.com/fogleman/gg",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/frankban/quicktest",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.6"
        },
        {
          "name": "github.com/fxamacker/cbor/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.9.0"
        },
        {
          "name": "github.com/gaissmai/bart",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.26.1"
        },
        {
          "name": "github.com/go-json-experiment/json",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250813024750-ebf49471dced"
        },
        {
          "name": "github.com/go-logr/zapr",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/go-ole/go-ole",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/go4org/hashtriemap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20251130024219-545ba229f689"
        },
        {
          "name": "github.com/go4org/plan9netshell",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250324183649-788daa080737"
        },
        {
          "name": "github.com/godbus/dbus/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.1.1-0.20230522191255-76236955d466"
        },
        {
          "name": "github.com/gokrazy/breakglass",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20251229072214-9dbc0478d486"
        },
        {
          "name": "github.com/gokrazy/gokrazy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260418085648-c38c3134b8a7"
        },
        {
          "name": "github.com/gokrazy/kernel.arm64",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260403054012-807489e0272a"
        },
        {
          "name": "github.com/gokrazy/serial-busybox",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250119153030-ac58ba7574e7"
        },
        {
          "name": "github.com/golang/groupcache",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20241129210726-2c02b8208cf8"
        },
        {
          "name": "github.com/golang/snappy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.4"
        },
        {
          "name": "github.com/golangci/golangci-lint",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.57.1"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-containerregistry",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.5"
        },
        {
          "name": "github.com/google/go-tpm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.4"
        },
        {
          "name": "github.com/google/gopacket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.19"
        },
        {
          "name": "github.com/google/nftables",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.1-0.20240414091927-5e242ec57806"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/goreleaser/nfpm/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.33.1"
        },
        {
          "name": "github.com/hashicorp/go-hclog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.2"
        },
        {
          "name": "github.com/hashicorp/raft",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.2"
        },
        {
          "name": "github.com/hashicorp/raft-boltdb/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.3.1"
        },
        {
          "name": "github.com/hdevalence/ed25519consensus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/huin/goupnp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/i582/cfmt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/illarion/gonotify/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.2"
        },
        {
          "name": "github.com/inetaf/tcpproxy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250203165043-ded522cbd03f"
        },
        {
          "name": "github.com/insomniacslk/dhcp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231206064809-8c70d406f6d2"
        },
        {
          "name": "github.com/jellydator/ttlcache/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.1.0"
        },
        {
          "name": "github.com/jsimonetti/rtnetlink",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/kballard/go-shellquote",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20180428030007-95032a82bc51"
        },
        {
          "name": "github.com/kdomanski/iso9660",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/klauspost/compress",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.18.5"
        },
        {
          "name": "github.com/kortschak/wol",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200729010619-da482cc4850a"
        },
        {
          "name": "github.com/mattn/go-colorable",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.13"
        },
        {
          "name": "github.com/mattn/go-isatty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.20"
        },
        {
          "name": "github.com/mdlayher/genetlink",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.2"
        },
        {
          "name": "github.com/mdlayher/netlink",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.3-0.20250113171957-fbb4dce95f42"
        },
        {
          "name": "github.com/mdlayher/sdnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/miekg/dns",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.58"
        },
        {
          "name": "github.com/mitchellh/go-ps",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/peterbourgon/ff/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.0"
        },
        {
          "name": "github.com/pires/go-proxyproto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.1"
        },
        {
          "name": "github.com/pkg/errors",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/pkg/sftp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.13.6"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.0"
        },
        {
          "name": "github.com/prometheus/common",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.65.0"
        },
        {
          "name": "github.com/prometheus/prometheus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.2-0.20240125131847-c3b8ef1694ff"
        },
        {
          "name": "github.com/robert-nix/ansihtml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.1"
        },
        {
          "name": "github.com/safchain/ethtool",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "github.com/skip2/go-qrcode",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200617195104-da1b6568686e"
        },
        {
          "name": "github.com/studio-b12/gowebdav",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "github.com/tailscale/certstore",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.1-0.20260409135935-3638fb84b77d"
        },
        {
          "name": "github.com/tailscale/depaware",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20251001183927-9c2ad255ef3f"
        },
        {
          "name": "github.com/tailscale/gliderssh",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.4-0.20260330083525-c1389c70ff89"
        },
        {
          "name": "github.com/tailscale/goexpect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20210902213824-6e8c725cea41"
        },
        {
          "name": "github.com/tailscale/gokrazy-kernel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240728225134-3d23beabda2e"
        },
        {
          "name": "github.com/tailscale/golang-x-crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250404221719-a5573b049869"
        },
        {
          "name": "github.com/tailscale/hujson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260302212456-ecc657c15afd"
        },
        {
          "name": "github.com/tailscale/mkctr",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260107121656-ea857e3e500b"
        },
        {
          "name": "github.com/tailscale/netlink",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.1-0.20240822203006-4d49adab4de7"
        },
        {
          "name": "github.com/tailscale/peercred",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250107143737-35a0c7bd7edc"
        },
        {
          "name": "github.com/tailscale/setec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20251203133219-2ab774e4129a"
        },
        {
          "name": "github.com/tailscale/ts-gokrazy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260429180033-fe741c6deb44"
        },
        {
          "name": "github.com/tailscale/web-client-prebuilt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250124233751-d4cd19a26976"
        },
        {
          "name": "github.com/tailscale/wf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240214030419-6fbb0a674ee6"
        },
        {
          "name": "github.com/tailscale/xnet",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240729143630-8497ac4dab2e"
        },
        {
          "name": "github.com/tc-hib/winres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.1"
        },
        {
          "name": "github.com/tcnksm/go-httpstat",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/toqueteos/webbrowser",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/u-root/u-root",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.14.0"
        },
        {
          "name": "github.com/vishvananda/netns",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.5"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.0"
        },
        {
          "name": "go4.org/mem",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20240501181205-ae6ca9944745"
        },
        {
          "name": "go4.org/netipx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231129151722-fdeea329fbba"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.50.0"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250620022241-b7579e27df2b"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.53.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.42.0"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.0"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.44.0"
        },
        {
          "name": "golang.zx2c4.com/wintun",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20230126152724-0fa3db229ce2"
        },
        {
          "name": "golang.zx2c4.com/wireguard/windows",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.3"
        },
        {
          "name": "gopkg.in/square/go-jose.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.0"
        },
        {
          "name": "gvisor.dev/gvisor",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260224225140-573d5e7127a8"
        },
        {
          "name": "helm.sh/helm/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.19.0"
        },
        {
          "name": "honnef.co/go/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/apiserver",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "sigs.k8s.io/controller-runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.19.4"
        },
        {
          "name": "sigs.k8s.io/controller-tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.17.0"
        },
        {
          "name": "sigs.k8s.io/kind",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.30.0"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "software.sslmate.com/src/go-pkcs12",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "tailscale.com/client/tailscale/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.9.0"
        },
        {
          "name": "github.com/AlekSi/pointer",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.16.27"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.41.5"
        },
        {
          "name": "github.com/aws/smithy-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.24.0"
        },
        {
          "name": "github.com/fatih/color",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.18.0"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.0"
        },
        {
          "name": "github.com/gorilla/csrf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.3"
        },
        {
          "name": "github.com/mdlayher/socket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.0"
        },
        {
          "name": "github.com/prometheus/client_model",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.2"
        },
        {
          "name": "github.com/sourcegraph/go-diff",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tailscale/go-winio",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231025203758-c4f33415bf55"
        },
        {
          "name": "github.com/ulikunitz/xz",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.15"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "k8s.io/apiextensions-apiserver",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250604170112-4c0f3b243397"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 7,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 3,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "bradfitz",
          "commits": 3319,
          "avatar_url": "https://avatars.githubusercontent.com/u/2621?v=4"
        },
        {
          "type": "User",
          "login": "danderson",
          "commits": 881,
          "avatar_url": "https://avatars.githubusercontent.com/u/1918?v=4"
        },
        {
          "type": "User",
          "login": "josharian",
          "commits": 401,
          "avatar_url": "https://avatars.githubusercontent.com/u/67496?v=4"
        },
        {
          "type": "User",
          "login": "raggi",
          "commits": 267,
          "avatar_url": "https://avatars.githubusercontent.com/u/348?v=4"
        },
        {
          "type": "User",
          "login": "andrew-d",
          "commits": 267,
          "avatar_url": "https://avatars.githubusercontent.com/u/1079173?v=4"
        },
        {
          "type": "User",
          "login": "jwhited",
          "commits": 244,
          "avatar_url": "https://avatars.githubusercontent.com/u/10344482?v=4"
        },
        {
          "type": "User",
          "login": "awly",
          "commits": 211,
          "avatar_url": "https://avatars.githubusercontent.com/u/1146263?v=4"
        },
        {
          "type": "User",
          "login": "irbekrm",
          "commits": 208,
          "avatar_url": "https://avatars.githubusercontent.com/u/24879183?v=4"
        },
        {
          "type": "User",
          "login": "dsnet",
          "commits": 193,
          "avatar_url": "https://avatars.githubusercontent.com/u/6354026?v=4"
        },
        {
          "type": "User",
          "login": "crawshaw",
          "commits": 186,
          "avatar_url": "https://avatars.githubusercontent.com/u/161319?v=4"
        }
      ],
      "contributors_sampled": 99,
      "top_contributor_share": 0.367
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "checklocks.yml",
        "cigocacher.yml",
        "codeql-analysis.yml",
        "docker-base.yml",
        "docker-file-build.yml",
        "flakehub-publish-tagged.yml",
        "golangci-lint.yml",
        "govulncheck.yml",
        "installer.yml",
        "kubemanifests.yaml",
        "natlab-basic.yml",
        "natlab-test.yml",
        "pin-github-actions.yml",
        "request-dataplane-review.yml",
        "ssh-integrationtest.yml",
        "test.yml",
        "update-flake.yml",
        "update-webclient-prebuilt.yml",
        "vet.yml",
        "webclient.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "go.sum",
        "yarn.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 6,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 6/22 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 33 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "97 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "96abef288847c5b4ce4869c8c18a828c31f37bb9",
        "ran_at": "2026-07-29T14:56:41Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T13:58:37Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-20T13:57:48Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/BARGHEST-ngo/tailscale-patched",
    "host": "github.com",
    "name": "tailscale-patched",
    "owner": "BARGHEST-ngo"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 56,
        "vitality": 79,
        "community": 40,
        "governance": 74,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 79,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "commits_last_year": 1292,
              "human_commit_share": 1,
              "days_since_last_push": 9,
              "active_weeks_last_year": 46
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 9 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "46/52 weeks with commits",
                "points": 31.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 46
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1292 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1292
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "releases_count": 95,
              "latest_release_tag": "v1.94.2",
              "releases_from_tags": true,
              "days_since_latest_release": 165,
              "mean_days_between_releases": 8.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "95 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 95
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 165 days ago",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 165
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 40,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (BSD-3-Clause)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "BSD-3-Clause"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 74,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 99,
              "top_contributor_share": 0.367
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 37% of commits",
                "points": 14.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 37
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "99 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 99
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 77,
            "inputs": {
              "merged_prs": 7,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "7/7 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 7,
                      "decided": 7
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 6/22 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "followers": 31,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "BARGHEST-ngo",
              "public_repos": 10,
              "account_age_days": 496
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "31 followers of BARGHEST-ngo",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 31,
                      "login": "BARGHEST-ngo"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~1 yr old",
                "points": 10.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "tailscale.com"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "232 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 232
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "20 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 6/22 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "97 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 18
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.89,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "89 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 89,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "go.sum",
                "yarn.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "docs/k8s/Makefile",
                "gokrazy/Makefile",
                "tool/goexe/Makefile",
                "tstest/tailmac/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "client/web/tsconfig.json",
                "cmd/tsconnect/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod",
                "tool/goexe/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "client/web/tsconfig.json, cmd/tsconnect/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "client/web/tsconfig.json, cmd/tsconnect/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 276136,
              "source_files_sampled": 2180,
              "oversized_source_files": 23
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "23/2180 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 2180,
                      "oversized": 23
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "example",
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example, examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example, examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T14:57:06.061922Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/BARGHEST-ngo/tailscale-patched.svg",
  "full_name": "BARGHEST-ngo/tailscale-patched",
  "license_state": "standard",
  "license_spdx": "BSD-3-Clause"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.