Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 20:46 UTC

FusionAuth / go-client

FusionAuth Go Client Library!

GoApache-2.0★ 31 stars⑂ 31 forkssince Mar 2019View on GitHub ↗

FusionAuth/go-client holds a health index of 64 out of 100, placing it in the Moderate band. It scores highest on Vitality (70/100) and lowest on Community & Adoption (46/100). It was last updated 7 days ago. A single contributor accounts for most of its recent work.

64
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

64
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

FusionAuthOrganization
368 followers267 public repossince Jul 2018

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/FusionAuth/go-clientv1.68.0-1227 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

70Good · 22% of overall
How it's scored
36/36Push recency — last push 7 days ago
24.2/36Commit cadence — 35/52 weeks with commits
17.6/18Commit volume — 90 commits in the last year
10/10OpenSSF Scorecard: Maintained — 12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year90
human_commit_share1
days_since_last_push7
active_weeks_last_year35
How it's scored
27/27Ships releases — 1 releases published
0/36Release recency — latest release 2,416 days ago
12.6/27Release cadence — cadence unknown (single release)
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count1
latest_release_tag1.12.1
releases_from_tagsno
days_since_latest_release2,416
mean_days_between_releases
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

46At risk · 18% of overall
How it's scored
24/60Stars — 31 stars
12.3/25Forks — 31 forks
6/15Watchers — 13 watchers
Inputs used
forks31
stars31
watchers13
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

65Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
7.2/22.5Commit distribution — top contributor authored 68% of commits
13.5/13.5Contributor breadth — 24 contributors
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Inputs used
bus_factor1
contributors_sampled24
top_contributor_share0.68
How it's scored
27.7/46.8Issue resolution — 59% of issues closed
30.9/38.3PR acceptance — 114/141 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 2/30 approved changesets -- score normalized to 0
Inputs used
merged_prs114
open_issues22
closed_issues32
issue_closed_ratio0.593
closed_unmerged_prs27
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
18.5/25Owner reach — 368 followers of FusionAuth
25/25Track record — 267 public repos, account ~7 yr old
Inputs used
followers368
owner_typeOrganization
is_verified
owner_loginFusionAuth
public_repos267
account_age_days2,913
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 27 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/FusionAuth/go-client
ecosystemsgo
any_deprecatedno
min_days_since_publish27

Engineering Quality

Are baseline engineering and documentation practices in place?

67Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://fusionauth.io/
10/10Repository description
10/10Topics — 5 topics
0/10Wiki
Inputs used
topicsgolang, golang-client, go-client, fusionauth, fusionauth-client
has_wikino
homepagehttps://fusionauth.io/
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

70Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 2/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.2
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages4
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 4 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

48At risk · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
19.2/40Legible commit history — 36 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.36
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
2/10Demonstrated agent practice — 1 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.01
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
36.7/55Manageable file sizes — 2/6 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes482,984
source_files_sampled6
oversized_source_files2

Key facts

31GitHub stars
24contributors
90commits, last 12 months
7days since last push
1releases
1bus factor
22open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 31 ⇿
0Stars
31Forks
1Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

01325383122019-032021-102024-05
Major 0Minor 0Patch 1

Each point covers 5 days.

OpenSSF Scorecard 6.2 / 10
6.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 20:46 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 2/30 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
Gogithub.com/stretchr/testifyv1.10.0go.mod
All dependencies 4

Full resolved dependency set from the GitHub dependency graph: 1 direct and 3 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/stretchr/testifyv1.10.0direct
Gogithub.com/davecgh/go-spewv1.1.1indirect
Gogithub.com/pmezard/go-difflibv1.0.0indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 4 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "golang",
        "golang-client",
        "go-client",
        "fusionauth",
        "fusionauth-client"
      ],
      "is_fork": false,
      "size_kb": 1203,
      "has_wiki": false,
      "homepage": "https://fusionauth.io/",
      "languages": {
        "Go": 834908
      },
      "pushed_at": "2026-07-15T23:05:02Z",
      "created_at": "2019-03-13T14:13:59Z",
      "owner_type": "Organization",
      "updated_at": "2026-06-30T14:33:12Z",
      "description": "FusionAuth Go Client Library!",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://fusionauth.io",
      "name": "FusionAuth",
      "type": "Organization",
      "login": "FusionAuth",
      "company": null,
      "location": "Denver, CO",
      "followers": 368,
      "avatar_url": "https://avatars.githubusercontent.com/u/41974756?v=4",
      "created_at": "2018-07-31T23:26:23Z",
      "is_verified": null,
      "public_repos": 267,
      "account_age_days": 2913
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "1.12.1",
          "kind": "patch",
          "published_at": "2019-12-11T17:53:29Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e1ad37c393fb7fdfae126441c10aaf74c8519649",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 8ac7a9897077",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-06-26T20:17:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56486e544891370ddcbddf2139b68719756be073",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 2f087c552f53",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-06-16T14:42:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bbe416653ba96909531f9b19f6ac781aa4b4ff8",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo ae414f6ce430",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-06-10T14:51:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64a68a09c4a1d2380cf663a4e2943f1807f13635",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 565c3faf9fb1",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-06-05T15:43:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e27e093d1408afe1c94949008aa54b335d0ac45b",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 910e0edb0ac2",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-06-01T20:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a141ddb42f8b620f9bbb07b8e9a806c8e4b82637",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo fb44388a5e35",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-05-18T21:18:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8f8cc6c78c875a729b3a8f704418f9b58a55d86",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 2918472a70a9",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-05-13T13:47:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5746d5c4769033f9e1ba0c8ecd61f7990f3be49e",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 6769111f347e",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-05-12T17:42:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad4224443ac1df2e146120d9e3ff9205ce7a6104",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 2a1444512d33",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-05-06T01:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "119f6712cf395468cc7859d432642838c88be828",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo a954e069cb91",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-05-01T16:51:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02af5b6b00793dff76dde71e2b95a9649efa49f9",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo cb9ebe6a0eaf",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-30T17:37:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3514c114bb878f88a1c9b827f8cc861af85ccd63",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 797cf4b8ea23",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-29T17:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "876c9a352254711ab8a0e045ed644bfd78153a4d",
          "body": null,
          "is_bot": false,
          "headline": "Sync from monorepo 40ffa432b77d",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-20T19:34:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b569681221e30beddf8cdca56e76dbf52d94c00",
          "body": null,
          "is_bot": false,
          "headline": "sync from monorepo f925969b3a30",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-16T15:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d80e920f221fef4fb13e5c82e434a203449701d",
          "body": null,
          "is_bot": false,
          "headline": "sync from monorepo 68e7f75f35fd",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-14T14:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35b94b2f0619df7bedc7e4999f8f883c3f4e2c73",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-03T19:27:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06625578945dbb1e5fdafd43220b921ccc876712",
          "body": null,
          "is_bot": false,
          "headline": "Merge hotfixes/1.64.1 into main for 1.64.1",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-03T19:26:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01dec29ab471bf29ffc70bedbf2208b640892208",
          "body": null,
          "is_bot": false,
          "headline": "sync from monorepo 4104cdbf0ffe",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-04-03T14:40:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89d5e831795520674a32c1c4efd0a60f2a9048f0",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.64.1",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-04-02T23:32:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86af8028c971e95af8d16e1e6bb76d7e4ff4d445",
          "body": null,
          "is_bot": false,
          "headline": "Add SECURITY.md with vulnerability reporting information (#187)",
          "author_name": "t0dd",
          "author_login": "appsec-tpc",
          "committed_at": "2026-03-25T21:35:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "680afb0b90129f25e2b5981b9b57a99b84a10b67",
          "body": "…n w/o API overrides. (#1309)\n\n* working backend\n\n* toggle\n\n* toggle\n\n* tests\n\n* libs\n\n* double the strategy double the fun\n\n* libs\n\n* test json\n\n* test the phone strategy\n\n* fix domain\n\n* openapi\n\n* fix equals\n\n* fix equals\n\n* pr feedback\n\n* typo\n\n* pr feedback",
          "is_bot": false,
          "headline": "ENG-677/ENG-3868 - Allow use of OTP codes for email passwordless logi…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2026-03-16T17:20:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ccf271e4bc49ed7c6a91f19452ab67e894cefd9",
          "body": null,
          "is_bot": false,
          "headline": "touch readme (#196)",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2026-03-16T16:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c45edd3a1a5e54b5e5c5d599a7245d63bd40945f",
          "body": "…ion (#1321)\n\nProblem:\nTo declare the license issue in a decent state, we must confront the fact that the Maxmind loader still has some issues. See https://linear.app/fusionauth/issue/ENG-4018/maxmind-loader-problems for what those are. We don't want to bite that off now, nor do we want to tell cust\n[…]\nr status values for items that have remote health involved, like Maxmind, from those that don't (CAPTCHA, etc. items that depend on threat detection). Breached password detection is already separated.",
          "is_bot": false,
          "headline": "ENG-4023 - Separate MaxMind Reactor Status from rest of Threat Detect…",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-03-13T00:25:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ab8aa87f3be41e051bd0326f489c1cc2f3f7419",
          "body": "Co-authored-by: Daniel King <daniel.king@fusionauth.io>",
          "is_bot": false,
          "headline": "Add secret key values and allow them to be used in lambdas (#1250)",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2026-03-12T21:01:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "779d943fbde9dc87023580b68615bfe71d2a1851",
          "body": "…nfiguration (#1307)\n\n* fix: added supported challenge methods to openid-configuration as specified in RFC 8414\n\n* chore: linting fixes after is int\n\n* revert: FusionAuthMain.java and fusionauth-plugin-api.iml\n\n* chore: revert FusionAuthMain.java eof",
          "is_bot": false,
          "headline": "ENG-466: code challenge methods supported field is added to openid co…",
          "author_name": "Ufuk",
          "author_login": "ucatbas",
          "committed_at": "2026-03-06T18:34:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79fb655a7e338338280a5448da9648088dae940d",
          "body": "* Add a build command to the Python and PHP clients\n* Warn about changing inputs (since separate repos)",
          "is_bot": false,
          "headline": "Add `build` command to Python/PHP clients and denote 'contract' (#1292)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-03-02T18:04:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "326ecfbdd8d75782df73104b8588e00d8b363370",
          "body": "Problems:\n1. Continued issues with plugin classpath and running tests\n\nSolution:\n1. Blew away .idea\n2. Brought in the old IPR file and fixed the paths, made sure it was running\n3. Then had intellij convert the IPR file, and made some minor tweaks.",
          "is_bot": false,
          "headline": "Try and fix `.idea` directory (again) (#1289)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-02-28T00:41:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0670974135520355b0a0f7f8cbdce483d7028043",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.64.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2026-02-26T17:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "352ff15bbe895cad0950c1d70e6ba3b36902c98b",
          "body": "DPoP support\n\n---------\n\nCo-authored-by: Brady Wied <brady.wied@fusionauth.io>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: Brady Wied <wied03@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Feature/dpop (#1269)",
          "author_name": "Brent Halsey",
          "author_login": "bhalsey",
          "committed_at": "2026-02-25T15:43:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53c580db13826b03be7e3ed855d5cd8520c249f2",
          "body": null,
          "is_bot": false,
          "headline": "ENG-3842: Include authentication type in MFA Lambda context (#1273)",
          "author_name": "Daniel King",
          "author_login": "kingds",
          "committed_at": "2026-02-25T15:42:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82884bcf8304b3631db4eb9b2cd3978d6c96a835",
          "body": "Added a field `PasswordValidationRules.disallowUserLoginId`, configurable per tenant. If enabled, passwords will be rejected if they contain the user's email, username, or phone number.",
          "is_bot": false,
          "headline": "ENG-990: Disallow password which is the same as user's login (#1225)",
          "author_name": "Daniel King",
          "author_login": "kingds",
          "committed_at": "2026-02-25T03:07:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ceca57bfc43754f6b6a256f71b5c15d86e2c2a34",
          "body": "Problem:\n1. We were missing tenantId on lookupIdentityProvider\n2. We were missing deleteWebAuthnCredentialsByUser\n\nSolution:\n1. Add lookupIdentityProviderByTenantId to go with lookupIdentityProvider\n2. Add a new deleteWebAuthnCredentialsForUser to go with deleteWebAuthnCredentials\n3. Surface some PMVC route printing code to deterministically get all of our routes and action classes.\n4. Add an AI written test that looks for missing parameters.",
          "is_bot": false,
          "headline": "ENG-3831 - Add missing client method lookups and test harness (#1244)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-02-19T20:15:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddb348e9d455e54840cd68acd9f06a1998f2e485",
          "body": "* one directory to rule them all\n\n* sync java client\n\n* Fix IJ build of java client\n\n- ../fusionauth-ij/queries was an unneeded directory, removed it in project structure\n- IJ complained plugin-api had src/main/java twice. Removed that and java client built properly\n\n* Can now run a test\n\n- Fix Java\n[…]\n\n\n* sb idea removes these\n\nAnd we should not need them (tests compile and run without this)\n\n* We need the copyright stuff in here too\n\n---------\n\nCo-authored-by: Brady Wied <brady.wied@fusionauth.io>",
          "is_bot": false,
          "headline": "one directory to rule them all (#1214)",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2026-02-09T18:16:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3bd8360f56708d4479506e962402581cbcefa8e",
          "body": "ENG-3720",
          "is_bot": false,
          "headline": "remove retrieveUserUsingJWT client method (#190)",
          "author_name": "Spencer Witt",
          "author_login": "spwitt",
          "committed_at": "2026-01-30T20:06:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34ef33fbec7e5c163d5a37a850819b4679d9cf60",
          "body": "Problem\nEvery year, we need to update the copyright year, or the builds start failing because, after running sb build on the client builder repo, the year on the files change and the repo state (is status check) is now dirty.\n\nSolution\nRun build again and update to 2026.",
          "is_bot": false,
          "headline": "Merge wied03/copyright_2026 (#185)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2026-01-05T18:39:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9d3710b4e8ff7e315049bc13a56093a82f71ba4",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-12-30T20:48:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47ea7cd5d1887d522cbecfaa83a75281c75e5647",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.62.1",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-30T20:24:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a82d3056da87faf2789b77ff9cf271ba14cc3f",
          "body": "[&] to [and] bc html",
          "is_bot": false,
          "headline": "Merge pull request #183 from FusionAuth/lyle/and-then",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T23:13:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93155c2bddaed91c50ec3dd9a4f956e8e0579c0e",
          "body": null,
          "is_bot": false,
          "headline": "[&] to [and] bc html",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T22:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9490073c9c8930853ac51dbc3a05aa99772c7a6",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.63.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-12-18T21:25:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c30168a87a8982a6670af91f441c73cd278b8682",
          "body": "…libs\n\nLyle/eng 3375/introspect and libs",
          "is_bot": false,
          "headline": "Merge pull request #162 from FusionAuth/lyle/ENG-3375/introspect-and-…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T21:02:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc6d03b00ff885be860179d73bddbfcfe333587d",
          "body": "…NG-3375/introspect-and-libs",
          "is_bot": false,
          "headline": "Merge branch 'develop' of github.com:FusionAuth/go-client into lyle/E…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T19:37:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "353c767a49f1e1f032deb1ade7871e362b1ab51b",
          "body": null,
          "is_bot": false,
          "headline": "handle GET on validateDeviceWithRequest with tenantId",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T19:35:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a5dc05db1d43d526209c67524c3c21e7a1d6ef8",
          "body": "Co-authored-by: Brady Wied <brady.wied@fusionauth.io>",
          "is_bot": false,
          "headline": "Working (#180)",
          "author_name": "Brian Pontarelli",
          "author_login": "voidmain",
          "committed_at": "2025-12-18T19:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "432d3356391966d633350425caf904d57cc04882",
          "body": "…NG-3375/introspect-and-libs",
          "is_bot": false,
          "headline": "Merge branch 'develop' of github.com:FusionAuth/go-client into lyle/E…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-18T02:41:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf0f9f1d33be3eaa70013d2aa9ac8668855257ca",
          "body": "* add verificationIds to combo API\n\n* add skipUserRequirement to other repos\n\n* add verificationIds to combo API (#163)\n\n* Merge wied03/ENG-2192/pre-verify-form-api (#165)\n\n* form step type added to clients\n\n* domain object updates\n\n* updated form step type\n\n* better comments on enum\n\n* add verifica\n[…]\ni/identity/verify/start pre-verify field rename\n\n* camelCase API\n\n---------\n\nCo-authored-by: Andy Pai <8798244+andrewpai@users.noreply.github.com>\nCo-authored-by: Lyle Schemmerling <lshem16@gmail.com>",
          "is_bot": false,
          "headline": "Merge feature/admin-app-reskin (#182)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-12-17T23:25:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7abf85eddf304d10c6dfc1cba385ce43bf15192f",
          "body": "* first lambda type\n\n* reduce client blast radius (#171)\n\n* MFA lambda configuration (#172)\n\n* ENG-3487: Tenant-scoped IdPs (#170)\n\n* update domain for tenantId on IdPs (#167)\n* add tenantId to IdP lookup by managed domain response (#169)\n\n* Merge wied03/ENG-3602/mfa-lambda-invocation (#173)\n\n* prop\n[…]\ny: Jaret Hendrickson <jaret.hendrickson+github@fusionauth.io>\nCo-authored-by: Spencer Witt <3409780+spwitt@users.noreply.github.com>\nCo-authored-by: Jaret Hendrickson <jaret.hendrickson@fusionauth.io>",
          "is_bot": false,
          "headline": "Merge feature/ENG-1111/mfa-lambda (#178)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-12-17T21:02:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "652d05aebba21df7ae2694c604be672460680125",
          "body": "…NG-3375/introspect-and-libs",
          "is_bot": false,
          "headline": "Merge branch 'develop' of github.com:FusionAuth/go-client into lyle/E…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-17T19:48:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6450e5ce6def31ef40a549515dc3d3a2bdaf207b",
          "body": null,
          "is_bot": false,
          "headline": "fix the casing issue in the go client",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-17T19:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f28dea98246c04ced0519711711add754378547",
          "body": "…nant id checks, update the client libraries to pass in the tenant id in request objects to preserve backwards compat, additional testing, and some cleanup",
          "is_bot": false,
          "headline": "PR Feedback, additional validation on oauth routes affected by the te…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-17T18:28:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "603d0d7b662cfd95b044174fbbaef3706d80881f",
          "body": null,
          "is_bot": false,
          "headline": "EdDSA key support (#179) (#181)",
          "author_name": "Spencer Witt",
          "author_login": "spwitt",
          "committed_at": "2025-12-16T21:49:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9496426f13bc9419d0c05b580c766a067dbb0687",
          "body": "…NG-3375/introspect-and-libs",
          "is_bot": false,
          "headline": "Merge branch 'develop' of github.com:FusionAuth/go-client into lyle/E…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-12-12T18:32:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ec4a2cf03fdb22cb6d1aeea62def51715545185",
          "body": null,
          "is_bot": false,
          "headline": "add retrieveTotalReportWithExcludes() to fusionauth client (#176)",
          "author_name": "Brent Halsey",
          "author_login": "bhalsey",
          "committed_at": "2025-12-10T19:13:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66bd163275e33b1a162f2529238ff864d80d74ca",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-12-10T17:26:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f202e387ae41d781cae39fb8b02e2b89a66c5ec",
          "body": "* update domain for tenantId on IdPs (#167)\n* add tenantId to IdP lookup by managed domain response (#169)",
          "is_bot": false,
          "headline": "ENG-3487: Tenant-scoped IdPs (#170)",
          "author_name": "Spencer Witt",
          "author_login": "spwitt",
          "committed_at": "2025-12-05T18:14:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b412314ab632ea7430f4c59688bdc2b4bdaf28b",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.61.2",
          "author_name": "Spencer Witt",
          "author_login": "spwitt",
          "committed_at": "2025-12-02T20:33:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb704e52b84e57ea1a8fa5fe625e4be2e586a0ac",
          "body": "…NG-3375/introspect-and-libs",
          "is_bot": false,
          "headline": "Merge branch 'develop' of github.com:FusionAuth/go-client into lyle/E…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-11-26T19:20:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e9e7465c87451caa34581aca245236554d1669e",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-11-24T19:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "963fe2d9778c8350dc41b30af97f7e335008fe3f",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.61.1",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-11-24T17:11:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2f8753f0f34609a3b3a2620876635bafb3b4717",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.62.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-11-13T22:29:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa7f3b858eccaa18babda3886985949193678a99",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-09-26T17:55:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a809b7acb855e228a7610b32afc256143bfa9f85",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.60.2",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-09-25T19:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da489255ebbcf2d74baaf0e2d6bc9a4e78bd2abc",
          "body": null,
          "is_bot": false,
          "headline": "remove incompatible go methods",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-09-23T19:07:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c32a12ddd4c3a5dad98250d0292340cbea61428f",
          "body": null,
          "is_bot": false,
          "headline": "validate and libs",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-09-23T18:17:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc05de93aa345a63dc0c1c10168e92c785a74139",
          "body": null,
          "is_bot": false,
          "headline": "new optional tenant id param added (breaking)",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-09-17T22:48:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba5a465390d07fdffebb41a25513ad3af3501770",
          "body": "Merge wied03/main_merge",
          "is_bot": false,
          "headline": "Merge pull request #161 from FusionAuth/wied03/main_merge",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-09-17T22:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb10603c58b3ec999e6c8912a3127e1709ff4ab1",
          "body": null,
          "is_bot": false,
          "headline": "Merge origin/main",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-09-17T20:09:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b753213863b817ccaf975c5dc673d0ef90247a5b",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.60.1",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-09-17T03:09:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a42ea7fa91b9d1a08169db7d32debdf882332ad",
          "body": "* add new overload case\n\n* fix comment capitalization",
          "is_bot": false,
          "headline": "Merge wied03/ENG-2158/change-password (#159)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-09-16T14:06:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8268700daa8999a827564963cf5c879ccd8cf6c4",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.61.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-09-11T15:54:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e5632f3b8cef1927d05830a53419dc47d9d23d4",
          "body": "…tions\n\ndegroff/eng 3075/vend restrictions",
          "is_bot": false,
          "headline": "Merge pull request #158 from FusionAuth/degroff/ENG-3075/vend_restric…",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-09-10T23:51:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaee05808497102fe2c18419a961ce239f5ebada",
          "body": null,
          "is_bot": false,
          "headline": "Domain sync",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-09-08T17:17:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "405bdb55f658f170af0ad31294c1e94541d98024",
          "body": null,
          "is_bot": false,
          "headline": "domain sync",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-09-08T10:48:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "821435a3618139391cc71092628c53249aadc904",
          "body": null,
          "is_bot": false,
          "headline": "domain build",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-09-04T14:50:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef46968953f83c7a80bca8b5d4757099be2e65e1",
          "body": "ENG-622 - Support for the prompt parameter",
          "is_bot": false,
          "headline": "Merge pull request #150 from FusionAuth/degroff/ENG-622/prompt",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-08-27T21:51:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ef33bbadad5d1da959158e5d3faa83077103530",
          "body": null,
          "is_bot": false,
          "headline": "sync domain builds",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-08-25T20:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e214d5c3e930f9ca9a4384278d0ca757353c8287",
          "body": "Merge wied03/main_merge",
          "is_bot": false,
          "headline": "Merge pull request #157 from FusionAuth/wied03/main_merge",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-08-20T21:56:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7e12860de374c6f25658f7a6cb097a71b29065d",
          "body": "# Conflicts:\n#\tbuild.savant",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into wied03/main_merge",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-08-20T18:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02efd0a3eda9e94eca6196619eaba28083cc8d10",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.59.1",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-08-20T02:14:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ada105f58a033ed25ef1c77dd96119afbf68e24",
          "body": null,
          "is_bot": false,
          "headline": "merge in develop",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-08-19T00:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2751b16048b5291261317c516422b31c0729b5e8",
          "body": null,
          "is_bot": false,
          "headline": "sync domain builds",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-08-18T16:01:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d37bb4fbab583a8fd42964c6309182340b661a1",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.60.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-08-14T17:37:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5eb0e5df44d7808e24a11c89ab4703f794a6074",
          "body": "* Client library updates from enums\n\n* latest client updates\n\n* Updated version for go-client to 1.55.0\n\n* Domain / Client Builder sync\n\n* Domain sync\n\n* domain sync\n\n* Updated version for go-client to 1.56.0\n\n* domain sync\n\n* Merge wied03/ENG-1/tenant-mode-internal-user-removal (#94)\n\n* Updated go \n[…]\n\nCo-authored-by: Brent Halsey <brent.halsey@fusionauth.io>\nCo-authored-by: Spencer Witt <3409780+spwitt@users.noreply.github.com>\nCo-authored-by: Brent Halsey <211656+bhalsey@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Merge degroff/ENG-1/issue1 (#155)",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-08-14T14:31:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32bf3b2b00888e84dad53d5e555bc590052d3e28",
          "body": "sync develop with main",
          "is_bot": false,
          "headline": "Merge pull request #156 from FusionAuth/main",
          "author_name": "Brady Wied",
          "author_login": "wied03",
          "committed_at": "2025-08-13T19:23:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "974b302a30f20aff3bd706eb16626a9e6e85f067",
          "body": "…rsioning\n\nupdates gomod version to match Go's release support policy (n-1).",
          "is_bot": false,
          "headline": "Merge pull request #153 from matthewhartstonge/bugfix/oldstable-go-ve…",
          "author_name": "John Jeffers",
          "author_login": "johnjeffers",
          "committed_at": "2025-08-07T16:14:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38e0964c669200734eb4abd00a6d434e315e85b5",
          "body": null,
          "is_bot": false,
          "headline": "updates gomod version to match Go's release support policy (n-1).",
          "author_name": "Matthew Hartstonge",
          "author_login": "matthewhartstonge",
          "committed_at": "2025-08-07T04:47:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8057cf16e49ec8af69701d20fead70c62cb19ac2",
          "body": null,
          "is_bot": false,
          "headline": "updates version of go under test to match version n-1.",
          "author_name": "Matthew Hartstonge",
          "author_login": "matthewhartstonge",
          "committed_at": "2025-08-07T04:46:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6844bbfd97329b32e93db047d81e922a7bba7032",
          "body": null,
          "is_bot": false,
          "headline": "sync client builder",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-08-01T19:04:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c99359b406bab30d87813d4417640bb720d1262c",
          "body": null,
          "is_bot": false,
          "headline": "Client builder sync",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-07-31T15:40:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f032e9554324e68b7cf4a25d21d57fcad8c606a6",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.59.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-07-24T00:09:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28617a30e8332dd290ae8ffb686a8dbe81c38686",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.58.2",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-07-23T23:20:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a667e7abd76d3c0c830d45c034788dcc8ac19397",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.59.0",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-07-23T22:07:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80be48a458f36b448702b94148f928e43f04d7ba",
          "body": "…-using-jwt\n\nchangePasswordUsingJWT",
          "is_bot": false,
          "headline": "Merge pull request #147 from FusionAuth/lyle/ENG-2742/change-password…",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-23T16:47:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abc5c7cd3dc9ccb587d86f2856d3a8286eefb8ef",
          "body": null,
          "is_bot": false,
          "headline": "reformat using the proper go version",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-23T16:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcb20ddac6a5610b5c7557b480cbd5f055a844ab",
          "body": null,
          "is_bot": false,
          "headline": "changePasswordUsingJWT",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-23T14:45:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b7e13f2273fcb432e3eb8660820ad4134936100",
          "body": "Main to dev",
          "is_bot": false,
          "headline": "Merge pull request #146 from FusionAuth/main-to-dev",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-23T12:56:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "043f052c64027ba95195b815055a8779e5835df2",
          "body": "# Conflicts:\n#\tbuild.savant",
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:FusionAuth/go-client into develop",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-23T04:17:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e623fb4fed5b1625ea6c1cdbefaaf05cf4b5c51",
          "body": null,
          "is_bot": false,
          "headline": "Updated version for go-client to 1.58.1",
          "author_name": "FusionAuth Automation",
          "author_login": null,
          "committed_at": "2025-07-22T19:55:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d2b215c0ab895f8b6ad27b84445bafe4e2f360e",
          "body": "* update clients\n\n* trimmed universal config (#140)\n\n* trimmed universal config\n\n* cleanup\n\n* domain update (#144)",
          "is_bot": false,
          "headline": "Tenant manager updates (#145)",
          "author_name": "Lyle Schemmerling",
          "author_login": "lyleschemmerling",
          "committed_at": "2025-07-21T18:46:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a88e76c3f6a385a5a9859a0408d0070ca717ca65",
          "body": "…patch\n\nENG-2805: generated code for client libraries",
          "is_bot": false,
          "headline": "Merge pull request #141 from FusionAuth/degroff/ENG-2805/fix_api_key_…",
          "author_name": "Daniel DeGroff",
          "author_login": "robotdan",
          "committed_at": "2025-07-18T19:19:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 90,
      "latest_release_at": "2019-12-11T17:53:29Z",
      "latest_release_tag": "1.12.1",
      "releases_from_tags": false,
      "days_since_last_push": 7,
      "active_weeks_last_year": 35,
      "days_since_latest_release": 2416,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/FusionAuth/go-client",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/FusionAuth/go-client",
          "is_deprecated": false,
          "latest_version": "v1.68.0",
          "repository_url": "https://github.com/FusionAuth/go-client",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-26T20:17:07Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        }
      ]
    },
    "popularity": {
      "forks": 31,
      "stars": 31,
      "watchers": 13,
      "fork_history": {
        "days": [
          {
            "date": "2019-03-14",
            "count": 1
          },
          {
            "date": "2019-03-17",
            "count": 1
          },
          {
            "date": "2019-09-09",
            "count": 1
          },
          {
            "date": "2019-11-28",
            "count": 1
          },
          {
            "date": "2019-12-03",
            "count": 1
          },
          {
            "date": "2019-12-21",
            "count": 1
          },
          {
            "date": "2020-02-14",
            "count": 2
          },
          {
            "date": "2020-03-25",
            "count": 1
          },
          {
            "date": "2020-04-03",
            "count": 1
          },
          {
            "date": "2020-04-09",
            "count": 1
          },
          {
            "date": "2020-05-13",
            "count": 1
          },
          {
            "date": "2020-05-21",
            "count": 1
          },
          {
            "date": "2020-06-19",
            "count": 1
          },
          {
            "date": "2020-06-21",
            "count": 1
          },
          {
            "date": "2020-07-25",
            "count": 1
          },
          {
            "date": "2020-08-06",
            "count": 1
          },
          {
            "date": "2020-11-22",
            "count": 1
          },
          {
            "date": "2020-11-24",
            "count": 1
          },
          {
            "date": "2021-03-09",
            "count": 1
          },
          {
            "date": "2021-06-08",
            "count": 1
          },
          {
            "date": "2021-09-09",
            "count": 1
          },
          {
            "date": "2021-11-10",
            "count": 1
          },
          {
            "date": "2022-02-09",
            "count": 2
          },
          {
            "date": "2022-04-12",
            "count": 1
          },
          {
            "date": "2022-05-13",
            "count": 1
          },
          {
            "date": "2022-11-08",
            "count": 1
          },
          {
            "date": "2022-11-30",
            "count": 1
          },
          {
            "date": "2023-11-28",
            "count": 1
          },
          {
            "date": "2024-05-13",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 31,
        "total_forks": 31
      },
      "star_history": null,
      "open_issues_and_prs": 24
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 482984,
      "source_files_sampled": 6,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 4,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 4,
        "direct_count": 1,
        "indirect_count": 3
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 114,
        "open_issues": 22,
        "closed_ratio": 0.593,
        "closed_issues": 32,
        "closed_unmerged_prs": 27
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "robotdan",
          "commits": 338,
          "avatar_url": "https://avatars.githubusercontent.com/u/1148709?v=4"
        },
        {
          "type": "User",
          "login": "lyleschemmerling",
          "commits": 31,
          "avatar_url": "https://avatars.githubusercontent.com/u/11809481?v=4"
        },
        {
          "type": "User",
          "login": "mooreds",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/91825?v=4"
        },
        {
          "type": "User",
          "login": "wied03",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/297123?v=4"
        },
        {
          "type": "User",
          "login": "matthew-altman",
          "commits": 20,
          "avatar_url": "https://avatars.githubusercontent.com/u/55401860?v=4"
        },
        {
          "type": "User",
          "login": "medhir",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/5160860?v=4"
        },
        {
          "type": "User",
          "login": "voidmain",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/377102?v=4"
        },
        {
          "type": "User",
          "login": "johnjeffers",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/11821214?v=4"
        },
        {
          "type": "User",
          "login": "bhalsey",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/211656?v=4"
        },
        {
          "type": "User",
          "login": "spwitt",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/3409780?v=4"
        }
      ],
      "contributors_sampled": 24,
      "top_contributor_share": 0.68
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "deploy.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 2/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e1ad37c393fb7fdfae126441c10aaf74c8519649",
        "ran_at": "2026-07-23T20:46:17Z",
        "aggregate_score": 6.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T13:52:21Z",
      "oldest_open_prs": [
        {
          "number": 61,
          "created_at": "2022-02-09T13:25:09Z",
          "last_comment_at": "2024-03-04T17:29:43Z",
          "last_comment_author": "mirobertod"
        },
        {
          "number": 80,
          "created_at": "2024-05-13T10:29:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-03-25T21:35:56Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 16,
          "created_at": "2020-01-26T09:14:13Z",
          "last_comment_at": "2020-05-12T18:15:26Z",
          "last_comment_author": "michaeldabbott"
        },
        {
          "number": 30,
          "created_at": "2020-07-19T19:34:54Z",
          "last_comment_at": "2020-07-22T04:01:01Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 34,
          "created_at": "2020-08-04T13:05:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 37,
          "created_at": "2020-08-12T00:51:27Z",
          "last_comment_at": "2020-11-19T04:13:25Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 38,
          "created_at": "2020-08-28T21:25:13Z",
          "last_comment_at": "2021-03-23T16:16:55Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 45,
          "created_at": "2020-11-24T17:13:55Z",
          "last_comment_at": "2020-12-04T17:10:20Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 48,
          "created_at": "2021-01-28T19:44:42Z",
          "last_comment_at": "2022-09-27T23:46:01Z",
          "last_comment_author": "benkloester"
        },
        {
          "number": 51,
          "created_at": "2021-04-02T08:48:48Z",
          "last_comment_at": "2021-04-02T15:07:36Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 54,
          "created_at": "2021-05-05T18:46:44Z",
          "last_comment_at": "2021-05-06T19:25:33Z",
          "last_comment_author": "mooreds"
        },
        {
          "number": 55,
          "created_at": "2021-06-20T14:50:54Z",
          "last_comment_at": "2021-06-30T13:20:41Z",
          "last_comment_author": "mooreds"
        },
        {
          "number": 56,
          "created_at": "2021-08-09T13:48:44Z",
          "last_comment_at": "2021-09-02T03:21:13Z",
          "last_comment_author": "matthewhartstonge"
        },
        {
          "number": 57,
          "created_at": "2021-08-10T20:16:52Z",
          "last_comment_at": "2021-08-11T22:17:04Z",
          "last_comment_author": "robotdan"
        },
        {
          "number": 60,
          "created_at": "2022-02-04T20:05:53Z",
          "last_comment_at": "2022-02-06T16:25:55Z",
          "last_comment_author": "mooreds"
        },
        {
          "number": 62,
          "created_at": "2022-02-17T13:31:03Z",
          "last_comment_at": "2022-02-25T09:13:56Z",
          "last_comment_author": "josedelrio85"
        },
        {
          "number": 65,
          "created_at": "2022-04-18T11:57:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 67,
          "created_at": "2022-05-17T10:47:56Z",
          "last_comment_at": "2025-02-13T14:02:48Z",
          "last_comment_author": "michaelholtermann"
        },
        {
          "number": 69,
          "created_at": "2022-10-07T19:50:39Z",
          "last_comment_at": "2022-10-11T19:05:00Z",
          "last_comment_author": "mooreds"
        },
        {
          "number": 72,
          "created_at": "2023-03-29T11:20:52Z",
          "last_comment_at": "2023-04-06T22:01:14Z",
          "last_comment_author": "mooreds"
        },
        {
          "number": 75,
          "created_at": "2023-07-25T20:39:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 76,
          "created_at": "2023-08-14T05:01:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/FusionAuth/go-client",
    "host": "github.com",
    "name": "go-client",
    "owner": "FusionAuth"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 70,
        "vitality": 70,
        "community": 46,
        "governance": 65,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 90,
              "human_commit_share": 1,
              "days_since_last_push": 7,
              "active_weeks_last_year": 35
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "35/52 weeks with commits",
                "points": 24.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 35
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "90 commits in the last year",
                "points": 17.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 90
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "1.12.1",
              "releases_from_tags": false,
              "days_since_latest_release": 2416,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2416 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2416
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 27,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 27 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 27
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 46,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "forks": 31,
              "stars": 31,
              "watchers": 13,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "31 stars",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "31 forks",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "13 watchers",
                "points": 6,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 65,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 24,
              "top_contributor_share": 0.68
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 68% of commits",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 68
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "24 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 24
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "merged_prs": 114,
              "open_issues": 22,
              "closed_issues": 32,
              "issue_closed_ratio": 0.593,
              "closed_unmerged_prs": 27
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "59% of issues closed",
                "points": 27.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 59
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "114/141 decided PRs merged",
                "points": 30.9,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 114,
                      "decided": 141
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "followers": 368,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "FusionAuth",
              "public_repos": 267,
              "account_age_days": 2913
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "368 followers of FusionAuth",
                "points": 18.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 368,
                      "login": "FusionAuth"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "267 public repos, account ~7 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 267
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/FusionAuth/go-client"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 27
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 27 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 27
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "golang",
                "golang-client",
                "go-client",
                "fusionauth",
                "fusionauth-client"
              ],
              "has_wiki": false,
              "homepage": "https://fusionauth.io/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://fusionauth.io/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "5 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 70,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 4 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 4
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 4,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 4,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 8
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 48,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 19,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.36,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "36 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 36,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 482984,
              "source_files_sampled": 6,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/6 source files over 60KB",
                "points": 36.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 6,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T20:46:34.222575Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/FusionAuth/go-client.svg",
  "full_name": "FusionAuth/go-client",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.