Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 09:17 UTC

NVIDIA / nvrc

The NVRC project provides a Rust binary that implements a simple init system for microVMs.

RustApache-2.0★ 35 stars⑂ 20 forkssince Jul 2024View on GitHub ↗

NVIDIA/nvrc holds a health index of 62 out of 100, placing it in the Moderate band. It scores highest on Vitality (89/100) and lowest on Engineering Quality (46/100). It was last updated 1 day ago. A single contributor accounts for most of its recent work.

62
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

62
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

NVIDIA CorporationOrganization
28,325 followers776 public repossince May 2012

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

89Excellent · 22% of overall
How it's scored
36/36Push recency — last push 1 days ago
22.2/36Commit cadence — 32/52 weeks with commits
18/18Commit volume — 387 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year387
human_commit_share0.85
days_since_last_push1
active_weeks_last_year32
How it's scored
27/27Ships releases — 6 releases published
36/36Release recency — latest release 15 days ago
19.8/27Release cadence — a release every ~54 days
10/10OpenSSF Scorecard: Signed-Releases — 5 out of the last 5 releases have a total of 10 signed artifacts.
Inputs used
releases_count6
latest_release_tagv0.1.5
releases_from_tagsno
days_since_latest_release15
mean_days_between_releases54

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

52Moderate · 18% of overall
How it's scored
24.8/60Stars — 35 stars
10.7/25Forks — 20 forks
0/15Watchers — 2 watchers
Inputs used
forks20
stars35
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

50Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
1.8/22.5Commit distribution — top contributor authored 92% of commits
5.4/13.5Contributor breadth — 4 contributors
10/10OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled4
top_contributor_share0.922
How it's scored
14.4/46.8Issue resolution — 31% of issues closed
33.8/38.3PR acceptance — 152/172 decided PRs merged
1.5/15OpenSSF Scorecard: Code-Review — Found 1/8 approved changesets -- score normalized to 1
Inputs used
merged_prs152
open_issues18
closed_issues8
issue_closed_ratio0.308
closed_unmerged_prs20
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
25/25Owner reach — 28,325 followers of NVIDIA
25/25Track record — 776 public repos, account ~14 yr old
Inputs used
followers28,325
owner_typeOrganization
is_verified
owner_loginNVIDIA
public_repos776
account_age_days5,189

Engineering Quality

Are baseline engineering and documentation practices in place?

46At risk · 20% of overall
How it's scored
24/24CI workflows — 18 workflow(s)
0/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsno
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

50Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

77Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 1/8 approved changesets -- score normalized to 1
2.5/2.5Contributors — project has 4 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
7.5/7.5Signed-Releases — 5 out of the last 5 releases have a total of 10 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate7.1
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages81
unassessed_packages1
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 81 resolved dependencies against OSV. 1 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

73Good · 0% of overall
How it's scored
45/45Agent instructions — .github/copilot-instructions.md, AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 85 of 85 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files.github/copilot-instructions.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes5,037
How it's scored
12.6/18One-command bootstrap — Cargo.toml, fuzz/Cargo.toml (toolchain convention, no task runner)
0/22Automated tests
0/11Lint / format config
11/11Static type checking — Rust (statically typed)
10/10Reproducible environment — lockfile
2/10Demonstrated agent practice — 1 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 15 of the last 100 commits are automated dependency updates
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Inputs used
has_nixno
has_testsno
lockfilesCargo.lock
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.01
toolchain_manifestsCargo.toml, fuzz/Cargo.toml
dependency_bot_commit_share0.15
How it's scored
45/45Type-checkable code — Rust (statically typed)
55/55Manageable file sizes — 0/26 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes18,085
source_files_sampled26
oversized_source_files0

Key facts

35GitHub stars
4contributors
387commits, last 12 months
1days since last push
6releases
1bus factor
18open issues
crates.iopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'NVRC' from its registry

More detail

Star and fork history 0 ★ / 20 ⇿
0Stars
20Forks
6Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0481216202012024-072025-072026-07
Major 0Minor 0Patch 6

Each point covers 2 days.

OpenSSF Scorecard 7.1 / 10
7.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 09:17 UTC

10Binary-Artifactsno binaries found in the repo
1Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 1/8 approved changesets -- score normalized to 1
10Contributorsproject has 4 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
10Signed-Releases5 out of the last 5 releases have a total of 10 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 8
RegistryPackageVersion constraintManifest
crates.ionix0.31.3Cargo.toml
crates.iocfg-if1.0.4Cargo.toml
crates.iolog0.4.29Cargo.toml
crates.iokernlog0.3Cargo.toml
crates.iorlimit0.11.0Cargo.toml
crates.iolibc0.2.178Cargo.toml
crates.ioonce_cell1.21.3Cargo.toml
crates.iosha20.11Cargo.toml
All dependencies 82

Full resolved dependency set from the GitHub dependency graph: 8 direct and 74 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
crates.iocfg-if1.0.4direct
crates.iokernlog0.3.1direct
crates.iolibc0.2.186direct
crates.iolog0.4.33direct
crates.ionix0.31.3direct
crates.ioonce_cell1.21.4direct
crates.iorlimit0.11.0direct
crates.iosha20.11.0direct
crates.ioaho-corasick1.1.4indirect
crates.ioautocfg1.4.0indirect
crates.iobitflags2.8.0indirect
crates.ioblock-buffer0.12.1indirect
crates.iocfg_aliases0.2.1indirect
crates.iocpufeatures0.3.0indirect
crates.iocrypto-common0.2.2indirect
crates.iodigest0.11.3indirect
crates.ioequivalent1.0.2indirect
crates.ioerrno0.3.10indirect
crates.iofastrand2.3.0indirect
crates.iofutures-core0.3.31indirect
crates.iofutures-executor0.3.31indirect
crates.iofutures-macro0.3.31indirect
crates.iofutures-task0.3.31indirect
crates.iofutures-timer3.0.4indirect
crates.iofutures-util0.3.31indirect
crates.iogetrandom0.2.15indirect
crates.iogetrandom0.3.1indirect
crates.ioglob0.3.3indirect
crates.iohashbrown0.17.1indirect
crates.iohybrid-array0.4.13indirect
crates.ioindexmap2.14.0indirect
crates.iolibfuzzer-sysindirect
crates.iolinux-raw-sys0.12.1indirect
crates.iolock_api0.4.12indirect
crates.iomemchr2.7.4indirect
crates.iomktemp0.5.1indirect
crates.ioparking_lot0.12.3indirect
crates.ioparking_lot_core0.9.10indirect
crates.iopin-project-lite0.2.16indirect
crates.iopin-utils0.1.0indirect
crates.ioproc-macro-crate3.5.0indirect
crates.ioproc-macro21.0.93indirect
crates.ioquote1.0.38indirect
crates.ioredox_syscall0.5.10indirect
crates.ioregex1.12.3indirect
crates.ioregex-automata0.4.14indirect
crates.ioregex-syntax0.8.10indirect
crates.iorelative-path1.9.3indirect
crates.iorstest0.26.1indirect
crates.iorstest_macros0.26.1indirect
crates.iorustc_version0.4.1indirect
crates.iorustix1.1.4indirect
crates.ioscopeguard1.2.0indirect
crates.iosemver1.0.28indirect
crates.ioserde_core1.0.228indirect
crates.ioserde_derive1.0.228indirect
crates.ioserial_test3.5.0indirect
crates.ioserial_test_derive3.5.0indirect
crates.ioslab0.4.9indirect
crates.iosmallvec1.13.2indirect
crates.iosyn2.0.98indirect
crates.iotempfile3.27.0indirect
crates.iotoml_datetime1.1.1+spec-1.1.0indirect
crates.iotoml_edit0.25.12+spec-1.1.0indirect
crates.iotoml_parser1.1.2+spec-1.1.0indirect
crates.iotypenum1.20.0indirect
crates.iounicode-ident1.0.16indirect
crates.iouuid1.4.1indirect
crates.iowasi0.11.0+wasi-snapshot-preview1indirect
crates.iowasi0.13.3+wasi-0.2.2indirect
crates.iowindows-sys0.59.0indirect
crates.iowindows-targets0.52.6indirect
crates.iowindows_aarch64_gnullvm0.52.6indirect
crates.iowindows_aarch64_msvc0.52.6indirect
crates.iowindows_i686_gnu0.52.6indirect
crates.iowindows_i686_gnullvm0.52.6indirect
crates.iowindows_i686_msvc0.52.6indirect
crates.iowindows_x86_64_gnu0.52.6indirect
crates.iowindows_x86_64_gnullvm0.52.6indirect
crates.iowindows_x86_64_msvc0.52.6indirect
crates.iowinnow1.0.3indirect
crates.iowit-bindgen-rt0.33.0indirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 81 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct. 1 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 691,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Rust": 178636,
        "Shell": 1955
      },
      "pushed_at": "2026-07-24T17:08:35Z",
      "created_at": "2024-07-17T15:58:39Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T17:08:42Z",
      "description": "The NVRC project provides a Rust binary that implements a simple init system for microVMs.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "https://nvidia.com",
      "name": "NVIDIA Corporation",
      "type": "Organization",
      "login": "NVIDIA",
      "company": null,
      "location": "2788 San Tomas Expressway, Santa Clara, CA, 95051",
      "followers": 28325,
      "avatar_url": "https://avatars.githubusercontent.com/u/1728152?v=4",
      "created_at": "2012-05-10T22:06:34Z",
      "is_verified": null,
      "public_repos": 776,
      "account_age_days": 5189
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-07-10T16:05:34Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-04-02T21:20:10Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-03-13T22:45:39Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-03-13T19:19:16Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-01-15T00:33:24Z"
        },
        {
          "tag": "v0.0.1",
          "kind": "patch",
          "published_at": "2025-10-13T18:48:27Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3840e8b5c553e2219966141005eb1b25f98c969b",
          "body": "ci: restrict dependabot auto-merge to cargo crates only",
          "is_bot": false,
          "headline": "Merge pull request #204 from zvonkok/ci/dependabot-cargo-only-auto-merge",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-24T17:08:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38d2243925e452c16ca9928abd5484db9a5df27e",
          "body": "GitHub Actions bumps require manual review before adoption; only\ncargo crate PRs should be merged automatically.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: restrict dependabot auto-merge to cargo crates only",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-24T16:52:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36647c53f7525c26569dbd9df4b847ed37979a7b",
          "body": "Bumps [tempfile](https://github.com/Stebalien/tempfile) from 3.23.0 to 3.27.0.\n- [Changelog](https://github.com/Stebalien/tempfile/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/Stebalien/tempfile/compare/v3.23.0...v3.27.0)\n\n---\nupdated-dependencies:\n- dependency-name: tempfile\n  dependenc\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump tempfile from 3.23.0 to 3.27.0 (#185)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T13:17:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c098505ac2158b8129f004e9f99c56423d0faf42",
          "body": "Bumps [rlimit](https://github.com/Nugine/rlimit) from 0.10.2 to 0.11.0.\n- [Changelog](https://github.com/Nugine/rlimit/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/Nugine/rlimit/compare/v0.10.2...v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: rlimit\n  dependency-version: 0.11.0\n  d\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump rlimit from 0.10.2 to 0.11.0 (#186)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-15T23:41:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8139d4cd4a383632130e979cdf2ac178ae39299e",
          "body": "fuzz: fix kernel_params fuzzer crash on validation panics",
          "is_bot": false,
          "headline": "Merge pull request #201 from zvonkok/fix/fuzz-kernel-params-result",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-15T23:28:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d2772832da0b4fabaeff52a0181bccf03e86476",
          "body": "cargo-fuzz forces -C panic=abort via RUSTFLAGS, so catch_unwind is\nsilently a no-op: every .expect() call in the numeric parsers aborts\nthe process and libFuzzer records it as a crash.\n\nIntroduce try_process_kernel_params() returning Result<(), String> as\nthe Result-based twin of process_kernel_para\n[…]\nnored; any unexpected\npanic from a genuine parser bug still aborts and is caught by libFuzzer.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fuzz: fix kernel_params fuzzer by using try_process_kernel_params",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-15T23:00:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5aeb7a454ea3cc212b5a4cbced0a86acb6b5e22a",
          "body": "libc::_exit skips atexit handlers, which is where the LLVM profile\nruntime writes .profraw files. The forked children that panic in the\nkata_agent tests exited without recording coverage, dropping\nkata_agent.rs below the 90% per-file gate.\n\nUnder cfg(coverage) call __llvm_profile_write_file() explic\n[…]\ne profraw pattern contains %p, so each child writes its own\nfile without clobbering the parent's.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: flush LLVM coverage counters before _exit in fork panic hook",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-15T22:57:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd72eb4a9babf84140fac347319a301da8412a72",
          "body": "std::process::exit flushes stdio and runs atexit handlers, which acquire\nlocks. In a forked child of the multi-threaded test harness, a parallel\ntest thread may hold the stderr mutex at fork time, leaving it permanently\nlocked in the child. eprintln! and std::process::exit then deadlock, causing\ntes\n[…]\n:write(2, ...) and libc::_exit, which are\nasync-signal-safe and bypass all stdio/atexit locks.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: use libc::write+_exit in fork test panic hook to prevent deadlock",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-15T14:35:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b491070478caa4ac04739068ad9e454dbbee381",
          "body": "ci: restore pull-requests:write on dependabot-ok-to-test",
          "is_bot": false,
          "headline": "Merge pull request #194 from zvonkok/fix/dependabot-label-permissions",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-15T01:48:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6874570e87b0eb40eb9fcfbe01d021b36fbe879",
          "body": "GitHub requires both issues=write and pull_requests=write when calling\naddLabels on a pull request via the Issues API (403 without it).\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: restore pull-requests:write on dependabot-ok-to-test",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T19:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "036c1ab388559b5dbe7657c19fb41b1f75b7a2bf",
          "body": "ci: pin cargo tool installs with --locked",
          "is_bot": false,
          "headline": "Merge pull request #193 from zvonkok/fix/cargo-audit-locked",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T19:37:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "253411541587e13e75c684568cd9e9887950a061",
          "body": "cargo bloat compiles the project and cargo-fuzz is a tool install;\nboth were missing --locked. Commands that only READ Cargo.lock (cargo\naudit, cargo deny check, cargo fmt, cargo llvm-cov report) need no\nchange since they perform no dependency resolution.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: add --locked to remaining cargo compile/install calls",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T19:20:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c6bfa2776e1eafb3fbe18b99c87ac2671cf3c88",
          "body": "cargo install without --locked resolves the latest transitive deps,\nwhich can pull in crates with a higher MSRV than the pinned toolchain.\nkstring v2.0.3 (Rust 1.96) entered the graph via cargo-audit v0.22.2\nwhile NVRC is pinned to 1.94, breaking static-checks on dependabot PRs.\n\n--locked uses each \n[…]\ns own published Cargo.lock, keeping transitive\ndeps at the versions the tool was tested with.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: pin cargo tool installs with --locked",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T17:42:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ce9a111f15ed108b00f64d9a5ac49d547ed63bc",
          "body": "ci: add dependabot ok-to-test and auto-merge workflows",
          "is_bot": false,
          "headline": "Merge pull request #192 from zvonkok/ci/dependabot-auto-merge",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T16:04:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15b1d061704531355fa0cb9cdf326d2152c30825",
          "body": "revoke-ok-to-test: skip dependabot PRs to eliminate the race condition\nwhere revoke and ok-to-test workflows both fire on synchronize and\nleave label state nondeterministic.\n\ndependabot-ok-to-test: drop pull-requests:write (only Issues API is\nused); add concurrency group to prevent duplicate label-a\n[…]\noncurrency group to prevent overlapping\ngh pr merge --auto calls on rapid synchronize events.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: address PR 192 review comments",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T15:19:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1424d36fb424d31ae29c798959e6f006e2ebdad",
          "body": "dependabot-ok-to-test: labels dependabot PRs with ok-to-test so E2E CI\nruns on the self-hosted runner without manual intervention. Ported from\ncncf-tags/container-device-interface-rs.\n\ndependabot-auto-merge: enables auto-merge on every dependabot PR.\nGitHub's branch-protection engine performs the ac\n[…]\n not github.actor.\n\nPre-requisite: \"Allow auto-merge\" must be enabled in repository Settings.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: add dependabot ok-to-test and auto-merge workflows",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T15:19:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17e0528f70440280221f1492b1f95d57a7fb56d2",
          "body": "build(deps): bump serial_test from 3.2.0 to 3.5.0",
          "is_bot": false,
          "headline": "Merge pull request #187 from NVIDIA/dependabot/cargo/serial_test-3.5.0",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T14:01:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b91c0efb5c1c1f9eb33e173177393a7c0a597575",
          "body": "fuzz: match exact expect messages, not broad prefix",
          "is_bot": false,
          "headline": "Merge pull request #191 from zvonkok/fix/fuzzing-failures",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T13:55:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "488085f44085eb27af2de92dc7df58f005672318",
          "body": ".expect(\"msg\") panics with \"msg: <parse error>\" appended, so exact\nequality never matches; starts_with handles the suffix correctly.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fuzz: use starts_with to match expect panic payloads",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T12:22:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e7d375356e0535a37b8093e876aebabcc1ad684",
          "body": "build(deps): bump once_cell from 1.21.3 to 1.21.4",
          "is_bot": false,
          "headline": "Merge pull request #188 from NVIDIA/dependabot/cargo/once_cell-1.21.4",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T12:17:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44a1bd35493fe2f721ef471e812aab801d873656",
          "body": "build(deps): bump log from 0.4.29 to 0.4.33",
          "is_bot": false,
          "headline": "Merge pull request #189 from NVIDIA/dependabot/cargo/log-0.4.33",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T12:17:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ddee78e47931bf915993d12ab1ba9c7720fcda1",
          "body": "Substring \"nvrc.smi.\" could mask unrelated panics that happen to\nmention that prefix; match the three exact .expect() messages instead.\n\nSigned-off-by: Zvonkou Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fuzz: match exact expect messages, not broad prefix",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T12:17:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f93f7b0e2e37854628bc8d85868f21fea8cad6a0",
          "body": "Bumps [serial_test](https://github.com/palfrey/serial_test) from 3.2.0 to 3.5.0.\n- [Release notes](https://github.com/palfrey/serial_test/releases)\n- [Commits](https://github.com/palfrey/serial_test/compare/v3.2.0...v3.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: serial_test\n  dependency-version: 3.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump serial_test from 3.2.0 to 3.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T02:27:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64f6e6891485e739d974041b9e37f4e5b2e51f7c",
          "body": "Bumps [log](https://github.com/rust-lang/log) from 0.4.29 to 0.4.33.\n- [Release notes](https://github.com/rust-lang/log/releases)\n- [Changelog](https://github.com/rust-lang/log/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/rust-lang/log/compare/0.4.29...0.4.33)\n\n---\nupdated-dependencies:\n- dependency-name: log\n  dependency-version: 0.4.33\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump log from 0.4.29 to 0.4.33",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T02:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "002941f30e127455883714b8fe5809527b39e627",
          "body": "Bumps [once_cell](https://github.com/matklad/once_cell) from 1.21.3 to 1.21.4.\n- [Changelog](https://github.com/matklad/once_cell/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/matklad/once_cell/compare/v1.21.3...v1.21.4)\n\n---\nupdated-dependencies:\n- dependency-name: once_cell\n  dependency-version: 1.21.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump once_cell from 1.21.3 to 1.21.4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T02:27:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d682ba4ea3985d418ba87dcd5b75bc06a699425",
          "body": "fuzz: fix kernel_params crashes and add missing mount_parsing target",
          "is_bot": false,
          "headline": "Merge pull request #190 from zvonkok/fix/fuzzing-failures",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-14T02:25:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52b4ee5443c7fbb114f3a8c37a0537cdd088ae33",
          "body": "fs_available: match exact last token per line instead of substring\nso \"mp\" no longer false-positives against \"tmpfs\"; empty fstype returns\nfalse.\n\nkernel_params harness: re-raise panics whose message does not contain\n\"nvrc.smi.\" so genuine parser bugs still surface as libFuzzer crashes.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fuzz: address review comments",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-13T19:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b79cb0d6650ea2abf39c3f46035afa323e586d3a",
          "body": "kernel_params fuzzer was reporting intentional fail-fast panics (invalid\nu32 for lgc/lmc/pl) as crashes; wrap in catch_unwind so libFuzzer focuses\non unexpected panics in the parsing logic.\n\nmount_parsing target was referenced in the CI matrix but never existed;\nexpose fs_available as pub and add the fuzz target + Cargo.toml entry.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fuzz: fix kernel_params crashes and add missing mount_parsing target",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-13T16:15:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e977c898bbae20c89fe35c79aeb0fac678b6927e",
          "body": "…-images\n\nnvrc: support Kata composable VM images",
          "is_bot": false,
          "headline": "Merge pull request #167 from fidencio/topic/adapt-for-composable-kata…",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-10T15:59:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d2fba0261da5821b7191fe349343d896d618d02",
          "body": "Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "release: bump to v0.1.5",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T15:48:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "170fdc041ccdc4d1aae18cd49600ba48f786f31e",
          "body": "nix was reintroduced as a direct dependency (mount, reboot, fork, poll,\nioctl), so the \"REMOVED\" note no longer reflects reality.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "docs: correct stale nix dependency note",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T15:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac40fa711265ac505890eff0c82e716a8107d7d9",
          "body": "Add guest-side support for the Kata composable VM images proposal\n(kata-containers#13029; systemd equivalent merged in kata-containers#13285).\nA lean base rootfs ships only NVRC and kata-agent, while purpose-specific\ncontent is cold-plugged as dm-verity/EROFS extension images. NVRC is the init\nsyste\n[…]\nted, so the monolithic NVIDIA image is unchanged. Adds rstest as a\ndev-dependency for parametrized tests in the new modules.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Cursor",
          "is_bot": false,
          "headline": "nvrc: support Kata composable VM images",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T15:48:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a1b614b277e8e7058751a49cb1fa34321bb387c",
          "body": "background() diverges via or_panic when the spawn fails, so the test never\nleaks a child; scope an allow to the test rather than the whole crate.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "test(execute): silence clippy zombie_processes false positive",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T15:47:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97c22f98babccd7866b5ecfcc31716aa12040a3b",
          "body": "…/sbom-action-0.24.0\n\nbuild(deps): bump anchore/sbom-action from 0.20.6 to 0.24.0",
          "is_bot": false,
          "headline": "Merge pull request #184 from NVIDIA/dependabot/github_actions/anchore…",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:47:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce28c64bb40b6152f29c7318068129c494afd8fc",
          "body": "…ps/action-gh-release-3.0.1\n\nbuild(deps): bump softprops/action-gh-release from 2.0.8 to 3.0.1",
          "is_bot": false,
          "headline": "Merge pull request #183 from NVIDIA/dependabot/github_actions/softpro…",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df0b54e700668f4d5520e7a2148d2f410c81b2e5",
          "body": "…/download-artifact-8.0.1\n\nbuild(deps): bump actions/download-artifact from 4.1.8 to 8.0.1",
          "is_bot": false,
          "headline": "Merge pull request #182 from NVIDIA/dependabot/github_actions/actions…",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:38:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d73744e6139094ee6aedcf38a2aa683b09eec4a0",
          "body": "…/checkout-7.0.0\n\nbuild(deps): bump actions/checkout from 4.2.2 to 7.0.0",
          "is_bot": false,
          "headline": "Merge pull request #181 from NVIDIA/dependabot/github_actions/actions…",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:36:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66fe146f6d5ef4d214746a37a5c34e71ec59b3ce",
          "body": "…codeql-action/upload-sarif-4.36.3\n\nbuild(deps): bump github/codeql-action/upload-sarif from 3.24.9 to 4.36.3",
          "is_bot": false,
          "headline": "Merge pull request #180 from NVIDIA/dependabot/github_actions/github/…",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:32:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd40b507f532468823a2bbb1d72b17e689ce6d2",
          "body": "build(deps): bump once_cell from 1.21.3 to 1.21.4",
          "is_bot": false,
          "headline": "Merge pull request #179 from NVIDIA/dependabot/cargo/once_cell-1.21.4",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:27:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3da939d6e05dec2b6d2d9406c5381f2102830a5",
          "body": "Bumps [once_cell](https://github.com/matklad/once_cell) from 1.21.3 to 1.21.4.\n- [Changelog](https://github.com/matklad/once_cell/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/matklad/once_cell/compare/v1.21.3...v1.21.4)\n\n---\nupdated-dependencies:\n- dependency-name: once_cell\n  dependency-version: 1.21.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump once_cell from 1.21.3 to 1.21.4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T08:15:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "092a5c9fb833934eec7a82f27ec4d2d9d09704b9",
          "body": "build(deps): bump sha2 from 0.10.9 to 0.11.0",
          "is_bot": false,
          "headline": "Merge pull request #178 from NVIDIA/dependabot/cargo/sha2-0.11.0",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:13:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "957a82a72a8de0f5ded01cee70b2074cf8cb01ff",
          "body": "build(deps): bump nix from 0.30.1 to 0.31.3",
          "is_bot": false,
          "headline": "Merge pull request #177 from NVIDIA/dependabot/cargo/nix-0.31.3",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:11:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9660aa52c0fe24ce9396cdd7b794bb55b822f96",
          "body": "build(deps): bump libc from 0.2.178 to 0.2.186",
          "is_bot": false,
          "headline": "Merge pull request #176 from NVIDIA/dependabot/cargo/libc-0.2.186",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e035e819f00143b7bf3151f1e32c3b50c639d078",
          "body": "build(deps): bump serial_test from 3.2.0 to 3.5.0",
          "is_bot": false,
          "headline": "Merge pull request #175 from NVIDIA/dependabot/cargo/serial_test-3.5.0",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-10T08:05:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f1002dc510479cd0fb2419ce4b57b6b122e9451",
          "body": "Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.20.6 to 0.24.0.\n- [Release notes](https://github.com/anchore/sbom-action/releases)\n- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)\n- [Commits](https://github.com/anchore/sbom-action/compare/f8bdd1d8\n[…]\npendency-name: anchore/sbom-action\n  dependency-version: 0.24.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump anchore/sbom-action from 0.20.6 to 0.24.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:26:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90466d8266114b670fcf39e73b168925d0448c72",
          "body": "Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.0.8 to 3.0.1.\n- [Release notes](https://github.com/softprops/action-gh-release/releases)\n- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/so\n[…]\ny-name: softprops/action-gh-release\n  dependency-version: 3.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump softprops/action-gh-release from 2.0.8 to 3.0.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:26:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ab8a44921245aaa40099c1cb23184fef515e201",
          "body": "Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.1.8 to 8.0.1.\n- [Release notes](https://github.com/actions/download-artifact/releases)\n- [Commits](https://github.com/actions/download-artifact/compare/fa0a91b85d4f404e444e00e005971372dc801d16...3e5f45b2cfb9172054\n[…]\nncy-name: actions/download-artifact\n  dependency-version: 8.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/download-artifact from 4.1.8 to 8.0.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:26:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "232f90188580c2d26229d7ee08f011e971c6ed3e",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/11bd71901bbe5b1630ceea7\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/checkout from 4.2.2 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:26:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2b626c82c75c557f88ce0177041d3fff356fe2e",
          "body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 3.24.9 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\n github/codeql-action/upload-sarif\n  dependency-version: 4.36.3\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump github/codeql-action/upload-sarif",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:26:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe91bb9847e4bb7703df587013132a8c17ef17c9",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f0e56d789f7b02a049c596034a13ea833ed3b21",
          "body": "Bumps [nix](https://github.com/nix-rust/nix) from 0.30.1 to 0.31.3.\n- [Changelog](https://github.com/nix-rust/nix/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nix-rust/nix/compare/v0.30.1...v0.31.3)\n\n---\nupdated-dependencies:\n- dependency-name: nix\n  dependency-version: 0.31.3\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump nix from 0.30.1 to 0.31.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:25:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d99092c9a5f30874eb6cc52bea388158cc7103c",
          "body": "Bumps [libc](https://github.com/rust-lang/libc) from 0.2.178 to 0.2.186.\n- [Release notes](https://github.com/rust-lang/libc/releases)\n- [Changelog](https://github.com/rust-lang/libc/blob/0.2.186/CHANGELOG.md)\n- [Commits](https://github.com/rust-lang/libc/compare/0.2.178...0.2.186)\n\n---\nupdated-dependencies:\n- dependency-name: libc\n  dependency-version: 0.2.186\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump libc from 0.2.178 to 0.2.186",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:25:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75ad777c0106e05080eaf8cd2265f3393323c628",
          "body": "Bumps [serial_test](https://github.com/palfrey/serial_test) from 3.2.0 to 3.5.0.\n- [Release notes](https://github.com/palfrey/serial_test/releases)\n- [Commits](https://github.com/palfrey/serial_test/compare/v3.2.0...v3.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: serial_test\n  dependency-version: 3.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "build(deps): bump serial_test from 3.2.0 to 3.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T01:25:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f267fc69f7fa7c34433920d90b15e9444d41856",
          "body": "ci/cd: Add several improvments",
          "is_bot": false,
          "headline": "Merge pull request #174 from zvonkok/ci-cd-enhancements",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-10T01:24:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "651e4b79820e910a9e9527df8d55d28d11710f10",
          "body": "The self-hosted runner now lives under /home/nvrc: point KATA_SRC_DIR,\nROOTFS_IMAGE_DIR and IMAGE_BUILDER_DIR there (kata-checkout still\ncarried a copy-pasted container-device-interface-rs path).\n\nThe nvrc.log=trace add/remove edited configuration.toml while the\nbaseline run was pinned to configurat\n[…]\nhe same file.\n\nThe gate-job comment still said \"CI Complete\"; the job is named\n\"Check CI Result\".\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: runner home is /home/nvrc, address review findings",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-10T01:12:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cb397934e80c900b80c49a6c534cf32f41da463",
          "body": "Additionally dependebot and codeql scanning\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>",
          "is_bot": false,
          "headline": "ci/cd: Add several improvments",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-09T23:36:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecb1d7ba7ebeb38a6c4205a0dc95cde948d35f6b",
          "body": "build: byte-reproducible releases, enforced in CI",
          "is_bot": false,
          "headline": "Merge pull request #170 from zvonkok/reproducible-builds",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:59:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "813d8a823267811f8fd4b11543cd76a655cd08ef",
          "body": "The hook installer test leaked the process-global hook, so every later\ncaught panic wrote /dev/kmsg and called sync(); the power_off variant\noutlived its test and powered off the machine on the next caught\npanic. Both hook tests now restore the previous hook, and a new test\nasserts a panic reaches t\n[…]\nd hook. power_off\nitself stays uncovered: executing it powers off the test machine.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: panic hook tests restore state and assert the shutdown path",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:09:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c222cde64bbbce830f0d415039a7e742b2fcf664",
          "body": "miri aborts at the first foreign operation it cannot interpret:\nprocess spawn and exec, fork, unix sockets, mount, O_NONBLOCK opens,\nraw syscall(SYS_getpid), the sudo re-exec in require_root, and hashing\n/proc/self/exe, which under miri is the interpreter binary. Each such\ntest carries cfg_attr(miri\n[…]\nbehind tagged pointers that\ndefeat the leak checker, and miri runs single-threaded.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: gate syscall-boundary tests under miri",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11c2ef838f65a6984c36acbae98ca7a980245fc6",
          "body": "Build the tree twice, varying the inputs a verifier cannot copy from\nCI (workspace directory, CARGO_HOME), and fail on hash mismatch with\na strings diff. Runs the same script as the release workflow.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: verify reproducibility on every pull request",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:09:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c46237444c41bc9d97f194a460552881d2760c0",
          "body": "Panic Location strings embed $CARGO_HOME/registry paths and, with the\nrust-src component installed, the sysroot source tree; both vary per\nmachine and change the sha256, breaking the boot-line to Rekor\ncorrelation from #166. scripts/build-release.sh remaps both onto\nstable forms, rejects unparseable\n[…]\nwith different CARGO_HOMEs\nproduce identical sha256; the binary remains static-PIE.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build: make release builds byte-reproducible",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33d95132e2bcce9bdc803ae8a6f677e3e786f744",
          "body": "dtolnay/rust-toolchain only sets the rustup default, which\nrust-toolchain.toml outranks: stable-labeled jobs ran the pin via an\nimplicit download and nightly tools broke against it. A composite\naction parses the pin, fails fast when unreadable, and installs what\ncargo will actually run; nightly-only\n[…]\ns --locked. The miri job drops || true so a finding\nfails CI, capped at 30 minutes.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: pin the toolchain install and enforce it everywhere",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-08T22:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cb04932c46caf1f49c37b7a2516794ad62c4194",
          "body": "rustc embeds /rustc/<commit-hash> stdlib paths in the binary, so the\ncompiler version is part of the release bytes. A floating \"stable\nminus 2 releases\" cannot reproduce a tag after the release calendar\nmoves; 1.94.0 is what it resolves to today. rustup applies the pin,\nmusl targets included, to every cargo invocation in the repo.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build: pin the toolchain",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-07T23:10:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2617ee40301c361adbfe8ac8a766e0b5841beadf",
          "body": "Rustflags in .cargo/config.toml override [profile.release] silently\nand apply to every profile: the manifest claimed opt-level \"s\" while\nmusl builds shipped \"z\", and forced panic=abort broke cargo test for\nmusl targets. The cargo config keeps target mechanics (linker,\n+crt-static); the release profile owns codegen. opt-level stays \"z\",\ncodegen-units=1 keeps fat LTO effective.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build: make Cargo.toml the single source of codegen truth",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-07T23:10:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e513011472ee9c8d4d5093d658f35516757b6a7a",
          "body": "coverage: enforce 90% per-file line coverage",
          "is_bot": false,
          "headline": "Merge pull request #172 from zvonkok/code-coverage-enforcing",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T22:41:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9421cb0365d51b85776ef906f342a3f53745d75d",
          "body": "The CI workflow also has a job named \"Detect changes\" and required\nstatus checks match check names globally; the collision would make one\nrequired entry cover two unrelated jobs. Unique names let the ruleset\nrequire the coverage filter and the coverage gate individually.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: give the coverage change filter a unique check name",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T22:34:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2ef46aa60d23e65177f3571487f17ca1a946bf8",
          "body": "Address PR review: the forward_message test joins the #[serial] lock\nshared with the kmsg test that removes and recreates /run/syslog.log,\nclosing a parallel-harness race. The as_pid1 fork test now only\nexists under cfg(coverage): the child allocates and locks stdio after\nfork, which can deadlock under the threaded harness, and the coverage\nrun is the one pinned to --test-threads=1.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: serialize syslog file test and gate fork test to coverage",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T22:19:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "570f6cf200e81d12b95d429dd3398cdcaa3c981a",
          "body": "Test code is instrumented too: the EINTR guard arm, fork-failure\npanic arm and _exit fallthrough never run, and the six untaken lines\ndragged init.rs to 87% - under the new 90% per-file gate. Reshape the\nsame semantics so every line executes on the happy path (init.rs now\n95.9% under a scoped cargo-llvm-cov 0.8.7 run); only the _exit\nfallthrough stays untaken.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: keep the fork guard test on the executed path",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T22:07:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bac3591cc0c62b3e24ea46434cbdba3e4fa43c6",
          "body": "- init.rs: retry waitpid on EINTR and report errno on fork failure\n- syslog.rs: unique nonce marker so accumulated /run/syslog.log\n  contents from earlier runs cannot satisfy the assertion\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: harden the new coverage tests per PR review",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T21:56:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8e9d7d971695af181718e86659d037a7e018735",
          "body": "An aggregate gate lets weak modules hide behind strong ones: init.rs\nsat at 80% and syslog.rs at 84% under a 96% total. Close the gaps:\n\n- init.rs: fork-based test runs the real as_pid1() guard and asserts\n  it exits 0 instead of falling through to init duties\n- syslog.rs: cover try_poll() and forwa\n[…]\n.8.7 via install-action v2.82.9 because\n--fail-under-file-lines does not exist in the 0.6.x line.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "coverage: enforce 90% per-file line coverage",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T21:14:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "739bce6ba098e2425efed573be4f2e81ac874cd5",
          "body": "ci: exempt main.rs from coverage and enforce 90% line minimum",
          "is_bot": false,
          "headline": "Merge pull request #171 from zvonkok/code-coverage-enforcing",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T21:05:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d22400b01fcaf021c3e484ab08c446e7b87e2f52",
          "body": "The CI-pinned cargo-llvm-cov 0.6.21 rejects --all-features on the\nreport subcommand (added in a later release). The flag is redundant\nanyway: report regenerates from the profdata and object files\nrecorded by the generate step, so no feature selection applies.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: drop --all-features from coverage gate",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T20:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfd25a77b690704e2ade1aff0f9d52bb160921fa",
          "body": "Address PR review: the README command now carries the CI test args so\nlocal numbers match the gate, and the report gate passes --all-features\nexplicitly. --workspace is not a report flag; report reuses the\nprofdata and object files recorded by the generate step.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: align gate flags and README coverage command with CI run",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T20:53:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38367f3fe8b87bf9ff151814ca179c25b7aaa19c",
          "body": "The docs-only filter skipped the coverage job for changes to\ncoverage.yaml, so edits to the gate never exercised it.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: run coverage when the coverage workflow itself changes",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T20:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5da24911f84a0784b00b901f3f9cce674be87a97",
          "body": "main.rs is dispatch-only plumbing that only runs as PID 1 in a VM.\nThe gate runs after the Coveralls upload so failing reports stay\nvisible.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: exempt main.rs from coverage and enforce 90% line minimum",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T20:33:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2ce239fca1dc39649417a3b3e4ebfcd245a6659",
          "body": "hash: log version and sha256 of /proc/self/exe at boot",
          "is_bot": false,
          "headline": "Merge pull request #166 from zvonkok/hash-self-exe",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T14:34:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c26e4aebe3da563ab7e6167dee0f3ac8f236f90",
          "body": "Make the workflow name more descriptive.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>",
          "is_bot": false,
          "headline": "ci: Update workflow name",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T14:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "047251477be19364579daf022740c8a8577293f6",
          "body": "Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>",
          "is_bot": false,
          "headline": "Potential fix for pull request finding",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T14:15:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "071f3593eeaa9fc901eeb9c8cdadbbb3d2905884",
          "body": "CARGO_PKG_VERSION alone cannot tell a clean release apart from a local\nor CI build of uncommitted code. CI computes a short commit (plus -dirty\nfor an unclean tree) and exports it as GIT_REV on the cargo build command;\nhash.rs reads it via option_env! and appends it as semver build metadata,\ne.g. \"v\n[…]\nthan a build.rs, which would\nmake the otherwise hermetic build depend on git state.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "hash: stamp boot identity and guard init against non-PID-1 runs",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T14:15:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed84ea20c18b3208de3180e0a8c01bfe60d51b6e",
          "body": "Lets operators correlate dmesg output against the cosign/Rekor digest\npublished in the release evidence bundle (ARCHITECTURE.md\n§\"Provenance & Supply-Chain Security\").\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "hash: log version and sha256 of /proc/self/exe at boot",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T14:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cba949a66dc7c3af9a2dc8252d86dd9d4b8f143",
          "body": "Signed-off-by: Zvonko Kaiser <zkaiser@nvidia.com>\nAssisted-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "claude: add self-describing code guideline",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T14:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fec8339fccf4cd16978be6b926e9efbc8b9a1bfd",
          "body": "ci: Fix update-kata workflow & CI failures after the kata upgrade to 3.32.0",
          "is_bot": false,
          "headline": "Merge pull request #169 from NVIDIA/ci/gpu-boot-fix",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-07-06T12:42:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bc4ccf0c0d15afbcf077a447a101d50cc3a3c73",
          "body": "The tests module imported std::panic without using it, which trips\nwarn(unused_imports). Remove it to keep the build warning-free.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "net: drop unused std::panic import from tests",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T07:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e5a2cd20a65e26ee616e472796ab1f7d882e5f3",
          "body": "The nvidia-gpu guest kernel enforces module signatures\n(CONFIG_MODULE_SIG_FORCE). kata signs modules with a key generated per\nkernel build: it embeds the public half in the vmlinuz and ships the\nprivate key, encrypted with KBUILD_SIGN_PIN, in the kernel headers so the\nrootfs build (nvidia_chroot.sh)\n[…]\neshly generated key, so the guest would reject the module. A fresh\nmatched build is the whole point.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: build a signed nvidia driver + matching kernel in update-kata",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T07:43:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4935b0c14e7c8bd0d6313bef627be0a73f62c74f",
          "body": "Several bugs stopped the runner-refresh workflow before it produced a\nrootfs:\n\n  * install the GitHub CLI when the runner lacks it;\n  * surface gh's real error instead of masking every failure as\n    \"release not found\", and download the kata-static .tar.zst assets\n    (kata moved off .tar.xz);\n  * \n[…]\nuser so the kata-deploy in-container git does not\n    trip \"dubious ownership\" against the checkout.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: fix the update-kata workflow so it runs to completion",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T07:43:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6841cb99d392c16e505584f4438c28a49d3e9d06",
          "body": "The GPU tests only surface nerdctl's stderr, so a \"create container\ntimeout\" leaves no guest-side evidence. Add an `if: failure()` step that\ndumps the relevant configuration.toml lines, the VFIO/GPU host state, host\ndmesg vfio/iommu lines, and the kata runtime log — including the guest\nconsole (kern\n[…]\nngs, guest-console markers, and a raw console tail) instead of\nthe raw, initcall_debug-flooded dump.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: capture kata/guest diagnostics when a GPU test fails",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T07:43:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93a14b6bd397a06f93ba23f6802e10caa6d8966c",
          "body": "The panic hook only wrote to init stderr and then powered the VM off.\ninit stdio is unreliable (the kernel wires it up only if /dev/console\nexisted at exec, and buffered bytes are lost in the power-off race), so\nNVRC panics vanished with no trace in the guest console.\n\nWrite the message to /dev/kmsg\n[…]\ns to the console during power-off, so the panic\nstays visible (and is captured in the kata journal).\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "lockdown: write panic messages to /dev/kmsg before power-off",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-07-06T07:19:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ceda0162eff42846247dd56c9d619bbc0180544",
          "body": "ci: add workflow_dispatch to update kata-containers on the runner",
          "is_bot": false,
          "headline": "Merge pull request #164 from fidencio/topic/ci-update-kata-workflow",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-29T16:55:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8869a24e97a2650326b90cc982e92c1868efe96e",
          "body": "Refreshes the self-hosted runner's kata-containers install and source\ntree from a given upstream release tag (or 'latest'). For the tag it:\n\n  * checks out kata-containers source at /home/ubuntu/actions-runner/_work/kata-containers\n    so tools/osbuilder & build/ match the release the CI runs agains\n[…]\nates kernel_params\nin place; the run summary points at /opt/kata/share/defaults/kata-containers/\nfor manual diffing when upstream defaults move.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: add workflow_dispatch to update kata-containers on the runner",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-29T16:51:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52476ce6affaf9f1ddf7643f9a6ecb8819def74f",
          "body": "…target\n\nci: Do not use pull_request_target",
          "is_bot": false,
          "headline": "Merge pull request #163 from NVIDIA/topic/ci-do-not-use-pull_request_…",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-29T15:27:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7931ec4aadf9f7de13edaf82b9403ee3aafb0a8",
          "body": "…ds-on-kata-side\n\nci: re-add nerdctl exit-code tolerance until kata fix lands",
          "is_bot": false,
          "headline": "Merge pull request #162 from NVIDIA/topic/re-add-or-true-till-fix-lan…",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-29T15:12:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf3fb5820065e64db72c880897a316ecd89559a8",
          "body": "Bind the ok-to-test approval to a specific revision. When new commits are\npushed, remove the label so the E2E workflow stops running unreviewed code\non the self-hosted runner. A maintainer re-applies the label after review,\nwhich fires a fresh labeled event and re-runs CI on the new HEAD.\n\nUses pull_request_target for pull-requests:write (label management), but\nruns no PR code so it is safe.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: revoke ok-to-test label on PR synchronize",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-29T15:10:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "daee98b6e3396f1815a08d48d86f13b0210e3c64",
          "body": "pull_request_target loads the workflow definition from the base branch,\nso changes to the CI YAML cannot be validated in the PR and only surface\nas failures after merge. Switch to pull_request so the workflow runs from\nthe PR's merge-ref and YAML changes are exercised before merge.\n\nThe 'ok-to-test'\n[…]\nt field used by the workflow exists\nidentically in the pull_request payload. As a bonus, fork PRs now run\nwith a read-only token and no secrets.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: use pull_request instead of pull_request_target",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-29T15:10:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "020ccc88fbc0a7ef82f2d3f2d39f93127ef4f767",
          "body": "The E2E steps run under 'set -euo pipefail' and validated the nerdctl\noutput with 'echo \"$output\" | grep -q PATTERN'. Under pipefail this is a\nfalse-negative trap: 'grep -q' exits on its first match and closes the\npipe, so the still-writing 'echo' is killed by SIGPIPE (141). pipefail\nthen reports th\n[…]\nis restores NVIDIA-SMI / NVRC as real hard checks; the exit-code\nand kata fatal-message checks remain warn-only pending the kata-containers\nfix.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: grep nerdctl output via here-strings to fix pipefail false negative",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-29T14:59:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c5bd4301809aadaffd8e6c5944f962e27e4b794",
          "body": "Commit 04b8be5 removed the '|| true' masks around the E2E nerdctl\ninvocations on the assumption that exit codes would propagate honestly\nafter the NVRC syslog::try_poll fix. That was premature: kata-containers\nstill returns 255 (and may emit 'ttrpc: closed'/'level=fatal') when the\nagent tears the VM\n[…]\ntent checks (NVIDIA-SMI banner, NVRC log presence/absence)\nstill gate the steps. Re-enable the hard failures once the\nkata-containers fix lands.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: re-add nerdctl exit-code tolerance until kata fix lands",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-29T14:47:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f04ea85991771c8ea12433e8cb74526e9c24488",
          "body": "agents: Add CLAUDE, AGENTS and copilot PR context",
          "is_bot": false,
          "headline": "Merge pull request #160 from zvonkok/add-agent-context",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-28T20:12:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c9a73ad4c6d9c009b0cb8fc91a827b70a15d18a",
          "body": "Consolidate all agent instructions in CLAUDE.md and symlink\nthe other needed files.\n\nSigned-off-by: Zvonko Kaiser <zkaiser@nvidia.com>",
          "is_bot": false,
          "headline": "agents: Add CLAUDE, AGENTS and copilot PR context",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-28T20:13:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6f5c0c5da927cb132e87088eff054106ef52202",
          "body": "ci: Improve visibility of errors & allow running from a \"devel\" branch",
          "is_bot": false,
          "headline": "Merge pull request #156 from fidencio/topic/ci-e2e-visibility",
          "author_name": "Zvonko Kaiser",
          "author_login": "zvonkok",
          "committed_at": "2026-05-25T14:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ee15800c4e51a7e62fc1708bf5408597e8a4871",
          "body": "Add a workflow_dispatch trigger to ci.yaml so the E2E job can be\nlaunched manually from the Actions UI against a branch that has no\nassociated pull request. Inputs mirror the existing workflow_call\nshape; commit-hash is optional and falls back to the dispatched ref\nso the typical case (run against the selected branch tip) needs no\ninput at all.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: allow manual workflow_dispatch runs",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-25T14:51:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cde996be637c5f26d98c0943a2cb2c8fee43075e",
          "body": "GitHub Actions runs `run:` blocks under `bash -e`. In that mode the\nshell aborts on the failing command substitution\n\n  output=$(sudo nerdctl run ... 2>&1)\n\nbefore the subsequent `echo \"$output\"` runs, so failed E2E steps print\nnothing useful and we can't tell whether nerdctl actually failed, why,\no\n[…]\n nerdctl output\ncontains `ttrpc: closed` or `level=fatal`, which indicate kata errors\nthat today can otherwise be masked by a zero-looking exit.\n\nSigned-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>",
          "is_bot": false,
          "headline": "ci: expose nerdctl exit code / kata errors in E2E logs",
          "author_name": "Fabiano Fidêncio",
          "author_login": "fidencio",
          "committed_at": "2026-05-25T14:50:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 6,
      "commits_last_year": 387,
      "latest_release_at": "2026-07-10T16:05:34Z",
      "latest_release_tag": "v0.1.5",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 32,
      "days_since_latest_release": 15,
      "mean_days_between_releases": 54
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 20,
      "stars": 35,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2024-07-18",
            "count": 1
          },
          {
            "date": "2024-10-09",
            "count": 1
          },
          {
            "date": "2025-03-06",
            "count": 1
          },
          {
            "date": "2025-05-15",
            "count": 1
          },
          {
            "date": "2025-08-29",
            "count": 1
          },
          {
            "date": "2025-09-03",
            "count": 1
          },
          {
            "date": "2025-09-14",
            "count": 1
          },
          {
            "date": "2025-09-23",
            "count": 1
          },
          {
            "date": "2025-11-27",
            "count": 1
          },
          {
            "date": "2026-01-20",
            "count": 1
          },
          {
            "date": "2026-01-21",
            "count": 1
          },
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-05-06",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          },
          {
            "date": "2026-07-10",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-22",
            "count": 1
          },
          {
            "date": "2026-07-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 20,
        "total_forks": 20
      },
      "star_history": null,
      "open_issues_and_prs": 24
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "fuzz/Cargo.toml"
      ],
      "largest_source_bytes": 18085,
      "source_files_sampled": 26,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        ".github/copilot-instructions.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 5037
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "fuzz/Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 81,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 1,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "nix",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.31.3"
        },
        {
          "name": "cfg-if",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.4"
        },
        {
          "name": "log",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.29"
        },
        {
          "name": "kernlog",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "rlimit",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.0"
        },
        {
          "name": "libc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2.178"
        },
        {
          "name": "once_cell",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.21.3"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "cfg-if",
            "direct": true,
            "version": "1.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "kernlog",
            "direct": true,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "libc",
            "direct": true,
            "version": "0.2.186",
            "ecosystem": "crates"
          },
          {
            "name": "log",
            "direct": true,
            "version": "0.4.33",
            "ecosystem": "crates"
          },
          {
            "name": "nix",
            "direct": true,
            "version": "0.31.3",
            "ecosystem": "crates"
          },
          {
            "name": "once_cell",
            "direct": true,
            "version": "1.21.4",
            "ecosystem": "crates"
          },
          {
            "name": "rlimit",
            "direct": true,
            "version": "0.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": true,
            "version": "0.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "aho-corasick",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "autocfg",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "bitflags",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "crates"
          },
          {
            "name": "block-buffer",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "crates"
          },
          {
            "name": "cfg_aliases",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "cpufeatures",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-common",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "digest",
            "direct": false,
            "version": "0.11.3",
            "ecosystem": "crates"
          },
          {
            "name": "equivalent",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "errno",
            "direct": false,
            "version": "0.3.10",
            "ecosystem": "crates"
          },
          {
            "name": "fastrand",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "futures-core",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "crates"
          },
          {
            "name": "futures-executor",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "crates"
          },
          {
            "name": "futures-macro",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "crates"
          },
          {
            "name": "futures-task",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "crates"
          },
          {
            "name": "futures-timer",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "futures-util",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.2.15",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": false,
            "version": "0.17.1",
            "ecosystem": "crates"
          },
          {
            "name": "hybrid-array",
            "direct": false,
            "version": "0.4.13",
            "ecosystem": "crates"
          },
          {
            "name": "indexmap",
            "direct": false,
            "version": "2.14.0",
            "ecosystem": "crates"
          },
          {
            "name": "libfuzzer-sys",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "linux-raw-sys",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "crates"
          },
          {
            "name": "lock_api",
            "direct": false,
            "version": "0.4.12",
            "ecosystem": "crates"
          },
          {
            "name": "memchr",
            "direct": false,
            "version": "2.7.4",
            "ecosystem": "crates"
          },
          {
            "name": "mktemp",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "parking_lot",
            "direct": false,
            "version": "0.12.3",
            "ecosystem": "crates"
          },
          {
            "name": "parking_lot_core",
            "direct": false,
            "version": "0.9.10",
            "ecosystem": "crates"
          },
          {
            "name": "pin-project-lite",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "crates"
          },
          {
            "name": "pin-utils",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro-crate",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro2",
            "direct": false,
            "version": "1.0.93",
            "ecosystem": "crates"
          },
          {
            "name": "quote",
            "direct": false,
            "version": "1.0.38",
            "ecosystem": "crates"
          },
          {
            "name": "redox_syscall",
            "direct": false,
            "version": "0.5.10",
            "ecosystem": "crates"
          },
          {
            "name": "regex",
            "direct": false,
            "version": "1.12.3",
            "ecosystem": "crates"
          },
          {
            "name": "regex-automata",
            "direct": false,
            "version": "0.4.14",
            "ecosystem": "crates"
          },
          {
            "name": "regex-syntax",
            "direct": false,
            "version": "0.8.10",
            "ecosystem": "crates"
          },
          {
            "name": "relative-path",
            "direct": false,
            "version": "1.9.3",
            "ecosystem": "crates"
          },
          {
            "name": "rstest",
            "direct": false,
            "version": "0.26.1",
            "ecosystem": "crates"
          },
          {
            "name": "rstest_macros",
            "direct": false,
            "version": "0.26.1",
            "ecosystem": "crates"
          },
          {
            "name": "rustc_version",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "rustix",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "scopeguard",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "1.0.28",
            "ecosystem": "crates"
          },
          {
            "name": "serde_core",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_derive",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serial_test",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "serial_test_derive",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "slab",
            "direct": false,
            "version": "0.4.9",
            "ecosystem": "crates"
          },
          {
            "name": "smallvec",
            "direct": false,
            "version": "1.13.2",
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": false,
            "version": "2.0.98",
            "ecosystem": "crates"
          },
          {
            "name": "tempfile",
            "direct": false,
            "version": "3.27.0",
            "ecosystem": "crates"
          },
          {
            "name": "toml_datetime",
            "direct": false,
            "version": "1.1.1+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "toml_edit",
            "direct": false,
            "version": "0.25.12+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "toml_parser",
            "direct": false,
            "version": "1.1.2+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "typenum",
            "direct": false,
            "version": "1.20.0",
            "ecosystem": "crates"
          },
          {
            "name": "unicode-ident",
            "direct": false,
            "version": "1.0.16",
            "ecosystem": "crates"
          },
          {
            "name": "uuid",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "wasi",
            "direct": false,
            "version": "0.11.0+wasi-snapshot-preview1",
            "ecosystem": "crates"
          },
          {
            "name": "wasi",
            "direct": false,
            "version": "0.13.3+wasi-0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.59.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-targets",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "winnow",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen-rt",
            "direct": false,
            "version": "0.33.0",
            "ecosystem": "crates"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 82,
        "direct_count": 8,
        "indirect_count": 74
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 152,
        "open_issues": 18,
        "closed_ratio": 0.308,
        "closed_issues": 8,
        "closed_unmerged_prs": 20
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "zvonkok",
          "commits": 388,
          "avatar_url": "https://avatars.githubusercontent.com/u/3725238?v=4"
        },
        {
          "type": "User",
          "login": "fidencio",
          "commits": 30,
          "avatar_url": "https://avatars.githubusercontent.com/u/112762?v=4"
        },
        {
          "type": "User",
          "login": "cclaudio",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/6483487?v=4"
        },
        {
          "type": "User",
          "login": "LandonTClipp",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/11232769?v=4"
        }
      ],
      "contributors_sampled": 4,
      "top_contributor_share": 0.922
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "actionlint.yaml",
        "ci-on-push.yaml",
        "ci.yaml",
        "codeql.yaml",
        "coverage.yaml",
        "dependabot-auto-merge.yaml",
        "dependabot-ok-to-test.yaml",
        "docs.yaml",
        "fuzzing.yaml",
        "kata-checkout.yaml",
        "release.yaml",
        "reproducible.yaml",
        "revoke-ok-to-test.yaml",
        "scorecard.yml",
        "shellcheck.yaml",
        "static-checks.yaml",
        "update-kata.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 1,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 1/8 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 10,
            "reason": "5 out of the last 5 releases have a total of 10 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3840e8b5c553e2219966141005eb1b25f98c969b",
        "ran_at": "2026-07-26T09:17:26Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T04:23:15Z",
      "oldest_open_prs": [
        {
          "number": 173,
          "created_at": "2026-07-07T02:30:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 195,
          "created_at": "2026-07-15T06:54:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 196,
          "created_at": "2026-07-15T06:55:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 197,
          "created_at": "2026-07-15T06:55:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 198,
          "created_at": "2026-07-15T06:55:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 199,
          "created_at": "2026-07-15T06:56:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T17:08:35Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 13,
          "created_at": "2025-03-25T21:12:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 104,
          "created_at": "2026-01-12T20:58:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 105,
          "created_at": "2026-01-12T20:58:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2026-01-12T20:58:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 107,
          "created_at": "2026-01-12T20:58:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 108,
          "created_at": "2026-01-12T20:58:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 109,
          "created_at": "2026-01-12T20:58:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-01-12T20:58:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 111,
          "created_at": "2026-01-12T20:58:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 112,
          "created_at": "2026-01-12T20:58:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 113,
          "created_at": "2026-01-12T20:58:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 114,
          "created_at": "2026-01-12T20:58:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 115,
          "created_at": "2026-01-12T20:58:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 116,
          "created_at": "2026-01-12T20:58:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 117,
          "created_at": "2026-01-12T20:58:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 118,
          "created_at": "2026-01-12T20:58:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 159,
          "created_at": "2026-05-27T15:30:37Z",
          "last_comment_at": "2026-07-20T15:05:48Z",
          "last_comment_author": "zvonkok"
        },
        {
          "number": 202,
          "created_at": "2026-07-18T10:34:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/NVIDIA/nvrc",
    "host": "github.com",
    "name": "nvrc",
    "owner": "NVIDIA"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 77,
        "vitality": 89,
        "community": 52,
        "governance": 50,
        "engineering": 46
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "commits_last_year": 387,
              "human_commit_share": 0.85,
              "days_since_last_push": 1,
              "active_weeks_last_year": 32
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "32/52 weeks with commits",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 32
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "387 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 387
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "releases_count": 6,
              "latest_release_tag": "v0.1.5",
              "releases_from_tags": false,
              "days_since_latest_release": 15,
              "mean_days_between_releases": 54
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "6 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 15 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~54 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 54
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 10 signed artifacts.",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 52,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "forks": 20,
              "stars": 35,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "35 stars",
                "points": 24.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 35
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "20 forks",
                "points": 10.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 50,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 4,
              "top_contributor_share": 0.922
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 92% of commits",
                "points": 1.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 92
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "4 contributors",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "merged_prs": 152,
              "open_issues": 18,
              "closed_issues": 8,
              "issue_closed_ratio": 0.308,
              "closed_unmerged_prs": 20
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "31% of issues closed",
                "points": 14.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 31
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "152/172 decided PRs merged",
                "points": 33.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 152,
                      "decided": 172
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/8 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "followers": 28325,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "NVIDIA",
              "public_repos": 776,
              "account_age_days": 5189
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "28,325 followers of NVIDIA",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 28325,
                      "login": "NVIDIA"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "776 public repos, account ~14 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 776
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 46,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "18 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/8 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 10 signed artifacts.",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 81 resolved dependencies against OSV; 1 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 81
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 1
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 81,
              "unassessed_packages": 1,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 81,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 6
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 73,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".github/copilot-instructions.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 5037
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "85 of 85 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 85,
                      "sampled": 85
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [
                "Cargo.toml",
                "fuzz/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.15
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml, fuzz/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml, fuzz/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "15 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 15,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 18085,
              "source_files_sampled": 26,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/26 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 26,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'NVRC' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T09:17:43.515624Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/NVIDIA/nvrc.svg",
  "full_name": "NVIDIA/nvrc",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statistics.