Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-24 06:41 UTC

UKGovernmentBEIS / control-arena

ControlArena is a collection of settings, model organisms and protocols - for running control experiments.

PythonMIT★ 212 stars⑂ 124 forkssince Feb 2025View on GitHub ↗

UKGovernmentBEIS/control-arena holds a health index of 78 out of 100, placing it in the Good band. It scores highest on Vitality (96/100) and lowest on Security (51/100). It was last updated today. 2 contributors account for most of its recent work.

78
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

78
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

242 followers114 public repossince May 2016

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
PyPIcontrol_arena17.1.222,413780 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

96Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
29.1/36Commit cadence — 42/52 weeks with commits
18/18Commit volume — 320 commits in the last year
10/10OpenSSF Scorecard: Maintained — 14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year320
human_commit_share1
days_since_last_push0
active_weeks_last_year42

Release discipline

100Excellent
How it's scored
27/27Ships releases — 83 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~13.4 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count83
latest_release_tagv17.1.2
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases13.4
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

68Moderate · 18% of overall
How it's scored
37.7/60Stars — 212 stars
17.4/25Forks — 124 forks
3.3/15Watchers — 5 watchers
Inputs used
forks124
stars212
watchers5
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes
How it's scored
58/80Monthly downloads — 22,413 downloads/month across pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagescontrol_arena
dependents
ecosystemspypi
total_downloads
monthly_downloads22,413
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

77Good · 24% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
14.7/22.5Commit distribution — top contributor authored 35% of commits
13.5/13.5Contributor breadth — 52 contributors
10/10OpenSSF Scorecard: Contributors — project has 7 contributing companies or organizations
Inputs used
bus_factor2
contributors_sampled52
top_contributor_share0.348
How it's scored
44.2/46.8Issue resolution — 94% of issues closed
31.7/38.3PR acceptance — 622/751 decided PRs merged
3/15OpenSSF Scorecard: Code-Review — Found 6/30 approved changesets -- score normalized to 2
Inputs used
merged_prs622
open_issues4
closed_issues69
issue_closed_ratio0.945
closed_unmerged_prs129
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
17.2/25Owner reach — 242 followers of UKGovernmentBEIS
25/25Track record — 114 public repos, account ~10 yr old
Inputs used
followers242
owner_typeOrganization
is_verified
owner_loginUKGovernmentBEIS
public_repos114
account_age_days3,730
How it's scored
25/25Published & resolvable — 1 package(s) on pypi
35/35Publish recency — latest publish 0 days ago
20/20Version history — 78 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagescontrol_arena
ecosystemspypi
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

88Excellent · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://control-arena.aisi.org.uk
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepagehttps://control-arena.aisi.org.uk
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

51Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 6/30 approved changesets -- score normalized to 2
2.5/2.5Contributors — project has 7 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 152 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.1
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
4.7/35Direct dependencies free of known advisories — 5 affected: gitpython 3.1.46 (critical 9.8), click 8.2.1 (high 7.2), click 8.3.1 (high 7.2), +2 more
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
32.3/40No advisories left outstanding — 2 advisory-carrying package(s) unaddressed past 90 days; oldest published 154 days ago
Inputs used
sourceosv
advisories269
affected_packages37
assessed_packages386
unassessed_packages4
affected_by_severitycritical 5, high 7, moderate 11, unknown 14
direct_affected_packages5
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 386 resolved dependencies against OSV. 4 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

81Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md
15/15Machine-readable docs (llms.txt) — llms.txt present
40/40Legible commit history — 96 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtyes
legible_history_share0.96
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes4,175
How it's scored
18/18One-command bootstrap — control_arena/settings/infra/Makefile
22/22Automated tests
11/11Lint / format config
11/11Static type checking — control_arena/py.typed
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 26 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesuv.lock
has_dockerfileyes
typed_languageno
bootstrap_filescontrol_arena/settings/infra/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configscontrol_arena/py.typed
agent_commit_share0.26
toolchain_manifests
dependency_bot_commit_share0
How it's scored
27/45Type-checkable code — Python with type-check config (control_arena/py.typed)
55/55Manageable file sizes — 0/563 source files over 60KB
Inputs used
primary_languagePython
largest_source_bytes48,150
source_files_sampled563
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples, notebooks
Inputs used
example_dirsexamples, notebooks
has_mcp_signalno
api_schema_files

Key facts

212GitHub stars
52contributors
320commits, last 12 months
0days since last push
83releases
2bus factor
4open issues
PyPIpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index pypi:control_arena@17.1.2; advisories assessed against the repository dependency graph instead
  • Advisory severity resolved for 120 of 242 advisories (lookup cap); the remainder are reported as unknown severity

More detail

Star and fork history 0 ★ / 124 ⇿
0Stars
124Forks
82Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

02040608010012010992025-032025-112026-07
Major 17Minor 33Patch 28

Each point covers 2 days.

OpenSSF Scorecard 5.1 / 10
5.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-24 06:40 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 6/30 approved changesets -- score normalized to 2
10Contributorsproject has 7 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities152 existing vulnerabilities detected
Direct dependencies 26
RegistryPackageVersion constraintManifest
PyPIagentdojo==0.1.33pyproject.toml
PyPIaiofiles>=25.1.0pyproject.toml
PyPIanthropic>=0.80.0pyproject.toml
PyPIanyio>=4.8.0pyproject.toml
PyPIclick>=8.1.7pyproject.toml
PyPIdatasets>=4.4.2pyproject.toml
PyPIdefusedxml>=0.7.1pyproject.toml
PyPIdocker>=7.1.0pyproject.toml
PyPIflask>=3.1.3pyproject.toml
PyPIgitpython>=3.1.44pyproject.toml
PyPIhuggingface-hub~=0.33pyproject.toml
PyPIinspect-ai>=0.3.159pyproject.toml
PyPIinspect-k8s-sandbox>=0.6.1pyproject.toml
PyPIkubernetes-asyncio>=32.0.0pyproject.toml
PyPIminio>=7.2.15pyproject.toml
PyPIminiopy-async>=1.21.1pyproject.toml
PyPIopenai>=2.26.0pyproject.toml
PyPIpandas>=2.3.0pyproject.toml
PyPIpandera>=0.26.0pyproject.toml
PyPIpsycopg>=3.2.6pyproject.toml
PyPIpyarrow>=20.0.0pyproject.toml
PyPIredis==5.2.1pyproject.toml
PyPIregex>=2024.11.6pyproject.toml
PyPIrich>=13.7.0pyproject.toml
PyPIseaborn>=0.13.2pyproject.toml
PyPIsniffio>=1.3.0pyproject.toml
All dependencies 390

Full resolved dependency set from the GitHub dependency graph: 30 direct and 360 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
PyPIagentdojo0.1.33direct
PyPIaiofiles25.1.0direct
PyPIanthropic0.86.0direct
PyPIanyio4.13.0direct
PyPIclick8.2.1direct
PyPIclick8.3.1direct
PyPIdatasets3.3.1direct
PyPIdatasets4.8.4direct
PyPIdefusedxml0.7.1direct
PyPIdocker7.1.0direct
PyPIflask3.0.0direct
PyPIflask3.1.3direct
PyPIgitpython3.1.46direct
PyPIhuggingface-hub0.36.2direct
PyPIhuggingface-hub1.8.0direct
PyPIinspect-ai0.3.201direct
PyPIinspect-k8s-sandbox0.6.1direct
PyPIkubernetes-asyncio35.0.1direct
PyPIminio7.2.20direct
PyPIminiopy-async1.23.4direct
PyPIopenai2.30.0direct
PyPIpandas3.0.2direct
PyPIpandera0.30.1direct
PyPIpsycopg3.3.3direct
PyPIpyarrow23.0.1direct
PyPIredis5.2.1direct
PyPIregex2026.3.32direct
PyPIrich14.3.3direct
PyPIseaborn0.13.2direct
PyPIsniffio1.3.1direct
PyPIaioboto315.5.0indirect
PyPIaiobotocore2.25.1indirect
PyPIaiohappyeyeballs2.6.1indirect
PyPIaiohttp3.13.4indirect
PyPIaiohttp-cors0.8.1indirect
PyPIaiohttp-retry2.9.1indirect
PyPIaioitertools0.13.0indirect
PyPIaiosignal1.4.0indirect
PyPIannotated-doc0.0.4indirect
PyPIannotated-types0.7.0indirect
PyPIappnope0.1.4indirect
PyPIargon2-cffi23.1.0indirect
PyPIargon2-cffi-bindings25.1.0indirect
PyPIarrow1.4.0indirect
PyPIasgiref3.11.1indirect
PyPIasttokens3.0.1indirect
PyPIasync-lru2.3.0indirect
PyPIasync-timeout5.0.1indirect
PyPIattrs26.1.0indirect
PyPIaws-cdk-libindirect
PyPIbabel2.18.0indirect
PyPIbeartype0.22.9indirect
PyPIbeautifulsoup44.14.3indirect
PyPIblack26.3.1indirect
PyPIbleach6.3.0indirect
PyPIblinker1.9.0indirect
PyPIboto31.40.61indirect
PyPIboto31.42.79indirect
PyPIbotocore1.40.61indirect
PyPIbotocore1.42.79indirect
PyPIbuild1.4.2indirect
PyPIcbor25.9.0indirect
PyPIcertifi2025.11.12indirect
PyPIcertifi2026.2.25indirect
PyPIcffi2.0.0indirect
PyPIcfgv3.5.0indirect
PyPIchardet7.4.0.post2indirect
PyPIcharset-normalizer3.4.6indirect
PyPIcohere5.21.1indirect
PyPIcolorama0.4.6indirect
PyPIcolorful0.5.8indirect
PyPIcomm0.2.3indirect
PyPIconstructsindirect
PyPIcontourpy1.3.3indirect
PyPIcryptography46.0.6indirect
PyPIcuda-bindings13.2.0indirect
PyPIcuda-pathfinder1.5.0indirect
PyPIcuda-toolkit13.0.2indirect
PyPIcycler0.12.1indirect
PyPIdebugpy1.8.20indirect
PyPIdecorator5.2.1indirect
PyPIdeepdiff9.0.0indirect
PyPIdill0.3.8indirect
PyPIdill0.4.1indirect
PyPIdistlib0.4.0indirect
PyPIdistro1.9.0indirect
PyPIdjango6.0.3indirect
PyPIdjango-cors-headers4.9.0indirect
PyPIdnspython2.8.0indirect
PyPIdocstring-parser0.17.0indirect
PyPIdurationpy0.10indirect
PyPIemail-validator2.3.0indirect
PyPIeval-type-backport0.3.1indirect
PyPIexecnet2.1.2indirect
PyPIexecuting2.2.1indirect
PyPIfastapi0.135.2indirect
PyPIfastavro1.12.1indirect
PyPIfastcore1.12.33indirect
PyPIfastjsonschema2.21.2indirect
PyPIfilelock3.25.2indirect
PyPIflake87.3.0indirect
PyPIflask-cors6.0.2indirect
PyPIflask-httpauth4.8.1indirect
PyPIfonttools4.62.1indirect
PyPIfqdn1.5.1indirect
PyPIfrozenlist1.8.0indirect
PyPIfsspec2024.12.0indirect
PyPIfsspec2025.9.0indirect
PyPIghapi1.0.13indirect
PyPIgitdb4.0.12indirect
PyPIgoogle-api-core2.30.1indirect
PyPIgoogle-auth2.49.1indirect
PyPIgoogle-genai1.69.0indirect
PyPIgoogleapis-common-protos1.73.1indirect
PyPIgriffe2.0.2indirect
PyPIgriffecli2.0.2indirect
PyPIgriffelib2.0.2indirect
PyPIgroq1.1.2indirect
PyPIgrpcio1.80.0indirect
PyPIgrpclib0.4.9indirect
PyPIh110.16.0indirect
PyPIh24.3.0indirect
PyPIhatch-vcs0.5.0indirect
PyPIhatchling1.29.0indirect
PyPIhf-xet1.4.2indirect
PyPIhpack4.1.0indirect
PyPIhttpcore1.0.9indirect
PyPIhttptools0.7.1indirect
PyPIhttpx0.28.1indirect
PyPIhyperframe6.1.0indirect
PyPIidentify2.6.18indirect
PyPIidna3.11indirect
PyPIijson3.5.0indirect
PyPIimportlib-metadata8.7.1indirect
PyPIimportlib-resources6.5.2indirect
PyPIiniconfig2.3.0indirect
PyPIinspect-podman0.1.2indirect
PyPIipdb0.13.13indirect
PyPIipykernel6.31.0indirect
PyPIipython8.22.0indirect
PyPIipython9.12.0indirect
PyPIipython-pygments-lexers1.1.1indirect
PyPIipywidgets8.1.8indirect
PyPIisoduration20.11.0indirect
PyPIitsdangerous2.2.0indirect
PyPIjedi0.19.2indirect
PyPIjinja23.1.6indirect
PyPIjiter0.13.0indirect
PyPIjmespath1.1.0indirect
PyPIjsiiindirect
PyPIjson50.14.0indirect
PyPIjsonlines4.0.0indirect
PyPIjsonpatch1.33indirect
PyPIjsonpath-ng1.8.0indirect
PyPIjsonpath-python1.1.5indirect
PyPIjsonpointer3.1.1indirect
PyPIjsonref1.1.0indirect
PyPIjsonschema4.26.0indirect
PyPIjsonschema-specifications2025.9.1indirect
PyPIjupyter1.1.1indirect
PyPIjupyter-client8.8.0indirect
PyPIjupyter-console6.6.3indirect
PyPIjupyter-core5.9.1indirect
PyPIjupyter-events0.12.0indirect
PyPIjupyter-lsp2.3.0indirect
PyPIjupyter-server2.17.0indirect
PyPIjupyter-server-terminals0.5.4indirect
PyPIjupyterlab4.5.6indirect
PyPIjupyterlab-pygments0.3.0indirect
PyPIjupyterlab-server2.28.0indirect
PyPIjupyterlab-widgets3.0.16indirect
PyPIkiwisolver1.5.0indirect
PyPIkubernetes35.0.0indirect
PyPIlangchain1.2.13indirect
PyPIlangchain-core1.2.23indirect
PyPIlanggraph1.1.3indirect
PyPIlanggraph-checkpoint4.0.1indirect
PyPIlanggraph-prebuilt1.0.8indirect
PyPIlanggraph-sdk0.3.12indirect
PyPIlangsmith0.7.23indirect
PyPIlark1.3.1indirect
PyPIlinkify-it-py2.1.0indirect
PyPImarkdown3.10.2indirect
PyPImarkdown-it-py4.0.0indirect
PyPImarkupsafe3.0.3indirect
PyPImatplotlib3.10.8indirect
PyPImatplotlib-inline0.2.1indirect
PyPImccabe0.7.0indirect
PyPImdit-py-plugins0.5.0indirect
PyPImdurl0.1.2indirect
PyPImistralai2.1.3indirect
PyPImistune3.2.0indirect
PyPImmh35.2.1indirect
PyPImodal1.4.1indirect
PyPImpmath1.3.0indirect
PyPImsgpack1.1.2indirect
PyPImultidict6.7.1indirect
PyPImultiprocess0.70.16indirect
PyPImultiprocess0.70.19indirect
PyPImypy-extensions1.1.0indirect
PyPInbclient0.10.4indirect
PyPInbconvert7.17.0indirect
PyPInbformat5.10.4indirect
PyPInest-asyncio1.6.0indirect
PyPInest-asyncio21.7.2indirect
PyPInetworkx3.6.1indirect
PyPInodeenv1.10.0indirect
PyPInotebook7.5.5indirect
PyPInotebook-shim0.2.4indirect
PyPInumpy2.4.4indirect
PyPInvidia-cublas13.1.0.3indirect
PyPInvidia-cuda-cupti13.0.85indirect
PyPInvidia-cuda-nvrtc13.0.88indirect
PyPInvidia-cuda-runtime13.0.96indirect
PyPInvidia-cudnn-cu139.19.0.56indirect
PyPInvidia-cufft12.0.0.61indirect
PyPInvidia-cufile1.15.1.6indirect
PyPInvidia-curand10.4.0.35indirect
PyPInvidia-cusolver12.0.4.66indirect
PyPInvidia-cusparse12.6.3.3indirect
PyPInvidia-cusparselt-cu130.8.0indirect
PyPInvidia-nccl-cu132.28.9indirect
PyPInvidia-nvjitlink13.0.88indirect
PyPInvidia-nvshmem-cu133.4.5indirect
PyPInvidia-nvtx13.0.85indirect
PyPIoauthlib3.3.1indirect
PyPIopenapi-pydantic0.5.1indirect
PyPIopencensus0.11.4indirect
PyPIopencensus-context0.1.3indirect
PyPIopentelemetry-api1.39.1indirect
PyPIopentelemetry-api1.40.0indirect
PyPIopentelemetry-exporter-prometheus0.61b0indirect
PyPIopentelemetry-proto1.40.0indirect
PyPIopentelemetry-sdk1.40.0indirect
PyPIopentelemetry-semantic-conventions0.60b1indirect
PyPIopentelemetry-semantic-conventions0.61b0indirect
PyPIorderly-set5.5.0indirect
PyPIorjson3.11.7indirect
PyPIormsgpack1.12.2indirect
PyPIoutcome1.3.0.post0indirect
PyPIoverrides7.7.0indirect
PyPIpackaging26.0indirect
PyPIpandas-stubs3.0.0.260204indirect
PyPIpandocfilters1.5.1indirect
PyPIpanflute2.3.1indirect
PyPIparso0.8.6indirect
PyPIpathlib-abc0.5.2indirect
PyPIpathspec1.0.4indirect
PyPIpexpect4.9.0indirect
PyPIpillow12.1.1indirect
PyPIpip-licenses5.5.5indirect
PyPIplatformdirs4.9.4indirect
PyPIpluggy1.6.0indirect
PyPIplum-dispatch2.8.0indirect
PyPIpre-commit4.5.1indirect
PyPIprettytable3.17.0indirect
PyPIprometheus-client0.24.1indirect
PyPIprompt-toolkit3.0.52indirect
PyPIpropcache0.4.1indirect
PyPIproto-plus1.27.2indirect
PyPIprotobuf6.33.6indirect
PyPIpsutil7.2.2indirect
PyPIpsycopg-binary3.3.3indirect
PyPIptyprocess0.7.0indirect
PyPIpure-eval0.2.3indirect
PyPIpy-spy0.4.1indirect
PyPIpyasn10.6.3indirect
PyPIpyasn1-modules0.4.2indirect
PyPIpycodestyle2.14.0indirect
PyPIpycparser3.0indirect
PyPIpycryptodome3.23.0indirect
PyPIpydantic2.12.5indirect
PyPIpydantic-core2.41.5indirect
PyPIpyflakes3.4.0indirect
PyPIpygments2.20.0indirect
PyPIpyparsing3.3.2indirect
PyPIpyproject-hooks1.2.0indirect
PyPIpyright1.1.408indirect
PyPIpytestindirect
PyPIpytest8.3.3indirect
PyPIpytest9.0.2indirect
PyPIpytest-asyncio1.3.0indirect
PyPIpytest-mock3.15.1indirect
PyPIpytest-xdist3.8.0indirect
PyPIpython-dateutil2.9.0.post0indirect
PyPIpython-discovery1.2.1indirect
PyPIpython-dotenv1.2.2indirect
PyPIpython-json-logger4.1.0indirect
PyPIpytokens0.4.1indirect
PyPIpywin32311indirect
PyPIpywinpty3.0.3indirect
PyPIpyyaml6.0.3indirect
PyPIpyzmq27.1.0indirect
PyPIquartodoc0.11.1indirect
PyPIray2.54.1indirect
PyPIreferencing0.37.0indirect
PyPIrequests2.31.0indirect
PyPIrequests2.33.1indirect
PyPIrequests-oauthlib2.0.0indirect
PyPIrequests-toolbelt1.0.0indirect
PyPIrfc3339-validator0.1.4indirect
PyPIrfc3986-validator0.1.1indirect
PyPIrfc3987-syntax1.1.0indirect
PyPIrpds-py0.30.0indirect
PyPIruff0.15.8indirect
PyPIs3fs2025.9.0indirect
PyPIs3transfer0.14.0indirect
PyPIs3transfer0.16.0indirect
PyPIsafetensors0.7.0indirect
PyPIsemver3.0.4indirect
PyPIsend2trash2.1.0indirect
PyPIsetuptools81.0.0indirect
PyPIsetuptools82.0.1indirect
PyPIsetuptools-scm10.0.5indirect
PyPIshade-arena0.1.0indirect
PyPIshellingham1.5.4indirect
PyPIshortuuid1.0.13indirect
PyPIsimple-parsing0.1.8indirect
PyPIsix1.17.0indirect
PyPIsmart-open7.5.1indirect
PyPIsmmap5.0.3indirect
PyPIsortedcontainers2.4.0indirect
PyPIsoupsieve2.8.3indirect
PyPIsphobjinv2.4indirect
PyPIsqlparse0.5.5indirect
PyPIstack-data0.6.3indirect
PyPIstarlette1.0.0indirect
PyPIswebench4.1.0indirect
PyPIsympy1.13.1indirect
PyPIsympy1.14.0indirect
PyPIsynchronicity0.12.1indirect
PyPIsyrupy5.1.0indirect
PyPItabulate0.10.0indirect
PyPItenacity9.1.4indirect
PyPItensorboardx2.6.4indirect
PyPIterminado0.18.1indirect
PyPItextual8.2.1indirect
PyPItiktoken0.12.0indirect
PyPItinycss21.4.0indirect
PyPItokenizers0.22.2indirect
PyPItoml0.10.2indirect
PyPItorch2.11.0indirect
PyPItorch2.6.0+cpuindirect
PyPItornado6.5.5indirect
PyPItqdm4.67.3indirect
PyPItraitlets5.14.3indirect
PyPItransformers4.57.6indirect
PyPItransformers5.4.0indirect
PyPItrio0.33.0indirect
PyPItriton3.6.0indirect
PyPItrove-classifiers2026.1.14.14indirect
PyPItypeguard4.5.1indirect
PyPItyper0.24.1indirect
PyPItypes-aiofiles25.1.0.20251011indirect
PyPItypes-certifi2021.10.8.3indirect
PyPItypes-networkx3.6.1.20260321indirect
PyPItypes-pyyaml6.0.12.20250915indirect
PyPItypes-requests2.33.0.20260327indirect
PyPItypes-seaborn0.13.2.20251221indirect
PyPItypes-toml0.10.8.20240310indirect
PyPItyping-extensions4.15.0indirect
PyPItyping-inspect0.9.0indirect
PyPItyping-inspection0.4.2indirect
PyPItzdata2025.3indirect
PyPIuc-micro-py2.0.0indirect
PyPIunidiff0.7.5indirect
PyPIuniversal-pathlib0.3.10indirect
PyPIuri-template1.3.0indirect
PyPIurllib32.6.3indirect
PyPIuuid-utils0.14.1indirect
PyPIuvicorn0.42.0indirect
PyPIuvloop0.22.1indirect
PyPIvcs-versioning1.1.1indirect
PyPIvirtualenv21.2.0indirect
PyPIwatchdog6.0.0indirect
PyPIwatchfiles1.1.1indirect
PyPIwcwidth0.6.0indirect
PyPIwebcolors25.10.0indirect
PyPIwebencodings0.5.1indirect
PyPIwebsocket-client1.9.0indirect
PyPIwebsockets16.0indirect
PyPIwerkzeug3.1.7indirect
PyPIwidgetsnbextension4.0.15indirect
PyPIwrapt1.17.3indirect
PyPIwrapt2.1.2indirect
PyPIxxhash3.6.0indirect
PyPIyarl1.23.0indirect
PyPIzipfile-zstd0.0.4indirect
PyPIzipp3.23.0indirect
PyPIzstandard0.25.0indirect
Dependency advisories 37

This repository publishes no package the index resolves, so its own dependency graph was assessed — 386 packages, which also include development and test pins that never ship: 37 carry known advisories, of which 5 are direct. 4 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
gitpython3.1.46directcritical123.1.52
cryptography46.0.6indirectcritical348.0.1
django6.0.3indirectcritical256.0.7
jupyterlab4.5.6indirectcritical127.5.6
notebook7.5.5indirectcritical47.5.6
click8.2.1directhigh18.3.3
click8.3.1directhigh18.3.3
aiohttp3.13.4indirecthigh223.14.1
jupyter-server2.17.0indirecthigh142.20.0
langchain-core1.2.23indirecthigh41.3.3
langsmith0.7.23indirecthigh51.0.7
mistune3.2.0indirecthigh323.3.0
anthropic0.86.0directmoderate40.87.0
flask3.0.0directmoderate23.1.3
bleach6.3.0indirectmoderate36.4.0
idna3.11indirectmoderate23.15
langchain1.2.13indirectmoderate21.4.6
langgraph-checkpoint4.0.1indirectmoderate24.1.1
langgraph-sdk0.3.12indirectmoderate20.3.15
pytest8.3.3indirectmoderate29.0.3
pytest9.0.2indirectmoderate29.0.3
requests2.31.0indirectmoderate62.33.0
urllib32.6.3indirectmoderate42.7.0
msgpack1.1.2indirectunknown1
nbconvert7.17.0indirectunknown4
pillow12.1.1indirectunknown36
pyasn10.6.3indirectunknown5
ray2.54.1indirectunknown2
setuptools81.0.0indirectunknown2
setuptools82.0.1indirectunknown2
soupsieve2.8.3indirectunknown4
starlette1.0.0indirectunknown10
torch2.11.0indirectunknown1
torch2.6.0+cpuindirectunknown21
tornado6.5.5indirectunknown7
transformers4.57.6indirectunknown7
transformers5.4.0indirectunknown1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 28011,
      "has_wiki": false,
      "homepage": "https://control-arena.aisi.org.uk",
      "languages": {
        "CSS": 9555,
        "HTML": 6922,
        "Shell": 28977,
        "Python": 2433747,
        "Makefile": 7724,
        "Dockerfile": 15195,
        "JavaScript": 34096,
        "Go Template": 1857,
        "Jupyter Notebook": 58068
      },
      "pushed_at": "2026-07-23T21:01:42Z",
      "created_at": "2025-02-06T13:56:44Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T21:01:33Z",
      "description": "ControlArena is a collection of settings, model organisms and protocols - for running control experiments.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Department of Business, Energy and Industrial Strategy",
      "type": "Organization",
      "login": "UKGovernmentBEIS",
      "company": null,
      "location": "United Kingdom",
      "followers": 242,
      "avatar_url": "https://avatars.githubusercontent.com/u/19221939?v=4",
      "created_at": "2016-05-06T09:18:54Z",
      "is_verified": null,
      "public_repos": 114,
      "account_age_days": 3730
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v17.1.2",
          "kind": "patch",
          "published_at": "2026-07-23T21:01:42Z"
        },
        {
          "tag": "v17.1.1",
          "kind": "patch",
          "published_at": "2026-06-30T11:02:25Z"
        },
        {
          "tag": "v17.1.0",
          "kind": "minor",
          "published_at": "2026-06-29T14:08:23Z"
        },
        {
          "tag": "v17.0.0",
          "kind": "major",
          "published_at": "2026-06-09T16:13:41Z"
        },
        {
          "tag": "v16.0.0",
          "kind": "major",
          "published_at": "2026-05-20T16:01:22Z"
        },
        {
          "tag": "v15.1.1",
          "kind": "patch",
          "published_at": "2026-04-27T10:07:59Z"
        },
        {
          "tag": "v15.1.0",
          "kind": "minor",
          "published_at": "2026-04-09T16:35:37Z"
        },
        {
          "tag": "v15.0.0",
          "kind": "major",
          "published_at": "2026-04-08T14:31:07Z"
        },
        {
          "tag": "v14.4.1",
          "kind": "patch",
          "published_at": "2026-03-26T11:26:19Z"
        },
        {
          "tag": "v14.4.0",
          "kind": "minor",
          "published_at": "2026-03-25T17:15:29Z"
        },
        {
          "tag": "v14.3.1",
          "kind": "patch",
          "published_at": "2026-03-24T21:32:01Z"
        },
        {
          "tag": "v14.3.0",
          "kind": "minor",
          "published_at": "2026-03-23T14:58:21Z"
        },
        {
          "tag": "v14.2.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:41:38Z"
        },
        {
          "tag": "v14.1.0",
          "kind": "minor",
          "published_at": "2026-02-16T14:19:39Z"
        },
        {
          "tag": "v14.0.0",
          "kind": "major",
          "published_at": "2026-02-04T14:25:55Z"
        },
        {
          "tag": "v13.5.1",
          "kind": "patch",
          "published_at": "2026-01-14T09:50:51Z"
        },
        {
          "tag": "v13.5.0",
          "kind": "minor",
          "published_at": "2026-01-08T13:47:24Z"
        },
        {
          "tag": "v13.4.0",
          "kind": "minor",
          "published_at": "2026-01-07T11:27:07Z"
        },
        {
          "tag": "v13.3.0",
          "kind": "minor",
          "published_at": "2026-01-06T11:55:29Z"
        },
        {
          "tag": "v13.2.0",
          "kind": "minor",
          "published_at": "2026-01-05T13:44:47Z"
        },
        {
          "tag": "v13.1.0",
          "kind": "minor",
          "published_at": "2025-12-18T17:48:57Z"
        },
        {
          "tag": "v13.0.0",
          "kind": "major",
          "published_at": "2025-12-17T09:52:22Z"
        },
        {
          "tag": "v12.3.0",
          "kind": "minor",
          "published_at": "2025-12-10T18:52:35Z"
        },
        {
          "tag": "v12.2.0",
          "kind": "minor",
          "published_at": "2025-12-10T14:42:13Z"
        },
        {
          "tag": "v12.1.0",
          "kind": "minor",
          "published_at": "2025-12-10T10:57:11Z"
        },
        {
          "tag": "v12.0.1",
          "kind": "patch",
          "published_at": "2025-12-08T18:10:49Z"
        },
        {
          "tag": "v12.0.0",
          "kind": "major",
          "published_at": "2025-12-08T12:27:57Z"
        },
        {
          "tag": "v11.4.0",
          "kind": "minor",
          "published_at": "2025-12-01T18:01:15Z"
        },
        {
          "tag": "v11.3.1",
          "kind": "patch",
          "published_at": "2025-11-26T11:24:20Z"
        },
        {
          "tag": "v11.3.0",
          "kind": "minor",
          "published_at": "2025-11-25T10:28:44Z"
        },
        {
          "tag": "v11.2.1",
          "kind": "patch",
          "published_at": "2025-11-24T17:59:32Z"
        },
        {
          "tag": "v11.2.0",
          "kind": "minor",
          "published_at": "2025-11-21T13:52:22Z"
        },
        {
          "tag": "v11.1.1",
          "kind": "patch",
          "published_at": "2025-11-20T17:18:31Z"
        },
        {
          "tag": "v11.1.0",
          "kind": "minor",
          "published_at": "2025-11-18T15:42:06Z"
        },
        {
          "tag": "v11.0.0",
          "kind": "major",
          "published_at": "2025-11-17T14:17:40Z"
        },
        {
          "tag": "v10.3.2",
          "kind": "patch",
          "published_at": "2025-11-14T14:54:03Z"
        },
        {
          "tag": "v10.3.1",
          "kind": "patch",
          "published_at": "2025-11-13T16:02:23Z"
        },
        {
          "tag": "v10.3.0",
          "kind": "minor",
          "published_at": "2025-11-13T12:33:39Z"
        },
        {
          "tag": "v10.2.0",
          "kind": "minor",
          "published_at": "2025-11-12T17:24:36Z"
        },
        {
          "tag": "v10.1.4",
          "kind": "patch",
          "published_at": "2025-11-12T09:58:29Z"
        },
        {
          "tag": "v10.1.3",
          "kind": "patch",
          "published_at": "2025-11-07T10:05:40Z"
        },
        {
          "tag": "v10.1.2",
          "kind": "patch",
          "published_at": "2025-11-05T10:41:24Z"
        },
        {
          "tag": "v10.1.1",
          "kind": "patch",
          "published_at": "2025-10-31T19:34:37Z"
        },
        {
          "tag": "v10.1.0",
          "kind": "minor",
          "published_at": "2025-10-31T09:25:09Z"
        },
        {
          "tag": "v10.0.0",
          "kind": "major",
          "published_at": "2025-10-30T16:00:58Z"
        },
        {
          "tag": "v9.0.1",
          "kind": "patch",
          "published_at": "2025-10-27T14:14:51Z"
        },
        {
          "tag": "v9.0.0",
          "kind": "major",
          "published_at": "2025-10-27T13:52:23Z"
        },
        {
          "tag": "v8.2.0",
          "kind": "minor",
          "published_at": "2025-10-16T08:50:00Z"
        },
        {
          "tag": "v8.1.1",
          "kind": "patch",
          "published_at": "2025-10-15T15:21:17Z"
        },
        {
          "tag": "v8.1.0",
          "kind": "minor",
          "published_at": "2025-10-14T13:49:01Z"
        },
        {
          "tag": "v8.0.0",
          "kind": "major",
          "published_at": "2025-10-07T17:31:17Z"
        },
        {
          "tag": "v7.0.2",
          "kind": "patch",
          "published_at": "2025-09-24T13:33:08Z"
        },
        {
          "tag": "v7.0.1",
          "kind": "patch",
          "published_at": "2025-09-24T12:36:13Z"
        },
        {
          "tag": "v7.0.0",
          "kind": "major",
          "published_at": "2025-09-22T09:56:48Z"
        },
        {
          "tag": "v6.2.0",
          "kind": "minor",
          "published_at": "2025-09-16T16:57:38Z"
        },
        {
          "tag": "v6.1.0",
          "kind": "minor",
          "published_at": "2025-09-15T10:51:00Z"
        },
        {
          "tag": "v6.0.1",
          "kind": "patch",
          "published_at": "2025-09-12T10:25:14Z"
        },
        {
          "tag": "v6.0.0",
          "kind": "major",
          "published_at": "2025-09-11T15:12:33Z"
        },
        {
          "tag": "v5.2.0",
          "kind": "minor",
          "published_at": "2025-09-02T14:49:34Z"
        },
        {
          "tag": "v5.1.0",
          "kind": "minor",
          "published_at": "2025-09-02T13:22:19Z"
        },
        {
          "tag": "v5.0.0",
          "kind": "major",
          "published_at": "2025-09-02T10:27:41Z"
        },
        {
          "tag": "v4.0.2",
          "kind": "patch",
          "published_at": "2025-09-01T14:04:34Z"
        },
        {
          "tag": "v4.0.1",
          "kind": "patch",
          "published_at": "2025-08-29T14:48:19Z"
        },
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2025-08-28T16:14:03Z"
        },
        {
          "tag": "v3.4.1",
          "kind": "patch",
          "published_at": "2025-08-27T16:30:10Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2025-08-27T08:58:40Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2025-08-26T12:16:11Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2025-08-26T08:44:17Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2025-08-22T15:15:54Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2025-08-21T17:15:20Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2025-08-21T09:54:32Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2025-08-12T14:30:52Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2025-08-11T14:30:51Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2025-08-06T09:17:45Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2025-07-31T12:39:45Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2025-07-21T14:12:15Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2025-06-18T10:06:35Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-05-07T14:07:50Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2025-04-15T15:30:59Z"
        },
        {
          "tag": "v0.2.0-alpha",
          "kind": "prerelease",
          "published_at": "2025-04-11T13:43:35Z"
        },
        {
          "tag": "v0.1.2-alpha",
          "kind": "prerelease",
          "published_at": "2025-03-26T12:11:21Z"
        },
        {
          "tag": "v0.1.1-alpha",
          "kind": "prerelease",
          "published_at": "2025-03-25T09:49:10Z"
        },
        {
          "tag": "v0.1.0-alpha",
          "kind": "prerelease",
          "published_at": "2025-03-24T14:22:44Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "bf7328e522615107bd9b9bfaee8c1bcbec4b6664",
          "body": "## Problem\n\n`iac_fast` (exported unguarded from `settings.entrypoint`)\nunconditionally imports the `docker` SDK in `fast_exec.py`, but\n`docker>=7.1.0` is declared only in `[dependency-groups].dev`. So a\nplain `pip install control-arena`:\n\n- cannot `import control_arena.settings.iac_fast` at all;\n- a\n[…]\npped given the\nresolution-markers set) — semantic no-ops from relocking with current\nuv.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: promote docker to a runtime dependency (#834)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-07-23T21:01:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5c4b19f8d98302199295d5309f47a83528265a3",
          "body": "…d user session (#831)\n\n## Summary\n\nFollow-up to #830 / #826. A user reported that `sandbox_type=\"podman\"`\nfails on their HPC node because netavark launches `aardvark-dns` via\n`systemd-run --user`, which fails when there is no systemd user manager\n(common on HPC compute nodes — systemd is PID 1 but \n[…]\nrk_mode: none` alone should still avoid aardvark for\n`apps`/`bigcodebench`/`rogue_eval`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(podman): avoid aardvark-dns/systemd-run on hosts without a system…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-30T11:01:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e67496d27c3925334cbe773e7c5d34104fc16fb0",
          "body": "## Summary\n\nCloses #826.\n\nAdds Podman as an alternative container backend for compose-file-based\nsettings, useful on hosts that don't have Docker Engine (e.g. HPC\nclusters that only provide Podman). Uses the\n[`inspect-podman`](https://github.com/VectorInstitute/inspect-podman)\npackage, which registe\n[…]\nrming `AppsSetting(sandbox_type=\"podman\")` works end-to-end\non their cluster.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add podman sandbox support for compose-based settings (#830)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-29T14:04:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f9a71f2915a6819e2710caa13475fc4c5aa3fe49",
          "body": "## Summary\n\nUpgrade inspect-k8s-sandbox to pick up the latest security updates\nwithin that package.\n\n## Test Plan\n\nManual run of infra setting (the only one currently using\ninspect-k8s-sandbox) still works as expected.",
          "is_bot": false,
          "headline": "fix: upgrade inspect-k8s-sandbox (#829)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-29T12:34:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9337de19d9e3897486cdfffec97918748434491",
          "body": "…dk-lib (#828)\n\n## Summary\n\nFixes #827.\n\nA fresh `iac_fast` docker build fails at the `patch_jsii_lazy.py` step\nwhen the resolved jsii version is **1.137.0**. The patcher previously\nlocated the minified `fs`/`path`/`zlib` aliases by regex-matching the\nwebpack import chain (e.g. `const f=m(9896),...`\n[…]\nut of scope.\n- Manual eval with updated `iac_fast` setting works as expected.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(iac_fast): make patch_jsii_lazy self-contained and pin jsii/aws-c…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-29T10:25:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3cceb4aba8f0511e47c2cf31206118b8343804b9",
          "body": "…ore (#823)\n\n## Summary\n\nFixes `control_arena.analysis.samples_df` raising\n`pandera.errors.SchemaErrors` on bash_arena logs (the required\n`main_task_success` column was missing), and adds first-class support\nfor a continuous main-task score.\n\n- **`samples_df`**: `score_values` now also flattens an o\n[…]\n `get_rating` handles both scalar and dict `side_task_success`\n- [x] ruff check + format + pyright clean on the touched surface\n- [ ] CI\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fix!: load bash_arena logs in samples_df; add continuous main_task_sc…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-09T13:00:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d50ef5d6500c1948845e6ae6138f12829f0536ef",
          "body": "## Summary\n\nAdds GitHub source-code links across the documentation so users can\nnavigate from a docs page to the code that implements it (motivated by\npages like the [Rogue Eval\nsetting](https://control-arena.aisi.org.uk/settings/rogue_eval.html),\nwhich previously had no link to its code).\n\n- **New \n[…]\n.txt`)\n- [x] `reference/agent_scaffolds.html#react_scaffold` renders full\n`react_scaffold` docs\n- [ ] CI docs build renders successfully\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "docs: add source-code links across the docs (#822)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-06-08T17:34:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1165d5013c355357e5f7e251de1aafa01f73c9a",
          "body": "Changes:\n- `because malicous code is executed` -> `because malicious code is\nexecuted` in `docs/settings/index.qmd` (1 occurrence(s))\n\nVerification:\n- Applied exact text replacements against the current upstream base\nbranch.\n- Verified no duplicate open PR was found for the referenced issue\nnumber(s) before opening this PR.\n\nSigned-off-by: Yoshiki <yosinn1@gmail.com>",
          "is_bot": false,
          "headline": "docs: fix malicious spelling in settings docs (#818)",
          "author_name": "yosinn1-blip",
          "author_login": "yosinn1-blip",
          "committed_at": "2026-06-01T09:10:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3369a0915ac63353615c90318afce4eddb2c5efd",
          "body": "## Summary\n- port the BashArena public 1.1 changes that map to the vendored\nBashArena setting\n- update `firewall-daemon` for the 1.1 `disable_firewall` hardening and\nadd the corresponding daemon diff artifact\n- add the BashArena 1.1 README note, task workspace run-id isolation,\nand malware wording u\n[…]\nck origin/main`\n- `python3 -m py_compile\ncontrol_arena/settings/bash_arena/task/task_utils.py\ncontrol_arena/settings/bash_arena/tests/test_side_tasks.py`\n- `uv run ruff check . --output-format=github`",
          "is_bot": false,
          "headline": "feat!: Update BashArena setting to 1.1 (#816)",
          "author_name": "tumberger",
          "author_login": "tumberger",
          "committed_at": "2026-05-18T08:35:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9aace1629b6143683ee26180d402a6efdc9b4a9b",
          "body": "## Summary\n- Accept `None` or an empty string for `reminder_prompt` in `bash_arena`\n`attack_policy`; when falsy, no reminder user message is appended after\neach tool call.\n- The max-tokens reminder still fires when applicable.",
          "is_bot": false,
          "headline": "fix: Support disabling user message reminder in BashArena (#815)",
          "author_name": "Jan Michelfei",
          "author_login": "jan-aisi",
          "committed_at": "2026-05-12T14:02:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0c31d44f3cd22458d9b96bf74e45e9327a4cb7c",
          "body": "## Summary\n\n- `DEFAULT_UNTRUSTED_MODEL`: `anthropic/claude-sonnet-4-5-20250929` →\n`anthropic/claude-sonnet-4-6` (Sonnet 4.6 only ships an alias ID, no\ndated snapshot per [Anthropic's models\npage](https://platform.claude.com/docs/en/about-claude/models/overview))\n- `DEFAULT_TRUSTED_MODEL`: `openai/gp\n[…]\nde evals with the trusted model\noverridden into the untrusted seat\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: update default trusted/untrusted models to latest versions (#813)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-05-01T15:23:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e3778b114f87d0f2df2a7f59c7820d8b2f93d19f",
          "body": "## Summary\n\nCloses #809.\n\n- `cot_message_formatter` embedded the monitored model's\n`assistant_message.content` directly into the monitor prompt via\n`prompt.format()`, with no structural boundary or escaping. An\nadversarial model could inject fake section markers or directives that\nthe monitor then t\n[…]\n [x] `uv run ruff format . && uv run ruff check .` clean\n- [x] `uv run pyright` clean (0 errors, 0 warnings on the 3 changed\nfiles)\n- [ ] CI\n\nCo-authored-by: John Kearney <johndanielkearney@gmail.com>",
          "is_bot": false,
          "headline": "fix!: sanitize chain-of-thought content in CoT prompt formatter (#810)",
          "author_name": "John Kearney",
          "author_login": "JohnKearney15",
          "committed_at": "2026-04-30T13:59:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9eb36f656d56cfc61d1694c95662d67954ca4ace",
          "body": "…zy (#808)\n\n## Summary\n\n- Fixes iac_fast Docker build failure on environments with jsii >= 1.128\n(released 2026-04-09), where `patch_jsii_lazy.py` aborts build step 21\nwith `RuntimeError: Could not find loadAssemblyFromPath to patch`\n- Adds a minified-form code path and keeps the legacy pattern for \n[…]\nacy branch still\nmatches and the patched file still syntax-checks.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(iac_fast): handle jsii >= 1.128 minified runtime in patch_jsii_la…",
          "author_name": "Diogo Cruz",
          "author_login": "diogo-cruz",
          "committed_at": "2026-04-27T09:54:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "589b91aa6b105f36e60609a089bd8fbaa8841bfb",
          "body": "`control_arena.tools.restricted_text_editor` is documented as a drop-in\nwrapper around `inspect_ai.tool.text_editor`, but its `execute`\nsignature omits the `insert_text` parameter. Claude models (4.5 / 4.6 /\n4.7) tend to call it with `insert_text=...`, which causes an error.\n\n## Fix\n\nAdd `insert_tex\n[…]\nix && uv run ruff format && uv run pyright\ncontrol_arena/tools/_restricted_text_editor.py\ncontrol_arena/tools/tests/test_tools.py`\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: accept insert_text kwarg in restricted_text_editor (#811)",
          "author_name": "Jordan Taylor",
          "author_login": "jordan-taylor-aisi",
          "committed_at": "2026-04-27T09:03:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "158f3280f7b8e585cd0a85d0ac54b590dc7d2ce7",
          "body": "## Summary\n- Add `scripts/check_licenses.py` — validates that all installed\npackages appear in `THIRD_PARTY_LICENSES.md` and that no stale entries\nremain for removed dependencies\n- Integrate the check into the `checks` job in\n`.github/workflows/checks.yml`\n- Regenerate `THIRD_PARTY_LICENSES.md` to r\n[…]\n the check to fail\n- [ ] CI runs the check successfully\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add CI check for third-party license file staleness (#807)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-13T14:00:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8cf4ab7d2540a9b6743b5e2cdda5569ca16e6a15",
          "body": "## Summary\n- Add branch naming convention (`<username>/<type>/<description>`) and\nconventional commit message guidelines to CONTRIBUTING.md, CLAUDE.md,\nand AGENTS.md\n- CONTRIBUTING.md gets the full human-readable section with examples\n- CLAUDE.md and AGENTS.md get concise, actionable guidance for AI\n[…]\nexisting practice\n(check `git log` and `git branch -r`)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add branch naming and conventional commit conventions (#806)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-13T13:18:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a3cee91d45a3a871148e74a442c6d105455f245",
          "body": "## Summary\n- Regenerate `THIRD_PARTY_LICENSES.md` using\n`scripts/generate_licenses.py` to reflect current dependency versions\n\n## Test plan\n- [ ] Verify the generated file looks correct and lists all current\ndependencies\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: update third-party licenses (#805)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-10T08:30:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a2746244a687531647cbca762adeb4076826909",
          "body": "## Summary\n\nReplaces all direct `asyncio` primitive usage across ControlArena with\n`anyio` equivalents, enabling compatibility with both **asyncio**\n(default) and **trio** async backends. This matches Inspect AI's backend\nsupport via the `INSPECT_ASYNC_BACKEND` environment variable.\n\n### What change\n[…]\nd for `anyio.open_process` mocking\n- [ ] CI checks pass\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: Add async backend support (trio/anyio) (#804)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-09T16:35:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7a91f59296731b8921dae3d5afcfed1872e97ce",
          "body": "## Summary\n\nAdds `control-arena eval suite`, a CLI command for running a cartesian\nproduct of settings, micro-protocols, modes, and models using inspect's\n`eval_set` (which provides resume and retry support).\n\nThis is a fresh implementation based on the original work in #698 by\n@sean-peters-au, upda\n[…]\nith [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Sean Peters <sean-peters-au@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: Add eval suite CLI backed by eval_set (#803)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T14:28:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45e37f729718f5b54ff32686664900cb79b64251",
          "body": "## Summary\n\nCloses #610.\n\n`get_submit_func` created `inspect.Parameter` objects without defaults,\nso all parameters appeared required in the function signature regardless\nof their Pydantic field defaults. `get_submit_tool_params` also asserted\nthat the schema must have required fields, which crashed\n[…]\nut type, and the exact scenario from the\nissue\n- [ ] CI\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: support optional parameters with defaults in submit tools (#802)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T13:17:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aa5decf142c8b38c89dec9446248758cc146682d",
          "body": "…es (#793)\n\n## Summary\n\n- Runs `uv lock --upgrade` on the main lockfile (minor transitive\nupgrades)\n- Upgrades infra docker dependencies to fix critical/high CVEs\n\n## Infra docker upgrades\n\n| Package | Before | After | CVEs fixed |\n|---------|--------|-------|-----------|\n| django | 5.1.7 | 6.0.3 | \n[…]\ns, lint)\n- [ ] Infra docker builds successfully with upgraded deps\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Upgrade vulnerable dependencies in main and infra docker lockfil…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T12:25:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c07f38a2c18e18dde3e0d3fedafd78f7a42a306",
          "body": "## Summary\n\nCloses #754.\n\nWhen the react loop's step limit is hit, auto-generated user messages\n(e.g. continue prompts like \"Please proceed to the next step...\") may be\nappended after the last assistant response. Monitors and prompt\nformatters previously assumed `messages[-1]` was always a\n`ChatMess\n[…]\nnd formatter\nrobustness with trailing messages\n- [ ] CI\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: strip trailing non-assistant messages after step limit (#801)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T12:25:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1a5306e37217f601638f30581ff00b34b5450427",
          "body": "…r bypass (#800)\n\n## Summary\n\nCloses #794.\n\n- `extract_xml_tag` used `re.search` (first match), so an attacker could\nembed `<score>0</score>` in untrusted content (filenames, URLs, command\ntext) that the monitor model quotes verbatim in its reasoning, causing\nthe parser to return the injected value \n[…]\nss (including 7 new ones)\n- [x] All 78 monitor tests pass\n- [ ] CI\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix!: extract_xml_tag returns last match by default to prevent monito…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T09:32:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ede56c51566023f21b584968d5accffd86f9f95b",
          "body": "## Summary\n\nCloses #796.\n\n- `check_cwd_allowed` used a purely lexical `is_relative_to` check, so\npaths containing `..` segments (e.g.\n`/workspace/project/../../etc/passwd`) passed the check despite\nresolving outside the allowed directory. Symlinks inside the allowed\ndirectory were also followed with\n[…]\next_editor`) still\npass (requires Docker sandbox, not run locally)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: resolve paths before access check to prevent path traversal (#799)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T09:18:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cda6d453788949a4aa9b033a926652026a64e0ec",
          "body": "## Summary\n\n- Serialize tool call arguments with `json.dumps()` instead of Python\n`str()` repr in `last_tool_calls` and `prefix` prompt formatters\n- Apply `html.escape(quote=False)` in the prefix formatter to prevent\nadversarial arguments from spoofing XML-like structural tags\n- Follows the conventi\n[…]\nGenerated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: John Kearney <johndanielkearney@gmail.com>\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix!: sanitize tool call arguments in monitor prompt formatters (#798)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-04-08T09:02:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ea585c6b1a0958a371a32b4e365bb66261bc3d8b",
          "body": "## Summary\n- Switch to `defusedxml.ElementTree` in `iac_fast/scorers.py` and\n`bash_arena/task/scorer.py` to prevent XXE attacks (consistent with\nexisting usage in `_blabbing_scorer.py`)\n- Bump `flask>=3.1.3` — fixes\n[CVE-2026-27205](https://nvd.nist.gov/vuln/detail/CVE-2026-27205)\n(session cache poi\n[…]\n\n- [ ] CI passes (lint, format, type check, unit tests)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Address security vulnerabilities in deps and XML parsing (#790)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-31T10:24:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5432beb777940d5f1114d6eee258b97c0a8d1de2",
          "body": "… makefun (#789)\n\n## Summary\n- Removes 11 unused direct dependencies: `aioboto3`, `aiobotocore`,\n`colorama`, `devtools`, `inquirer`, `makefun`, `pathspec`, `pymongo`,\n`scikit-learn`, `scipy`, `simple-term-menu` (also removes `pymongo` from\ndev deps)\n- Reimplements `sklearn.metrics.roc_auc_score` wit\n[…]\nere removed\n- [ ] CI passes (lint, format, type check, unit tests)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: Remove 11 unused dependencies, reimplement scikit-learn and…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-26T11:25:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f41bb5a6e27222a5603e7d5cb639d9b85b3e2e21",
          "body": "## Summary\n- Removes `litellm` as a direct dependency, motivated by the [recent\nsupply chain\nattack](https://blog.gitguardian.com/litellm-supply-chain-attack/)\n(TeamPCP, March 2026) that compromised versions 1.82.7 and 1.82.8 on\nPyPI\n- Replaces `litellm.cost_calculator.cost_per_token` with a new\n`_g\n[…]\nsults\n- [ ] Confirm `litellm` is no longer in `uv.lock`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: Remove litellm dependency, use llm-prices API instead (#788)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-26T11:07:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3756a20eb474bb3c1eebb0c9cffbccc28d6a3e53",
          "body": "## Summary\n- Adds a `cache` parameter to `basic_monitor_builder` that controls\nwhether the monitor model's `generate` calls are cached\n- Defaults to `True` to preserve existing behaviour\n- Allows users to disable caching when needed (e.g. for debugging or\nwhen non-deterministic responses are desired\n[…]\n/9 passing)\n- [x] Pyright type check passes\n- [x] Ruff lint passes\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: Make cache parameter configurable in basic_monitor_builder (#787)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-25T17:11:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d42c9c238f22ad58122ae1c84798250c9fb502d1",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:UKGovernmentBEIS/control-arena",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-25T12:03:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec99fe6db426f5daa1f32f8ca8f04110b12bb960",
          "body": "…luded",
          "is_bot": false,
          "headline": "docs: Add generated settings tables with swebench_django_sidetask inc…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-25T12:03:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "523edb181e9691d3d1d65a67a55b36375a063b2c",
          "body": "LiteLLM has been compromised on two versions, explicitly avoid them, see\nthe incident issue from them here:\nhttps://github.com/BerriAI/litellm/issues/24518",
          "is_bot": false,
          "headline": "Explicitly avoid compromised LiteLLM versions (#786)",
          "author_name": "Ed Saunders",
          "author_login": "seddy-aisi",
          "committed_at": "2026-03-24T21:30:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67c54315c440bb50926be8a60c9a80e08f6416c2",
          "body": "## Summary\n\nAdds docs for SWEBench setting\n\n## Test Plan\n\nDocs render",
          "is_bot": false,
          "headline": "docs: Update SWEBench setting docs (#785)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-23T14:56:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e60b6b7f72d4ae3aa81991fdfba272e60f89cee4",
          "body": "## Summary\n\nThis PR supersedes #566 with a fundamentally different approach to\nSWE-bench side tasks.\n\n**Why:** The backdoor harness in #566 (SubmitAttackArgs with\nmodule/qualified_name/secret_input) leads to attack mode collapse.\nModels either plant if-statement backdoors or ignore the side task\nent\n[…]\nngoSidetaskSetting()`\nwithout `side_tasks_dataset_path`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: SWE-bench Django side tasks setting (#782)",
          "author_name": "Joachim Schaeffer",
          "author_login": "JoachimSchaeffer",
          "committed_at": "2026-03-23T13:44:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fec64cf2b38e5c0b9362f5542cfc59c88e6604ea",
          "body": "## Summary\n\nInspect updated the samples_df signature to allow passing EvalLog\nobjects directly. This updates the same in ControlArena so we support\nthis directly\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "chore: Update samples_df signature (#784)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-23T10:46:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "980fa2b6f3d4149f6b4f2102a8cb94a60371388e",
          "body": "## Summary\n\n- Adds a registry-based `@agent_scaffold` decorator and `AgentScaffold`\nbase class for creating custom agent scaffolds that can replace the\nhard-coded `react()` loop in `control_solver`\n- Adds `AgentToModel` adapter that wraps an Inspect AI `Agent` as a\n`Model`, enabling micro-protocols \n[…]\ned for `AgentScaffold`\n- [x] Ruff format and lint clean\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: customisable agent scaffolds (#778)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-03-12T10:40:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd57383b7022ffb56b54784993922775c22ba196",
          "body": "## Summary\n\nUpdating BashArena readme in order to put an important piece of\nenvironment setup in a more prominent place, as well as pointing to a\npublic repo with additional tools.\n\n## Test Plan\n\nNo changes to code were made.",
          "is_bot": false,
          "headline": "Small updates to the BashArena readme (#777)",
          "author_name": "Adam Kaufman",
          "author_login": "Eccentr1city",
          "committed_at": "2026-02-27T00:45:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaa9377eb17661d7cdbda5f27d26c9bea5638309",
          "body": "## Summary\n\nFixes a rendering error in the evaluation docs.\n\n## Test Plan\n\nQuarto preview works as expected. Added CI step to check docs build\n(without execution for now) to catch some issues with docs before merge",
          "is_bot": false,
          "headline": "fix: Quarto docs render error (#773)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-02-24T18:30:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24aedcaa09bcfc00cdc02ee581f3e64d649298eb",
          "body": null,
          "is_bot": false,
          "headline": "docs: Update IaCFast docs",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-02-16T15:17:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61919bb230c81791411d8a10258aeb3e3ef052de",
          "body": null,
          "is_bot": false,
          "headline": "docs: Add IaCFast page to docs and update README",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-02-16T14:25:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f6911be4eae4bd277f2e56e52ab4d10ec828b8d",
          "body": "## Summary\n\nAdds the IaCFast setting, which offers significant tool call speed-ups\ncompared to the original IaC setting with a few caveats (see the setting\ndocs).\n\n## Test Plan\n\nManual run of trajectory in setting works as expected. All unit tests\npass",
          "is_bot": false,
          "headline": "feat: IaCFast Setting (#776)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-02-16T13:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d1ce80dfb7ae51e5ccc80ac2f67def34c36fac2",
          "body": "## Summary\n\nPreviously sample ids for many setting were constructed following the\npattern `MT:{main_task_name}_ST:{side_task_name}`, but this was\nincompatible with some internal parsing done by inspect causing issues\nin some cases. Separately, inspect view also had trouble with the\nBigCodeBench samp\n[…]\ng to distinguish epochs of the same sample\nid. This PR removes special characters from sample ids to avoid these\nissues.\n\n## Test Plan\n\nUnit tests still pass. Manual runs of settings look as expected.",
          "is_bot": false,
          "headline": "feat!: Update sample ids to avoid using special characters (#775)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-02-04T14:25:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc837a91698465d5ba6c6942e39047615ca7dd0f",
          "body": "psycopg[binary]==3.2.6 is incompatible with Python 3.14. Relax the\nconstraint to >= so we can use a newer version.",
          "is_bot": false,
          "headline": "fix: Relax psycopg version requirement (#774)",
          "author_name": "Kerrick Staley",
          "author_login": "kerrickstaley",
          "committed_at": "2026-02-02T09:34:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0164dbca362af126029fffb00892197dd28ad524",
          "body": "## Summary\n\nMinor grammar issue in default prompt",
          "is_bot": false,
          "headline": "fix!: Grammar in default prompts text (#771)",
          "author_name": "Asa Cooper Stickland",
          "author_login": "asacsz",
          "committed_at": "2026-01-23T14:07:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12607828f3ef6978caff1880a7bfde26f5ffaabb",
          "body": "## Summary\n\nAdds llms.txt file and related html.md docs files similar to inspect to\nmake it easier to work with ControlArena using LLMs.\n\n## Test Plan\n\nQuarto preview works as expected",
          "is_bot": false,
          "headline": "docs: Add llms.txt file plus html.md files for docs (#770)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-20T13:49:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15a74ce90c4adeaecf5a03348f66de295f20089c",
          "body": "…port path typo in quickstart (#768)\n\n## Summary\n\nChanging the names of some strings that slipped through when updating\nnaming from \"bash bench 2\" to \"bash arena\" the last time around.\nEspecially important is an updated import path in the quickstart guide,\nwhich currently errors on main as the file it points to has an updated\nname.\n\n## Test Plan\n\nNothing functional has changed, just the names of some variables",
          "is_bot": false,
          "headline": "chore: Update old 'bb2' strings to bash arena, including important im…",
          "author_name": "Adam Kaufman",
          "author_login": "Eccentr1city",
          "committed_at": "2026-01-14T09:50:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4d3383a184abc4297911707ca5885fa48abca56",
          "body": "## Summary\n\nAllows specification of Inspect Approvers at the setting or task (via\n`get_control_task`) level to allow custom tool call approval setups.\n\n## Test Plan\n\nCreated new unit tests which pass. Existing unit tests pass",
          "is_bot": false,
          "headline": "feat: Inspect Approval integration (#764)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-08T13:46:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24e2196893de633e229e90f7e0907aab248965ed",
          "body": "## Summary\n\ncontrol_agents previously had the same signature as inspect agents but\ndidn't support some of the inspect agent features such as `handoff` and\n`as_tool`. This PR adds registration with the inspect registry to\ncontrol_agent creation so that these features work\n\n## Test Plan\n\nCreated new unit tests which pass. Old unit tests still pass",
          "is_bot": false,
          "headline": "feat: Register control_agents as inspect agents (#762)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-07T11:26:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8764f475ee04c89475e4467119a776d47b421d84",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:UKGovernmentBEIS/control-arena",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-06T12:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17a9cc8406b6103cb55795e302235139971557aa",
          "body": null,
          "is_bot": false,
          "headline": "docs: Add BigCodeBench setting to table in readme",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-06T12:00:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d62c9ea203466e41666e2061d6c2de5055b79374",
          "body": "## Summary\n\nAdds the BigCodeBench setting as a successor to APPS, with the same side\ntask and side task scoring logic.\n\n## Test Plan\n\nCreated new unit tests which pass. All other unit tests still pass.\nManually ran some trajectories which look as expected",
          "is_bot": false,
          "headline": "feat: BigCodeBench Setting (#761)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-06T11:54:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bfd842c0a11d972c0b4b0ddf7e0e806d8a443b1",
          "body": "…760)\n\nUpdates inspect-ai from 0.3.153 to 0.3.159 and fixes breaking change\nwhere tools_info was renamed to get_tools_info.",
          "is_bot": false,
          "headline": "chore: Bump inspect-ai to 0.3.159 and update get_tools_info import (#…",
          "author_name": "Jan Michelfei",
          "author_login": "jan-aisi",
          "committed_at": "2026-01-06T11:40:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cccb094f1bc322846289bf1bfca557b11c513953",
          "body": "## Summary\n\nThe datasets dependency was capped below v4.0.0 due to a previous issue\nwith the apps dataset. This now seems to work without problems for\nv4.4.2 so this is set as the new minimum version.\n\n## Test Plan\n\nManually check that an eval works with apps when using datasets v4.4.2",
          "is_bot": false,
          "headline": "chore: Update datasets dependency version (#759)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-05T13:44:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9cd1672f3936cb6a7e589af0738f6f9fdd84cb2",
          "body": "## Summary\n\nTransformers and Torch are only required for the rogue-eval setting.\nThis PR makes them optional and updates the docs accordingly\n\n## Test Plan\n\nCheck manually that `pip install control-arena[rogue-eval]` works as\nexpected for rogue-eval and otherwise normal install works as expected\nwhen not using rogue-eval",
          "is_bot": false,
          "headline": "feat: Make transformers and torch optional dependencies (#758)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2026-01-05T12:04:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af8a492449b67d8800c694b504462a29bc0265a2",
          "body": "## Summary\n\nThis PR adds the `tools` param to the `Setting` object, allowing you to\noverride the default setting tools. The submit tool will always still be\nadded automatically.\n\n## Test Plan\n\nManual run works as expected",
          "is_bot": false,
          "headline": "feat: Custom setting tools (#756)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-18T17:24:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caae0e5ea8aca31acf2c8c89bc0d28c4c9cb6756",
          "body": null,
          "is_bot": false,
          "headline": "docs: Add BashArena to README",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-18T16:19:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7318a919db039ce178cd3cc28fccfbb3976aa506",
          "body": null,
          "is_bot": false,
          "headline": "docs: Update readme and docs for BashArena",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-18T15:57:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "943a1276177ef8f9399335fba1c370a25a5a2f30",
          "body": "## Summary\n\n- Update firewall daemon to use inotify to make it robust to extremely\nrare timing edge case\n- Fix eval mode getting overridden by removing it from DatasetSpec\n- Various small updates\n- Rename to BashArena to match upcoming paper\n\n## Test Plan\n\n*Describe how you tested your PR to ensure your contribution is high\nquality and doesn't introduce regressions. This should be written in a\nway where the reviewer could execute the test steps if they'd like to.*",
          "is_bot": false,
          "headline": "feat!: BB2 -> BashArena (#704)",
          "author_name": "Adam Kaufman",
          "author_login": "Eccentr1city",
          "committed_at": "2025-12-17T09:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b936720c94e8af080924bb4a7080c8f2f541502",
          "body": "## Summary\n\nAdds the `dataset` parameter to `get_control_task` (and `datasets` to\n`get_control_task_product`), allowing users to override the dataset\nprovided by the setting. This can help in cases where e.g. we need to\ncreate different tasks for different subsets of the same dataset for the\nsame setting. In this case we can split up the dataset once and use\nthat, rather than having to re-filter the dataset multiple times.\n\n## Test Plan\n\nCreated new unit tests. Unit tests pass",
          "is_bot": false,
          "headline": "feat: Add dataset parameter to get_control_task (#753)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-10T18:51:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b53fbc8ae89c09d02f408a0f3514a6a9bdab998",
          "body": "## Summary\n\nApps samples previously didn't have a value for `main_task_name`. This\nPR sets the main task name to the sample id, allowing easy filtering by\nsample id using the main task filter.\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat: Add main_task_name value for Apps (#751)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-10T14:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a60aa55f7222361368a45c02437a510f2ec49289",
          "body": "## Summary\n\nAdds standardised main and side task filtering for Settings, so that\n`Setting` subclasses can be instantiated with filtering on main and side\ntasks pre-applied via the `filter_main_task_names` and\n`filter_side_task_names` parameters\n\n## Test Plan\n\nAdded new unit tests. All unit tests pass",
          "is_bot": false,
          "headline": "feat: Add standardised task filtering for Settings (#750)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-10T10:56:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2405cd6ecadc9cef3efdabb36151c6722c898c32",
          "body": null,
          "is_bot": false,
          "headline": "docs: Fix research page links and name",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-09T12:57:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0971076d61d2b4b8b5a48b8233ff05f6b4d2289a",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:UKGovernmentBEIS/control-arena",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-09T11:56:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a974b9ecb14b44e45e7a7c4b9765a698390e374c",
          "body": null,
          "is_bot": false,
          "headline": "docs: Fix old imports in docs",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-09T11:56:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1a18b9e829ae2ea6972e44ba11fe3fcb5ba6927",
          "body": "## Summary\n\n`samples_df` previously could only deal with a single scorer with dict\nvalue, and only \"main_task_success\" and \"side_task_success\" were valid\nkeys in this dict. This PR removes this constraint and properly handles\ncustom scorers with different keys, and multiple scorers with main and\nside task success keys.\n\n## Test Plan\n\nUnit tests still pass. Manual test of a scenario where this didn't load\na .eval file before but does now works",
          "is_bot": false,
          "headline": "fix: Make samples_df more flexible for custom scorers (#749)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T18:10:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "994c97a1f73486ee0ebd74782f67925a9fac5493",
          "body": "## Summary\n\nUpdates the migration script for migration to v12\n\n## Test Plan\n\nCreated a test file and verified that the migration script migrated it\ncorrectly",
          "is_bot": false,
          "headline": "feat: v12 migration script (#748)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T12:23:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64020da705ea3c5806c66f2bbf66f42cf0fe7a4c",
          "body": "## Summary\n\nThere have been a few useful new features and bug fixes released\nrecently for Inspect. This PR updates the minimum required version to\nensure these are in place while using ControlArena. There were also some\ndependency issues when updating which this PR also resolves\n\n## Test Plan\n\nUnit tests pass. Manual test that dependency resolution with pip works\nas expected",
          "is_bot": false,
          "headline": "fix!: Bump inspect version and resolve dependency issues (#747)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T12:01:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "666dae64ac6190727a55f559a0dac6d325ed1228",
          "body": "## Summary\n\nTo be merged after #741 \n\n### Motivation\n\nPreviously, ControlArena agents required a triple-nested function\nstructure:\n1. **Deployment-level**: Captured configuration parameters\n2. **Trajectory-level**: Received `ControlTaskMetadata` as a parameter\n3. **Step-level**: The actual agent log\n[…]\nnning (except from some\nthat seem to be broken from before this PR)\n- Manual inspection of .eval log from an eval looks as expected\n- CLI works as expected, with manual specification of micro protocol",
          "is_bot": false,
          "headline": "feat!: control_agent refactor (#745)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T11:12:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e7db51c15cbae12a16665a65e425c6332dbcf3c",
          "body": "## Summary\n\nPreviously different settings had custom subclasses of\nControlTaskMetadata but this made it harder to understand what exactly\nwould be present for all settings vs only for specific settings. This PR\nstandardises all settings to use `ControlTaskMetadata` directly, and the\n`metadata` field of that for custom metadata.\n\n## Test Plan\n\nUnit tests still pass. Manual runs of affected settings work as expected",
          "is_bot": false,
          "headline": "refactor!: Standardise use of ControlTaskMetadata (#741)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T10:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859edd6410fe607e75a84f2f9aeaecc1a26b1e07",
          "body": "## Summary\n\n`ephemeral_reminder` was `True` by default in the built-in\n`attack_policy` implementation but with more recent models this has been\nobserved to usually cause more problems than it solves as they are\nalready able to follow the instructions from the initial user & system\nmessages. This PR makes it False by default\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat!: Make ephemeral reminder false by default in attack_policy (#744)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-08T10:48:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42e68873920edd06dbe98a6e9972f7e5877d36d8",
          "body": "Errors with provided command.",
          "is_bot": false,
          "headline": "docs: Update command from 'run' to 'eval' in README (#740)",
          "author_name": "Uzay-G",
          "author_login": "Uzay-G",
          "committed_at": "2025-12-02T09:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7efb59e19e15c87e2fffc29fd214cb5533a948c",
          "body": "## Summary\n\nThe monitor output range was set to 0-1 in a recent update, however some\nusers prefer a different output range. This PR allows the output range\nto be specified as part of the `MonitorScoreRange` object.\n\n## Test Plan\n\nCreated new unit tests for this functionality. Existing unit tests pass",
          "is_bot": false,
          "headline": "feat: Configurable monitor output score range (#739)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-12-01T18:00:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07962c33b9ab173ff8f081a2c945d4ab7395b711",
          "body": null,
          "is_bot": false,
          "headline": "docs: vLLM side task filtering docs",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-26T18:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d53c61e1b1a6f08e7cbf9bbc86c842062054f23",
          "body": "## Summary\n\nThe prompt for the end of trajectory monitor in the CLI was not\ncompatible with the configured full-trajectory prompt formatter. This\nupdates the monitor to use the correct prompts\n\n## Test Plan\n\nUnit tests still pass, manual test worked correctly",
          "is_bot": false,
          "headline": "fix: Incorrect prompt for end of trajectory monitor in CLI (#737)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-26T11:23:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30d8a263e06d8b2d83e8cf73c1633c6fa25a218c",
          "body": "## Summary\n\nIaC samples didn't have ids, making it hard to e.g. re-run a specific\nsample by id. This adds them following the same\n`\"MT:{main_task_name}_ST:{side_task_name}\"` pattern used in some other\nsettings.\n\n## Test Plan\n\nUnit tests still pass. Manual run of IaC works as expected",
          "is_bot": false,
          "headline": "fix: Add IDs for IaC samples (#736)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-26T11:10:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abc5fd09b48dfed37f82c1c2ba5a769adfba1cc1",
          "body": "This allow, but does not require, using {main_task_description} in the\nattack prompt.",
          "is_bot": false,
          "headline": "feat: Add main task description to the attack prompt formatter (#735)",
          "author_name": "Alan Cooney",
          "author_login": "alan-cooney-dsit",
          "committed_at": "2025-11-25T10:28:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba81865c4120b87c987de073db8e601eb65de770",
          "body": "## Summary\n\nAdd function to compute monitor performance metrics such as TPR or AUC\nbased on scores produced by the monitor (scorer) on attack and honest\nsamples.\n\nHigh-level methods:\n- `compute_monitor_classification_metrics()`  computes TPR, FPR,\nROC AUC, and sample count metrics for a single set o\n[…]\ned_confidence_interval()` compute confidence interval\nfor a given estimator function on given honest and attack scores using\nthe bootstrap method to resample multiple times\n\n## Test Plan\n\n* Unit tests",
          "is_bot": false,
          "headline": "feat: Monitor analysis functions (#732)",
          "author_name": "Jan Michelfei",
          "author_login": "jan-aisi",
          "committed_at": "2025-11-24T20:15:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b53dc08d9c1f8973fac44df3974f7686f216535b",
          "body": "## Summary\n\nThe IaC setting copied tests into the sandbox for scoring, but these\nwere left in the sandbox after scoring. This meant that if allowing the\nagent to retry after scoring it could just find the tests and work out\nhow to succeed based on those which is not what we want. This PR updates\nthe scorer to delete the tests from the sandbox again immediately after\nscoring\n\n## Test Plan\n\nManual run works as expected, unit tests still pass",
          "is_bot": false,
          "headline": "fix: Delete tests again after scoring for IaC (#734)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-24T17:58:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc6bbfb75afe080db34a2931b7fe42cdeebbe5f",
          "body": "to -> do\n\nThis typo may have been making every evaluation using the default prompt\nslightly worse.",
          "is_bot": false,
          "headline": "fix: Typo in default monitor prompt (#730)",
          "author_name": "Matthew Khoriaty",
          "author_login": "AMindToThink",
          "committed_at": "2025-11-24T10:14:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d09b43df14462a5a01c80ee67e9c565a82faf2f",
          "body": "…729)\n\n## Summary\n\nAdd `ephemeral_reminder_prompt` parameter to `attack_policy`, allowing\nconfiguration of the prompt used for the ephemeral reminder. Move\ndefault prompt to\n`control_arena/policy/prompts/attack_policy_ephemeral_reminder.txt` to\nclean up the attack policy implementation\n\n## Test Plan\n\nUnit tests still pass. Manual run with ephemeral reminder active works\nas expected",
          "is_bot": false,
          "headline": "feat: Make ephemeral reminder prompt configurable in attack policy (#…",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-21T13:51:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf66314742b60d67c045c69523840a49837a54c7",
          "body": "## Summary\n\nBecause ShadeARENA was imported above vLLM in\n`control_arena/settings/entrypoint.py` but ShadeARENA is an optional\ndependency, if you didn't have shade arena installed an error would be\nraised and the vLLM import would not execute either. This moves the vLLM\nimport above and puts ShadeArena in a try/except to avoid this issue\nfrom reappearing\n\n## Test Plan\n\nvLLM via CLI works, unit tests still pass",
          "is_bot": false,
          "headline": "fix: vLLM / ShadeARENA entrypoint import order (#728)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-20T17:18:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c68998719d001a2c54a027d56b3a9a81bbcc9aad",
          "body": "## Summary\n\nAdds the `run_monitor_for_messages` function which allows a monitor to\nbe run for messages within a list of messages.\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat: Add run_monitor_for_messages function (#727)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-18T15:41:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c6c441bb18ab8b38fde0bd8ef80c7e07313e54f",
          "body": null,
          "is_bot": false,
          "headline": "docs: Update sidebar for MonitorScoreRange",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-18T10:04:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e71e7af2b1281a55f712980b550cd870359d7c4e",
          "body": null,
          "is_bot": false,
          "headline": "docs: Add note to tutorial about apps-specific prompts",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-18T09:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e72b5a70c2bbd363b41268e8ae877de981b08cc7",
          "body": "## Summary\n\nUpdates the migration script for v11\n\n## Test Plan\n\nCreated a test script with patterns to be migrated and checked that\nthese were all migrated as expected",
          "is_bot": false,
          "headline": "feat: Update migration script for v11 (#725)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-17T14:15:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "319fa7a5e30538939d981adda2501fd7726a53c3",
          "body": "## Summary\n\nThe diff prompt formatter was exactly the same as the last tool call\nprompt formatter. This PR removes it to avoid confusion and unnecessary\ncode\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat!: Remove diff prompt formatter (#724)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-17T13:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78177be3a49a5e76da71d4ec469ef0553b69e1e8",
          "body": "## Summary\n\nRemoves code deprecated in v10 of ControlArena. This mainly affects the\n`full_trajectory_monitor`, which is now replaced by\n`end_of_trajectory_monitor` combined with a monitor and prompt\nformatter.\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat!: Remove deprecated code for v11 (#722)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-17T13:42:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28b7d7280e62bc14165877fb57c2675287d5778c",
          "body": "## Summary\n\nAdds three recent papers using ControlArena to the docs\n\n## Test Plan\n\nQuarto preview works, links to papers work",
          "is_bot": false,
          "headline": "docs: Add new research 17/11/2025 (#723)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-17T12:03:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf83fb60a6d9c0eb3d54772a66370cf04b40b967",
          "body": "## Summary\n\nPreviously monitor scores completely depended on your monitor prompt.\nThis normalises them to between 0 and 1 and also hopefully addresses\n#714\n\n## Test Plan\n\nUnit tests still pass. Examples tests still pass. Docs still compile",
          "is_bot": false,
          "headline": "feat!: Normalise monitor scores to 0.-1. (#717)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-17T11:30:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a423bedf81235e176e257ce3d24a300c0806391d",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:UKGovernmentBEIS/control-arena",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-14T16:04:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba1ce81ee13ed3b90ec8cc2eb186df6e9d3721ec",
          "body": null,
          "is_bot": false,
          "headline": "fix: Incorrect link to Control-Tax paper",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-14T16:04:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1551561fe21832493bb876922d805147cea040c2",
          "body": "## Summary\n\nAdds an `__init__.py` file for the SHADE arena setting.\n\n## Test Plan\n\nUnit tests still pass. Manual run of shade arena via CLI works as\nexpected",
          "is_bot": false,
          "headline": "fix: Add __init__.py for shade arena (#716)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-14T14:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "231b5d7ffa120edbba761e86503cb8de870ea28c",
          "body": "## Summary\n\nThe honest decorator would convert the agent state but wouldn't update\nthe state.output value, causing this to become stale. This would then\npotentially cause issues downstream as the `react` agent checks\n`state.output` to determine whether the output has any tool calls in\norder to e.g. \n[…]\ntimes throw an error due to consecutive\nChatMessageAssistant objects in state.messages which is not permitted by\nsome APIs\n\n## Test Plan\n\nCreated a new unit test which passes, existing unit tests pass",
          "is_bot": false,
          "headline": "fix: Honest decorator not updating state.output (#715)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-13T16:01:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5f6657828bf4a0ae60d71b4efbdc975bd244450",
          "body": "## Summary\n\nThe trusted_response metadata in defer_to_trusted was set as\nstate.output.message but this ended up referring not to the last trusted\nmessage but from previous messages if state.output was not updated as\nexpected, which can easily happen. This changes it to take the last\nmessage from the messages list instead which is more robust.\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "fix: Stale trusted_response metadata in defer_to_trusted (#713)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-13T14:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35a36914df0d214ada8cbff91c66956e5b2be5f8",
          "body": "## Summary\n\nAddresses #710 as suggested by using dataset_spec.eval_mode if provided\notherwise eval_mode passed to get_dataset.\n\n## Test Plan\n\nUnit tests still pass. CLI run of bash bench 2 task in both honest and\nattack mode works as expected",
          "is_bot": false,
          "headline": "fix: BashBench2 eval mode specification (#712)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-13T12:33:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ab846b67f1025e78cddb4858fd2090559807b5a",
          "body": "## Summary\n\nAddresses #708 by making some utility functions public again\n\n## Test Plan\n\nUnit tests still pass, utils can be exported, quarto preview works",
          "is_bot": false,
          "headline": "feat: Export private utils (#711)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-13T12:04:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "237ae01560349f4352741f5f1d411a1961f3dd26",
          "body": "## Summary\n\nSeparates message formatters from prompt formatters so these can be used\nindependently.\n\n## Test Plan\n\nUnit tests still pass",
          "is_bot": false,
          "headline": "feat: Separate message formatters (#709)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-12T17:24:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c64fdfd890f7de0c53155367a7f57dfe99394c07",
          "body": "## Summary\n\nThe agentdojo eval mode was reversed in the metadata. This fixes that\nand also updates the setting description to encourage the agent to\nsubmit its answer using the submit tool otherwise this was sometimes not\ndone leading to an infinite loop.\n\n## Test Plan\n\nUnit tests still pass. manual run looks correct",
          "is_bot": false,
          "headline": "fix: Agentdojo eval mode (#707)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-12T09:57:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb7940f6b4d06b9847d58ec0f612fc7271b139be",
          "body": "## Summary\n\nAdded instructions for adjusting inotify resource limits for kind\ncluster in Infra.\n\n## Test Plan\n\nOnly touches the README",
          "is_bot": false,
          "headline": "docs: Update README with inotify resource limits instructions (#706)",
          "author_name": "Asa Cooper Stickland",
          "author_login": "asacsz",
          "committed_at": "2025-11-11T09:45:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d47f95af9b6e1f979349ac143c7750703ff3a348",
          "body": "## Summary\n\nThe `full_trajectory_monitor` and `git_diff_monitor` scorers didn't work\nproperly when no arguments were provided as the defaults were `Field`\nobjects which resolved to `FieldInfo` objects rather than the desired\ndefaults. This PR sets defaults directly rather than as `Field` objects\n\n## Test Plan\n\n`control-arena eval single -s apps --limit 1 --trusted-model\nopenai/gpt-5-nano --untrusted-model openai/gpt-5-nano`, which failed\npreviously, now runs correctly. Unit tests still pass",
          "is_bot": false,
          "headline": "fix: Broken defaults for full_trajectory_monitor (#705)",
          "author_name": "Rogan-Inglis",
          "author_login": "Rogan-Inglis",
          "committed_at": "2025-11-07T10:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 83,
      "commits_last_year": 320,
      "latest_release_at": "2026-07-23T21:01:42Z",
      "latest_release_tag": "v17.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 42,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 13.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "control_arena",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/control_arena/",
          "is_deprecated": false,
          "latest_version": "17.1.2",
          "repository_url": "https://github.com/UKGovernmentBEIS/control-arena",
          "versions_count": 78,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 22413,
          "first_published_at": "2025-03-25T22:29:12.610926Z",
          "latest_published_at": "2026-07-23T21:12:14.089771Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 124,
      "stars": 212,
      "watchers": 5,
      "fork_history": {
        "days": [
          {
            "date": "2025-03-10",
            "count": 1
          },
          {
            "date": "2025-03-12",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 2
          },
          {
            "date": "2025-03-19",
            "count": 1
          },
          {
            "date": "2025-03-20",
            "count": 1
          },
          {
            "date": "2025-03-23",
            "count": 1
          },
          {
            "date": "2025-03-25",
            "count": 2
          },
          {
            "date": "2025-03-27",
            "count": 1
          },
          {
            "date": "2025-03-28",
            "count": 1
          },
          {
            "date": "2025-03-29",
            "count": 8
          },
          {
            "date": "2025-03-30",
            "count": 1
          },
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-09",
            "count": 1
          },
          {
            "date": "2025-04-11",
            "count": 1
          },
          {
            "date": "2025-04-13",
            "count": 1
          },
          {
            "date": "2025-04-17",
            "count": 1
          },
          {
            "date": "2025-04-23",
            "count": 2
          },
          {
            "date": "2025-04-27",
            "count": 1
          },
          {
            "date": "2025-04-29",
            "count": 1
          },
          {
            "date": "2025-04-30",
            "count": 1
          },
          {
            "date": "2025-05-07",
            "count": 1
          },
          {
            "date": "2025-05-09",
            "count": 1
          },
          {
            "date": "2025-05-15",
            "count": 1
          },
          {
            "date": "2025-05-22",
            "count": 3
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-29",
            "count": 1
          },
          {
            "date": "2025-06-09",
            "count": 1
          },
          {
            "date": "2025-06-17",
            "count": 1
          },
          {
            "date": "2025-06-26",
            "count": 1
          },
          {
            "date": "2025-06-29",
            "count": 1
          },
          {
            "date": "2025-07-01",
            "count": 1
          },
          {
            "date": "2025-07-11",
            "count": 1
          },
          {
            "date": "2025-07-16",
            "count": 1
          },
          {
            "date": "2025-07-31",
            "count": 1
          },
          {
            "date": "2025-08-07",
            "count": 1
          },
          {
            "date": "2025-08-22",
            "count": 1
          },
          {
            "date": "2025-08-30",
            "count": 1
          },
          {
            "date": "2025-09-11",
            "count": 1
          },
          {
            "date": "2025-09-12",
            "count": 1
          },
          {
            "date": "2025-09-15",
            "count": 2
          },
          {
            "date": "2025-09-22",
            "count": 1
          },
          {
            "date": "2025-09-25",
            "count": 1
          },
          {
            "date": "2025-09-26",
            "count": 1
          },
          {
            "date": "2025-09-29",
            "count": 1
          },
          {
            "date": "2025-09-30",
            "count": 1
          },
          {
            "date": "2025-10-07",
            "count": 1
          },
          {
            "date": "2025-11-03",
            "count": 2
          },
          {
            "date": "2025-11-12",
            "count": 1
          },
          {
            "date": "2025-11-16",
            "count": 1
          },
          {
            "date": "2025-11-17",
            "count": 1
          },
          {
            "date": "2025-12-01",
            "count": 1
          },
          {
            "date": "2025-12-02",
            "count": 1
          },
          {
            "date": "2025-12-09",
            "count": 1
          },
          {
            "date": "2025-12-17",
            "count": 1
          },
          {
            "date": "2025-12-21",
            "count": 1
          },
          {
            "date": "2026-01-05",
            "count": 1
          },
          {
            "date": "2026-01-06",
            "count": 1
          },
          {
            "date": "2026-01-07",
            "count": 1
          },
          {
            "date": "2026-01-12",
            "count": 1
          },
          {
            "date": "2026-01-31",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-02-24",
            "count": 1
          },
          {
            "date": "2026-03-03",
            "count": 1
          },
          {
            "date": "2026-03-06",
            "count": 1
          },
          {
            "date": "2026-03-08",
            "count": 1
          },
          {
            "date": "2026-03-17",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 3
          },
          {
            "date": "2026-03-21",
            "count": 3
          },
          {
            "date": "2026-03-22",
            "count": 2
          },
          {
            "date": "2026-03-23",
            "count": 2
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-11",
            "count": 1
          },
          {
            "date": "2026-04-13",
            "count": 1
          },
          {
            "date": "2026-04-15",
            "count": 2
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-05-14",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-11",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 2
          },
          {
            "date": "2026-07-10",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 109,
        "total_forks": 124
      },
      "star_history": null,
      "open_issues_and_prs": 12
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "notebooks"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "control_arena/settings/infra/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "control_arena/py.typed"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 48150,
      "source_files_sampled": 563,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 4175
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "gitpython",
            "direct": true,
            "version": "3.1.46",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-2f96-g7mh-g2hx",
              "GHSA-7545-fcxq-7j24",
              "GHSA-956x-8gvw-wg5v",
              "GHSA-mv93-w799-cj2w",
              "GHSA-rpm5-65cw-6hj4",
              "GHSA-rwj8-pgh3-r573",
              "GHSA-v87r-6q3f-2j67",
              "GHSA-x2qx-6953-8485",
              "PYSEC-2026-2160",
              "PYSEC-2026-2161"
            ],
            "fixed_version": "3.1.52",
            "advisory_count": 12,
            "oldest_advisory_days": 89
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "46.0.6",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-537c-gmf6-5ccf",
              "GHSA-p423-j2cm-9vmq",
              "PYSEC-2026-36"
            ],
            "fixed_version": "48.0.1",
            "advisory_count": 3,
            "oldest_advisory_days": 106
          },
          {
            "name": "django",
            "direct": false,
            "version": "6.0.3",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-5hrc-gvxj-w55p",
              "GHSA-5mf9-h53q-7mhq",
              "GHSA-7h2m-m8vj-598h",
              "GHSA-933h-hp56-hf7m",
              "GHSA-mm6v-q8q9-pgcf",
              "GHSA-mmwr-2jhp-mc7j",
              "GHSA-mvfq-ggxm-9mc5",
              "GHSA-pwjp-ccjc-ghwg",
              "GHSA-w26r-rmm8-9c29",
              "PYSEC-2026-197"
            ],
            "fixed_version": "6.0.7",
            "advisory_count": 25,
            "oldest_advisory_days": 107
          },
          {
            "name": "jupyterlab",
            "direct": false,
            "version": "4.5.6",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.6,
            "advisory_ids": [
              "GHSA-37w4-hwhx-4rc4",
              "GHSA-89vp-jrxv-24w8",
              "GHSA-gx64-gj6p-pc4c",
              "GHSA-h5v5-8746-g7mm",
              "GHSA-mqcg-5x36-vfcg",
              "GHSA-pppj-hq3g-57pj",
              "GHSA-rch3-82jr-f9w9",
              "GHSA-vmhf-c436-hxj4",
              "GHSA-whvh-wf3x-g77j",
              "PYSEC-2026-164"
            ],
            "fixed_version": "7.5.6",
            "advisory_count": 12,
            "oldest_advisory_days": 84
          },
          {
            "name": "notebook",
            "direct": false,
            "version": "7.5.5",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.6,
            "advisory_ids": [
              "GHSA-mqcg-5x36-vfcg",
              "GHSA-rch3-82jr-f9w9",
              "PYSEC-2026-2681",
              "PYSEC-2026-2682"
            ],
            "fixed_version": "7.5.6",
            "advisory_count": 4,
            "oldest_advisory_days": 84
          },
          {
            "name": "click",
            "direct": true,
            "version": "8.2.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.2,
            "advisory_ids": [
              "PYSEC-2026-2132"
            ],
            "fixed_version": "8.3.3",
            "advisory_count": 1,
            "oldest_advisory_days": 84
          },
          {
            "name": "click",
            "direct": true,
            "version": "8.3.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.2,
            "advisory_ids": [
              "PYSEC-2026-2132"
            ],
            "fixed_version": "8.3.3",
            "advisory_count": 1,
            "oldest_advisory_days": 84
          },
          {
            "name": "aiohttp",
            "direct": false,
            "version": "3.13.4",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2fqr-mr3j-6wp8",
              "GHSA-4fvr-rgm6-gqmc",
              "GHSA-4m7w-qmgq-4wj5",
              "GHSA-63hw-fmq6-xxg2",
              "GHSA-9x8q-7h8h-wcw9",
              "GHSA-g3cq-j2xw-wf74",
              "GHSA-hg6j-4rv6-33pg",
              "GHSA-hpj7-wq8m-9hgp",
              "GHSA-jg22-mg44-37j8",
              "GHSA-m6qw-4cw2-hm4m"
            ],
            "fixed_version": "3.14.1",
            "advisory_count": 22,
            "oldest_advisory_days": 51
          },
          {
            "name": "jupyter-server",
            "direct": false,
            "version": "2.17.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-24qx-w28j-9m6p",
              "GHSA-5789-5fc7-67v3",
              "GHSA-5mrq-x3x5-8v8f",
              "GHSA-fcw5-x6j4-ccmp",
              "GHSA-gf7q-q4j7-hp7c",
              "GHSA-qh7q-6qm3-653w",
              "GHSA-v42x-x7jp-845h",
              "PYSEC-2026-2187",
              "PYSEC-2026-2532",
              "PYSEC-2026-3472"
            ],
            "fixed_version": "2.20.0",
            "advisory_count": 14,
            "oldest_advisory_days": 79
          },
          {
            "name": "langchain-core",
            "direct": false,
            "version": "1.2.23",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.2,
            "advisory_ids": [
              "GHSA-926x-3r5x-gfhw",
              "GHSA-pjwx-r37v-7724",
              "PYSEC-2026-2563",
              "PYSEC-2026-2564"
            ],
            "fixed_version": "1.3.3",
            "advisory_count": 4,
            "oldest_advisory_days": 106
          },
          {
            "name": "langsmith",
            "direct": false,
            "version": "0.7.23",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.7,
            "advisory_ids": [
              "GHSA-3644-q5cj-c5c7",
              "GHSA-f4xh-w4cj-qxq8",
              "GHSA-rr7j-v2q5-chgv",
              "PYSEC-2026-2582",
              "PYSEC-2026-2583"
            ],
            "fixed_version": "1.0.7",
            "advisory_count": 5,
            "oldest_advisory_days": 99
          },
          {
            "name": "mistune",
            "direct": false,
            "version": "3.2.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2hm2-hc3v-44h9",
              "GHSA-4j32-57v6-6g45",
              "GHSA-58cw-g322-p94v",
              "GHSA-6269-cqxg-mhhv",
              "GHSA-8c25-4j27-2rv3",
              "GHSA-8g87-j6q8-g93x",
              "GHSA-8mp2-v27r-99xp",
              "GHSA-8mpj-m6qm-5qr8",
              "GHSA-c8j7-8cv4-2xmq",
              "GHSA-ccfx-mfmx-2fx9"
            ],
            "fixed_version": "3.3.0",
            "advisory_count": 32,
            "oldest_advisory_days": 78
          },
          {
            "name": "anthropic",
            "direct": true,
            "version": "0.86.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-q5f5-3gjm-7mfm",
              "GHSA-w828-4qhx-vxx3",
              "PYSEC-2026-2114",
              "PYSEC-2026-2115"
            ],
            "fixed_version": "0.87.0",
            "advisory_count": 4,
            "oldest_advisory_days": 114
          },
          {
            "name": "flask",
            "direct": true,
            "version": "3.0.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 4.3,
            "advisory_ids": [
              "GHSA-68rp-wp8r-4726",
              "PYSEC-2026-2151"
            ],
            "fixed_version": "3.1.3",
            "advisory_count": 2,
            "oldest_advisory_days": 154
          },
          {
            "name": "bleach",
            "direct": false,
            "version": "6.3.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.1,
            "advisory_ids": [
              "GHSA-8rfp-98v4-mmr6",
              "GHSA-g75f-g53v-794x",
              "GHSA-gj48-438w-jh9v"
            ],
            "fixed_version": "6.4.0",
            "advisory_count": 3,
            "oldest_advisory_days": 37
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.11",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-65pc-fj4g-8rjx",
              "PYSEC-2026-215"
            ],
            "fixed_version": "3.15",
            "advisory_count": 2,
            "oldest_advisory_days": 65
          },
          {
            "name": "langchain",
            "direct": false,
            "version": "1.2.13",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.5,
            "advisory_ids": [
              "GHSA-gr75-jv2w-4656",
              "PYSEC-2026-2192"
            ],
            "fixed_version": "1.4.6",
            "advisory_count": 2,
            "oldest_advisory_days": 37
          },
          {
            "name": "langgraph-checkpoint",
            "direct": false,
            "version": "4.0.1",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-fjqc-hq36-qh5p",
              "PYSEC-2026-2573"
            ],
            "fixed_version": "4.1.1",
            "advisory_count": 2,
            "oldest_advisory_days": 28
          },
          {
            "name": "langgraph-sdk",
            "direct": false,
            "version": "0.3.12",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 4.2,
            "advisory_ids": [
              "GHSA-w39p-vh2g-g8g5",
              "PYSEC-2026-2575"
            ],
            "fixed_version": "0.3.15",
            "advisory_count": 2,
            "oldest_advisory_days": 28
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "8.3.3",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-6w46-j5rx-g56g",
              "PYSEC-2026-1845"
            ],
            "fixed_version": "9.0.3",
            "advisory_count": 2,
            "oldest_advisory_days": 183
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.0.2",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-6w46-j5rx-g56g",
              "PYSEC-2026-1845"
            ],
            "fixed_version": "9.0.3",
            "advisory_count": 2,
            "oldest_advisory_days": 183
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.31.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.6,
            "advisory_ids": [
              "GHSA-9hjg-9r4m-mvj7",
              "GHSA-9wx4-h78v-vm56",
              "GHSA-gc5v-m9x4-r6x2",
              "PYSEC-2026-1872",
              "PYSEC-2026-1873",
              "PYSEC-2026-2275"
            ],
            "fixed_version": "2.33.0",
            "advisory_count": 6,
            "oldest_advisory_days": 794
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.6.3",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-mf9v-mfxr-j63j",
              "GHSA-qccp-gfcp-xxvc",
              "PYSEC-2026-141",
              "PYSEC-2026-142"
            ],
            "fixed_version": "2.7.0",
            "advisory_count": 4,
            "oldest_advisory_days": 73
          },
          {
            "name": "msgpack",
            "direct": false,
            "version": "1.1.2",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-6v7p-g79w-8964"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": null
          },
          {
            "name": "nbconvert",
            "direct": false,
            "version": "7.17.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-4c99-qj7h-p3vg",
              "GHSA-7jqv-fw35-gmx9",
              "PYSEC-2026-2229",
              "PYSEC-2026-2230"
            ],
            "fixed_version": null,
            "advisory_count": 4,
            "oldest_advisory_days": null
          },
          {
            "name": "pillow",
            "direct": false,
            "version": "12.1.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-45hq-cxwh-f6vc",
              "GHSA-4x4j-2g7c-83w6",
              "GHSA-5x94-69rx-g8h2",
              "GHSA-5xmw-vc9v-4wf2",
              "GHSA-62p4-gmf7-7g93",
              "GHSA-6r8x-57c9-28j4",
              "GHSA-8v84-f9pq-wr9x",
              "GHSA-9hw9-ch79-4vh6",
              "GHSA-fj7v-r99m-22gq",
              "GHSA-jjj6-mw9f-p565"
            ],
            "fixed_version": null,
            "advisory_count": 36,
            "oldest_advisory_days": null
          },
          {
            "name": "pyasn1",
            "direct": false,
            "version": "0.6.3",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-8ppf-4f7h-5ppj",
              "GHSA-hm4w-wwcw-mr6r",
              "PYSEC-2026-3455",
              "PYSEC-2026-3456",
              "PYSEC-2026-3457"
            ],
            "fixed_version": null,
            "advisory_count": 5,
            "oldest_advisory_days": null
          },
          {
            "name": "ray",
            "direct": false,
            "version": "2.54.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-mw35-8rx3-xf9r",
              "PYSEC-2026-2273"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": null
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "81.0.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-h35f-9h28-mq5c",
              "PYSEC-2026-3447"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": null
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "82.0.1",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-h35f-9h28-mq5c",
              "PYSEC-2026-3447"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": null
          },
          {
            "name": "soupsieve",
            "direct": false,
            "version": "2.8.3",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-2wc2-fm75-p42x",
              "GHSA-836r-79rf-4m37",
              "PYSEC-2026-3071",
              "PYSEC-2026-3072"
            ],
            "fixed_version": null,
            "advisory_count": 4,
            "oldest_advisory_days": null
          },
          {
            "name": "starlette",
            "direct": false,
            "version": "1.0.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-82w8-qh3p-5jfq",
              "GHSA-86qp-5c8j-p5mr",
              "GHSA-jp82-jpqv-5vv3",
              "GHSA-wqp7-x3pw-xc5r",
              "GHSA-x746-7m8f-x49c",
              "PYSEC-2026-161",
              "PYSEC-2026-2280",
              "PYSEC-2026-2281",
              "PYSEC-2026-248",
              "PYSEC-2026-249"
            ],
            "fixed_version": null,
            "advisory_count": 10,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.11.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-rrmf-rvhw-rf47"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": null
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.6.0+cpu",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3749-ghw9-m3mg",
              "GHSA-887c-mr87-cxwp",
              "GHSA-qfhq-4f3w-5fph",
              "GHSA-rrmf-rvhw-rf47",
              "GHSA-vgrw-7cvw-pwgx",
              "PYSEC-2025-191",
              "PYSEC-2025-198",
              "PYSEC-2025-199",
              "PYSEC-2025-200",
              "PYSEC-2025-201"
            ],
            "fixed_version": null,
            "advisory_count": 21,
            "oldest_advisory_days": null
          },
          {
            "name": "tornado",
            "direct": false,
            "version": "6.5.5",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-3x9g-8vmp-wqvf",
              "GHSA-cx3h-4qpv-8hc9",
              "GHSA-mgf9-4vpg-hj56",
              "GHSA-pw6j-qg29-8w7f",
              "PYSEC-2026-3387",
              "PYSEC-2026-3388",
              "PYSEC-2026-3389"
            ],
            "fixed_version": null,
            "advisory_count": 7,
            "oldest_advisory_days": null
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.57.6",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-29pf-2h5f-8g72",
              "GHSA-69w3-r845-3855",
              "GHSA-fgcw-684q-jj6r",
              "PYSEC-2025-217",
              "PYSEC-2026-2288",
              "PYSEC-2026-2289",
              "PYSEC-2026-2290"
            ],
            "fixed_version": null,
            "advisory_count": 7,
            "oldest_advisory_days": null
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "5.4.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-fgcw-684q-jj6r"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": null
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 7,
          "unknown": 14,
          "critical": 5,
          "moderate": 11
        },
        "advisory_count": 269,
        "affected_count": 37,
        "assessed_count": 386,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 4,
        "direct_affected_count": 5
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "agentdojo",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==0.1.33"
        },
        {
          "name": "aiofiles",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=25.1.0"
        },
        {
          "name": "anthropic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.80.0"
        },
        {
          "name": "anyio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.8.0"
        },
        {
          "name": "click",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.1.7"
        },
        {
          "name": "datasets",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.4.2"
        },
        {
          "name": "defusedxml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.7.1"
        },
        {
          "name": "docker",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=7.1.0"
        },
        {
          "name": "flask",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1.3"
        },
        {
          "name": "gitpython",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1.44"
        },
        {
          "name": "huggingface-hub",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "~=0.33"
        },
        {
          "name": "inspect-ai",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.3.159"
        },
        {
          "name": "inspect-k8s-sandbox",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.6.1"
        },
        {
          "name": "kubernetes-asyncio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=32.0.0"
        },
        {
          "name": "minio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=7.2.15"
        },
        {
          "name": "miniopy-async",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.21.1"
        },
        {
          "name": "openai",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.26.0"
        },
        {
          "name": "pandas",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.3.0"
        },
        {
          "name": "pandera",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.26.0"
        },
        {
          "name": "psycopg",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.2.6"
        },
        {
          "name": "pyarrow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=20.0.0"
        },
        {
          "name": "redis",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==5.2.1"
        },
        {
          "name": "regex",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2024.11.6"
        },
        {
          "name": "rich",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.7.0"
        },
        {
          "name": "seaborn",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.13.2"
        },
        {
          "name": "sniffio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.3.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "agentdojo",
            "direct": true,
            "version": "0.1.33",
            "ecosystem": "pypi"
          },
          {
            "name": "aiofiles",
            "direct": true,
            "version": "25.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "anthropic",
            "direct": true,
            "version": "0.86.0",
            "ecosystem": "pypi"
          },
          {
            "name": "anyio",
            "direct": true,
            "version": "4.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": true,
            "version": "8.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": true,
            "version": "8.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "datasets",
            "direct": true,
            "version": "3.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "datasets",
            "direct": true,
            "version": "4.8.4",
            "ecosystem": "pypi"
          },
          {
            "name": "defusedxml",
            "direct": true,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "docker",
            "direct": true,
            "version": "7.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "flask",
            "direct": true,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "flask",
            "direct": true,
            "version": "3.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "gitpython",
            "direct": true,
            "version": "3.1.46",
            "ecosystem": "pypi"
          },
          {
            "name": "huggingface-hub",
            "direct": true,
            "version": "0.36.2",
            "ecosystem": "pypi"
          },
          {
            "name": "huggingface-hub",
            "direct": true,
            "version": "1.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "inspect-ai",
            "direct": true,
            "version": "0.3.201",
            "ecosystem": "pypi"
          },
          {
            "name": "inspect-k8s-sandbox",
            "direct": true,
            "version": "0.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "kubernetes-asyncio",
            "direct": true,
            "version": "35.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "minio",
            "direct": true,
            "version": "7.2.20",
            "ecosystem": "pypi"
          },
          {
            "name": "miniopy-async",
            "direct": true,
            "version": "1.23.4",
            "ecosystem": "pypi"
          },
          {
            "name": "openai",
            "direct": true,
            "version": "2.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pandas",
            "direct": true,
            "version": "3.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pandera",
            "direct": true,
            "version": "0.30.1",
            "ecosystem": "pypi"
          },
          {
            "name": "psycopg",
            "direct": true,
            "version": "3.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyarrow",
            "direct": true,
            "version": "23.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "redis",
            "direct": true,
            "version": "5.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "regex",
            "direct": true,
            "version": "2026.3.32",
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": true,
            "version": "14.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "seaborn",
            "direct": true,
            "version": "0.13.2",
            "ecosystem": "pypi"
          },
          {
            "name": "sniffio",
            "direct": true,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "aioboto3",
            "direct": false,
            "version": "15.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "aiobotocore",
            "direct": false,
            "version": "2.25.1",
            "ecosystem": "pypi"
          },
          {
            "name": "aiohappyeyeballs",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "aiohttp",
            "direct": false,
            "version": "3.13.4",
            "ecosystem": "pypi"
          },
          {
            "name": "aiohttp-cors",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "pypi"
          },
          {
            "name": "aiohttp-retry",
            "direct": false,
            "version": "2.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "aioitertools",
            "direct": false,
            "version": "0.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "aiosignal",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "annotated-doc",
            "direct": false,
            "version": "0.0.4",
            "ecosystem": "pypi"
          },
          {
            "name": "annotated-types",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "appnope",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "argon2-cffi",
            "direct": false,
            "version": "23.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "argon2-cffi-bindings",
            "direct": false,
            "version": "25.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "arrow",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "asgiref",
            "direct": false,
            "version": "3.11.1",
            "ecosystem": "pypi"
          },
          {
            "name": "asttokens",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "async-lru",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "async-timeout",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "aws-cdk-lib",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "babel",
            "direct": false,
            "version": "2.18.0",
            "ecosystem": "pypi"
          },
          {
            "name": "beartype",
            "direct": false,
            "version": "0.22.9",
            "ecosystem": "pypi"
          },
          {
            "name": "beautifulsoup4",
            "direct": false,
            "version": "4.14.3",
            "ecosystem": "pypi"
          },
          {
            "name": "black",
            "direct": false,
            "version": "26.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "bleach",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "blinker",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.40.61",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.42.79",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.40.61",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.42.79",
            "ecosystem": "pypi"
          },
          {
            "name": "build",
            "direct": false,
            "version": "1.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "cbor2",
            "direct": false,
            "version": "5.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2025.11.12",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.2.25",
            "ecosystem": "pypi"
          },
          {
            "name": "cffi",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cfgv",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "chardet",
            "direct": false,
            "version": "7.4.0.post2",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "cohere",
            "direct": false,
            "version": "5.21.1",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "colorful",
            "direct": false,
            "version": "0.5.8",
            "ecosystem": "pypi"
          },
          {
            "name": "comm",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "pypi"
          },
          {
            "name": "constructs",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "contourpy",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "46.0.6",
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-bindings",
            "direct": false,
            "version": "13.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-pathfinder",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cuda-toolkit",
            "direct": false,
            "version": "13.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "cycler",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "debugpy",
            "direct": false,
            "version": "1.8.20",
            "ecosystem": "pypi"
          },
          {
            "name": "decorator",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "deepdiff",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "dill",
            "direct": false,
            "version": "0.3.8",
            "ecosystem": "pypi"
          },
          {
            "name": "dill",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "distlib",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "distro",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "django",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "django-cors-headers",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "dnspython",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "docstring-parser",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "durationpy",
            "direct": false,
            "version": "0.10",
            "ecosystem": "pypi"
          },
          {
            "name": "email-validator",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "eval-type-backport",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "execnet",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "executing",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "fastapi",
            "direct": false,
            "version": "0.135.2",
            "ecosystem": "pypi"
          },
          {
            "name": "fastavro",
            "direct": false,
            "version": "1.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "fastcore",
            "direct": false,
            "version": "1.12.33",
            "ecosystem": "pypi"
          },
          {
            "name": "fastjsonschema",
            "direct": false,
            "version": "2.21.2",
            "ecosystem": "pypi"
          },
          {
            "name": "filelock",
            "direct": false,
            "version": "3.25.2",
            "ecosystem": "pypi"
          },
          {
            "name": "flake8",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "flask-cors",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "flask-httpauth",
            "direct": false,
            "version": "4.8.1",
            "ecosystem": "pypi"
          },
          {
            "name": "fonttools",
            "direct": false,
            "version": "4.62.1",
            "ecosystem": "pypi"
          },
          {
            "name": "fqdn",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "frozenlist",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fsspec",
            "direct": false,
            "version": "2024.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fsspec",
            "direct": false,
            "version": "2025.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ghapi",
            "direct": false,
            "version": "1.0.13",
            "ecosystem": "pypi"
          },
          {
            "name": "gitdb",
            "direct": false,
            "version": "4.0.12",
            "ecosystem": "pypi"
          },
          {
            "name": "google-api-core",
            "direct": false,
            "version": "2.30.1",
            "ecosystem": "pypi"
          },
          {
            "name": "google-auth",
            "direct": false,
            "version": "2.49.1",
            "ecosystem": "pypi"
          },
          {
            "name": "google-genai",
            "direct": false,
            "version": "1.69.0",
            "ecosystem": "pypi"
          },
          {
            "name": "googleapis-common-protos",
            "direct": false,
            "version": "1.73.1",
            "ecosystem": "pypi"
          },
          {
            "name": "griffe",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "griffecli",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "griffelib",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "groq",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "grpcio",
            "direct": false,
            "version": "1.80.0",
            "ecosystem": "pypi"
          },
          {
            "name": "grpclib",
            "direct": false,
            "version": "0.4.9",
            "ecosystem": "pypi"
          },
          {
            "name": "h11",
            "direct": false,
            "version": "0.16.0",
            "ecosystem": "pypi"
          },
          {
            "name": "h2",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "hatch-vcs",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "hatchling",
            "direct": false,
            "version": "1.29.0",
            "ecosystem": "pypi"
          },
          {
            "name": "hf-xet",
            "direct": false,
            "version": "1.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "hpack",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "httpcore",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "pypi"
          },
          {
            "name": "httptools",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "httpx",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "pypi"
          },
          {
            "name": "hyperframe",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "identify",
            "direct": false,
            "version": "2.6.18",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.11",
            "ecosystem": "pypi"
          },
          {
            "name": "ijson",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "importlib-metadata",
            "direct": false,
            "version": "8.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "importlib-resources",
            "direct": false,
            "version": "6.5.2",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "inspect-podman",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "ipdb",
            "direct": false,
            "version": "0.13.13",
            "ecosystem": "pypi"
          },
          {
            "name": "ipykernel",
            "direct": false,
            "version": "6.31.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ipython",
            "direct": false,
            "version": "8.22.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ipython",
            "direct": false,
            "version": "9.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ipython-pygments-lexers",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "ipywidgets",
            "direct": false,
            "version": "8.1.8",
            "ecosystem": "pypi"
          },
          {
            "name": "isoduration",
            "direct": false,
            "version": "20.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "itsdangerous",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jedi",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "pypi"
          },
          {
            "name": "jinja2",
            "direct": false,
            "version": "3.1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "jiter",
            "direct": false,
            "version": "0.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jmespath",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsii",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "0.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonlines",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpatch",
            "direct": false,
            "version": "1.33",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpath-ng",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpath-python",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpointer",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonref",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "4.26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-specifications",
            "direct": false,
            "version": "2025.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-client",
            "direct": false,
            "version": "8.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-console",
            "direct": false,
            "version": "6.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-core",
            "direct": false,
            "version": "5.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-events",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-lsp",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-server",
            "direct": false,
            "version": "2.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-server-terminals",
            "direct": false,
            "version": "0.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyterlab",
            "direct": false,
            "version": "4.5.6",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyterlab-pygments",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyterlab-server",
            "direct": false,
            "version": "2.28.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jupyterlab-widgets",
            "direct": false,
            "version": "3.0.16",
            "ecosystem": "pypi"
          },
          {
            "name": "kiwisolver",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "kubernetes",
            "direct": false,
            "version": "35.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "langchain",
            "direct": false,
            "version": "1.2.13",
            "ecosystem": "pypi"
          },
          {
            "name": "langchain-core",
            "direct": false,
            "version": "1.2.23",
            "ecosystem": "pypi"
          },
          {
            "name": "langgraph",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "langgraph-checkpoint",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "langgraph-prebuilt",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "pypi"
          },
          {
            "name": "langgraph-sdk",
            "direct": false,
            "version": "0.3.12",
            "ecosystem": "pypi"
          },
          {
            "name": "langsmith",
            "direct": false,
            "version": "0.7.23",
            "ecosystem": "pypi"
          },
          {
            "name": "lark",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "linkify-it-py",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown",
            "direct": false,
            "version": "3.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-it-py",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markupsafe",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "matplotlib",
            "direct": false,
            "version": "3.10.8",
            "ecosystem": "pypi"
          },
          {
            "name": "matplotlib-inline",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "mccabe",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mdit-py-plugins",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mdurl",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mistralai",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "mistune",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mmh3",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "modal",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "mpmath",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "msgpack",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "multidict",
            "direct": false,
            "version": "6.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "multiprocess",
            "direct": false,
            "version": "0.70.16",
            "ecosystem": "pypi"
          },
          {
            "name": "multiprocess",
            "direct": false,
            "version": "0.70.19",
            "ecosystem": "pypi"
          },
          {
            "name": "mypy-extensions",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nbclient",
            "direct": false,
            "version": "0.10.4",
            "ecosystem": "pypi"
          },
          {
            "name": "nbconvert",
            "direct": false,
            "version": "7.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nbformat",
            "direct": false,
            "version": "5.10.4",
            "ecosystem": "pypi"
          },
          {
            "name": "nest-asyncio",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nest-asyncio2",
            "direct": false,
            "version": "1.7.2",
            "ecosystem": "pypi"
          },
          {
            "name": "networkx",
            "direct": false,
            "version": "3.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "nodeenv",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "notebook",
            "direct": false,
            "version": "7.5.5",
            "ecosystem": "pypi"
          },
          {
            "name": "notebook-shim",
            "direct": false,
            "version": "0.2.4",
            "ecosystem": "pypi"
          },
          {
            "name": "numpy",
            "direct": false,
            "version": "2.4.4",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cublas",
            "direct": false,
            "version": "13.1.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cuda-cupti",
            "direct": false,
            "version": "13.0.85",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cuda-nvrtc",
            "direct": false,
            "version": "13.0.88",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cuda-runtime",
            "direct": false,
            "version": "13.0.96",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cudnn-cu13",
            "direct": false,
            "version": "9.19.0.56",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cufft",
            "direct": false,
            "version": "12.0.0.61",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cufile",
            "direct": false,
            "version": "1.15.1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-curand",
            "direct": false,
            "version": "10.4.0.35",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cusolver",
            "direct": false,
            "version": "12.0.4.66",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cusparse",
            "direct": false,
            "version": "12.6.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-cusparselt-cu13",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-nccl-cu13",
            "direct": false,
            "version": "2.28.9",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-nvjitlink",
            "direct": false,
            "version": "13.0.88",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-nvshmem-cu13",
            "direct": false,
            "version": "3.4.5",
            "ecosystem": "pypi"
          },
          {
            "name": "nvidia-nvtx",
            "direct": false,
            "version": "13.0.85",
            "ecosystem": "pypi"
          },
          {
            "name": "oauthlib",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "openapi-pydantic",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "opencensus",
            "direct": false,
            "version": "0.11.4",
            "ecosystem": "pypi"
          },
          {
            "name": "opencensus-context",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-api",
            "direct": false,
            "version": "1.39.1",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-api",
            "direct": false,
            "version": "1.40.0",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-exporter-prometheus",
            "direct": false,
            "version": "0.61b0",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-proto",
            "direct": false,
            "version": "1.40.0",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-sdk",
            "direct": false,
            "version": "1.40.0",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-semantic-conventions",
            "direct": false,
            "version": "0.60b1",
            "ecosystem": "pypi"
          },
          {
            "name": "opentelemetry-semantic-conventions",
            "direct": false,
            "version": "0.61b0",
            "ecosystem": "pypi"
          },
          {
            "name": "orderly-set",
            "direct": false,
            "version": "5.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "orjson",
            "direct": false,
            "version": "3.11.7",
            "ecosystem": "pypi"
          },
          {
            "name": "ormsgpack",
            "direct": false,
            "version": "1.12.2",
            "ecosystem": "pypi"
          },
          {
            "name": "outcome",
            "direct": false,
            "version": "1.3.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "overrides",
            "direct": false,
            "version": "7.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pandas-stubs",
            "direct": false,
            "version": "3.0.0.260204",
            "ecosystem": "pypi"
          },
          {
            "name": "pandocfilters",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "panflute",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "parso",
            "direct": false,
            "version": "0.8.6",
            "ecosystem": "pypi"
          },
          {
            "name": "pathlib-abc",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pathspec",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pexpect",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pillow",
            "direct": false,
            "version": "12.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pip-licenses",
            "direct": false,
            "version": "5.5.5",
            "ecosystem": "pypi"
          },
          {
            "name": "platformdirs",
            "direct": false,
            "version": "4.9.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "plum-dispatch",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pre-commit",
            "direct": false,
            "version": "4.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "prettytable",
            "direct": false,
            "version": "3.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-client",
            "direct": false,
            "version": "0.24.1",
            "ecosystem": "pypi"
          },
          {
            "name": "prompt-toolkit",
            "direct": false,
            "version": "3.0.52",
            "ecosystem": "pypi"
          },
          {
            "name": "propcache",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "proto-plus",
            "direct": false,
            "version": "1.27.2",
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": false,
            "version": "6.33.6",
            "ecosystem": "pypi"
          },
          {
            "name": "psutil",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "psycopg-binary",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "ptyprocess",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pure-eval",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "pypi"
          },
          {
            "name": "py-spy",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyasn1",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyasn1-modules",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pycodestyle",
            "direct": false,
            "version": "2.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycparser",
            "direct": false,
            "version": "3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": false,
            "version": "2.12.5",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-core",
            "direct": false,
            "version": "2.41.5",
            "ecosystem": "pypi"
          },
          {
            "name": "pyflakes",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyparsing",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pyproject-hooks",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyright",
            "direct": false,
            "version": "1.1.408",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-asyncio",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-mock",
            "direct": false,
            "version": "3.15.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-xdist",
            "direct": false,
            "version": "3.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dateutil",
            "direct": false,
            "version": "2.9.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-discovery",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "python-json-logger",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytokens",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32",
            "direct": false,
            "version": "311",
            "ecosystem": "pypi"
          },
          {
            "name": "pywinpty",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyzmq",
            "direct": false,
            "version": "27.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "quartodoc",
            "direct": false,
            "version": "0.11.1",
            "ecosystem": "pypi"
          },
          {
            "name": "ray",
            "direct": false,
            "version": "2.54.1",
            "ecosystem": "pypi"
          },
          {
            "name": "referencing",
            "direct": false,
            "version": "0.37.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.31.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.33.1",
            "ecosystem": "pypi"
          },
          {
            "name": "requests-oauthlib",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests-toolbelt",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3339-validator",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3986-validator",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3987-syntax",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rpds-py",
            "direct": false,
            "version": "0.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ruff",
            "direct": false,
            "version": "0.15.8",
            "ecosystem": "pypi"
          },
          {
            "name": "s3fs",
            "direct": false,
            "version": "2025.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "s3transfer",
            "direct": false,
            "version": "0.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "s3transfer",
            "direct": false,
            "version": "0.16.0",
            "ecosystem": "pypi"
          },
          {
            "name": "safetensors",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "pypi"
          },
          {
            "name": "send2trash",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "81.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "82.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools-scm",
            "direct": false,
            "version": "10.0.5",
            "ecosystem": "pypi"
          },
          {
            "name": "shade-arena",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "shellingham",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "shortuuid",
            "direct": false,
            "version": "1.0.13",
            "ecosystem": "pypi"
          },
          {
            "name": "simple-parsing",
            "direct": false,
            "version": "0.1.8",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "smart-open",
            "direct": false,
            "version": "7.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "smmap",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "sortedcontainers",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "soupsieve",
            "direct": false,
            "version": "2.8.3",
            "ecosystem": "pypi"
          },
          {
            "name": "sphobjinv",
            "direct": false,
            "version": "2.4",
            "ecosystem": "pypi"
          },
          {
            "name": "sqlparse",
            "direct": false,
            "version": "0.5.5",
            "ecosystem": "pypi"
          },
          {
            "name": "stack-data",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "starlette",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "swebench",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sympy",
            "direct": false,
            "version": "1.13.1",
            "ecosystem": "pypi"
          },
          {
            "name": "sympy",
            "direct": false,
            "version": "1.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "synchronicity",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "syrupy",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tabulate",
            "direct": false,
            "version": "0.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tenacity",
            "direct": false,
            "version": "9.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "tensorboardx",
            "direct": false,
            "version": "2.6.4",
            "ecosystem": "pypi"
          },
          {
            "name": "terminado",
            "direct": false,
            "version": "0.18.1",
            "ecosystem": "pypi"
          },
          {
            "name": "textual",
            "direct": false,
            "version": "8.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "tiktoken",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tinycss2",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tokenizers",
            "direct": false,
            "version": "0.22.2",
            "ecosystem": "pypi"
          },
          {
            "name": "toml",
            "direct": false,
            "version": "0.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": false,
            "version": "2.6.0+cpu",
            "ecosystem": "pypi"
          },
          {
            "name": "tornado",
            "direct": false,
            "version": "6.5.5",
            "ecosystem": "pypi"
          },
          {
            "name": "tqdm",
            "direct": false,
            "version": "4.67.3",
            "ecosystem": "pypi"
          },
          {
            "name": "traitlets",
            "direct": false,
            "version": "5.14.3",
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "4.57.6",
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": "5.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "trio",
            "direct": false,
            "version": "0.33.0",
            "ecosystem": "pypi"
          },
          {
            "name": "triton",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "trove-classifiers",
            "direct": false,
            "version": "2026.1.14.14",
            "ecosystem": "pypi"
          },
          {
            "name": "typeguard",
            "direct": false,
            "version": "4.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "typer",
            "direct": false,
            "version": "0.24.1",
            "ecosystem": "pypi"
          },
          {
            "name": "types-aiofiles",
            "direct": false,
            "version": "25.1.0.20251011",
            "ecosystem": "pypi"
          },
          {
            "name": "types-certifi",
            "direct": false,
            "version": "2021.10.8.3",
            "ecosystem": "pypi"
          },
          {
            "name": "types-networkx",
            "direct": false,
            "version": "3.6.1.20260321",
            "ecosystem": "pypi"
          },
          {
            "name": "types-pyyaml",
            "direct": false,
            "version": "6.0.12.20250915",
            "ecosystem": "pypi"
          },
          {
            "name": "types-requests",
            "direct": false,
            "version": "2.33.0.20260327",
            "ecosystem": "pypi"
          },
          {
            "name": "types-seaborn",
            "direct": false,
            "version": "0.13.2.20251221",
            "ecosystem": "pypi"
          },
          {
            "name": "types-toml",
            "direct": false,
            "version": "0.10.8.20240310",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspect",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspection",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "tzdata",
            "direct": false,
            "version": "2025.3",
            "ecosystem": "pypi"
          },
          {
            "name": "uc-micro-py",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "unidiff",
            "direct": false,
            "version": "0.7.5",
            "ecosystem": "pypi"
          },
          {
            "name": "universal-pathlib",
            "direct": false,
            "version": "0.3.10",
            "ecosystem": "pypi"
          },
          {
            "name": "uri-template",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "uuid-utils",
            "direct": false,
            "version": "0.14.1",
            "ecosystem": "pypi"
          },
          {
            "name": "uvicorn",
            "direct": false,
            "version": "0.42.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uvloop",
            "direct": false,
            "version": "0.22.1",
            "ecosystem": "pypi"
          },
          {
            "name": "vcs-versioning",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "watchdog",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "watchfiles",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "wcwidth",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "webcolors",
            "direct": false,
            "version": "25.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "webencodings",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "websocket-client",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "websockets",
            "direct": false,
            "version": "16.0",
            "ecosystem": "pypi"
          },
          {
            "name": "werkzeug",
            "direct": false,
            "version": "3.1.7",
            "ecosystem": "pypi"
          },
          {
            "name": "widgetsnbextension",
            "direct": false,
            "version": "4.0.15",
            "ecosystem": "pypi"
          },
          {
            "name": "wrapt",
            "direct": false,
            "version": "1.17.3",
            "ecosystem": "pypi"
          },
          {
            "name": "wrapt",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "xxhash",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "yarl",
            "direct": false,
            "version": "1.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "zipfile-zstd",
            "direct": false,
            "version": "0.0.4",
            "ecosystem": "pypi"
          },
          {
            "name": "zipp",
            "direct": false,
            "version": "3.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "zstandard",
            "direct": false,
            "version": "0.25.0",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 390,
        "direct_count": 30,
        "indirect_count": 360
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 622,
        "open_issues": 4,
        "closed_ratio": 0.945,
        "closed_issues": 69,
        "closed_unmerged_prs": 129
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "Rogan-Inglis",
          "commits": 440,
          "avatar_url": "https://avatars.githubusercontent.com/u/190838885?v=4"
        },
        {
          "type": "User",
          "login": "ollie-matthews",
          "commits": 405,
          "avatar_url": "https://avatars.githubusercontent.com/u/188081561?v=4"
        },
        {
          "type": "User",
          "login": "tylerthecoder",
          "commits": 59,
          "avatar_url": "https://avatars.githubusercontent.com/u/17890689?v=4"
        },
        {
          "type": "User",
          "login": "mruwnik",
          "commits": 54,
          "avatar_url": "https://avatars.githubusercontent.com/u/3942390?v=4"
        },
        {
          "type": "User",
          "login": "asacsz",
          "commits": 34,
          "avatar_url": "https://avatars.githubusercontent.com/u/186037390?v=4"
        },
        {
          "type": "User",
          "login": "tcatling",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/155444638?v=4"
        },
        {
          "type": "User",
          "login": "alan-cooney-dsit",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/176403005?v=4"
        },
        {
          "type": "User",
          "login": "rasmusfaber",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/2798829?v=4"
        },
        {
          "type": "User",
          "login": "zarSou9",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/148247390?v=4"
        },
        {
          "type": "User",
          "login": "metatrot",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/97564335?v=4"
        }
      ],
      "contributors_sampled": 52,
      "top_contributor_share": 0.348
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "checks.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 6/30 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 7 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "152 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "bf7328e522615107bd9b9bfaee8c1bcbec4b6664",
        "ran_at": "2026-07-24T06:40:45Z",
        "aggregate_score": 5.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T21:12:17Z",
      "oldest_open_prs": [
        {
          "number": 691,
          "created_at": "2025-10-27T14:33:26Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 703,
          "created_at": "2025-11-05T17:23:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 812,
          "created_at": "2026-05-01T09:41:07Z",
          "last_comment_at": "2026-07-23T00:46:59Z",
          "last_comment_author": "ChrisHarig"
        },
        {
          "number": 817,
          "created_at": "2026-05-21T16:55:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 819,
          "created_at": "2026-06-01T07:16:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 820,
          "created_at": "2026-06-04T10:37:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 825,
          "created_at": "2026-06-18T07:26:30Z",
          "last_comment_at": "2026-07-02T04:46:28Z",
          "last_comment_author": "AUTHENSOR"
        },
        {
          "number": 833,
          "created_at": "2026-07-15T12:28:03Z",
          "last_comment_at": "2026-07-22T10:27:59Z",
          "last_comment_author": "Rogan-Inglis"
        }
      ],
      "last_merged_pr_at": "2026-07-23T21:01:05Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 755,
          "created_at": "2025-12-12T16:45:51Z",
          "last_comment_at": "2026-01-19T11:35:58Z",
          "last_comment_author": "Rogan-Inglis"
        },
        {
          "number": 779,
          "created_at": "2026-03-20T20:00:12Z",
          "last_comment_at": "2026-04-07T09:46:11Z",
          "last_comment_author": "Rogan-Inglis"
        },
        {
          "number": 814,
          "created_at": "2026-05-10T13:52:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 832,
          "created_at": "2026-07-10T17:40:54Z",
          "last_comment_at": "2026-07-13T16:45:18Z",
          "last_comment_author": "Aarav500"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/UKGovernmentBEIS/control-arena",
    "host": "github.com",
    "name": "control-arena",
    "owner": "UKGovernmentBEIS"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 78,
      "inputs": {
        "security": 51,
        "vitality": 96,
        "community": 68,
        "governance": 77,
        "engineering": 88
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 96,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "commits_last_year": 320,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 42
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "42/52 weeks with commits",
                "points": 29.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 42
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "320 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 320
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 83,
              "latest_release_tag": "v17.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 13.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "83 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 83
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~13.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 13.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 68,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "forks": 124,
              "stars": 212,
              "watchers": 5,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "212 stars",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 212
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "124 forks",
                "points": 17.4,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 124
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "5 watchers",
                "points": 3.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "packages": [
                "control_arena"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 22413
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "22,413 downloads/month across pypi",
                "points": 58,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 22413,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 77,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 52,
              "top_contributor_share": 0.348
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 35% of commits",
                "points": 14.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 35
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "52 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 52
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "merged_prs": 622,
              "open_issues": 4,
              "closed_issues": 69,
              "issue_closed_ratio": 0.945,
              "closed_unmerged_prs": 129
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "94% of issues closed",
                "points": 44.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "622/751 decided PRs merged",
                "points": 31.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 622,
                      "decided": 751
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 6/30 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "followers": 242,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "UKGovernmentBEIS",
              "public_repos": 114,
              "account_age_days": 3730
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "242 followers of UKGovernmentBEIS",
                "points": 17.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 242,
                      "login": "UKGovernmentBEIS"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "114 public repos, account ~10 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 114
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 10
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "control_arena"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "78 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 78
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 88,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://control-arena.aisi.org.uk",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://control-arena.aisi.org.uk",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 51,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 6/30 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "14 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "152 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "at_risk",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 386 resolved dependencies against OSV; 4 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 386
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 4
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "osv",
              "advisories": 269,
              "affected_packages": 37,
              "assessed_packages": 386,
              "unassessed_packages": 4,
              "affected_by_severity": "critical 5, high 7, moderate 11, unknown 14",
              "direct_affected_packages": 5
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "5 affected: gitpython 3.1.46 (critical 9.8), click 8.2.1 (high 7.2), click 8.3.1 (high 7.2), +2 more",
                "points": 4.7,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 5,
                      "packages": "gitpython 3.1.46 (critical 9.8), click 8.2.1 (high 7.2), click 8.3.1 (high 7.2)"
                    }
                  },
                  {
                    "code": "advisories_affected_more",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "2 advisory-carrying package(s) unaddressed past 90 days; oldest published 154 days ago",
                "points": 32.3,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 2,
                      "oldest": 154
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 386,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.96,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 4175
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "control_arena/settings/infra/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "control_arena/py.typed"
              ],
              "agent_commit_share": 0.26,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "control_arena/settings/infra/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "control_arena/settings/infra/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "control_arena/py.typed",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "control_arena/py.typed"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "26 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 26,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 48150,
              "source_files_sampled": 563,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (control_arena/py.typed)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "control_arena/py.typed",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/563 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 563,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples",
                "notebooks"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, notebooks",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, notebooks"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index pypi:control_arena@17.1.2; advisories assessed against the repository dependency graph instead",
    "Advisory severity resolved for 120 of 242 advisories (lookup cap); the remainder are reported as unknown severity"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T06:41:15.090722Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/u/UKGovernmentBEIS/control-arena.svg",
  "full_name": "UKGovernmentBEIS/control-arena",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPyPI.