Public record
Software health reportschema 0.27.0 · metrics 2.3.1 · 2026-07-30 22:21 UTC

aliyun / darabonba-openapi

Python · Go · C#No license detected★ 21 stars⑂ 12 forkssince Aug 2020View on GitHub ↗

aliyun/darabonba-openapi holds a health index of 56 out of 100, placing it in the Moderate band. It scores highest on Sustainability & Governance (68/100) and lowest on Community & Adoption (44/100). It was last updated 1 day ago. A single contributor accounts for most of its recent work.

56
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

56
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 54 is calibrated to 56 on the published index scale (record calibration 2026-08-02).

Ownership

Alibaba CloudOrganization
1,922 followers689 public repossince Jul 2011

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Mavencom.aliyun:tea-openapi0.3.15-5252 days ago
Gogithub.com/alibabacloud-go/darabonba-openapi/v2points to another repo — not scoredv2.2.4-3530 days ago
npm@alicloud/openapi-core1.0.8259,506916 days ago
Packagistalibabacloud/openapi-corepoints to another repo — not scored1.0.1025,6981117 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

47Weak · 21% of overall
How it's scored
36/36Push recency — last push 1 days ago
16.6/36Commit cadence — 24/52 weeks with commits
15.5/18Commit volume — 52 commits in the last year
10/10OpenSSF Scorecard: Maintained — 17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year52
human_commit_share1
days_since_last_push1
active_weeks_last_year24
How it's scored
0/27Ships releases — no releases published
0/36Release recency — no releases
0/27Release cadence — no releases
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count0
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

44Weak · 17% of overall
How it's scored
21.1/60Stars — 21 stars
8.7/25Forks — 12 forks
1.7/15Watchers — 3 watchers
Inputs used
forks12
stars21
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
0/22.5License — no license file detected
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseno
readme_badges
has_contributingno
has_issue_templateno
has_code_of_conductno
readme_badge_services
has_pull_request_templateno
How it's scored
72.2/80Monthly downloads — 259,506 downloads/month across maven, npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagescom.aliyun:tea-openapi, @alicloud/openapi-core
dependents
ecosystemsmaven, npm
total_downloads
monthly_downloads259,506
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

68Good · 23% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
11/22.5Commit distribution — top contributor authored 51% of commits
13.5/13.5Contributor breadth — 15 contributors
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Inputs used
bus_factor1
contributors_sampled15
top_contributor_share0.512
How it's scored
17.8/42Issue resolution — 42% of issues closed
27.4/30PR acceptance — 221/242 decided PRs merged
0/13Newcomer PR acceptance — no first-time contributor's PR decided in 30d
9/15OpenSSF Scorecard: Code-Review — Found 19/30 approved changesets -- score normalized to 6
Inputs used
merged_prs221
open_issues19
closed_issues14
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0.424
closed_unmerged_prs21
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluded from scoring (no data or not applicable): newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
23.6/25Owner reach — 1,922 followers of aliyun
25/25Track record — 689 public repos, account ~15 yr old
Inputs used
followers1,922
owner_typeOrganization
is_verified
owner_loginaliyun
public_repos689
account_age_days5,482

Package maintenance

100Exceptional
How it's scored
25/25Published & resolvable — 2 package(s) on maven, npm
35/35Publish recency — latest publish 16 days ago
20/20Version history — 52 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagescom.aliyun:tea-openapi, @alicloud/openapi-core
ecosystemsmaven, npm
any_deprecatedno
min_days_since_publish16

Engineering Quality

Are baseline engineering and documentation practices in place?

56Moderate · 19% of overall
How it's scored
24/24CI workflows — 8 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
18/20OpenSSF Scorecard: CI-Tests — 19 out of 20 merged PRs checked by a CI test -- score normalized to 9
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
0/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionno

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

50Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.2/2.5CI-Tests — 19 out of 20 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
4.5/7.5Code-Review — Found 19/30 approved changesets -- score normalized to 6
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5License — license file not detected
7.5/7.5Maintained — 17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
3/5SAST — SAST tool is not run on all commits -- score normalized to 6
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 21 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4.4
Excluded from scoring (no data or not applicable): branch_protection, packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
8.1/25Indirect dependencies free of known advisories — 2 affected: net.minidev:json-smart 2.5.0 (high 7.5), org.bouncycastle:bcprov-jdk18on 1.78.1 (high 7.7)
29/40No advisories left outstanding — 2 advisory-carrying package(s) unaddressed past 90 days; oldest published 539 days ago
Inputs used
sourceosv
advisories3
affected_packages2
assessed_packages26
unassessed_packages0
affected_by_severityhigh 2
direct_affected_packages0
Matched the maven:com.aliyun:tea-openapi@0.3.15 runtime dependency closure — what installing the published package pulls in — 26 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

48Weak · 4% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
19.2/40Legible commit history — 36 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.36
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — csharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj, csharp/core/client.csproj, golang/go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — ts/tsconfig.json
10/10Reproducible environment — lockfile
2/10Demonstrated agent practice — 1 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsts/tsconfig.json
agent_commit_share0.01
toolchain_manifestscsharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj, csharp/core/client.csproj, golang/go.mod, java/pom.xml
dependency_bot_commit_share0
How it's scored
27/45Type-checkable code — Python with type-check config (ts/tsconfig.json)
50/55Manageable file sizes — 13/144 source files over 60KB
Inputs used
primary_languagePython
largest_source_bytes196,444
source_files_sampled144
oversized_source_files13

Key facts

21GitHub stars
15contributors
52commits, last 12 months
1days since last push
0releases
1bus factor
19open issues
Go, Maven, npm, Packagist, PyPIpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • go package 'github.com/alibabacloud-go/darabonba-openapi/v2' points at a different repository (https://github.com/alibabacloud-go/darabonba-openapi); excluded from ecosystem scoring
  • packagist package 'alibabacloud/openapi-core' points at a different repository (https://github.com/alibabacloud-sdk-php/openapi-core); excluded from ecosystem scoring

More detail

Star and fork history 0 ★ / 12 ⇿
0Stars
12Forks

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0246810121212020-082023-032025-11

Each point covers 5 days.

OpenSSF Scorecard 4.4 / 10
4.4aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-30 22:21 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
9CI-Tests19 out of 20 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
6Code-ReviewFound 19/30 approved changesets -- score normalized to 6
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
6SASTSAST tool is not run on all commits -- score normalized to 6
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities21 existing vulnerabilities detected
Direct dependencies 20
RegistryPackageVersion constraintManifest
Gogithub.com/alibabacloud-go/alibabacloud-gateway-popv0.0.6golang/go.mod
Gogithub.com/alibabacloud-go/alibabacloud-gateway-spiv0.0.5golang/go.mod
Gogithub.com/alibabacloud-go/teav1.5.2golang/go.mod
Gogithub.com/alibabacloud-go/tea-utils/v2v2.0.9golang/go.mod
Gogithub.com/aliyun/credentials-gov1.4.5golang/go.mod
Gogithub.com/tjfoc/gmsmv1.4.1golang/go.mod
Mavencom.aliyun:tea-util0.2.23java/pom.xml
Mavencom.aliyun:credentials-java0.3.10java/pom.xml
Mavencom.aliyun:openapiutil0.2.1java/pom.xml
Mavencom.aliyun:tea[1.1.14, 2.0.0)java/pom.xml
Mavencom.aliyun:alibabacloud-gateway-spi0.0.2java/pom.xml
Mavencom.aliyun:tea-xml0.1.6java/pom.xml
Mavenorg.jacoco:org.jacoco.agent0.8.4java/pom.xml
Packagistalibabacloud/credentials^1.2.2php/composer.json
Packagistalibabacloud/darabonba^1.0.5php/composer.json
Packagistalibabacloud/gateway-spi^1php/composer.json
npm@alicloud/credentials^2.4.2ts/package.json
npm@alicloud/gateway-pop0.0.6ts/package.json
npm@alicloud/gateway-spi^0.0.8ts/package.json
npm@darabonba/typescript^1.0.5ts/package.json
All dependencies 61

Full resolved dependency set from the GitHub dependency graph: 22 direct and 39 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/alibabacloud-go/alibabacloud-gateway-popv0.0.6direct
Gogithub.com/alibabacloud-go/alibabacloud-gateway-spiv0.0.5direct
Gogithub.com/alibabacloud-go/tea1.1.15direct
Gogithub.com/alibabacloud-go/teav1.5.2direct
Gogithub.com/alibabacloud-go/tea-utils/v2v2.0.9direct
Gogithub.com/aliyun/credentials-go1.1.2direct
Gogithub.com/aliyun/credentials-gov1.4.5direct
Gogithub.com/tjfoc/gmsmv1.4.1direct
Mavencom.aliyun:alibabacloud-gateway-spi0.0.2direct
Mavencom.aliyun:credentials-java0.3.10direct
Mavencom.aliyun:openapiutil0.2.1direct
Mavencom.aliyun:teadirect
Mavencom.aliyun:tea-util0.2.23direct
Mavencom.aliyun:tea-xml0.1.6direct
Mavenorg.jacoco:org.jacoco.agent0.8.4direct
npm@alicloud/credentials^2.4.2direct
npm@alicloud/gateway-pop0.0.6direct
npm@alicloud/gateway-spi^0.0.8direct
npm@darabonba/typescript^1.0.5direct
Packagistalibabacloud/credentialsdirect
Packagistalibabacloud/darabonbadirect
Packagistalibabacloud/gateway-spidirect
Gogithub.com/alibabacloud-go/darabonba-string1.0.0indirect
Gogithub.com/alibabacloud-go/openapi-util0.0.7indirect
Gogithub.com/alibabacloud-go/tea-utils1.3.9indirect
Gogithub.com/niemeyer/pretty0.0.0-20200227124842-a10e7caefd8eindirect
Mavencom.aliyun:alibabacloud-gateway-pop0.0.6indirect
Mavencom.github.tomakehurst:wiremock-standalone2.27.2indirect
Mavenjunit:junit4.13.2indirect
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.6.1indirect
Mavenorg.apache.maven.plugins:maven-gpg-plugin1.6indirect
Mavenorg.apache.maven.plugins:maven-javadoc-plugin3.1.1indirect
Mavenorg.apache.maven.plugins:maven-surefire-plugin2.22.1indirect
Mavenorg.jacoco:jacoco-maven-plugin0.8.4indirect
Mavenorg.sonatype.plugins:nexus-staging-maven-plugin1.6.3indirect
npm@types/mocha^5.2.7indirect
npm@types/node^12.12.26indirect
npmmocha^6.2.0indirect
npmnyc^14.1.1indirect
npmsource-map-support^0.5.16indirect
npmts-node^8.6.2indirect
npmtypescript^3.7.5indirect
NuGetAlibabaCloud.GatewayPop0.1.3indirect
NuGetAlibabaCloud.GatewaySpi0.0.3indirect
NuGetAliyun.Credentials1.5.2indirect
NuGetDarabonba1.0.1indirect
NuGetMicrosoft.NET.Test.Sdk16.11.0indirect
NuGetMicrosoft.NETFramework.ReferenceAssemblies1.0.0-preview.2indirect
NuGetxunit2.1.0indirect
NuGetxunit2.4.2indirect
NuGetxunit.runner.visualstudio2.1.0indirect
NuGetxunit.runner.visualstudio2.4.5indirect
Packagistphpindirect
Packagistphpunit/phpunitindirect
Packagistsymfony/dotenvindirect
Packagistsymfony/var-dumperindirect
PyPIalibabacloud-credentialsindirect
PyPIalibabacloud-gateway-spiindirect
PyPIalibabacloud-tea-utilindirect
PyPIcryptographyindirect
PyPIdarabonba-coreindirect
Dependency advisories 2

Installing maven:com.aliyun:tea-openapi@0.3.15 pulls in 26 packages, direct and transitive: 2 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
net.minidev:json-smart2.5.0indirecthigh12.5.2
org.bouncycastle:bcprov-jdk18on1.78.1indirecthigh21.84

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1498,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "C#": 321638,
        "Go": 337608,
        "C++": 208444,
        "PHP": 202416,
        "Tea": 53026,
        "Java": 164940,
        "Ruby": 1029,
        "CMake": 13120,
        "Swift": 87048,
        "Python": 401250,
        "JavaScript": 914,
        "TypeScript": 217046
      },
      "pushed_at": "2026-07-29T08:59:48Z",
      "created_at": "2020-08-12T08:15:36Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T03:15:54Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "master",
      "license_spdx_raw": null,
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "Go",
        "C#",
        "TypeScript",
        "C++"
      ]
    },
    "owner": {
      "blog": "www.alibabacloud.com",
      "name": "Alibaba Cloud",
      "type": "Organization",
      "login": "aliyun",
      "company": null,
      "location": "Hangzhou.China",
      "followers": 1922,
      "avatar_url": "https://avatars.githubusercontent.com/u/941070?v=4",
      "created_at": "2011-07-27T02:38:58Z",
      "is_verified": null,
      "public_repos": 689,
      "account_age_days": 5482
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "8b916ca848bbdcb8348fceb2fbb65af906cc7aec",
          "body": "* fix: detect throttling by x-acs-retry-after header\n\nTreat any HTTP error response with x-acs-retry-after as throttling\nand use that value for backoff, instead of requiring Code to contain\n\"Throttling\".\n\n* fix: treat non-positive x-acs-retry-after as absent\n\ngetThrottlingTimeLeft now returns null/-\n[…]\n CI for C++ unused getTimeLeft and PHP Dara::isNull\n\nRemove dead getTimeLeft helpers that trip -Werror=unused-function, and\nuse is_null() for retryAfter checks since AlibabaCloud\\Dara has no isNull().",
          "is_bot": false,
          "headline": "fix: detect throttling by x-acs-retry-after header (#283)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-07-21T03:15:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c36a43d950e6d967f9d9fab60e7384d3254f8f31",
          "body": null,
          "is_bot": false,
          "headline": "[tea]Bump 0.1.28",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-07-16T10:30:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbdb58a0df8f657f486e64bd416dd213f84fdffc",
          "body": "Co-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "[python]Bump 0.4.5, [ts]Bump 1.0.8 (#281)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-07-14T08:05:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d735d0695ebc2ce0bf317c0b87eb904c8bc17efd",
          "body": "* feat: add WebSocket protocol support (align golang)\n\n* Add WebSocket support to TypeScript OpenAPI client.\n\nIntroduce websocketUtils for AWAP/general sub-protocols and route ws/wss requests through the tea WebSocket client in doRequest.\n\n* Add WebSocket support to Python OpenAPI client.\n\nPort webs\n[…]\n: point WebSocket deps at published tea packages\n\nTea cores are released (darabonba-core 1.0.8, alibabacloud/darabonba 1.0.5,\n@darabonba/typescript 1.0.5); drop git/VCS CI installs and raise minimums.",
          "is_bot": false,
          "headline": "feat: add WebSocket protocol support (#280)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-07-13T10:04:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e305158ddd7228dea15e624e0a648785d0d67c7",
          "body": "- 移除cmake -G硬编码Visual Studio版本,改为自动检测\n- 新增windows-2022矩阵,同时覆盖VS 2022和最新VS版本\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "fix(ci): Windows CI适配VS版本升级,增加VS 2022覆盖 (#279)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-06-30T08:38:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655d8bda7606f9fd4aba0f5c9c95240bf4374405",
          "body": null,
          "is_bot": false,
          "headline": "update workflow",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-30T06:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ecf57d66e9d2733ab1764e2c7f7b3210dbea15c",
          "body": null,
          "is_bot": false,
          "headline": "update workflows",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-30T04:46:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48387a3dc0c34b0b6e3e2df81975f5879de9ccee",
          "body": null,
          "is_bot": false,
          "headline": "[swift]Bump 1.0.10",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-30T03:54:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3499305ab5ef68fae65aed2fe29233cc491b8afc",
          "body": null,
          "is_bot": false,
          "headline": "fix: resolve backoff delay for retry (#278)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-30T03:02:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da082a3738c05c10c22ad0ad9a0cccd6ed72e3cd",
          "body": "* fix(openapi): 修复 OpenApiRequest 中 body 字段赋值逻辑\n\n- 修正 fromMap 方法中 body 字段的赋值判断,避免 body 被错误污染\n- 只在 dict 包含 body key 时,才对 body 赋值\n- 添加了包含各种情况的单元测试覆盖 body 相关逻辑\n- 新增测试 target AlibabacloudOpenApiTests 并包含对应测试用例\n- 确保 toMap 方法对 body 字段的正确处理与一致性验证\n\n* add swift tests\n\n* Potential fix for pull request finding\n[…]\n版本号\n- 保留代码检出和构建步骤以简化流程\n\n---------\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(openapi): 修复 OpenApiRequest 中 body 字段赋值逻辑 (#277)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-06-29T08:13:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5b369de2481a2271590e916b04dec2c5e9dfe32",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.27",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-24T08:32:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1eecb82023f08d1f94a227939010782af3e2309",
          "body": null,
          "is_bot": false,
          "headline": "fix: rename webSocketClient (#276)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-24T08:09:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb1d2ae2cedbf717e82115b5ce8a36c3c64611fb",
          "body": "* feat: support error detail && retry for throttling\n\n* remove default retry policy\n\n* update\n\n* add testcase\n\n* add test case\n\n* add ci\n\n* fix test cases\n\n* fix test cases\n\n* update\n\n* update\n\n* update\n\n* update",
          "is_bot": false,
          "headline": "feat: support error detail && retry for throttling (#274)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-06-23T08:26:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aca043e300f69dfa573cc473b3b3d6a995ed6aba",
          "body": null,
          "is_bot": false,
          "headline": "fix WebSocketClient validator (#270)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-05-28T03:31:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a27a021e41c69cc425d1a728a81308fbc64dbb77",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.25",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-05-27T08:51:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd3fd33393ccdef381a55d8814d3339a742db2a3",
          "body": null,
          "is_bot": false,
          "headline": "fix websocket client (#269)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-05-27T08:20:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d57fbb99b3e66987cc9b3b00afbe20a4e2dc10c3",
          "body": "* add ws\n\n---------\n\nCo-authored-by: 原根 <mingming.zhumingmi@alibaba-inc.com>\nCo-authored-by: yndu13 <33746446+yndu13@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Websocket (#242)",
          "author_name": "AllyW",
          "author_login": "AllyW",
          "committed_at": "2026-05-26T12:00:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c293756e4df689d0d2ac928b8197287fb9692be6",
          "body": "* refactor(client): 优化连接管理和请求重试逻辑\n\n- 将连接相关参数由 maxIdleConns 改为 maxConnections 和 maxHostConnections\n- 移除 Client 中用于调试的 RPC 头部设置及获取接口\n- 修改请求中合并 headers 的逻辑,去除冗余的条件判断\n- 更新重试循环判断条件,由 allowRetry 改为 shouldRetry\n- 调整请求参数结构,添加 keepAlive 支持\n- 替换依赖仓库地址为 TsinghuaDream 的镜像版本\n\n* 收束到线上包\n\n* config add _maxIdleConns\n\n---------\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "refactor(client): 优化连接管理和请求重试逻辑 (#262)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-04-08T08:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a676355d43fff2b4b803f68f2b087e8849e21201",
          "body": null,
          "is_bot": false,
          "headline": "[python]Bump 0.4.4",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-03-26T10:00:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "711ca5af62a7c282d5c2ebc51d6d1616a499ad25",
          "body": "- 解决cryptography版本兼容性问题和已知漏洞,提高包的安全性\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "fix(python): 修复cryptography依赖版本以适配Python版本 (#264)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-03-26T09:57:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e27af0522138213b3777fc990a96c24340d1fd",
          "body": null,
          "is_bot": false,
          "headline": "fix: resolve ToForm method (#263)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-03-23T13:20:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "190bd3ad79610dc7f676a5e8d3a8a21bda880f1d",
          "body": null,
          "is_bot": false,
          "headline": "support env for user agent (#261)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-03-17T11:45:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73bee68197ca5d0673f93120da86565956344519",
          "body": "- 根据不同操作系统定义默认的os字符串(Windows、Darwin、Linux等)\n- 根据不同架构定义arch字符串(x86_64、i386、aarch64、arm等)\n- 组合生成格式为\"AlibabaCloud (os; arch) C++/版本 TeaDSL/2\"的UserAgent\n- 修改getUserAgent函数使用新默认UserAgent生成逻辑替代固定字符串\n- 提升UserAgent信息的准确性和辨识度\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "feat(utils): 添加默认UserAgent生成方法 (#259)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-03-04T12:53:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c3f1a1f8f7c192cfe97ce6d5a405449dc0636d3",
          "body": "- 将编译选项从全局 add_compile_options 改为 target_compile_options\n  解决 D9025 警告(/W3 与 /W4 冲突),避免影响外部依赖库\n- 为 Windows MSVC 预创建多配置目录(Debug/Release等)\n  解决 DLL 复制到不存在的 Release/ 目录失败的问题\n- 添加 static_cast<int>() 显式类型转换\n  解决 C4267 警告(size_t 到 int 的隐式转换)\n\nfix(cpp): 修复Windows MSVC构建问题\n\n- CI 使用 Visual Studio 生成器替代 Ninja,消除 D9025 警告\n- 为 MSVC 预创建多配置目录,防止 DLL 复制失败\n- 为 alibabacloud_credentials 添加 CMAKE_SKIP_INSTALL_RULES\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "fix(cpp): 修复Windows MSVC构建问题 (#258)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-02-28T09:05:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "297171c34d012f4a32a773cb9aff3ca3aadc074b",
          "body": "* refactor(cpp): 重构build系统和代码依赖以提升兼容性和维护性\n\n- 将CMake最低版本要求更新至3.13,改进编译选项管理和平台兼容性\n- 统一并优化Windows和类Unix系统的编译和链接配置\n- 采用位置无关代码(PIC),支持静态与动态库灵活构建\n- 调整依赖库alibabacloud_credential为alibabacloud_credentials,并更新相关CMakeLists\n- 移除冗余依赖检测逻辑,改用更简洁有效的外部库查找和链接方式\n- 规范并增强库目标属性和安装规则,改进CMake配置文件生成与导出\n- 替换代码中Credential相关引用\n[…]\n列化对应字段\n- 移除多余的_lastRequest及_lastResponse成员变量及相关赋值,简化代码逻辑\n- 修正部分错误消息和描述字段的拼接,使日志信息更准确和一致\n- 统一处理访问被拒绝详情accessDeniedDetail的JSON获取方式,增强健壮性\n\n---------\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "refactor(cpp): 重构build系统和代码依赖以提升兼容性和维护性 (#255)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-02-10T12:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d0cf49cb076b859a5f5969d8902c813da037584",
          "body": null,
          "is_bot": false,
          "headline": "fix: resolve response body type in execute (#256)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-02-10T09:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54ac32bd74c6faf50c1be923214266f0c069c478",
          "body": null,
          "is_bot": false,
          "headline": "[ts]Bump 1.0.7",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-01-15T07:56:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84518a2e7de3c03f061230538e83b06dbccedf20",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.24",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-01-15T07:54:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed224cfed9fda5d9494c1cc7513599d3bdbe4d12",
          "body": null,
          "is_bot": false,
          "headline": "update go.sum",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2026-01-15T07:01:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "027610a5218919d9713762fdbe97adcd94180ba2",
          "body": null,
          "is_bot": false,
          "headline": "Feat: add mapToFlatStyle method(#253)",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2026-01-15T06:47:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46753daa608b1553f544ee3b85479b604235b050",
          "body": null,
          "is_bot": false,
          "headline": "Feat: fix getter",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2026-01-09T11:26:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fdbc78d5af212f16e3f80495a35f9a1e599fbc6",
          "body": null,
          "is_bot": false,
          "headline": "Feat: init darabonba-openapi v2",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2026-01-09T11:26:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b921aa9e7d26ca1ebb1667d33b2f85f16953722",
          "body": null,
          "is_bot": false,
          "headline": "fix: update user agent and coreVersion (#249)",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-12-30T07:35:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95d71874c92944d0a0bbe446bffc13db8a1ce24d",
          "body": null,
          "is_bot": false,
          "headline": "[csharp]Bump 0.2.1 (#248)",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-12-30T07:17:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb0c61f245a5f19adcbfe000ad17f6b1a26f3773",
          "body": "* refactor: resolve endpoints and exception\n\n* Feat: fix tests\n\n* Feat: tests support PHPUnit 5.7\n\n* Feat: rm return null for support php5.6\n\n* Fix (ci): Restrict CI workflow trigger path\n-Add path filtering to CI workflows for Go, Java, PHP, Python, and Node.js, triggering only when the correspondi\n[…]\n and RetryCondition in test cases to enhance the coverage of retry strategy testing\n\n* fix test\n\n* Feat: rm retry for sse\n\n* fix tests\n\n---------\n\nCo-authored-by: weeping <xwp01146046@alibaba-inc.com>",
          "is_bot": false,
          "headline": "refactor: resolve endpoints and exception (#247)",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-12-30T03:04:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c83a19be813823fe1057d9d7c3f69062ab913bea",
          "body": null,
          "is_bot": false,
          "headline": "feat: support CallSSEApi method",
          "author_name": "飞澋",
          "author_login": null,
          "committed_at": "2025-12-29T09:57:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d722210e9dda1f0b3d287a3311608d0d5adf762e",
          "body": null,
          "is_bot": false,
          "headline": "[python]Bump 0.4.2",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-11-21T10:10:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aded579b69cf1a6981eaa74d6b07b1023cf02aa",
          "body": null,
          "is_bot": false,
          "headline": "Fix: add function default_any",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-11-21T10:08:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ccdf841881f430450831071567245f0f4324b2d",
          "body": null,
          "is_bot": false,
          "headline": "[ts]Bump 1.0.6",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-11-07T03:26:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43882527c87b78a19bf46ad6f96bf80ad15fa7da",
          "body": null,
          "is_bot": false,
          "headline": "Use version ^2.4.2",
          "author_name": "Nils Neumann",
          "author_login": "Neumann-Nils",
          "committed_at": "2025-11-07T03:23:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d1e07f03a09193aef1f53323eac71a46e1d4301",
          "body": null,
          "is_bot": false,
          "headline": " Use version \"^2.4.4\" for \"@alicloud/tea-typescript\"",
          "author_name": "Nils Neumann",
          "author_login": "Neumann-Nils",
          "committed_at": "2025-11-07T03:23:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09ed68f43d8cf73b4bdec9f5957e6997939d4a2a",
          "body": null,
          "is_bot": false,
          "headline": "fix: upgrade csharp AlibabaCloud.OpenApiClient to v2",
          "author_name": "飞澋",
          "author_login": null,
          "committed_at": "2025-10-23T03:59:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "375f4833f2ff200a97370894d61f242d787ef0b8",
          "body": null,
          "is_bot": false,
          "headline": "[swift]Bump 1.0.9",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-10-19T07:47:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1aaf90d56303bac816399758983049bca5752091",
          "body": null,
          "is_bot": false,
          "headline": "Update tea version for golang sdk",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2025-10-16T06:42:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e9bcd1be07a12526670e30cb18d02704c125cc6",
          "body": null,
          "is_bot": false,
          "headline": "Feat: support idleTimeout",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2025-10-13T03:44:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c0d0cf14bbf5a31f11f46cdf4f5268a950b8b4b",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.22",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2025-09-12T02:15:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "463507c861baaa03318f36943048c2cc599cf815",
          "body": null,
          "is_bot": false,
          "headline": "fix golang callSSEApi",
          "author_name": "weeping",
          "author_login": null,
          "committed_at": "2025-09-11T10:24:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44eb1b24b68d8023a3b42481eb582148cc682c2a",
          "body": null,
          "is_bot": false,
          "headline": "update the go core",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-08-20T03:11:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3a16a8d516769dbbb41b7f5d88ea5cc34e795d6",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.20",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-08-12T06:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e34d94fb932bb9f5ef7478dc4a820b85ed368480",
          "body": null,
          "is_bot": false,
          "headline": "Fix: python sse",
          "author_name": "weeping",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-08-12T06:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5900c341bb110863dc85e8e21da7030d28730c6f",
          "body": null,
          "is_bot": false,
          "headline": "[Tea]Bump 0.1.19",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-08-11T06:24:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c271e2a3a2f00bede3e5337cbe1c999c9efe2e9f",
          "body": null,
          "is_bot": false,
          "headline": "feat: recodegen from v1",
          "author_name": "yndu13",
          "author_login": "yndu13",
          "committed_at": "2025-08-11T06:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c8b9e89cc8e0c32e619d1114d95a395418bd7e0",
          "body": null,
          "is_bot": false,
          "headline": "fix: add params.validate",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67a688898ca73627cf9cd3aa7bc85da540b2f409",
          "body": null,
          "is_bot": false,
          "headline": "fix: add idtoken in credentials",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba9f248d815309cb8f99cb9e1a8d29fa00e61d15",
          "body": null,
          "is_bot": false,
          "headline": "fix: comment out flatMap and update main.tea",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1f35b65d9d2d6b8cfd7d1776a39a0b5124ac173",
          "body": null,
          "is_bot": false,
          "headline": "fix: merge fix in 1.x: attributeMap",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2e8b80e6ae876777fe4c5e4f4c578d0ea5fb970",
          "body": null,
          "is_bot": false,
          "headline": "fix: darabonba.runtime to darabonba.models",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea1047ef271b4f69593013926a995aae93025094",
          "body": null,
          "is_bot": false,
          "headline": "fix",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1f25d8a7718b5a96428cf842e9fcdb41dde2b95",
          "body": null,
          "is_bot": false,
          "headline": "fix",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9bee363b20ab8b251fcb01ed6db7e9a09f23585",
          "body": null,
          "is_bot": false,
          "headline": "feat: csharp v2",
          "author_name": "飞澋",
          "author_login": null,
          "committed_at": "2025-08-11T02:38:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "947df6aac9d8727213ccc39f7802f15b0f3b72f9",
          "body": null,
          "is_bot": false,
          "headline": "add go context",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-07-23T12:13:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "560b300e20a6406f366eedcf5cfde061bb46544b",
          "body": null,
          "is_bot": false,
          "headline": "add alibabacloud_tea_util",
          "author_name": "weeping",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-07-23T08:54:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06b0dd864f5728f57b30bee97bb0510052190286",
          "body": null,
          "is_bot": false,
          "headline": "Update Teafile",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-07-10T07:52:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17b259bc84832004134b82f694d0c12882a579fa",
          "body": null,
          "is_bot": false,
          "headline": "Update Teafile",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-07-04T02:50:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c9fe2777c68cce8b45c50e52b320ff6e6a9577e",
          "body": null,
          "is_bot": false,
          "headline": "Update Teafile",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-07-02T11:36:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87c81be573e59f982be40908131ebc92168fae01",
          "body": null,
          "is_bot": false,
          "headline": "release python 0.4.0rc4",
          "author_name": "weeping",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-06-09T09:46:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ca9bc011734b1f005b1e042de893df44f1acc98",
          "body": null,
          "is_bot": false,
          "headline": "fix setup.py",
          "author_name": "weeping",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-06-09T08:47:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "781908350e71c9a0d07da66824f8fb1c4c957f34",
          "body": null,
          "is_bot": false,
          "headline": "Bump 1.0.8",
          "author_name": "nanhe",
          "author_login": "yndu13",
          "committed_at": "2025-05-15T09:47:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b1d2060a3716981d5c4b2617ea1f06c1b2144f2",
          "body": null,
          "is_bot": false,
          "headline": "feat: codegen swift",
          "author_name": "nanhe",
          "author_login": "yndu13",
          "committed_at": "2025-05-15T09:47:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5acc2a5973ee0f4d232b484b8a853e34fd8dd89",
          "body": null,
          "is_bot": false,
          "headline": "[ts]Bump 1.0.4",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-05-15T09:46:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aca809cc343bf7732c2238930ed9190cc90682f1",
          "body": null,
          "is_bot": false,
          "headline": "add tls in config",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-05-06T06:06:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8891159b76ddb1091370c512ab58dec3b0e9a2ed",
          "body": null,
          "is_bot": false,
          "headline": "fix php endpoint",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-29T11:51:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "343f37e7303ef14d845dac911e9d87743a659ab4",
          "body": null,
          "is_bot": false,
          "headline": "Bump [ts]1.0.3",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-29T11:51:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "382b743974be8a589bea4c5abbe4e01e21d4bcc2",
          "body": null,
          "is_bot": false,
          "headline": "Updata README.md",
          "author_name": "weeping",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-04-29T04:13:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e222dbf019342791836e6af21a6262624b20598",
          "body": null,
          "is_bot": false,
          "headline": "improve golang dir structure",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-28T11:29:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7f10dab724b4a8ce30ad73be021dc5a66b88f31",
          "body": null,
          "is_bot": false,
          "headline": "improve the ts dir structure",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-28T11:29:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a25be5fff95967e6ab14246304a3ec9dccbd230",
          "body": null,
          "is_bot": false,
          "headline": "fix the arrTostring",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-27T08:58:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef4a89827fe8fab89521669c7ad35d90b8c30669",
          "body": null,
          "is_bot": false,
          "headline": "[python]Bump 0.4.0rc3",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-16T06:01:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e95fa647c5d2caabc001b6b7ab732e83dd568555",
          "body": null,
          "is_bot": false,
          "headline": "feat: update from v1",
          "author_name": "nanhe",
          "author_login": "yndu13",
          "committed_at": "2025-04-16T05:55:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52c9b8bbff939d166c965aadf8765b1c49815814",
          "body": null,
          "is_bot": false,
          "headline": "change model & exception dir",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-15T13:36:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ed7d42186cb50cdbfcf8595f54f8a3af9a7287f",
          "body": null,
          "is_bot": false,
          "headline": "update python version",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-10T03:33:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "272ee5c10dc2b367c899472c8296921f4038243b",
          "body": null,
          "is_bot": false,
          "headline": "Update utils_models.py",
          "author_name": "WenPing",
          "author_login": "TsinghuaDream",
          "committed_at": "2025-04-10T03:13:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b4ccaa09bceb8d089c311abac99dfe0e294e74b",
          "body": null,
          "is_bot": false,
          "headline": "[golang]Bump 2.1.7",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-07T10:04:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82dbff80a3658a284bc434664f3ea42bdd65f6cf",
          "body": null,
          "is_bot": false,
          "headline": "fix the useragent",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-07T03:38:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0549b658c986a73cbba53c91584a29529852cef0",
          "body": null,
          "is_bot": false,
          "headline": "[Python]Bump 0.4.0rc1",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-03T02:12:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fcf2abc7625fbebb72d6221ef4f2af70dba9848",
          "body": null,
          "is_bot": false,
          "headline": "update dsl to compatible with old core",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-03T02:12:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95248fb0ab55f0b8b84a5e03a1ae79dc1cedaaa5",
          "body": null,
          "is_bot": false,
          "headline": "upgrade python by darbaonba v2",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-04-03T02:12:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e1a235316028b987cbbcd7d4b97259a7d359838",
          "body": null,
          "is_bot": false,
          "headline": "fix err & add httpclient",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-27T08:55:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b47463985594de569e89e66433376d85df663f6a",
          "body": null,
          "is_bot": false,
          "headline": "fix: add exports for csharp in teafile",
          "author_name": "PanPanZou",
          "author_login": "PanPanZou",
          "committed_at": "2025-03-26T10:00:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb65ba4b150c07982b6038ffce36a90da78c8665",
          "body": null,
          "is_bot": false,
          "headline": "Update go.mod",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-03-25T07:26:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7de17f71f2916f9dcba54109bca8de4bdd0aa0dd",
          "body": null,
          "is_bot": false,
          "headline": "add stringify map val",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-13T06:48:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75f45494a3cd2c3e0b2366909445e35b25afab37",
          "body": null,
          "is_bot": false,
          "headline": "add to array",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-12T07:30:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d07ce73ab2aae7a83516cc3751d01310b9376bb",
          "body": null,
          "is_bot": false,
          "headline": "[tea]Bump 0.1.4",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-04T08:08:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "effa79a48fd72bad71ac534ac5b7c1054d808274",
          "body": null,
          "is_bot": false,
          "headline": "[ts]Bump 1.0.2",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-04T07:32:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52063e41bba1b35718b242291d4521d238d26347",
          "body": "Fix credential check",
          "is_bot": false,
          "headline": "Merge pull request #182 from aliyun/fix-credential-check",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-03-04T07:26:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa8e58f530426939df629ca43528ab92839cb67c",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'master' into fix-credential-check",
          "author_name": "page",
          "author_login": "peze",
          "committed_at": "2025-03-04T06:02:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "591efd7604a462d9ac922261949c9425cf7f2d17",
          "body": null,
          "is_bot": false,
          "headline": "fix the credential check",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-04T05:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f764853313a601de74e8254603be7ba2dd1b605",
          "body": null,
          "is_bot": false,
          "headline": "add getEndpoint in go utils",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-03T14:02:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9b177a8ce30934152388cabff9c9f9553acaa93",
          "body": null,
          "is_bot": false,
          "headline": "add getEndpoint in go utils",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-03T13:55:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d30d0ae3ebb4718118ea7b3c3fdd25b6d2a7d7d9",
          "body": null,
          "is_bot": false,
          "headline": "[tea]Bump 0.1.2",
          "author_name": "peze",
          "author_login": "peze",
          "committed_at": "2025-03-03T07:55:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 52,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 24,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 12,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "com.aliyun:tea-openapi",
          "exists": true,
          "license": "The Apache License, Version 2.0",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/com.aliyun/tea-openapi",
          "is_deprecated": false,
          "latest_version": "0.3.15",
          "repository_url": "https://github.com/aliyun/darabonba-openapi",
          "versions_count": 52,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-08T06:07:16Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 52
        },
        {
          "name": "github.com/alibabacloud-go/darabonba-openapi/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": false,
          "registry_url": "https://pkg.go.dev/github.com/alibabacloud-go/darabonba-openapi/v2",
          "is_deprecated": false,
          "latest_version": "v2.2.4",
          "repository_url": "https://github.com/alibabacloud-go/darabonba-openapi",
          "versions_count": 35,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-30T03:02:01Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 30
        },
        {
          "name": "@alicloud/openapi-core",
          "exists": true,
          "license": "ISC",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@alicloud/openapi-core",
          "is_deprecated": false,
          "latest_version": "1.0.8",
          "repository_url": "https://github.com/aliyun/darabonba-openapi",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 5,
          "monthly_downloads": 259506,
          "first_published_at": "2025-01-09T12:34:37.278000Z",
          "latest_published_at": "2026-07-14T13:26:29.609000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 16
        },
        {
          "name": "alibabacloud/openapi-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": false,
          "registry_url": "https://packagist.org/packages/alibabacloud/openapi-core",
          "is_deprecated": false,
          "latest_version": "1.0.10",
          "repository_url": "https://github.com/alibabacloud-sdk-php/openapi-core",
          "versions_count": 11,
          "total_downloads": 260107,
          "dependents_count": 383,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 25698,
          "first_published_at": null,
          "latest_published_at": "2026-07-13T10:04:10Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 17
        }
      ]
    },
    "popularity": {
      "forks": 12,
      "stars": 21,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2020-08-14",
            "count": 1
          },
          {
            "date": "2021-02-08",
            "count": 1
          },
          {
            "date": "2021-07-07",
            "count": 1
          },
          {
            "date": "2021-07-16",
            "count": 1
          },
          {
            "date": "2022-09-18",
            "count": 1
          },
          {
            "date": "2023-04-28",
            "count": 1
          },
          {
            "date": "2024-03-21",
            "count": 1
          },
          {
            "date": "2025-02-18",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-08-25",
            "count": 1
          },
          {
            "date": "2025-11-06",
            "count": 1
          },
          {
            "date": "2025-11-13",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 12,
        "total_forks": 12
      },
      "star_history": null,
      "open_issues_and_prs": 29
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "ts/tsconfig.json"
      ],
      "toolchain_manifests": [
        "csharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj",
        "csharp/core/client.csproj",
        "golang/go.mod",
        "java/pom.xml"
      ],
      "largest_source_bytes": 196444,
      "source_files_sampled": 144,
      "oversized_source_files": 13,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "golang/go.mod",
        "java/pom.xml",
        "php/composer.json",
        "python/setup.py",
        "ts/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "net.minidev:json-smart",
            "direct": false,
            "version": "2.5.0",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-pq2g-wx69-c263"
            ],
            "fixed_version": "2.5.2",
            "advisory_count": 1,
            "oldest_advisory_days": 539
          },
          {
            "name": "org.bouncycastle:bcprov-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.7,
            "advisory_ids": [
              "GHSA-574f-3g2m-x479",
              "GHSA-c3fc-8qff-9hwx"
            ],
            "fixed_version": "1.84",
            "advisory_count": 2,
            "oldest_advisory_days": 104
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2
        },
        "advisory_count": 3,
        "affected_count": 2,
        "assessed_count": 26,
        "malicious_count": 0,
        "assessed_package": "maven:com.aliyun:tea-openapi@0.3.15",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "maven",
        "npm",
        "packagist",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "github.com/alibabacloud-go/alibabacloud-gateway-pop",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.6"
        },
        {
          "name": "github.com/alibabacloud-go/alibabacloud-gateway-spi",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.5"
        },
        {
          "name": "github.com/alibabacloud-go/tea",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.2"
        },
        {
          "name": "github.com/alibabacloud-go/tea-utils/v2",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.9"
        },
        {
          "name": "github.com/aliyun/credentials-go",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.5"
        },
        {
          "name": "github.com/tjfoc/gmsm",
          "manifest": "golang/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.1"
        },
        {
          "name": "com.aliyun:tea-util",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.2.23"
        },
        {
          "name": "com.aliyun:credentials-java",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.10"
        },
        {
          "name": "com.aliyun:openapiutil",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.2.1"
        },
        {
          "name": "com.aliyun:tea",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "[1.1.14, 2.0.0)"
        },
        {
          "name": "com.aliyun:alibabacloud-gateway-spi",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.0.2"
        },
        {
          "name": "com.aliyun:tea-xml",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.1.6"
        },
        {
          "name": "org.jacoco:org.jacoco.agent",
          "manifest": "java/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.8.4"
        },
        {
          "name": "alibabacloud/credentials",
          "manifest": "php/composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.2.2"
        },
        {
          "name": "alibabacloud/darabonba",
          "manifest": "php/composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0.5"
        },
        {
          "name": "alibabacloud/gateway-spi",
          "manifest": "php/composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1"
        },
        {
          "name": "@alicloud/credentials",
          "manifest": "ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.2"
        },
        {
          "name": "@alicloud/gateway-pop",
          "manifest": "ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.0.6"
        },
        {
          "name": "@alicloud/gateway-spi",
          "manifest": "ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.0.8"
        },
        {
          "name": "@darabonba/typescript",
          "manifest": "ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.5"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/alibabacloud-go/alibabacloud-gateway-pop",
            "direct": true,
            "version": "v0.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/alibabacloud-gateway-spi",
            "direct": true,
            "version": "v0.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea",
            "direct": true,
            "version": "1.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea",
            "direct": true,
            "version": "v1.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea-utils/v2",
            "direct": true,
            "version": "v2.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/credentials-go",
            "direct": true,
            "version": "1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/credentials-go",
            "direct": true,
            "version": "v1.4.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tjfoc/gmsm",
            "direct": true,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "com.aliyun:alibabacloud-gateway-spi",
            "direct": true,
            "version": "0.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "com.aliyun:credentials-java",
            "direct": true,
            "version": "0.3.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.aliyun:openapiutil",
            "direct": true,
            "version": "0.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.aliyun:tea",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.aliyun:tea-util",
            "direct": true,
            "version": "0.2.23",
            "ecosystem": "maven"
          },
          {
            "name": "com.aliyun:tea-xml",
            "direct": true,
            "version": "0.1.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.jacoco:org.jacoco.agent",
            "direct": true,
            "version": "0.8.4",
            "ecosystem": "maven"
          },
          {
            "name": "@alicloud/credentials",
            "direct": true,
            "version": "^2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@alicloud/gateway-pop",
            "direct": true,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@alicloud/gateway-spi",
            "direct": true,
            "version": "^0.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@darabonba/typescript",
            "direct": true,
            "version": "^1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "alibabacloud/credentials",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "alibabacloud/darabonba",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "alibabacloud/gateway-spi",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-string",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/openapi-util",
            "direct": false,
            "version": "0.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea-utils",
            "direct": false,
            "version": "1.3.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/niemeyer/pretty",
            "direct": false,
            "version": "0.0.0-20200227124842-a10e7caefd8e",
            "ecosystem": "go"
          },
          {
            "name": "com.aliyun:alibabacloud-gateway-pop",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "maven"
          },
          {
            "name": "com.github.tomakehurst:wiremock-standalone",
            "direct": false,
            "version": "2.27.2",
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": "4.13.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": "1.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": "2.22.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.jacoco:jacoco-maven-plugin",
            "direct": false,
            "version": "0.8.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.sonatype.plugins:nexus-staging-maven-plugin",
            "direct": false,
            "version": "1.6.3",
            "ecosystem": "maven"
          },
          {
            "name": "@types/mocha",
            "direct": false,
            "version": "^5.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^12.12.26",
            "ecosystem": "npm"
          },
          {
            "name": "mocha",
            "direct": false,
            "version": "^6.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "nyc",
            "direct": false,
            "version": "^14.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "^0.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "ts-node",
            "direct": false,
            "version": "^8.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^3.7.5",
            "ecosystem": "npm"
          },
          {
            "name": "AlibabaCloud.GatewayPop",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "nuget"
          },
          {
            "name": "AlibabaCloud.GatewaySpi",
            "direct": false,
            "version": "0.0.3",
            "ecosystem": "nuget"
          },
          {
            "name": "Aliyun.Credentials",
            "direct": false,
            "version": "1.5.2",
            "ecosystem": "nuget"
          },
          {
            "name": "Darabonba",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "nuget"
          },
          {
            "name": "Microsoft.NET.Test.Sdk",
            "direct": false,
            "version": "16.11.0",
            "ecosystem": "nuget"
          },
          {
            "name": "Microsoft.NETFramework.ReferenceAssemblies",
            "direct": false,
            "version": "1.0.0-preview.2",
            "ecosystem": "nuget"
          },
          {
            "name": "xunit",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "nuget"
          },
          {
            "name": "xunit",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "nuget"
          },
          {
            "name": "xunit.runner.visualstudio",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "nuget"
          },
          {
            "name": "xunit.runner.visualstudio",
            "direct": false,
            "version": "2.4.5",
            "ecosystem": "nuget"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpunit/phpunit",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/dotenv",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/var-dumper",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "alibabacloud-credentials",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "alibabacloud-gateway-spi",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "alibabacloud-tea-util",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "darabonba-core",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 61,
        "direct_count": 22,
        "indirect_count": 39
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 221,
        "open_issues": 19,
        "closed_ratio": 0.424,
        "closed_issues": 14,
        "closed_unmerged_prs": 21
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "yndu13",
          "commits": 165,
          "avatar_url": "https://avatars.githubusercontent.com/u/33746446?v=4"
        },
        {
          "type": "User",
          "login": "peze",
          "commits": 52,
          "avatar_url": "https://avatars.githubusercontent.com/u/4003467?v=4"
        },
        {
          "type": "User",
          "login": "wenzuochao",
          "commits": 20,
          "avatar_url": "https://avatars.githubusercontent.com/u/46237635?v=4"
        },
        {
          "type": "User",
          "login": "TsinghuaDream",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/43798276?v=4"
        },
        {
          "type": "User",
          "login": "atptro",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/35919368?v=4"
        },
        {
          "type": "User",
          "login": "Orisdaddy",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/44864234?v=4"
        },
        {
          "type": "User",
          "login": "liaoyustudent",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/22883768?v=4"
        },
        {
          "type": "User",
          "login": "PanPanZou",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/60998291?v=4"
        },
        {
          "type": "User",
          "login": "JacksonTian",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/327019?v=4"
        },
        {
          "type": "User",
          "login": "Neumann-Nils",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/8270077?v=4"
        }
      ],
      "contributors_sampled": 15,
      "top_contributor_share": 0.512
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "cpp.yml",
        "csharp.yml",
        "go.yml",
        "java.yml",
        "php.yml",
        "python.yml",
        "swift.yml",
        "ts.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "19 out of 20 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 6,
            "reason": "Found 19/30 approved changesets -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 6,
            "reason": "SAST tool is not run on all commits -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "21 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8b916ca848bbdcb8348fceb2fbb65af906cc7aec",
        "ran_at": "2026-07-30T22:21:10Z",
        "aggregate_score": 4.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T18:53:15Z",
      "oldest_open_prs": [
        {
          "number": 116,
          "created_at": "2022-07-05T10:42:37Z",
          "last_comment_at": "2022-07-15T08:52:26Z",
          "last_comment_author": "codecov-commenter"
        },
        {
          "number": 145,
          "created_at": "2024-03-20T06:50:01Z",
          "last_comment_at": "2024-03-20T06:50:33Z",
          "last_comment_author": "codecov-commenter"
        },
        {
          "number": 146,
          "created_at": "2024-03-21T12:25:51Z",
          "last_comment_at": "2024-08-21T13:45:09Z",
          "last_comment_author": "JacksonTian"
        },
        {
          "number": 148,
          "created_at": "2024-05-28T05:46:48Z",
          "last_comment_at": "2024-06-05T08:26:49Z",
          "last_comment_author": "codecov-commenter"
        },
        {
          "number": 160,
          "created_at": "2024-07-15T14:59:31Z",
          "last_comment_at": "2024-07-15T15:00:34Z",
          "last_comment_author": "codecov-commenter"
        },
        {
          "number": 235,
          "created_at": "2025-10-22T07:37:08Z",
          "last_comment_at": "2025-10-22T07:40:12Z",
          "last_comment_author": "CLAassistant"
        },
        {
          "number": 251,
          "created_at": "2026-01-10T12:42:35Z",
          "last_comment_at": "2026-01-10T12:42:42Z",
          "last_comment_author": "CLAassistant"
        },
        {
          "number": 282,
          "created_at": "2026-07-20T11:52:50Z",
          "last_comment_at": "2026-07-23T08:46:03Z",
          "last_comment_author": "yndu13"
        },
        {
          "number": 284,
          "created_at": "2026-07-21T08:16:21Z",
          "last_comment_at": "2026-07-21T08:21:28Z",
          "last_comment_author": "codecov-commenter"
        },
        {
          "number": 285,
          "created_at": "2026-07-29T07:08:43Z",
          "last_comment_at": "2026-07-29T07:11:03Z",
          "last_comment_author": "codecov-commenter"
        }
      ],
      "last_merged_pr_at": "2026-07-21T03:15:48Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 125,
          "created_at": "2022-10-21T02:02:26Z",
          "last_comment_at": "2024-09-13T07:19:34Z",
          "last_comment_author": "JacksonTian"
        },
        {
          "number": 133,
          "created_at": "2023-05-26T14:14:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 134,
          "created_at": "2023-06-13T15:46:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 136,
          "created_at": "2023-09-15T06:19:38Z",
          "last_comment_at": "2023-11-23T07:12:18Z",
          "last_comment_author": "yndu13"
        },
        {
          "number": 140,
          "created_at": "2024-01-25T11:55:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 159,
          "created_at": "2024-07-15T14:06:32Z",
          "last_comment_at": "2024-09-13T07:19:00Z",
          "last_comment_author": "JacksonTian"
        },
        {
          "number": 169,
          "created_at": "2024-10-15T05:50:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 171,
          "created_at": "2024-11-16T13:48:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 172,
          "created_at": "2024-11-26T13:23:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 177,
          "created_at": "2025-02-17T02:23:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 206,
          "created_at": "2025-04-23T06:22:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 215,
          "created_at": "2025-05-21T02:44:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 218,
          "created_at": "2025-06-09T18:30:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 221,
          "created_at": "2025-07-04T05:34:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 225,
          "created_at": "2025-07-22T09:06:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 238,
          "created_at": "2025-11-15T03:08:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 260,
          "created_at": "2026-03-11T02:06:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 266,
          "created_at": "2026-05-07T03:31:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 275,
          "created_at": "2026-06-23T10:12:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/aliyun/darabonba-openapi",
    "host": "github.com",
    "name": "darabonba-openapi",
    "owner": "aliyun"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 54 is calibrated to 56 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 54,
            "calibrated": 56,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 56,
      "inputs": {
        "security": 50,
        "vitality": 47,
        "community": 44,
        "governance": 68,
        "calibration": "2026-08-02",
        "engineering": 56,
        "ai_readiness": 48,
        "weighted_overall_raw": 54
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "weak",
        "name": "Vitality",
        "value": 47,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 52,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "52 commits in the last year",
                "points": 15.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 52
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 13,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 13 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "forks": 12,
              "stars": 21,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "21 stars",
                "points": 21.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "12 forks",
                "points": 8.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "readme_badges": null,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 90,
            "inputs": {
              "packages": [
                "com.aliyun:tea-openapi",
                "@alicloud/openapi-core"
              ],
              "dependents": null,
              "ecosystems": "maven, npm",
              "total_downloads": null,
              "monthly_downloads": 259506
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "259,506 downloads/month across maven, npm",
                "points": 72.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 259506,
                      "ecosystems": "maven, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 68,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "weak",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 15,
              "top_contributor_share": 0.512
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 51% of commits",
                "points": 11,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 51
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "15 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "merged_prs": 221,
              "open_issues": 19,
              "closed_issues": 14,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.424,
              "closed_unmerged_prs": 21,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "42% of issues closed",
                "points": 17.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 42
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "221/242 decided PRs merged",
                "points": 27.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 221,
                      "decided": 242
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 19/30 approved changesets -- score normalized to 6",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "followers": 1922,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "aliyun",
              "public_repos": 689,
              "account_age_days": 5482
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,922 followers of aliyun",
                "points": 23.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1922,
                      "login": "aliyun"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "689 public repos, account ~15 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 689
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "com.aliyun:tea-openapi",
                "@alicloud/openapi-core"
              ],
              "ecosystems": "maven, npm",
              "any_deprecated": false,
              "min_days_since_publish": 16
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on maven, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "maven, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 16 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "52 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 52
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 56,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "19 out of 20 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "weak",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 50,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "19 out of 20 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 19/30 approved changesets -- score normalized to 6",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "17 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "21 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the maven:com.aliyun:tea-openapi@0.3.15 runtime dependency closure — what installing the published package pulls in — 26 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:com.aliyun:tea-openapi@0.3.15",
                  "assessed": 26
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "source": "osv",
              "advisories": 3,
              "affected_packages": 2,
              "assessed_packages": 26,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "2 affected: net.minidev:json-smart 2.5.0 (high 7.5), org.bouncycastle:bcprov-jdk18on 1.78.1 (high 7.7)",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "net.minidev:json-smart 2.5.0 (high 7.5), org.bouncycastle:bcprov-jdk18on 1.78.1 (high 7.7)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "2 advisory-carrying package(s) unaddressed past 90 days; oldest published 539 days ago",
                "points": 29,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 2,
                      "oldest": 539
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 26,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "weak",
        "name": "AI Readiness",
        "value": 48,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 19,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.36,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "36 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 36,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "ts/tsconfig.json"
              ],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [
                "csharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj",
                "csharp/core/client.csproj",
                "golang/go.mod",
                "java/pom.xml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "csharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj, csharp/core/client.csproj, golang/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "csharp/OpenApiClientUnitTests/OpenApiClientUnitTests.csproj, csharp/core/client.csproj, golang/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "ts/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "ts/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 196444,
              "source_files_sampled": 144,
              "oversized_source_files": 13
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (ts/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "ts/tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "13/144 source files over 60KB",
                "points": 50,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 144,
                      "oversized": 13
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "library"
      ],
      "scores": {
        "library": 12
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:maven",
          "weight": 6
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "go package 'github.com/alibabacloud-go/darabonba-openapi/v2' points at a different repository (https://github.com/alibabacloud-go/darabonba-openapi); excluded from ecosystem scoring",
    "packagist package 'alibabacloud/openapi-core' points at a different repository (https://github.com/alibabacloud-sdk-php/openapi-core); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T22:21:30.433699Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/aliyun/darabonba-openapi.svg",
  "full_name": "aliyun/darabonba-openapi",
  "license_state": "absent",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.3.1, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsMaven, Go, npm, Packagist.