Public record
Software health reportschema 0.23.0 · metrics 1.13.0 · 2026-07-21 20:38 UTC

cisco-open / forge

ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.

HCL · PythonApache-2.0★ 210 stars⑂ 9 forkssince May 2025View on GitHub ↗

cisco-open/forge holds a health index of 78 out of 100, placing it in the Good band. It scores highest on Vitality (96/100) and lowest on Sustainability & Governance (55/100). It was last updated today. A single contributor accounts for most of its recent work.

78
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

78
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

CiscoOrganization
462 followers120 public repossince Dec 2021

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
PyPIforgepoints to another repo — not scored0.22.01,697431287 days agodjangosaasforgeframework

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

96Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
29.1/36Commit cadence — 42/52 weeks with commits
18/18Commit volume — 354 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year354
human_commit_share0.67
days_since_last_push0
active_weeks_last_year42

Release discipline

100Excellent
How it's scored
27/27Ships releases — 55 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~2 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count55
latest_release_tagv4.1.2
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases2
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

68Moderate · 18% of overall
How it's scored
37.6/60Stars — 210 stars
7.5/25Forks — 9 forks
1.7/15Watchers — 3 watchers
Inputs used
forks9
stars210
watchers3
growth_stateorganic
growth_factor_pct100

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

55Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.1/22.5Commit distribution — top contributor authored 99% of commits
2.7/13.5Contributor breadth — 2 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.994
How it's scored
31.2/46.8Issue resolution — 67% of issues closed
35.8/38.3PR acceptance — 434/464 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs434
open_issues7
closed_issues14
issue_closed_ratio0.667
closed_unmerged_prs30
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
19.2/25Owner reach — 462 followers of cisco-open
22.3/25Track record — 120 public repos, account ~4 yr old
Inputs used
followers462
owner_typeOrganization
is_verified
owner_logincisco-open
public_repos120
account_age_days1,690

Engineering Quality

Are baseline engineering and documentation practices in place?

92Excellent · 20% of overall
How it's scored
24/24CI workflows — 16 workflow(s)
24/24Tests present
16/16Linter config
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://cisco-open.github.io/forge/
10/10Repository description
10/10Topics — 20 topics
0/10Wiki
Inputs used
topicsci-cd, devops, github-actions, self-hosted-runners, terraform, aws, ephemeral, kubernetes, actions-runner-controller, automation, aws-eks, devsecops, ec2, infrastructure-as-code, multi-tenancy, terragrunt, iam, oidc, open-source, platform-engineering
has_wikino
homepagehttps://cisco-open.github.io/forge/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

82Good · 16% of overall

Security posture

93Excellent
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
1.2/2.5CII-Best-Practices — badge detected: Passing
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate9.3
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
5.7/35Direct dependencies free of known advisories — 3 affected: black 22.12.0 (critical 9.8), pytest 7.4.4 (moderate 6.8), python-dotenv 0.20.0 (moderate 6.6)
8.6/25Indirect dependencies free of known advisories — 1 affected: gunicorn 20.1.0 (high 8.2)
22.4/40No advisories left outstanding — 4 advisory-carrying package(s) unaddressed past 90 days; oldest published 854 days ago
Inputs used
sourceosv
advisories13
affected_packages4
assessed_packages53
unassessed_packages0
affected_by_severitycritical 1, high 1, moderate 2
direct_affected_packages3
Matched the pypi:forge@0.22.0 runtime dependency closure — what installing the published package pulls in — 53 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

57Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 67 of 67 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — docs/operations/repo-blueprints/containers/containers/action-runner/Makefile, docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile, tests/smoke/Makefile
22/22Automated tests
11/11Lint / format config
0/11Static type checking
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 17 of the last 100 commits are automated dependency updates
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Inputs used
has_nixno
has_testsyes
lockfilesuv.lock
has_dockerfileyes
typed_languageno
bootstrap_filesdocs/operations/repo-blueprints/containers/containers/action-runner/Makefile, docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile, tests/smoke/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.17
How it's scored
0/45Type-checkable code — HCL without a type-check config
55/55Manageable file sizes — 0/69 source files over 60KB
Inputs used
primary_languageHCL
largest_source_bytes20,524
source_files_sampled69
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

210GitHub stars
2contributors
354commits, last 12 months
0days since last push
55releases
1bus factor
7open issues
PyPIpackage ecosystems

Data collection warnings

  • pypi package 'forge' points at a different repository (https://github.com/forgepackages/forge); excluded from ecosystem scoring

More detail

Star and fork history 210 ★ / 9 ⇿
210Stars
9Forks
52Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

040801201602002402109492025-052025-122026-07
Major 4Minor 22Patch 26

Each point covers 2 days.

OpenSSF Scorecard 9.3 / 10
9.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-21 20:38 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
5CII-Best-Practicesbadge detected: Passing
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
All dependencies 124

Full resolved dependency set from the GitHub dependency graph: 0 direct and 124 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
PyPIannotated-types0.7.0indirect
PyPIantlr4-python3-runtime4.13.2indirect
PyPIattrs26.1.0indirect
PyPIaws-sam-translator1.111.0indirect
PyPIaws-xray-sdk2.15.0indirect
PyPIbabel2.18.0indirect
PyPIbackrefs7.0indirect
PyPIbandit1.9.4indirect
PyPIblinker1.9.0indirect
PyPIboolean-py5.0indirect
PyPIboto31.35.90indirect
PyPIboto31.43.40indirect
PyPIboto31.43.47indirect
PyPIbotocore1.35.90indirect
PyPIbotocore1.43.40indirect
PyPIbotocore1.43.47indirect
PyPIcachecontrol0.14.4indirect
PyPIcertifi2026.6.17indirect
PyPIcffi2.1.0indirect
PyPIcfgv3.5.0indirect
PyPIcfn-lint1.53.0indirect
PyPIcharset-normalizer3.4.9indirect
PyPIclick8.4.2indirect
PyPIcolorama0.4.6indirect
PyPIcoverage7.15.2indirect
PyPIcryptography49.0.0indirect
PyPIcyclonedx-python-lib11.11.0indirect
PyPIdefusedxml0.7.1indirect
PyPIdistlib0.4.3indirect
PyPIdocker7.2.0indirect
PyPIfilelock3.31.0indirect
PyPIflask3.1.3indirect
PyPIforge0.0.0indirect
PyPIghp-import2.1.0indirect
PyPIgraphql-core3.2.11indirect
PyPIhypothesis6.157.0indirect
PyPIidentify2.6.19indirect
PyPIidna3.18indirect
PyPIiniconfig2.3.0indirect
PyPIitsdangerous2.2.0indirect
PyPIjinja23.1.6indirect
PyPIjmespath1.1.0indirect
PyPIjoserfc1.7.4indirect
PyPIjsonpatch1.33indirect
PyPIjsonpath-ng1.8.0indirect
PyPIjsonpointer3.1.1indirect
PyPIjsonschema4.26.0indirect
PyPIjsonschema-path0.5.0indirect
PyPIjsonschema-specifications2025.9.1indirect
PyPIlazy-object-proxy1.12.0indirect
PyPIlicense-expression30.4.4indirect
PyPImarkdown3.10.2indirect
PyPImarkdown-it-py4.2.0indirect
PyPImarkupsafe3.0.3indirect
PyPImdurl0.1.2indirect
PyPImergedeep1.3.4indirect
PyPImkdocs1.6.1indirect
PyPImkdocs-get-deps0.2.2indirect
PyPImkdocs-material9.7.6indirect
PyPImkdocs-material-extensions1.3.1indirect
PyPImoto5.2.2indirect
PyPImpmath1.3.0indirect
PyPImsgpack1.2.1indirect
PyPImultipart2.0.0indirect
PyPInetworkx3.6.1indirect
PyPInodeenv1.10.0indirect
PyPIopenapi-schema-validator0.9.0indirect
PyPIopenapi-spec-validator0.9.0indirect
PyPIpackageurl-python0.17.6indirect
PyPIpackaging26.2indirect
PyPIpaginate0.5.7indirect
PyPIpathable0.6.0indirect
PyPIpathspec1.1.1indirect
PyPIpip26.1.2indirect
PyPIpip-api0.0.34indirect
PyPIpip-audit2.10.1indirect
PyPIpip-requirements-parser32.0.1indirect
PyPIplatformdirs4.10.1indirect
PyPIpluggy1.6.0indirect
PyPIpre-commit4.6.0indirect
PyPIpy-partiql-parser0.6.3indirect
PyPIpy-serializable2.1.0indirect
PyPIpycparser3.0indirect
PyPIpydantic2.13.4indirect
PyPIpydantic-core2.46.4indirect
PyPIpydantic-settings2.14.2indirect
PyPIpygments2.20.0indirect
PyPIpyjwt2.13.0indirect
PyPIpymdown-extensions11.0.1indirect
PyPIpyparsing3.3.2indirect
PyPIpytest9.0.3indirect
PyPIpytest9.1.1indirect
PyPIpytest-cov7.1.0indirect
PyPIpython-dateutil2.9.0.post0indirect
PyPIpython-discovery1.4.4indirect
PyPIpython-dotenv1.2.2indirect
PyPIpywin32312indirect
PyPIpyyaml6.0.3indirect
PyPIpyyaml-env-tag1.1indirect
PyPIreferencing0.37.0indirect
PyPIregex2026.7.19indirect
PyPIrequests2.34.2indirect
PyPIresponses0.26.1indirect
PyPIresponses0.26.2indirect
PyPIrfc3339-validator0.1.4indirect
PyPIrich15.0.0indirect
PyPIrpds-py2026.6.3indirect
PyPIs3transfer0.19.1indirect
PyPIsetuptools83.0.0indirect
PyPIsix1.17.0indirect
PyPIsortedcontainers2.4.0indirect
PyPIstevedore5.9.0indirect
PyPIsympy1.14.0indirect
PyPItomli2.4.1indirect
PyPItomli-w1.2.0indirect
PyPItyping-extensions4.16.0indirect
PyPItyping-inspection0.4.2indirect
PyPIurllib32.7.0indirect
PyPIuv0.11.28indirect
PyPIvirtualenv21.6.1indirect
PyPIwatchdog6.0.0indirect
PyPIwerkzeug3.1.8indirect
PyPIwrapt2.2.2indirect
PyPIxmltodict1.0.4indirect
Dependency advisories 4

Installing pypi:forge@0.22.0 pulls in 53 packages, direct and transitive: 4 carry known advisories, of which 3 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
black22.12.0directcritical526.3.1
gunicorn20.1.0indirecthigh422.0.0
pytest7.4.4directmoderate29.0.3
python-dotenv0.20.0directmoderate21.2.2

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ci-cd",
        "devops",
        "github-actions",
        "self-hosted-runners",
        "terraform",
        "aws",
        "ephemeral",
        "kubernetes",
        "actions-runner-controller",
        "automation",
        "aws-eks",
        "devsecops",
        "ec2",
        "infrastructure-as-code",
        "multi-tenancy",
        "terragrunt",
        "iam",
        "oidc",
        "open-source",
        "platform-engineering"
      ],
      "is_fork": false,
      "size_kb": 4665,
      "has_wiki": false,
      "homepage": "https://cisco-open.github.io/forge/",
      "languages": {
        "HCL": 1468024,
        "HTML": 834,
        "Shell": 74315,
        "Python": 420988,
        "Smarty": 2726,
        "Makefile": 818,
        "Dockerfile": 8263,
        "Go Template": 796,
        "Open Policy Agent": 4999
      },
      "pushed_at": "2026-07-21T20:04:25Z",
      "created_at": "2025-05-12T14:54:17Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T20:04:43Z",
      "description": "ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "HCL",
      "significant_languages": [
        "HCL",
        "Python"
      ]
    },
    "owner": {
      "blog": "https://opensource.cisco.com",
      "name": "Cisco",
      "type": "Organization",
      "login": "cisco-open",
      "company": null,
      "location": null,
      "followers": 462,
      "avatar_url": "https://avatars.githubusercontent.com/u/95529662?v=4",
      "created_at": "2021-12-04T11:47:54Z",
      "is_verified": null,
      "public_repos": 120,
      "account_age_days": 1690
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v4.1.2",
          "kind": "patch",
          "published_at": "2026-07-21T20:04:25Z"
        },
        {
          "tag": "v4.1.1",
          "kind": "patch",
          "published_at": "2026-07-20T17:44:30Z"
        },
        {
          "tag": "v4.1.0",
          "kind": "minor",
          "published_at": "2026-07-16T15:47:21Z"
        },
        {
          "tag": "v4.0.5",
          "kind": "patch",
          "published_at": "2026-07-15T13:13:37Z"
        },
        {
          "tag": "v4.0.4",
          "kind": "patch",
          "published_at": "2026-07-13T17:33:36Z"
        },
        {
          "tag": "v4.0.3",
          "kind": "patch",
          "published_at": "2026-07-13T15:41:36Z"
        },
        {
          "tag": "v4.0.2",
          "kind": "patch",
          "published_at": "2026-07-09T15:50:15Z"
        },
        {
          "tag": "v4.0.1",
          "kind": "patch",
          "published_at": "2026-07-06T11:23:58Z"
        },
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2026-07-05T17:52:18Z"
        },
        {
          "tag": "v3.12.0",
          "kind": "minor",
          "published_at": "2026-07-03T12:43:33Z"
        },
        {
          "tag": "v3.11.0",
          "kind": "minor",
          "published_at": "2026-07-03T10:57:54Z"
        },
        {
          "tag": "v3.10.0",
          "kind": "minor",
          "published_at": "2026-07-02T20:21:35Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-07-01T15:02:54Z"
        },
        {
          "tag": "v3.9.1",
          "kind": "patch",
          "published_at": "2026-07-01T12:04:01Z"
        },
        {
          "tag": "v3.9.0",
          "kind": "minor",
          "published_at": "2026-06-30T17:43:34Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2026-06-30T09:36:59Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-06-29T21:10:48Z"
        },
        {
          "tag": "v3.6.1",
          "kind": "patch",
          "published_at": "2026-06-26T19:14:45Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-06-24T23:12:54Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-06-22T19:57:45Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-06-17T14:13:08Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-06-15T09:47:57Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2026-06-11T14:39:20Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-06-11T12:09:48Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-11T08:55:46Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-06-05T15:33:19Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-06-02T14:12:21Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2025-12-15T18:58:06Z"
        },
        {
          "tag": "v1.10.4",
          "kind": "patch",
          "published_at": "2025-12-03T13:03:08Z"
        },
        {
          "tag": "v1.10.3",
          "kind": "patch",
          "published_at": "2025-12-01T21:04:57Z"
        },
        {
          "tag": "v1.10.2",
          "kind": "patch",
          "published_at": "2025-11-27T16:46:29Z"
        },
        {
          "tag": "v1.10.1",
          "kind": "patch",
          "published_at": "2025-11-14T21:02:40Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2025-11-07T13:49:07Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2025-10-29T23:10:28Z"
        },
        {
          "tag": "v1.8.2",
          "kind": "patch",
          "published_at": "2025-10-21T19:59:48Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2025-10-15T14:52:39Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2025-10-13T20:57:12Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2025-09-26T11:08:02Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2025-09-05T21:27:46Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2025-08-29T19:43:00Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2025-08-21T16:50:31Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2025-08-21T11:50:26Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2025-08-08T17:17:50Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2025-08-06T20:26:59Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2025-07-11T17:25:48Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2025-06-23T10:46:58Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-06-18T11:16:53Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2025-06-09T14:21:32Z"
        },
        {
          "tag": "v1.0.6",
          "kind": "patch",
          "published_at": "2025-06-03T20:34:45Z"
        },
        {
          "tag": "v1.0.5",
          "kind": "patch",
          "published_at": "2025-05-30T21:22:31Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2025-05-27T12:03:21Z"
        },
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2025-05-22T16:54:50Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2025-05-21T15:43:02Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2025-05-20T20:10:05Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2025-05-15T19:30:34Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9d50d2d9ee58ebe0b0ea2fb1aeb9aa07f6346c19",
          "body": "* chore(main): release 4.1.2\n\n* chore(main): release 4.1.2\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.1.2 (#485)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T20:04:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3ab1e3b1408d31bfd3913c5f22022d85ac950fb",
          "body": "* fix(forge-runners): propagate webhook update failures\n\n* refactor(forge-runners): migrate webhook updater to Python\n\n* test(splunk-opencost): stop pinning chart versions",
          "is_bot": false,
          "headline": "fix(forge-runners): make GitHub App webhook updates retryable (#484)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-21T19:22:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98922f142de4ff5e05a5d004bd98005b911bdd56",
          "body": "* chore(main): release 4.1.1\n\n* chore(main): release 4.1.1\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.1.1 (#482)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-20T17:44:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fd570c24331022edccb8ccdee1294fcef132a82",
          "body": "* chore(deps): update github actions dependencies (#305)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update gcr.io/oss-fuzz-base/base-builder-python:v1 docker digest to 5a4612c (#306)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.no\n[…]\nr version to v7.10.0 (#320)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: update dependencies for GitHub Actions and Docker images (#483)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-20T17:23:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "540a15d432cc2b3b0b61432db32717d8e6a82ab6",
          "body": null,
          "is_bot": false,
          "headline": "fix(splunk-otel): allow chart version updates (#481)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-17T13:59:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c422cb80229af395101c424ac559e3a863bc16e",
          "body": "* chore(main): release 4.1.0\n\n* chore(main): release 4.1.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.1.0 (#479)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-16T15:46:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3a1fa403df3aeeb97330024a4e52291857c6f0c",
          "body": null,
          "is_bot": false,
          "headline": "fix(helpers): add License Manager service role (#480)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-16T15:35:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea10bca806bb2517a826e67394428f2ce097152e",
          "body": "* feat(helpers): add dedicated Mac hosts and Config recording\n\n* fix(examples): use eu-west-1 for helper deployments\n\n* fix(helpers): use eu-west-1 in dedicated host test\n\n* feat(config): support selectable resource types\n\n* chore(helpers): remove dedicated hosts lock file\n\n* refactor(config): use e\n[…]\nery bucket\n\n* test(config): use eu-west-1 region\n\n* refactor(config): centralize storage dependency\n\n* fix(storage): allow AWS Config delivery\n\n* chore(config): document selective recording exceptions",
          "is_bot": false,
          "headline": "feat(helpers): add dedicated Mac hosts and Config recording (#475)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-16T11:49:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "155de01a064371cbb10b543bca0ce6a925f70f7d",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): update Forge dependency pins (#478)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-16T11:43:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d29a73ae1373d6f92400948ad63479761beb0b75",
          "body": "…s (#476)\n\nBumps the github-actions-dependencies group with 2 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\n\nUpdates `astral-sh/setup-uv` from 8.3.1 to 8.3.2\n- [Release notes](https://github.com\n[…]\nemver-minor\n  dependency-group: github-actions-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the github-actions-dependencies group with 2 update…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T10:17:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d9104b394211641f80a154399a56944d7e33fe4",
          "body": "* chore(main): release 4.0.5\n\n* chore(main): release 4.0.5\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.5 (#472)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-15T13:13:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5573be69b33bfdfab719b0173d0380525c0ff6a9",
          "body": null,
          "is_bot": false,
          "headline": "fix(dispatcher): alias reserved result attribute (#474)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-15T12:42:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e30bcf2888330cb2f4e5a0cb76bfc90967506f9",
          "body": "Bumps the github-actions-dependencies group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).\n\n\nUpdates `astral-sh/setup-uv` from 8.3.0 to 8.3.1\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/d3114\n[…]\nemver-patch\n  dependency-group: github-actions-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump astral-sh/setup-uv (#473)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-15T12:13:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "64642aa0c02f9d90807b3a8b9ed88aca3dc59c01",
          "body": null,
          "is_bot": false,
          "headline": "fix(examples): order shared Splunk config after dispatcher (#471)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-14T10:53:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f9953d617daaac1f39cf634423718c414e02391",
          "body": "…s (#470)\n\nBumps the github-actions-dependencies group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).\n\n\nUpdates `step-security/harden-runner` from 2.19.4 to 2.20.0\n- [Release notes](https:\n[…]\nemver-minor\n  dependency-group: github-actions-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the github-actions-dependencies group with 2 update…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T09:00:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39c422e4d12674a28a6e67446f94c4b34c823a03",
          "body": "* chore(main): release 4.0.4\n\n* chore(main): release 4.0.4\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.4 (#469)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T17:33:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6054d8cbd5806e580028a681db940cf944f2f38f",
          "body": "…-fatal (#468)\n\n* fix(ec2): make runner job-hooks non-fatal and log cause on failure\n\nThe job-started/job-completed hook wrappers fetch the real hook from SSM,\ndecompress, and run it. On a fetch/decode error they exited non-zero\n(exit 1 on Linux/macOS, $ErrorActionPreference='Stop' throw on Windows)\n[…]\nrunner's EC2 instance profile -- the real cause of the\nGetParameter failure. Unset those vars at the top of every wrapper (matching\nwhat the real hook already does) so SSM/STS always resolve via IMDS.",
          "is_bot": false,
          "headline": "fix(ec2): use instance profile for runner job-hooks and make them non…",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-13T17:02:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b3c0d4d5efe36333e7d2336f77924135beeccb3",
          "body": "* test(tofu): add module behavior contracts\n\n* test(tofu): normalize behavior test filenames",
          "is_bot": false,
          "headline": "test(tofu): add module behavior contracts (#466)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-13T16:57:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37934c1c37b96b907de0500655aa3b5a5b132a40",
          "body": "* test(tofu): add source inventory contracts\n\n* test(tofu): normalize source inventory filenames",
          "is_bot": false,
          "headline": "test(tofu): add source inventory contracts (#463)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-13T16:03:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89dfa214c03bd41a7af32f0068f32dd365ade565",
          "body": "* test(tofu): add module interface contracts\n\n* test(tofu): enforce interface contract suffix",
          "is_bot": false,
          "headline": "test(tofu): add module interface contracts (#464)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-13T15:43:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "707b345f5feeab345d4f28560bc74828d4038520",
          "body": "* chore(main): release 4.0.3\n\n* chore(main): release 4.0.3\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.3 (#461)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T15:41:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd16d5e2cfaaa4ab45f6766b0c754b69763c50f",
          "body": null,
          "is_bot": false,
          "headline": "fix(splunk): fix alert for multiple matches in stuck jobs (#462)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-13T14:13:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ae79725bda0ccbd1fc75495ee517ed82d84e9fb",
          "body": "* fix(splunk): fix query with breaking change in lambda logs\n\n* fix: add escape in the regex",
          "is_bot": false,
          "headline": "fix(splunk): fix query with breaking change in lambda logs (#460)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-10T15:09:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b3d80e273ce6ec7e883ede8b118a553f56ef10d",
          "body": "* chore(deps): update dependency hypothesis to v6.156.4 (#274)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update ministackorg/ministack docker tag to v1.4.0 (#268)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n\n[…]\nock file maintenance (#275)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(deps): update Forge dependency pins (#459)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T19:48:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22d4fc7c126e09a8d6148d2af8c7d87c223cfb76",
          "body": null,
          "is_bot": false,
          "headline": "chore(pre-commit): remove duplicate uv hook dependency (#456)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T17:37:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b84cea75cc3309fc25065e45211103bbac25275",
          "body": "* chore(security): add infrascan audit workflow\n\n* fix(security): scope infrascan audit input\n\n* fix(security): ignore docs in infrascan input",
          "is_bot": false,
          "headline": "chore(security): add infrascan audit workflow (#458)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T17:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d2cfc376f54c962b5d6dd1436d0fb5e7fd8b326",
          "body": "* chore(main): release 4.0.2\n\n* chore(main): release 4.0.2\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.2 (#443)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-09T15:49:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f34a94c5bb22914afd2bc422b07bb2e59ba2e25",
          "body": "* chore(deps): update ministackorg/ministack docker tag to v1.3.71 (#259)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update renovatebot/github-action action to v46.1.18 (#260)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.g\n[…]\nt] <29139614+renovate[bot]@users.noreply.github.com>\n\n* fix: use correct required_version in module contract\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(deps): update Forge dependency pins (#453)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T15:27:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec4003ada208a59ed31a9f509006a4f14a9e9fab",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): add repository status badges (#457)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T15:07:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f0bc28bbdce9f9f47dea143f8387bae286b8ddf",
          "body": "* test(quality): add example release contracts\n\n* test(smoke): exercise trust validator handlers\n\n* test(iac): reject forbidden module contract literals",
          "is_bot": false,
          "headline": "test(ci): improve Forge coverage gates (#454)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T15:07:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d3211c4e80338be9070fee946ac7150fb3e1e3d",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): ignore ubuntu docker update noise (#455)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T13:22:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "451047cb77cbb318d76ad1a908718298b17e0a29",
          "body": "…y with 2 updates (#452)\n\nBumps the python-dependencies group with 2 updates in the / directory: [pre-commit](https://github.com/pre-commit/pre-commit) and [hypothesis](https://github.com/HypothesisWorks/hypothesis).\n\n\nUpdates `pre-commit` from 4.0.0 to 4.6.0\n- [Release notes](https://github.com/pre\n[…]\nupdate:semver-minor\n  dependency-group: python-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the python-dependencies group across 1 director…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T12:21:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43f01238962860e1a6332462708c87eaa98bccf5",
          "body": "* fix(splunk-aws-billing): set billing view ARN\n\n* fix(splunk-aws-billing): wait for data export bucket policy",
          "is_bot": false,
          "headline": "fix(splunk-aws-billing): set billing view ARN (#449)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T12:09:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c73f596aa6ebffc381d07dd9219b54a2fc769048",
          "body": null,
          "is_bot": false,
          "headline": "fix(deps): update uv lockfile automation (#450)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T12:08:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04a86b1ab3e1f5532f43ab47fc943e98ba89fc45",
          "body": "* chore(deps): centralize Python tooling dependencies\n\n* test(tofu): add native module contract coverage\n\n* test(lambda): expand handler boundary coverage\n\n* test(iac): add offline Terraform contract tests\n\n* test(mutation): add trusted-boundary mutation gates\n\n* test(smoke): add MiniStack liveness \n[…]\ntack healthcheck\n\n* fix(ci): remove redundant setup steps\n\n* fix(ci): restore locked test dependency groups\n\n* fix(smoke): use Python MiniStack healthcheck\n\n* fix(smoke): use STS MiniStack healthcheck",
          "is_bot": false,
          "headline": "test: expand Forge test coverage and CI gates (#437)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T11:00:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "993d60326cde764ec97d1328116eeab9a8cb2a2a",
          "body": null,
          "is_bot": false,
          "headline": "fix(splunk): suppress AWS billing export drift (#444)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-09T10:06:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96f9aef2513ec7240338f13f0bd1c9f099736b03",
          "body": null,
          "is_bot": false,
          "headline": "ci(pre-commit): install tools from locked dependencies (#440)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-08T21:54:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e7b96c87226bfb0b9c752efbb721a75a8e696f8",
          "body": null,
          "is_bot": false,
          "headline": "test(tofu): add module contract tests (#438)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-08T21:38:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b75ab7f776c15ba532449625902348bfd2bcbb5d",
          "body": null,
          "is_bot": false,
          "headline": "fix(splunk-billing): add log group dependencies (#442)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-08T21:25:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f68f9497ae4dd55785db4b94b475f05f5560db33",
          "body": null,
          "is_bot": false,
          "headline": "chore(examples): move splunk cloud shared config (#441)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-08T21:04:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e21b1cd53f3d41e173e4860e1c435ffb8e6a709",
          "body": null,
          "is_bot": false,
          "headline": "chore(tests): remove tf-ministack sandbox (#439)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-08T20:45:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84d5b7542926d31262775c6f1a0d212d5dce3041",
          "body": null,
          "is_bot": false,
          "headline": "chore(examples): standardize template placeholders (#435)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-07T18:54:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e7d759ed902d248a5520f4ffc18ffc9bec5e180",
          "body": "…433)\n\nBumps the pre-commit-dependencies group with 2 updates: [https://github.com/mrtazz/checkmake.git](https://github.com/mrtazz/checkmake) and [https://github.com/gitleaks/gitleaks](https://github.com/gitleaks/gitleaks).\n\n\nUpdates `https://github.com/mrtazz/checkmake.git` from v0.3.0 to 0.3.2\n- [\n[…]\nrect:production\n  dependency-group: pre-commit-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the pre-commit-dependencies group with 2 updates (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T00:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "753611ab842c5d2adab01276af33a594c73363f7",
          "body": "Bumps the github-actions-dependencies group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).\n\n\nUpdates `astral-sh/setup-uv` from 8.1.0 to 8.2.0\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/08807\n[…]\nemver-minor\n  dependency-group: github-actions-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump astral-sh/setup-uv (#434)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T00:11:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36dfe46399df63e0bcf612cbe63245d0b7351d23",
          "body": "Bumps the docker-compose-dependencies group in /tests/smoke with 1 update: ministackorg/ministack.\n\n\nUpdates `ministackorg/ministack` from 1.3.71-full to 1.3.72-full\n\n---\nupdated-dependencies:\n- dependency-name: ministackorg/ministack\n  dependency-version: 1.3.72-full\n  dependency-type: direct:produ\n[…]\nemver-patch\n  dependency-group: docker-compose-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ministackorg/ministack (#431)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T00:11:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9c5adddca7aed8ee7e2f4f6b2e7cf4c223c6ff2",
          "body": "* chore(deps): update ministackorg/ministack docker tag to v1.3.71 (#259)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update renovatebot/github-action action to v46.1.18 (#260)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.g\n[…]\ner digest to 6768b69 (#261)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(deps): update deps managed by renovate (#430)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T20:15:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1452274b9d1c9a93c121ff5cd2e9a9fe39d0aeb",
          "body": null,
          "is_bot": false,
          "headline": "docs(operations): add terraform terragrunt stuck runbook (#429)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T15:41:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "676d49b8faee80156c8c661a536dea8d5815a4f6",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): update OpenSSF Best Practices badge (#428)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T12:04:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d0b24ec68421b40ad61b3675e8291fc90561b4f",
          "body": "* chore(main): release 4.0.1\n\n* chore(main): release 4.0.1\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.1 (#427)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-06T11:23:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f792381b1d2d0bd370585e3a42f729c6f3d3a70c",
          "body": "* test(fuzzing): add ClusterFuzzLite coverage\n\n* ci(fuzzing): pin ClusterFuzzLite tag commit\n\n* ci(fuzzing): move matrix concurrency to jobs\n\n* ci(fuzzing): scope ClusterFuzzLite concurrency to jobs\n\n* test(fuzzing): skip invalid env fuzzer values\n\n* ci(fuzzing): remove duplicate concurrency keys\n\n*\n[…]\n payloads\n\n* ci(fuzzing): allow longer ClusterFuzzLite runs\n\n* docs(diagrams): add Mermaid draft conversions\n\n* fix(fuzzing): tolerate malformed queued URLs\n\n* docs(diagrams): remove draft conversions",
          "is_bot": false,
          "headline": "test(fuzzing): add ClusterFuzzLite coverage (#425)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T11:13:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd6c8e9fff69d03e8b9f608af95df0d8c460838a",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): clarify ForgeMT runner platform (#426)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T11:13:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26df3a2afac0e799f30374dea27d165c8e53b875",
          "body": "* fix(splunk): use PyJWT for GitHub app JWTs\n\n* fix(splunk): use requests for redelivery calls\n\n* docs: update project links\n\n* fix(splunk): redeliver by alert delivery ID\n\n* fix(splunk): resolve alert delivery GUIDs\n\n* docs(readme): remove duplicate technical article link",
          "is_bot": false,
          "headline": "fix(splunk): use PyJWT for GitHub app JWTs (#424)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-06T10:53:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0b185417d858c60e43a2538a982745b35d04c93",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): add OpenSSF badges (#423)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T19:18:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b8513a44d8fedbf61518f143f40c2fee80716a7",
          "body": "* chore: update terraform-aws-github-runner\n\n* chore(containers): pin blueprint base images\n\n* chore(deps): pin pre-commit hooks by hash",
          "is_bot": false,
          "headline": "chore(ec2-deployment): update runner module to v7.9.0 (#391)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T19:03:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "011fd1b8ce2fdbd6950c518074ae8e2486df0418",
          "body": "* chore(main): release 4.0.0\n\n* chore(main): release 4.0.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 4.0.0 (#418)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-05T17:52:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "733c9e4b3873a68b62f110e82ecaeb398620221c",
          "body": "* fix(ci): lock Python workflow dependencies with uv\n\n* chore(renovate): group github runner source updates",
          "is_bot": false,
          "headline": "fix(docs): hash-pin docs dependencies (#422)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T17:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b6fdba29d708d42b5c1d1c9d1e3fbaf618f45dc",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): group runner Renovate updates (#421)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T16:38:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac368dfcfe5e6a39779f5fc5dd4ce36d1cb0e7ae",
          "body": null,
          "is_bot": false,
          "headline": "chore(dispatcher): document tenant config checkov exception (#420)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T16:38:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7688e3ef793bea9666cf9453245140e2904c5b2",
          "body": "* chore(deps): pin ministackorg/ministack docker tag to 48ce646 (#252)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update dependency community.general to v13 (#250)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n\n[…]\n python dependencies (#241)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: update deps from renovatebot (#412)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T16:17:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2791806731112fa049ddbd5a1bfa4bc5c182d786",
          "body": "BREAKING CHANGE: Forge module paths were reorganized into platform, infra, integrations, and helpers. Consumers must update module source paths before upgrading.",
          "is_bot": false,
          "headline": "refactor!: redesign Forge module layout (#419)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T15:48:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6869d9b5617ed337f2d12e32b35a07879a7c4fe8",
          "body": "Bumps the docker-compose-dependencies group in /tests/smoke with 1 update: ministackorg/ministack.\n\n\nUpdates `ministackorg/ministack` from 1.3.69-full to 1.3.70-full\n\n---\nupdated-dependencies:\n- dependency-name: ministackorg/ministack\n  dependency-version: 1.3.70-full\n  dependency-type: direct:produ\n[…]\nemver-patch\n  dependency-group: docker-compose-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ministackorg/ministack (#415)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-05T14:52:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96d7c00fb174f1ef62d6456b788edca99b9f87fa",
          "body": "…y with 3 updates (#417)\n\nBumps the python-dependencies group with 3 updates in the /tests/smoke directory: [pytest](https://github.com/pytest-dev/pytest), [boto3](https://github.com/boto/boto3) and [botocore](https://github.com/boto/botocore).\n\n\nUpdates `pytest` from 9.0.3 to 9.1.1\n- [Release notes\n[…]\nupdate:semver-minor\n  dependency-group: python-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the python-dependencies group across 1 director…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-05T14:49:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e6232e8d1ec375c2a80655497134de5358d247f",
          "body": "* refactor(modules): reorganize modules and examples\n\n* test(splunk): validate metadata sidecar fixture shape\n\n* feat(splunk): add workflow run duration dashboard\n\n* chore(pre-commit): exclude documentation blueprints\n\n* docs(blueprints): add operations repo blueprints\n\n* docs(forge): reorganize doc\n[…]\n mkdocs site output\n\n* chore(github-app): test register container\n\n* chore(ci): harden workflows\n\n* chore(checkov): skip pending module findings\n\n* chore(pre-commit): update forge subscription exclude",
          "is_bot": false,
          "headline": "refactor(modules): reorganize modules (#413)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-05T14:06:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae026f989cdf50be89a29266d023edbd08447bf1",
          "body": "* fix(lambdas): close webhook and retry gaps\n\n* test(lambdas): expand critical path coverage\n\n* ci(lambdas): publish unit test summary\n\n* chore(tests): move lambda deps to pyproject\n\n* test(lambdas): sign MiniStack webhook smoke event\n\n* test(lambdas): expand MiniStack webhook smoke coverage\n\n* test(lambdas): add MiniStack guard smoke coverage\n\n* test(lambdas): add MiniStack smoke happy paths\n\n* test(smoke): silence botocore utcnow warning",
          "is_bot": false,
          "headline": "test(lambdas): expand coverage and close retry gaps (#411)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-04T01:10:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "946c603ca11cbcf1cc105f66e45cfbf741be917d",
          "body": null,
          "is_bot": false,
          "headline": "feat(runner-logs): enrich splunk fields from metadata sidecar (#410)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T23:21:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3176c90de1ab59dc5c06645cb334ea9d4760299b",
          "body": "* feat(splunk): add EC2 scale-up failure dashboards\n\n* feat(splunk): add runner control-plane dashboards\n\n* feat(splunk): add runner control-plane field extractions",
          "is_bot": false,
          "headline": "feat(splunk): add EC2 scale-up failure dashboards (#408)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T22:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79f98ab41e6f60992014bada07d4b197a94ab565",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document accepted policy exceptions (#407)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T21:24:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3d4693159691bb95ca4bbc795b08e4916d8f6fa",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document S3 access logging exception (#404)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T21:02:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29e94056b2d785de06bea33f2654a5320a349422",
          "body": null,
          "is_bot": false,
          "headline": "docs(forge): clarify tenant runner role policies (#405)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T20:42:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4f18fcfc2b55a11f496170ec354599fd0ec1628",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document Packer build exception (#403)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T20:37:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92c6028f86d9662b1cc3e0069eeb3db2c7a7a471",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document S3 replication exception (#401)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T20:37:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "688b67d9ccf1bfcbcf687961a7355483ec27cee8",
          "body": "…406)\n\nBumps the python-dependencies group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pytest-cov](https://github.com/pytest-dev/pytest-cov) | `6.0.0` | `7.1.0` |\n| [moto](https://github.com/getmoto/moto) | `5.0.28` | `5.2.2` |\n| [boto3](https://github.com/boto/boto3) | `1.35.90`\n[…]\nupdate:semver-major\n  dependency-group: python-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the python-dependencies group with 5 updates (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T20:34:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c90d99534af8d76900c24da4ff5628148d19f3aa",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): group Dependabot updates (#402)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T20:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc411d832ae0f10cbdc0adc24d06fe6dabc89228",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document CloudFormation exception (#400)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T19:39:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a438f3f89f8845f65c53016e5afa099582d5c8",
          "body": "Bumps [pytest](https://github.com/pytest-dev/pytest) from 9.0.3 to 9.1.1.\n- [Release notes](https://github.com/pytest-dev/pytest/releases)\n- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)\n- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.1)\n\n---\nupdated-\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump pytest from 9.0.3 to 9.1.1 (#396)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T19:37:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ccf68119ee69ec0a2b274e0809b17b5fe133e06",
          "body": "Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2.\n- [Release notes](https://github.com/psf/requests/releases)\n- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)\n- [Commits](https://github.com/psf/requests/compare/v2.33.0...v2.34.2)\n\n---\nupdated-dependencies:\n-\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump requests from 2.33.0 to 2.34.2 (#398)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T19:37:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f89630f582712b3d4d0bf6827fb5488ab1daf25",
          "body": "Bumps [responses](https://github.com/getsentry/responses) from 0.25.3 to 0.26.1.\n- [Release notes](https://github.com/getsentry/responses/releases)\n- [Changelog](https://github.com/getsentry/responses/blob/master/CHANGES)\n- [Commits](https://github.com/getsentry/responses/compare/0.25.3...0.26.1)\n\n-\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump responses from 0.25.3 to 0.26.1 (#397)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T19:37:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f50f7500ee97efdcfcdfb240a06445d25440e1d0",
          "body": null,
          "is_bot": false,
          "headline": "chore(checkov): document log retention exception (#393)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T19:32:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "953403adec549b8b9632bb2227a7d92fb5896ea7",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): remediate zizmor alerts (#392)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T19:32:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcd0e42bbb052ab147d86f4d1024fdba23845ce7",
          "body": "* chore(main): release 3.12.0\n\n* chore(main): release 3.12.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.12.0 (#390)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-03T12:43:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee1bb792b644c754af515895ac683e260da18e77",
          "body": null,
          "is_bot": false,
          "headline": "feat(splunk-o11y): add Forge impact dynamic variables (#389)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T12:41:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0554c0c63d11ada2788784670b876a42bf6252bf",
          "body": "* chore(main): release 3.11.0\n\n* chore(main): release 3.11.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.11.0 (#388)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-03T10:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b0e83051a16c24331c63dbacda4783d12ec2ac9",
          "body": null,
          "is_bot": false,
          "headline": "feat: allow Splunk O11y dashboard group naming (#387)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T10:46:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1abd95f0175ce4598156a291e2699d878589b46a",
          "body": null,
          "is_bot": false,
          "headline": "fix: enable OpenCost Prometheus source metrics (#386)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-03T10:46:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b464c2f259195b5a64f9862a78e8c212cb3242b",
          "body": "Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.1.0 to 4.2.0.\n- [Release notes](https://github.com/docker/setup-buildx-action/releases)\n- [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...bb05f3f5519dd8\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0 (#383)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T10:40:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06d75f13566a337a5bfbf5c57793461205d30167",
          "body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.3.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...c99871dec2022cc055c062a10cc1a1310835ceb4)\n\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action from 4.2.0 to 4.3.0 (#384)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T10:05:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "374f529bc6c5a1ce5ab54cc99d285c7e7af92858",
          "body": "Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 6.1.0 to 6.2.0.\n- [Release notes](https://github.com/docker/metadata-action/releases)\n- [Commits](https://github.com/docker/metadata-action/compare/80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9...dc802804100637a589fabce1cb79ff\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 (#385)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T10:04:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60f543e5469f6f9b7f70bb5914a180780c162313",
          "body": "* chore(main): release 3.10.0\n\n* chore(main): release 3.10.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.10.0 (#380)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-02T20:21:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8be17434679ecab24d8a4bb0e74ad50f57ccb191",
          "body": "* feat: add OpenCost O11y dashboard\n\n* fix: add tenant filter to OpenCost dashboard\n\n* fix: add cluster filter to OpenCost dashboard",
          "is_bot": false,
          "headline": "feat: add OpenCost O11y dashboard (#382)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-02T20:19:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a7726c26f0b26e45b43115b39c8fa284bd11d2",
          "body": "* feat: add Splunk OpenCost EKS integration\n\n* chore(deps): bump OpenCost Helm chart\n\n* fix: force OpenCost scrape annotations to strings",
          "is_bot": false,
          "headline": "feat: add Splunk OpenCost EKS integration (#378)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-02T19:33:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3fdb24a18be93ad88e92f1897ee87d83dc93ba2",
          "body": "* chore(deps): update ubuntu:24.04 docker digest to 4fbb8e6 (#224)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n* chore(deps): update dependency gruntwork-io/terragrunt to v1.1.0 (#223)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.c\n[…]\non action to v4.36.3 (#225)\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(deps): update Renovate-managed dependencies (#379)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-02T18:36:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5be35ac3611f1ca4c43973359cf78c875c9e1e8a",
          "body": "Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.2.0 to 7.3.0.\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-push-action/compare/f9f3042f7e2789586610d6e8b85c8f03e5195baf...53b7df96c91f9c12dcc8a0\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 (#377)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-02T18:02:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56149df6e749517690718135a4718488ffd564a1",
          "body": "* chore(main): release 3.9.2\n\n* chore(main): release 3.9.2\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.9.2 (#376)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T15:02:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a600cb28f866b2c259e881fb72b363f2346f904",
          "body": "* fix: avoid windows hook log contention\n\n* fix: order ami lookup after runner updates",
          "is_bot": false,
          "headline": "fix: avoid windows hook log contention (#375)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-01T14:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bdffdcc860139d57167618903548e86bee5686f0",
          "body": "* chore(main): release 3.9.1\n\n* chore(main): release 3.9.1\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.9.1 (#374)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T12:03:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c599a81fee4410d249b89767ff20d741515e5b7c",
          "body": null,
          "is_bot": false,
          "headline": "fix: break ec2 runner ami destroy cycle (#373)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-07-01T11:56:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5135560405fd36e9c3e8065a202e6eb1fbe9d91d",
          "body": "* chore(main): release 3.9.0\n\n* chore(main): release 3.9.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.9.0 (#372)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-30T17:43:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06bc409721585f52d1f92104a0e543440809a292",
          "body": "* feat: skip Splunk redelivery for active runners\n\n* test: cover terminated Splunk runner execution\n\n* fix: preserve empty Splunk result batches\n\n* feat: add Splunk dispatcher dashboards\n\n* fix: avoid dispatcher Splunk extraction resources\n\n* fix: use static Splunk dispatcher transforms\n\n* fix: spli\n[…]\nr GitHub delivery references\n\n* fix: cap stuck workflow job age window\n\n* fix: update queued job dashboard threshold\n\n* fix: use numeric repeat match flag\n\n* fix: ignore Splunk webhook allowlist drift",
          "is_bot": false,
          "headline": "feat: skip Splunk redelivery for active runners (#371)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-06-30T17:41:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af79fdaf873d5c10e799a284f3e7ca6dcd857036",
          "body": null,
          "is_bot": false,
          "headline": "chore: document accepted code scanning exceptions (#370)",
          "author_name": "Ederson Brilhante",
          "author_login": "edersonbrilhante",
          "committed_at": "2026-06-30T11:24:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f92bc728203b2bb99e266a6be7ccbab14e716ab",
          "body": "* chore(main): release 3.8.0\n\n* chore(main): release 3.8.0\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 3.8.0 (#369)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-30T09:36:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 55,
      "commits_last_year": 354,
      "latest_release_at": "2026-07-21T20:04:25Z",
      "latest_release_tag": "v4.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 42,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "forge",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "django",
            "saas",
            "forge",
            "framework",
            "Environment :: Web Environment",
            "Framework :: Django",
            "Framework :: Django :: 4",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: MIT License",
            "Operating System :: OS Independent",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.8",
            "Programming Language :: Python :: 3.9"
          ],
          "ecosystem": "pypi",
          "matches_repo": false,
          "registry_url": "https://pypi.org/project/forge/",
          "is_deprecated": false,
          "latest_version": "0.22.0",
          "repository_url": "https://github.com/forgepackages/forge",
          "versions_count": 43,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1697,
          "first_published_at": "2022-04-11T15:55:47.806932Z",
          "latest_published_at": "2023-01-11T20:28:49.871675Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1287
        }
      ]
    },
    "popularity": {
      "forks": 9,
      "stars": 210,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2025-05-22",
            "count": 1
          },
          {
            "date": "2025-05-24",
            "count": 1
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-10-03",
            "count": 1
          },
          {
            "date": "2025-10-29",
            "count": 1
          },
          {
            "date": "2025-11-07",
            "count": 1
          },
          {
            "date": "2025-11-12",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-06-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 9,
        "total_forks": 9
      },
      "star_history": {
        "days": [
          {
            "date": "2025-05-14",
            "count": 2
          },
          {
            "date": "2025-05-15",
            "count": 8
          },
          {
            "date": "2025-05-16",
            "count": 9
          },
          {
            "date": "2025-05-17",
            "count": 5
          },
          {
            "date": "2025-05-18",
            "count": 3
          },
          {
            "date": "2025-05-19",
            "count": 5
          },
          {
            "date": "2025-05-20",
            "count": 6
          },
          {
            "date": "2025-05-21",
            "count": 16
          },
          {
            "date": "2025-05-22",
            "count": 37
          },
          {
            "date": "2025-05-23",
            "count": 12
          },
          {
            "date": "2025-05-24",
            "count": 4
          },
          {
            "date": "2025-05-25",
            "count": 2
          },
          {
            "date": "2025-05-26",
            "count": 5
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-05-29",
            "count": 1
          },
          {
            "date": "2025-05-30",
            "count": 1
          },
          {
            "date": "2025-06-02",
            "count": 1
          },
          {
            "date": "2025-06-05",
            "count": 3
          },
          {
            "date": "2025-06-06",
            "count": 2
          },
          {
            "date": "2025-06-12",
            "count": 1
          },
          {
            "date": "2025-06-16",
            "count": 1
          },
          {
            "date": "2025-06-27",
            "count": 1
          },
          {
            "date": "2025-07-02",
            "count": 1
          },
          {
            "date": "2025-07-03",
            "count": 1
          },
          {
            "date": "2025-07-09",
            "count": 1
          },
          {
            "date": "2025-07-14",
            "count": 1
          },
          {
            "date": "2025-07-16",
            "count": 1
          },
          {
            "date": "2025-07-17",
            "count": 1
          },
          {
            "date": "2025-07-29",
            "count": 5
          },
          {
            "date": "2025-07-30",
            "count": 11
          },
          {
            "date": "2025-07-31",
            "count": 6
          },
          {
            "date": "2025-08-01",
            "count": 2
          },
          {
            "date": "2025-08-02",
            "count": 1
          },
          {
            "date": "2025-08-03",
            "count": 5
          },
          {
            "date": "2025-08-04",
            "count": 6
          },
          {
            "date": "2025-08-05",
            "count": 1
          },
          {
            "date": "2025-08-07",
            "count": 2
          },
          {
            "date": "2025-08-08",
            "count": 1
          },
          {
            "date": "2025-08-11",
            "count": 1
          },
          {
            "date": "2025-08-12",
            "count": 3
          },
          {
            "date": "2025-08-17",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2025-08-22",
            "count": 2
          },
          {
            "date": "2025-08-28",
            "count": 2
          },
          {
            "date": "2025-09-09",
            "count": 1
          },
          {
            "date": "2025-09-18",
            "count": 1
          },
          {
            "date": "2025-09-23",
            "count": 1
          },
          {
            "date": "2025-09-26",
            "count": 2
          },
          {
            "date": "2025-10-09",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-10-17",
            "count": 1
          },
          {
            "date": "2025-10-25",
            "count": 1
          },
          {
            "date": "2025-11-14",
            "count": 1
          },
          {
            "date": "2025-11-20",
            "count": 1
          },
          {
            "date": "2025-12-08",
            "count": 1
          },
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-03-07",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-04-14",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-30",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 2
          },
          {
            "date": "2026-06-22",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          },
          {
            "date": "2026-07-11",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 210,
        "total_stars": 210
      },
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "docs/operations/repo-blueprints/containers/containers/action-runner/Makefile",
        "docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile",
        "tests/smoke/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 20524,
      "source_files_sampled": 69,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "black",
            "direct": true,
            "version": "22.12.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-3936-cmfr-pm3m",
              "GHSA-fj7x-q9j7-g6q6",
              "PYSEC-2024-48",
              "PYSEC-2026-2120",
              "PYSEC-2026-2121"
            ],
            "fixed_version": "26.3.1",
            "advisory_count": 5,
            "oldest_advisory_days": 854
          },
          {
            "name": "gunicorn",
            "direct": false,
            "version": "20.1.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.2,
            "advisory_ids": [
              "GHSA-hc5x-x2vx-497g",
              "GHSA-w3h3-4rj7-4ph4",
              "PYSEC-2026-1433",
              "PYSEC-2026-1434"
            ],
            "fixed_version": "22.0.0",
            "advisory_count": 4,
            "oldest_advisory_days": 826
          },
          {
            "name": "pytest",
            "direct": true,
            "version": "7.4.4",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-6w46-j5rx-g56g",
              "PYSEC-2026-1845"
            ],
            "fixed_version": "9.0.3",
            "advisory_count": 2,
            "oldest_advisory_days": 180
          },
          {
            "name": "python-dotenv",
            "direct": true,
            "version": "0.20.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.6,
            "advisory_ids": [
              "GHSA-mf9w-mj56-hr94",
              "PYSEC-2026-2270"
            ],
            "fixed_version": "1.2.2",
            "advisory_count": 2,
            "oldest_advisory_days": 92
          }
        ],
        "collected": true,
        "truncated": false,
        "by_severity": {
          "high": 1,
          "critical": 1,
          "moderate": 2
        },
        "advisory_count": 13,
        "affected_count": 4,
        "assessed_count": 53,
        "assessed_package": "pypi:forge@0.22.0",
        "unassessed_count": 0,
        "direct_affected_count": 3
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "annotated-types",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "antlr4-python3-runtime",
            "direct": false,
            "version": "4.13.2",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "aws-sam-translator",
            "direct": false,
            "version": "1.111.0",
            "ecosystem": "pypi"
          },
          {
            "name": "aws-xray-sdk",
            "direct": false,
            "version": "2.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "babel",
            "direct": false,
            "version": "2.18.0",
            "ecosystem": "pypi"
          },
          {
            "name": "backrefs",
            "direct": false,
            "version": "7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "bandit",
            "direct": false,
            "version": "1.9.4",
            "ecosystem": "pypi"
          },
          {
            "name": "blinker",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "boolean-py",
            "direct": false,
            "version": "5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.35.90",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.43.40",
            "ecosystem": "pypi"
          },
          {
            "name": "boto3",
            "direct": false,
            "version": "1.43.47",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.35.90",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.43.40",
            "ecosystem": "pypi"
          },
          {
            "name": "botocore",
            "direct": false,
            "version": "1.43.47",
            "ecosystem": "pypi"
          },
          {
            "name": "cachecontrol",
            "direct": false,
            "version": "0.14.4",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.6.17",
            "ecosystem": "pypi"
          },
          {
            "name": "cffi",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cfgv",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cfn-lint",
            "direct": false,
            "version": "1.53.0",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.9",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "coverage",
            "direct": false,
            "version": "7.15.2",
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "49.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "cyclonedx-python-lib",
            "direct": false,
            "version": "11.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "defusedxml",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "distlib",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "pypi"
          },
          {
            "name": "docker",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "filelock",
            "direct": false,
            "version": "3.31.0",
            "ecosystem": "pypi"
          },
          {
            "name": "flask",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "forge",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ghp-import",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "graphql-core",
            "direct": false,
            "version": "3.2.11",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis",
            "direct": false,
            "version": "6.157.0",
            "ecosystem": "pypi"
          },
          {
            "name": "identify",
            "direct": false,
            "version": "2.6.19",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.18",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "itsdangerous",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jinja2",
            "direct": false,
            "version": "3.1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "jmespath",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "joserfc",
            "direct": false,
            "version": "1.7.4",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpatch",
            "direct": false,
            "version": "1.33",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpath-ng",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpointer",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "4.26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-path",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-specifications",
            "direct": false,
            "version": "2025.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "lazy-object-proxy",
            "direct": false,
            "version": "1.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "license-expression",
            "direct": false,
            "version": "30.4.4",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown",
            "direct": false,
            "version": "3.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-it-py",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markupsafe",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "mdurl",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mergedeep",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "pypi"
          },
          {
            "name": "mkdocs",
            "direct": false,
            "version": "1.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "mkdocs-get-deps",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mkdocs-material",
            "direct": false,
            "version": "9.7.6",
            "ecosystem": "pypi"
          },
          {
            "name": "mkdocs-material-extensions",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "moto",
            "direct": false,
            "version": "5.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mpmath",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "msgpack",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "multipart",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "networkx",
            "direct": false,
            "version": "3.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "nodeenv",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "openapi-schema-validator",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "openapi-spec-validator",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packageurl-python",
            "direct": false,
            "version": "0.17.6",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "paginate",
            "direct": false,
            "version": "0.5.7",
            "ecosystem": "pypi"
          },
          {
            "name": "pathable",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pathspec",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pip",
            "direct": false,
            "version": "26.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pip-api",
            "direct": false,
            "version": "0.0.34",
            "ecosystem": "pypi"
          },
          {
            "name": "pip-audit",
            "direct": false,
            "version": "2.10.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pip-requirements-parser",
            "direct": false,
            "version": "32.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "platformdirs",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pre-commit",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "py-partiql-parser",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "py-serializable",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycparser",
            "direct": false,
            "version": "3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": false,
            "version": "2.13.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-core",
            "direct": false,
            "version": "2.46.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-settings",
            "direct": false,
            "version": "2.14.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": false,
            "version": "2.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pymdown-extensions",
            "direct": false,
            "version": "11.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyparsing",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-cov",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dateutil",
            "direct": false,
            "version": "2.9.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-discovery",
            "direct": false,
            "version": "1.4.4",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32",
            "direct": false,
            "version": "312",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml-env-tag",
            "direct": false,
            "version": "1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "referencing",
            "direct": false,
            "version": "0.37.0",
            "ecosystem": "pypi"
          },
          {
            "name": "regex",
            "direct": false,
            "version": "2026.7.19",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "responses",
            "direct": false,
            "version": "0.26.1",
            "ecosystem": "pypi"
          },
          {
            "name": "responses",
            "direct": false,
            "version": "0.26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3339-validator",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": false,
            "version": "15.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rpds-py",
            "direct": false,
            "version": "2026.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "s3transfer",
            "direct": false,
            "version": "0.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": "83.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sortedcontainers",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "stevedore",
            "direct": false,
            "version": "5.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sympy",
            "direct": false,
            "version": "1.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli-w",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.16.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspection",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uv",
            "direct": false,
            "version": "0.11.28",
            "ecosystem": "pypi"
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": "21.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "watchdog",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "werkzeug",
            "direct": false,
            "version": "3.1.8",
            "ecosystem": "pypi"
          },
          {
            "name": "wrapt",
            "direct": false,
            "version": "2.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "xmltodict",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 124,
        "direct_count": 0,
        "indirect_count": 124
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 434,
        "open_issues": 7,
        "closed_ratio": 0.667,
        "closed_issues": 14,
        "closed_unmerged_prs": 30
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "edersonbrilhante",
          "commits": 357,
          "avatar_url": "https://avatars.githubusercontent.com/u/1094995?v=4"
        },
        {
          "type": "User",
          "login": "Rostislavz",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/16332508?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.994
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build-forge-github-app-register.yml",
        "build-pre-commit.yml",
        "cflite_build.yml",
        "cflite_pr.yml",
        "dependency-review.yml",
        "docs-pages.yml",
        "iac-policy.yml",
        "infrascan-security-audit.yml",
        "lambda-tests.yml",
        "ministack-smoke.yml",
        "ossf-scorecard.yml",
        "pre-commit.yml",
        "quality-gates.yml",
        "release.yml",
        "semantic-check.yml",
        "zizmor.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 5,
            "reason": "badge detected: Passing",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9d50d2d9ee58ebe0b0ea2fb1aeb9aa07f6346c19",
        "ran_at": "2026-07-21T20:38:00Z",
        "aggregate_score": 9.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cisco-open/forge",
    "host": "github.com",
    "name": "forge",
    "owner": "cisco-open"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 78,
      "inputs": {
        "security": 82,
        "vitality": 96,
        "community": 68,
        "governance": 55,
        "engineering": 92
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 96,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "commits_last_year": 354,
              "human_commit_share": 0.67,
              "days_since_last_push": 0,
              "active_weeks_last_year": 42
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "42/52 weeks with commits",
                "points": 29.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 42
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "354 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 354
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 55,
              "latest_release_tag": "v4.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "55 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 55
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 68,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 9,
              "stars": 210,
              "watchers": 3,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "210 stars",
                "points": 37.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 210
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "9 forks",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.994
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "merged_prs": 434,
              "open_issues": 7,
              "closed_issues": 14,
              "issue_closed_ratio": 0.667,
              "closed_unmerged_prs": 30
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "67% of issues closed",
                "points": 31.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 67
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "434/464 decided PRs merged",
                "points": 35.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 434,
                      "decided": 464
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "followers": 462,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "cisco-open",
              "public_repos": 120,
              "account_age_days": 1690
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "462 followers of cisco-open",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 462,
                      "login": "cisco-open"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "120 public repos, account ~4 yr old",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 120
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 92,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "16 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ci-cd",
                "devops",
                "github-actions",
                "self-hosted-runners",
                "terraform",
                "aws",
                "ephemeral",
                "kubernetes",
                "actions-runner-controller",
                "automation",
                "aws-eks",
                "devsecops",
                "ec2",
                "infrastructure-as-code",
                "multi-tenancy",
                "terragrunt",
                "iam",
                "oidc",
                "open-source",
                "platform-engineering"
              ],
              "has_wiki": false,
              "homepage": "https://cisco-open.github.io/forge/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://cisco-open.github.io/forge/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 82,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "excellent",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 93,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 9.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: Passing",
                "points": 1.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "at_risk",
            "name": "Dependency advisories",
            "note": "Matched the pypi:forge@0.22.0 runtime dependency closure — what installing the published package pulls in — 53 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "pypi:forge@0.22.0",
                  "assessed": 53
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "osv",
              "advisories": 13,
              "affected_packages": 4,
              "assessed_packages": 53,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 1, high 1, moderate 2",
              "direct_affected_packages": 3
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "3 affected: black 22.12.0 (critical 9.8), pytest 7.4.4 (moderate 6.8), python-dotenv 0.20.0 (moderate 6.6)",
                "points": 5.7,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 3,
                      "packages": "black 22.12.0 (critical 9.8), pytest 7.4.4 (moderate 6.8), python-dotenv 0.20.0 (moderate 6.6)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: gunicorn 20.1.0 (high 8.2)",
                "points": 8.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "gunicorn 20.1.0 (high 8.2)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "4 advisory-carrying package(s) unaddressed past 90 days; oldest published 854 days ago",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 4,
                      "oldest": 854
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 53,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 67,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "docs/operations/repo-blueprints/containers/containers/action-runner/Makefile",
                "docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile",
                "tests/smoke/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.17
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "docs/operations/repo-blueprints/containers/containers/action-runner/Makefile, docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile, tests/smoke/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/operations/repo-blueprints/containers/containers/action-runner/Makefile, docs/operations/repo-blueprints/containers/containers/pre-commit/Makefile, tests/smoke/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "17 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 17,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "HCL",
              "largest_source_bytes": 20524,
              "source_files_sampled": 69,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "HCL without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "HCL"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/69 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 69,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "pypi package 'forge' points at a different repository (https://github.com/forgepackages/forge); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T20:38:19.237949Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cisco-open/forge.svg",
  "full_name": "cisco-open/forge",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.23.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPyPI.